EBA Consults on Guidelines on ICT and Security Risk Management
EBA launched a consultation on the draft guidelines on ICT and security risk management. These guidelines establish requirements for credit institutions, investment firms, and payment service providers (PSPs) on the mitigation and management of their information and communication technology (ICT) risks and aim to ensure a consistent and robust approach across the Single Market. The consultation runs until March 13, 2019.
The guidelines outline expectations in relation to governance, risk assessment process, information security requirements, ICT operational management, security in the change and development processes, and business continuity management to mitigate ICT and security risks. Due to an increasing reliance on ICT for their operational functioning, financial institutions are vulnerable to increased threats from internal and external attacks, including cyber-attacks, or breaches that may arise from inadequate business continuity planning for ICT systems and processes, or poor processes related to ICT change management. These guidelines aim to mitigate all ICT risks—whether internal or external—, including security-related risks, for all financial institutions.
The Guidelines are addressed to credit institutions and investment firms as defined in the Capital Requirements Directive (CRD), for all of their activities, and to PSPs subject to the revised Payment Services Directive (PSD2), for their payment services. These guidelines respond to EC's FinTech Action plan request for the EBA to develop guidelines on ICT risk management and mitigation requirements in the financial sector in EU. The guidelines on security measures for operational and security risks (EBA GL/2017/17) have been fully integrated in the EBA guidelines on ICT and security risk management and will be repealed when these proposed guidelines enter into force.
Related Links
Comment Due Date: March 13, 2019
Keywords: Europe, EU, Banking, PMI, Guidelines, Cyber Risk, ICT Risk, Regtech, CRD, PSD2, EBA
Previous Article
US Agencies Adopt Final Guidance for Resolution Plan SubmissionsRelated Articles
ESAs Publish Reporting Templates for Financial Conglomerates
ESAs published the final draft implementing technical standards on reporting of intra-group transactions and risk concentration of financial conglomerates subject to the supplementary supervision in EU.
EBA Publishes Report on Asset Encumbrance of Banks in EU
EBA published the annual report on asset encumbrance of banks in EU.
US Agencies Publish Updates for Call Reports, FFIEC 101, and FR Y-9C
FED updated the reporting form and instructions for the FR Y-9C report on consolidated financial statements for holding companies.
EBA Proposes Guidelines for Establishing Intermediate Parent Entities
EBA issued a consultation paper on the guidelines on monitoring of the threshold and other procedural aspects of the establishment of intermediate EU parent undertakings, or IPUs, as laid down in the Capital Requirements Directive.
EC Adopts Financial Reporting Changes Arising from Benchmark Reforms
EC published Regulation 2021/25 that addresses amendments related to the financial reporting consequences of replacement of the existing interest rate benchmarks with alternative reference rates.
BIS Bulletin Examines Key Elements of Policy Response to Cyber Risk
BIS published a bulletin, or a note, that examines the cyber threat landscape in the context of the pandemic and discusses policies to reduce risks to financial stability.
HMT Updates List of Post-Brexit Equivalence Decisions in UK
HM Treasury, also known as HMT, has updated the table containing the list of the equivalence decisions that came into effect in UK at the end of the transition period of its withdrawal from EU.
EBA Issues Erratum for Technical Package on Reporting Framework 3.0
EBA published an erratum for technical package on phase 1 of the reporting framework 3.0.
APRA Publishes FAQ on Measurement of Credit Risk Weighted Assets
APRA updated a frequently asked question (FAQ), for authorized deposit-taking institutions, on the measurement of credit risk weighted assets.
ECB Letter Sets Out Strategies to Address Issue of Nonperforming Loans
ECB published a letter from Andrea Enria, the Chair of the Supervisory Board of ECB, answering questions raised by the President of the Bundestag (the German federal parliament) on how ECB assesses the financial stability of the euro area in the context of the significant level of nonperforming loans.