CSSF published a circular (20/750) that implements the EBA guidelines on management of information and communication technology (ICT) and security risks. In this circular, CSSF explains that it has integrated the EBA guidelines into its administrative practice and its regulatory approach to promote the convergence of supervisory practices in this area at the European level. The circular specifies that content of the ICT guidelines also corresponds to the expectations of CSSF concerning the risk management measures and the control and security mechanisms, as mentioned in the Law, dated April 05, 1993, on the financial sector and the Law, dated November 10, 2009, on payment services. The circular came into force on the date of its publication—that is, August 25, 2020.
The annex to the circular provides the EBA guidelines on management of ICT and security risks. The guidelines set out expectations on the way in which all financial institutions should manage their internal and external ICT and security risks. The guidelines provide financial institutions with a better understanding of supervisory expectations for the management of these risks, covering sound internal governance, information security requirements, ICT operations, project and change management, and business continuity management.
Related Links (in French)
Effective Date: August 25, 2020
Keywords: Europe, Luxembourg, Banking, ICT Risk, Operational Risk, Proportionality, EBA, CSSF
Previous ArticleAPRA Proposes to Amend EFS Reporting Standards and Guidance
PRA proposed rules (in CP12/21) for the application of existing consolidated prudential requirements to financial holding companies and mixed financial holding companies that have been approved or designated in accordance with Part 12B of the Financial Services and Markets Act 2000 (FSMA).
ECB Banking Supervision announced that euro area banks it directly supervises may continue to exclude certain central bank exposures from the leverage ratio until March 2022.
OSFI decided to increase the Domestic Stability Buffer from 1.00% to 2.50% of total risk-weighted assets, with effect from October 31, 2021.
HKMA is requesting banks to participate in a tech baseline assessment, which forms part of the HKMA Fintech 2025 strategy.
OSFI published two documents to consult on the management of operational risk capital data for institutions required, or for those applying, to use the Basel III standardized approach for operational risk capital in Canada.
The NGFS Study Group on Biodiversity and Financial Stability published a Vision paper exploring the case for action in addressing the financial stability concerns arising from biodiversity loss.
ACPR published the final version of CREDITIMMO 2.3.0 taxonomy for the decree of October 31, 2021.
EC, has approved, under the EU State Aid rules, the fourth prolongation of the Italian guarantee scheme to facilitate the securitization of non-performing loans.
ECB published Guideline 2021/975, which amends Guideline ECB/2014/31, on the additional temporary measures relating to Eurosystem refinancing operations and eligibility of collateral.
EIOPA published a report, from the Consultative Expert Group on Digital Ethics, that sets out artificial intelligence governance principles for an ethical and trustworthy artificial intelligence in the insurance sector in EU.