General Information & Client Service
  • Americas: +1.212.553.1653
  • Asia: +852.3551.3077
  • China: +86.10.6319.6580
  • EMEA: +44.20.7772.5454
  • Japan: +81.3.5408.4100
Media Relations
  • New York: +1.212.553.0376
  • London: +44.20.7772.5456
  • Hong Kong: +852.3758.1350
  • Tokyo: +813.5408.4110
  • Sydney: +61.2.9270.8141
  • Mexico City: +001.888.779.5833
  • Buenos Aires: +0800.666.3506
  • São Paulo: +0800.891.2518
December 13, 2018

EBA launched a consultation on the draft guidelines on ICT and security risk management. These guidelines establish requirements for credit institutions, investment firms, and payment service providers (PSPs) on the mitigation and management of their information and communication technology (ICT) risks and aim to ensure a consistent and robust approach across the Single Market. The consultation runs until March 13, 2019.

The guidelines outline expectations in relation to governance, risk assessment process, information security requirements, ICT operational management, security in the change and development processes, and business continuity management to mitigate ICT and security risks. Due to an increasing reliance on ICT for their operational functioning, financial institutions are vulnerable to increased threats from internal and external attacks, including cyber-attacks, or breaches that may arise from inadequate business continuity planning for ICT systems and processes, or poor processes related to ICT change management. These guidelines aim to mitigate all ICT risks—whether internal or external—, including security-related risks, for all financial institutions. 

The Guidelines are addressed to credit institutions and investment firms as defined in the Capital Requirements Directive (CRD), for all of their activities, and to PSPs subject to the revised Payment Services Directive (PSD2), for their payment services. These guidelines respond to EC's FinTech Action plan request for the EBA to develop guidelines on ICT risk management and mitigation requirements in the financial sector in EU. The guidelines on security measures for operational and security risks (EBA GL/2017/17) have been fully integrated in the EBA guidelines on ICT and security risk management and will be repealed when these proposed guidelines enter into force.

 

Related Links

Comment Due Date: March 13, 2019

Keywords: Europe, EU, Banking, PMI, Guidelines, Cyber Risk, ICT Risk, Regtech, CRD, PSD2, EBA

Related Articles
News

HKMA Decides to Maintain Countercyclical Capital Buffer at 2.5%

HKMA announced that, in accordance with the Banking (Capital) Rules, the countercyclical capital buffer (CCyB) ratio for Hong Kong remains at 2.5%.

April 16, 2019 WebPage Regulatory News
News

EP Approves Agreement on Package of CRD 5, CRR 2, BRRD 2, and SRMR 2

The European Parliament (EP) approved the final agreement on a package of reforms proposed by EC to strengthen the resilience and resolvability of European banks.

April 16, 2019 WebPage Regulatory News
News

FDIC Consults on Approach to Resolution Planning for IDIs

FDIC approved an Advance Notice of Proposed Rulemaking (ANPR) and is seeking comment on ways to tailor and improve its rule requiring certain insured depository institutions (IDIs) to submit resolution plans.

April 16, 2019 WebPage Regulatory News
News

EP Resolution on Proposal for Sovereign Bond Backed Securities

The European Parliament (EP) published adopted text on the proposal for a regulation of the European Parliament and of the Council on sovereign bond-backed securities (SBBS).

April 16, 2019 WebPage Regulatory News
News

PRA Seeks Input and Issues Specifications for Insurance Stress Tests

PRA announced that it will conduct an insurance stress test for the largest regulated life and general insurers from July to September 2019.

April 15, 2019 WebPage Regulatory News
News

PRA Finalizes Policy on Approach to Managing Climate Change Risks

PRA published the policy statement PS11/19, which contains final supervisory statement (SS3/19) on enhancing banks’ and insurers’ approaches to managing the financial risks from climate change (Appendix).

April 15, 2019 WebPage Regulatory News
News

EBA Single Rulebook Q&A: First Update for April 2019

EBA published answers to nine questions under the Single Rulebook question and answer (Q&A) updates for this week.

April 12, 2019 WebPage Regulatory News
News

EIOPA Statement on Application of Proportionality in SCR Supervision

EIOPA published a supervisory statement on the application of proportionality principle in the supervision of the Solvency Capital Requirement (SCR) calculated in accordance with the standard formula.

April 11, 2019 WebPage Regulatory News
News

FED Updates Form and Supplemental Instructions for FR Y-9C Reporting

FED updated the form and supplemental instructions for FR Y-9C reporting. FR Y-9C is used to collect data from domestic bank holding companies, savings and loan holding companies, U.S intermediate holding companies, and securities holding companies with total consolidated assets of USD 3 billion or more.

April 11, 2019 WebPage Regulatory News
News

OSFI Finalizes Guidelines on Liquidity Adequacy and NSFR Disclosures

OSFI published the final Liquidity Adequacy Requirements (LAR) guideline and the net stable funding ratio (NSFR) disclosure requirements guideline.

April 11, 2019 WebPage Regulatory News
RESULTS 1 - 10 OF 2920