Featured Product

    EBA Consults on Guidelines on ICT and Security Risk Management

    December 13, 2018

    EBA launched a consultation on the draft guidelines on ICT and security risk management. These guidelines establish requirements for credit institutions, investment firms, and payment service providers (PSPs) on the mitigation and management of their information and communication technology (ICT) risks and aim to ensure a consistent and robust approach across the Single Market. The consultation runs until March 13, 2019.

    The guidelines outline expectations in relation to governance, risk assessment process, information security requirements, ICT operational management, security in the change and development processes, and business continuity management to mitigate ICT and security risks. Due to an increasing reliance on ICT for their operational functioning, financial institutions are vulnerable to increased threats from internal and external attacks, including cyber-attacks, or breaches that may arise from inadequate business continuity planning for ICT systems and processes, or poor processes related to ICT change management. These guidelines aim to mitigate all ICT risks—whether internal or external—, including security-related risks, for all financial institutions. 

    The Guidelines are addressed to credit institutions and investment firms as defined in the Capital Requirements Directive (CRD), for all of their activities, and to PSPs subject to the revised Payment Services Directive (PSD2), for their payment services. These guidelines respond to EC's FinTech Action plan request for the EBA to develop guidelines on ICT risk management and mitigation requirements in the financial sector in EU. The guidelines on security measures for operational and security risks (EBA GL/2017/17) have been fully integrated in the EBA guidelines on ICT and security risk management and will be repealed when these proposed guidelines enter into force.

     

    Related Links

    Comment Due Date: March 13, 2019

    Keywords: Europe, EU, Banking, PMI, Guidelines, Cyber Risk, ICT Risk, Regtech, CRD, PSD2, EBA

    Related Articles
    News

    PRA Consults on Implementation of Certain Provisions of CRD5

    PRA, via the consultation paper CP12/20, proposed changes to its rules, supervisory statements, and statements of policy to implement certain elements of the Capital Requirements Directive (CRD5).

    July 31, 2020 WebPage Regulatory News
    News

    EIOPA Report Identifies Key Financial Stability Risks for Insurers

    EIOPA published the financial stability report that provides detailed quantitative and qualitative assessment of the key risks identified for the insurance and occupational pensions sectors in the European Economic Area.

    July 30, 2020 WebPage Regulatory News
    News

    EBA Publishes Risk Dashboard for First Quarter of 2020

    EBA published its risk dashboard for the first quarter of 2020 together with the results of the risk assessment questionnaire.

    July 30, 2020 WebPage Regulatory News
    News

    EBA Issues Updates on Stress Test Exercise for Banks in EU

    EBA announced that the next stress testing exercise is expected to be launched at the end of January 2021 and its results are to be published at the end of July 2021.

    July 30, 2020 WebPage Regulatory News
    News

    PRA Proposes Guidance Related to Matching Adjustment under Solvency II

    PRA published the consultation paper CP11/20 that sets out its expectations and guidance related to auditors’ work on the matching adjustment under Solvency II.

    July 30, 2020 WebPage Regulatory News
    News

    MAS Issues Guidance on Dividend Distributions by Banks

    MAS published a statement guidance on dividend distribution by banks.

    July 30, 2020 WebPage Regulatory News
    News

    APRA Updates Guidance on Capital Management for Banks

    APRA updated its capital management guidance for banks, particularly easing restrictions around paying dividends as institutions continue to manage the disruption caused by COVID-19 pandemic.

    July 29, 2020 WebPage Regulatory News
    News

    FSB Report Reviews Macro-Prudential Framework and Tools in Germany

    FSB published a report that reviews the progress on data collection for macro-prudential analysis and the availability and use of macro-prudential tools in Germany.

    July 29, 2020 WebPage Regulatory News
    News

    EBA Urges Firms to Finalize Preparations for End of Brexit Transition

    EBA issued a statement reminding financial institutions that the transition period between EU and UK will expire on December 31, 2020; this will end the possibility for the UK-based financial institutions to offer financial services to EU customers on a cross-border basis via passporting.

    July 29, 2020 WebPage Regulatory News
    News

    SRB on Operational Continuity in Resolution and FMI Contingency Plans

    SRB published guidance on operational continuity in resolution and financial market infrastructure (FMI) contingency plans.

    July 29, 2020 WebPage Regulatory News
    RESULTS 1 - 10 OF 5606