Featured Product

    EC Statement on Cybersecurity Act and Certification Rules in EU

    June 26, 2019

    The European Cybersecurity Act is entering into force on June 27, 2019, thus setting the new mandate of ENISA, which is the EU Agency for Cybersecurity, and establishing the European cybersecurity certification framework. The European cybersecurity certification framework, the first of its kind, establishes the governance and rules for EU-wide certification of information communications technology (ICT) products, processes, and services.

    The EU Cybersecurity Act gives ENISA, the EU Agency for Cybersecurity, more tasks and resources to assist EU member states in dealing with cyber-attacks. ENISA will improve the cybersecurity preparedness and resilience in EU, contributing to better information-sharing between EU member states through the network of Computer Security Incident Response Teams (CSIRTs) and by organizing regular pan-European cybersecurity exercises. 

    Additionally, the Cybersecurity Act introduces for the first time EU-wide rules for cybersecurity certification. Companies in EU will benefit from having to certify their products, processes, and services only once and see their certificates recognized across EU. Under the framework, multiple schemes will be created for different categories of ICT products, processes, and services. Each scheme will specify, among  others, the type or categories of ICT products, services and processes covered, the purpose, the security standards that shall be met, and the evaluation methods.  The schemes will also indicate the period of validity for the certificates issued. ENISA, on request from EC or the European Cybersecurity Certification Group (composed by member states), will prepare the certification schemes that will then be adopted by EC through implementing acts. 

    Regarding the certification framework, EC will prepare the first requests for ENISA to develop certification schemes and set-up the governance structure with the establishment of the relevant expert groups:

    • The European Cybersecurity Certification Group, comprising representatives from member states that will have to appoint the representatives from their competent authorities 
    • The Stakeholder Cybersecurity Certification Group, which will be responsible to advise ENISA and EC

     

    Related Links

    Keywords: Europe, EU, Banking, Insurance, Securities, Cybersecurity Act, ENISA, Cyber Risk, Cybersecurity Certification, Cyber Resilience, EC

    Related Articles
    News

    APRA Revises Standard on Margin Rules for Uncleared Derivatives

    APRA revised CPS 226, which is the prudential standard on margin and risk mitigation requirements for non-centrally cleared derivatives.

    September 19, 2019 WebPage Regulatory News
    News

    SEC Adopts Rules and Amendments Under Regulatory Regime for Swaps

    SEC announced that it took a significant step toward establishing the regulatory regime for security-based swap dealers (SBSDs) by adopting a package of rules and rule amendments under Title VII of the Dodd-Frank Act.

    September 19, 2019 WebPage Regulatory News
    News

    PRA Issues Consultation on Prudent Person Principle Under Solvency II

    PRA, via the consultation paper CP22/19, has set out its proposed expectations for investment by firms, in accordance with the Prudent Person Principle (PPP).

    September 18, 2019 WebPage Regulatory News
    News

    PRA Proposal on Probability of Default and LGD Estimation

    PRA proposed, via the consultation paper CP21/19, an approach to implementing EBA’s recent regulatory products relating to Probability of Default (PD) estimation, Loss Given Default (LGD) estimation, and the treatment of defaulted exposures in the internal ratings-based (IRB) approach to credit risk.

    September 18, 2019 WebPage Regulatory News
    News

    BIS Formalizes Agreement to Set Up Innovation Hub in Hong Kong SAR

    BIS and HKMA signed the Operational Agreement on the BIS Innovation Hub Center in Hong Kong Special Administrative Region (SAR).

    September 18, 2019 WebPage Regulatory News
    News

    APRA Observations from Thematic Review on Recovery Plans of Insurers

    APRA issued a letter to general insurers and life insurers, outlining observations from a recent thematic review on recovery planning by insurers.

    September 18, 2019 WebPage Regulatory News
    News

    BNM Publishes Financial Stability Review for the First Half of 2019

    BNM published Financial Stability Review for the first half of 2019.

    September 18, 2019 WebPage Regulatory News
    News

    CFTC Extends Comment Period for Proposals on Cross-Border Clearing

    CFTC announced that it is extending, until November 18, 2019, the comment period for the proposal for an alternative compliance framework for derivatives clearing organizations (DCOs) that are organized outside of U.S. and that do not pose substantial risk to the U.S. financial system.

    September 18, 2019 WebPage Regulatory News
    News

    FASB Issues Summary of Tentative Board Decisions at September Meeting

    FASB published a summary of the tentative decisions taken at its Board meeting in September 2019.

    September 18, 2019 WebPage Regulatory News
    News

    EIOPA Forms Consultative Expert Group on Digital Ethics in Insurance

    EIOPA established the Consultative Expert Group on Digital Ethics in Insurance to assist EIOPA in the development of digital responsibility principles in insurance.

    September 17, 2019 WebPage Regulatory News
    RESULTS 1 - 10 OF 3848