General Information & Client Services
  • Americas: +1.212.553.1653
  • Asia: +852.3551.3077
  • China: +86.10.6319.6580
  • EMEA: +44.20.7772.5454
  • Japan: +81.3.5408.4100
Media Relations
  • New York: +1.212.553.0376
  • London: +44.20.7772.5456
  • Hong Kong: +852.3758.1350
  • Tokyo: +813.5408.4110
  • Sydney: +61.2.9270.8141
  • Mexico City: +001.888.779.5833
  • Buenos Aires: +0800.666.3506
  • São Paulo: +0800.891.2518
August 07, 2018

ECB published the Services Procurement Guidelines, which are referred to in, and are an integral part of, the Threat Intelligence-Based Ethical Red Teaming (TIBER-EU) framework. The guidelines set out in detail the different elements of TIBER-EU procurement. TIBER-EU framework enables European and national authorities to work with financial infrastructures and institutions to put in place a program to test and improve their resilience against sophisticated cyber attacks. Due to the sensitive nature of TIBER-EU tests, entities need to carefully select threat intelligence and red teaming providers that can provide an appropriate level of professional expertise and support for conducting the test.

The first part of the document sets out the requirements and standards that must be met by threat intelligence providers to deliver recognized TIBER-EU tests and offers guiding principles and selection criteria for entities, as they look to procure services from prospective providers. Then, the document sets out the requirements and standards that must be met by red teaming providers to deliver recognized TIBER-EU tests and offer guiding principles and selection criteria for entities, as they look to procure services from prospective providers. Next, it provides guidance to authorities that are looking to implement TIBER-EU at the national and European levels, with regard to procurement. Annex 1 provides a list of certifications that staff members and providers may be, depending on the case, required to possess. Annexes 2-5 provide questions that entities could use when considering prospective providers and agreement checklists to assist the procurement functions during their procurement process.

The guidelines are directed at authorities responsible for the adoption, implementation, and management of the TIBER-EU Framework at national and European levels; entities looking to undertake TIBER-EU tests; organizations interested in providing cyber threat intelligence services under TIBER-EU; organizations interested in providing red team testing services under TIBER-EU; and accreditation and certification providers. As the TIBER-EU Framework is implemented across EU, the TIBER-EU Knowledge Center (TKC) will monitor the evolution of the threat intelligence and red team testing market and update the requirements, if necessary. TKC will undertake this task by closely liaising with the authorities that adopt the TIBER-EU Framework, the entities that undertake the tests, and the threat intelligence/red teaming providers that deliver the tests.

 

Related Link: Guidelines (PDF)

Keywords: Europe, EU, Banking, Insurance, Securities, PMI, Cyber Risk, TIBER-EU, Cyber Resilience, Procurement Services Guidelines, ECB

Related Insights
News

EBA Single Rulebook Q&A: First Update for November 2018

EBA published answers to seven questions under the Single Rulebook question and answer (Q&A) updates for this week.

November 09, 2018 WebPage Regulatory News
News

FED Finalizes the Large Financial Institution Rating System

FED finalized the new supervisory rating system for Large Financial Institutions (LFIs), to better align with the current supervisory programs and practices for these firms.

November 09, 2018 WebPage Regulatory News
News

ECB Publishes Guides for Capital and Liquidity Management by Banks

ECB published the guides for capital and liquidity management by banks in EU.

November 09, 2018 WebPage Regulatory News
News

EC Amends Regulation on Prudent Valuation for Supervisory Reporting

EC published the amended Implementing Regulation (EU) 2018/1627 on prudent valuation for supervisory reporting. Regulation 2018/1627 amends the Implementing Regulation 680/2014.

November 09, 2018 WebPage Regulatory News
News

FED Intends to Publish the Financial Stability Report in November 2018

FED intends to begin publishing a semiannual report presenting its view of the outlook for U.S. financial stability, on November 28. The financial stability report will include a summary of the FED framework for assessing the resilience of the financial system in the United States.

November 09, 2018 WebPage Regulatory News
News

ESMA Asks Clients of CRAs and TRs to Prepare for No-Deal Brexit

ESMA issued a public statement to raise awareness, among the market participants, on the readiness of credit rating agencies (CRAs) and trade repositories (TRs) for the possibility of no agreement being reached in the context of the United Kingdom withdrawing from the European Union (Brexit).

November 09, 2018 WebPage Regulatory News
News

EIOPA Publishes Result of the Work of EU-US Insurance Dialog Project

EIOPA published four papers resulting from the work of the EU–U.S. Insurance Dialog Project (EU-U.S. Project) in 2018.

November 08, 2018 WebPage Regulatory News
News

EIOPA Publishes Q&A on Regulations in November 2018

EIOPA published new sets of questions and answers (Q&A) on implementing and delegated regulations applicable to insurers in Europe.

November 07, 2018 WebPage Regulatory News
News

APRA Finalizes CPS 234 to Help Combat Threat of Cyber Attacks

APRA has released the final version of its prudential standard focused on information security management.

November 07, 2018 WebPage Regulatory News
News

US Agencies Propose Reduced Reporting for Qualifying Institutions

US agencies (FDIC, FED, and OCC) proposed to reduce regulatory reporting burden on small institutions by expanding the number of regulated institutions eligible for streamlined reporting.

November 07, 2018 WebPage Regulatory News
RESULTS 1 - 10 OF 2192