Featured Product

    EBA Consults on Guidelines on ICT and Security Risk Management

    December 13, 2018

    EBA launched a consultation on the draft guidelines on ICT and security risk management. These guidelines establish requirements for credit institutions, investment firms, and payment service providers (PSPs) on the mitigation and management of their information and communication technology (ICT) risks and aim to ensure a consistent and robust approach across the Single Market. The consultation runs until March 13, 2019.

    The guidelines outline expectations in relation to governance, risk assessment process, information security requirements, ICT operational management, security in the change and development processes, and business continuity management to mitigate ICT and security risks. Due to an increasing reliance on ICT for their operational functioning, financial institutions are vulnerable to increased threats from internal and external attacks, including cyber-attacks, or breaches that may arise from inadequate business continuity planning for ICT systems and processes, or poor processes related to ICT change management. These guidelines aim to mitigate all ICT risks—whether internal or external—, including security-related risks, for all financial institutions. 

    The Guidelines are addressed to credit institutions and investment firms as defined in the Capital Requirements Directive (CRD), for all of their activities, and to PSPs subject to the revised Payment Services Directive (PSD2), for their payment services. These guidelines respond to EC's FinTech Action plan request for the EBA to develop guidelines on ICT risk management and mitigation requirements in the financial sector in EU. The guidelines on security measures for operational and security risks (EBA GL/2017/17) have been fully integrated in the EBA guidelines on ICT and security risk management and will be repealed when these proposed guidelines enter into force.

     

    Related Links

    Comment Due Date: March 13, 2019

    Keywords: Europe, EU, Banking, PMI, Guidelines, Cyber Risk, ICT Risk, Regtech, CRD, PSD2, EBA

    Related Articles
    News

    APRA Revises Standard on Margin Rules for Uncleared Derivatives

    APRA revised CPS 226, which is the prudential standard on margin and risk mitigation requirements for non-centrally cleared derivatives.

    September 19, 2019 WebPage Regulatory News
    News

    SEC Adopts Rules and Amendments Under Regulatory Regime for Swaps

    SEC announced that it took a significant step toward establishing the regulatory regime for security-based swap dealers (SBSDs) by adopting a package of rules and rule amendments under Title VII of the Dodd-Frank Act.

    September 19, 2019 WebPage Regulatory News
    News

    PRA Issues Consultation on Prudent Person Principle Under Solvency II

    PRA, via the consultation paper CP22/19, has set out its proposed expectations for investment by firms, in accordance with the Prudent Person Principle (PPP).

    September 18, 2019 WebPage Regulatory News
    News

    PRA Proposal on Probability of Default and LGD Estimation

    PRA proposed, via the consultation paper CP21/19, an approach to implementing EBA’s recent regulatory products relating to Probability of Default (PD) estimation, Loss Given Default (LGD) estimation, and the treatment of defaulted exposures in the internal ratings-based (IRB) approach to credit risk.

    September 18, 2019 WebPage Regulatory News
    News

    BIS Formalizes Agreement to Set Up Innovation Hub in Hong Kong SAR

    BIS and HKMA signed the Operational Agreement on the BIS Innovation Hub Center in Hong Kong Special Administrative Region (SAR).

    September 18, 2019 WebPage Regulatory News
    News

    APRA Observations from Thematic Review on Recovery Plans of Insurers

    APRA issued a letter to general insurers and life insurers, outlining observations from a recent thematic review on recovery planning by insurers.

    September 18, 2019 WebPage Regulatory News
    News

    BNM Publishes Financial Stability Review for the First Half of 2019

    BNM published Financial Stability Review for the first half of 2019.

    September 18, 2019 WebPage Regulatory News
    News

    CFTC Extends Comment Period for Proposals on Cross-Border Clearing

    CFTC announced that it is extending, until November 18, 2019, the comment period for the proposal for an alternative compliance framework for derivatives clearing organizations (DCOs) that are organized outside of U.S. and that do not pose substantial risk to the U.S. financial system.

    September 18, 2019 WebPage Regulatory News
    News

    FASB Issues Summary of Tentative Board Decisions at September Meeting

    FASB published a summary of the tentative decisions taken at its Board meeting in September 2019.

    September 18, 2019 WebPage Regulatory News
    News

    EIOPA Forms Consultative Expert Group on Digital Ethics in Insurance

    EIOPA established the Consultative Expert Group on Digital Ethics in Insurance to assist EIOPA in the development of digital responsibility principles in insurance.

    September 17, 2019 WebPage Regulatory News
    RESULTS 1 - 10 OF 3848