Featured Product

    EBA Consults on Guidelines on ICT and Security Risk Management

    December 13, 2018

    EBA launched a consultation on the draft guidelines on ICT and security risk management. These guidelines establish requirements for credit institutions, investment firms, and payment service providers (PSPs) on the mitigation and management of their information and communication technology (ICT) risks and aim to ensure a consistent and robust approach across the Single Market. The consultation runs until March 13, 2019.

    The guidelines outline expectations in relation to governance, risk assessment process, information security requirements, ICT operational management, security in the change and development processes, and business continuity management to mitigate ICT and security risks. Due to an increasing reliance on ICT for their operational functioning, financial institutions are vulnerable to increased threats from internal and external attacks, including cyber-attacks, or breaches that may arise from inadequate business continuity planning for ICT systems and processes, or poor processes related to ICT change management. These guidelines aim to mitigate all ICT risks—whether internal or external—, including security-related risks, for all financial institutions. 

    The Guidelines are addressed to credit institutions and investment firms as defined in the Capital Requirements Directive (CRD), for all of their activities, and to PSPs subject to the revised Payment Services Directive (PSD2), for their payment services. These guidelines respond to EC's FinTech Action plan request for the EBA to develop guidelines on ICT risk management and mitigation requirements in the financial sector in EU. The guidelines on security measures for operational and security risks (EBA GL/2017/17) have been fully integrated in the EBA guidelines on ICT and security risk management and will be repealed when these proposed guidelines enter into force.

     

    Related Links

    Comment Due Date: March 13, 2019

    Keywords: Europe, EU, Banking, PMI, Guidelines, Cyber Risk, ICT Risk, Regtech, CRD, PSD2, EBA

    Related Articles
    News

    BCBS Amends Guidelines on Sound Management of AML/CFT Risks

    BCBS amended the guidelines on sound management of risks related to money laundering and financing of terrorism (ML/FT).

    July 02, 2020 WebPage Regulatory News
    News

    US Agencies Finalize Amendments to Swap Margin Rule

    US Agencies (Farm Credit Administration, FDIC, FED, FHFA, and OCC) finalized changes to the swap margin rule to facilitate implementation of prudent risk management strategies at banks and other entities with significant swap activities.

    July 01, 2020 WebPage Regulatory News
    News

    PRA Letter Sets Expectations on Approach to Managing Climate Risks

    PRA published a letter that builds on the expectations set out in the supervisory statement (SS3/19) on enhancing banks' and insurers' approaches to managing the financial risks from climate change.

    July 01, 2020 WebPage Regulatory News
    News

    EBA Guidelines on Treatment of Structural Foreign Exchange Under CRR

    EBA finalized the guidelines on treatment of structural foreign-exchange (FX) positions under Article 352(2) of the Capital Requirements Regulation (CRR).

    July 01, 2020 WebPage Regulatory News
    News

    FSB Issues Statement on Impact of COVID-19 Crisis on Benchmark Reform

    FSB published a statement on the impact of COVID-19 pandemic on global benchmark transition.

    July 01, 2020 WebPage Regulatory News
    News

    IAIS Publishes List of Internationally Active Insurance Groups

    IAIS published the list of Internationally Active Insurance Groups (IAIGs) publicly disclosed by group-wide supervisors.

    July 01, 2020 WebPage Regulatory News
    News

    FED Temporarily Revises FR Y-9C With Respect to PPPLF and CARES Act

    FED has temporarily revised the reporting form on consolidated financial statements for holding companies (FR Y-9C; OMB No. 7100-0128).

    July 01, 2020 WebPage Regulatory News
    News

    EC Launches Consultation on Review of Solvency II Directive

    EC launched a consultation on the review of the key elements of Solvency II Directive, with the comment period ending on October 21, 2020.

    July 01, 2020 WebPage Regulatory News
    News

    ECB Consults on Supervisory Approach to Consolidation in Banking

    ECB launched a consultation on the guide that sets out supervisory approach to consolidation projects in the banking sector.

    July 01, 2020 WebPage Regulatory News
    News

    IAIS on Package for 2020 Data Collection on ICS and Aggregation Method

    IAIS published technical specifications, questionnaires, and templates for 2020 Insurance Capital Standard (ICS) and Aggregation Method data collections.

    June 30, 2020 WebPage Regulatory News
    RESULTS 1 - 10 OF 5425