EBA欧洲银行-Guidelines-on-the-security-measures-under-PSD2-28EBA-GL-2017-1729_SK_16页_287kb
报告摘要
Summary of EBA/GL/2017/17: Compliance and Security Measures for Payment Services
Core Content
The document EBA/GL/2017/17 outlines guidelines for compliance with the regulatory requirements under Regulation (EU) No 1093/2010 and Directive (EU) 2015/2366 (PSD2). It focuses on security measures, risk management, incident response, and business continuity planning for payment service providers (PSPs).
Main Requirements
- Compliance Obligations: PSPs must inform the EBA whether they comply with the guidelines or intend to do so, or provide reasons for non-compliance by 12 March 2018. Failure to respond implies non-compliance.
- Reporting Obligations: PSPs must submit reports through the designated form to compliance@eba.europa.eu along with the reference EBA/GL/2017/17.
- Implementation Timeline: The guidelines apply from 13 January 2018.
Scope and Applicability
- The guidelines apply to payment service providers as defined in Article 4(11) of PSD2.
- They also apply to supervisory authorities under Article 4(2)(i) of Regulation (EU) No 1093/2010.
- The definitions provided in the document align with those in PSD2 and Regulation (EU) No 1093/2010.
Key Definitions
| Term | Definition |
|---|---|
| Supervisory Authority | In the context of payment service providers, this refers to the competent authority defined in Article 3(1)(7) of Directive 2013/36/EU for those that are authorized institutions. |
| Payment or Security Incident | An event or series of events that were not planned and may have or likely will have a negative impact on the integrity, availability, confidentiality, authenticity, and/or continuity of payment services. |
| Senior Management | In the context of payment service providers, this refers to individuals who perform executive functions and are accountable to the supervisory authority for the management of the provider. |
| Security Risk | A risk arising from inadequate internal procedures or external events that may have a negative impact on the integrity, availability, confidentiality, and/or continuity of payment services. This includes cyber attacks and insufficient physical security. |
General Principles
- All payment service providers should comply with the guidelines.
- The level of detail should be appropriate to the size, nature, scope, complexity, and risk profile of the specific payment services they provide.
Risk Management
Risk Framework
- PSPs must implement an effective risk management framework that is approved and reviewed at least once a year by the supervisory authority and senior management.
- The framework should:
- Include a comprehensive security policy document.
- Be aligned with the institution's ability and potential to take on risks.
- Define key roles and responsibilities.
- Include procedures and systems for identifying, measuring, monitoring, and managing risks.
Risk Assessment
- PSPs must conduct continuous risk assessments for their business functions, supporting processes, and information assets.
- They must classify these based on their critical nature.
- Risk assessments should be performed before significant changes to infrastructure, processes, or procedures that affect payment security.
Risk Treatment
- PSPs must ensure that their existing security measures are appropriate for the identified risks and that they are updated regularly.
- They must also ensure that their security controls are sufficient to address identified vulnerabilities and threats.
Security Measures
- Preventive Security Measures: PSPs must implement preventive security measures to protect against identified risks.
- Defense-in-Depth Approach: A multi-layered security strategy must be applied, including technical, procedural, and human controls.
- Access Control: Access to IKT systems must be granted only to authorized personnel, with access limited based on need-to-know principles.
- Incident Monitoring and Reporting: PSPs must establish procedures for the continuous monitoring and reporting of payment or security incidents, including user notifications and customer support.
Business Continuity
Business Continuity Management
- PSPs must establish reliable business continuity management to ensure the uninterrupted provision of payment services and minimize losses in case of disruption.
- They must analyze their exposure to critical disruptions and assess the potential impact using internal and external data and scenarios.
Continuity Plans
- PSPs must develop continuity plans to ensure a timely and appropriate response to emergencies.
- These plans should:
- Be based on risk assessments and identified scenarios.
- Be documented and accessible to relevant internal and external parties.
- Be updated regularly based on testing results, new risks, and changes in recovery objectives and priorities.
Testing of Continuity Plans
- Continuity plans must be tested at least once a year, with a focus on critical functions.
- Testing should include:
- A set of relevant scenarios.
- Procedures for verifying the ability of staff and processes to respond to these scenarios.
- Communication protocols for crisis situations.
Crisis Communication
- In the event of a disruption or emergency, PSPs must ensure that effective communication measures are in place to inform all relevant internal and external parties, including external service providers.
Security Testing
-
PSPs must implement a security testing framework to verify the stability and effectiveness of their security measures.
-
Testing should be conducted:
- As part of a formal change management process.
- By independent test personnel with the necessary expertise.
- At least once a year for critical systems, and every three years for non-critical systems.
-
Testing must include:
- Vulnerability assessments and penetration tests.
- Updates based on the results of testing.
Awareness and Training
-
PSPs must establish processes for identifying and monitoring security and operational risks.
-
They must analyze incidents and update their security measures accordingly.
-
They must monitor technological developments to stay informed about security risks.
-
Security Awareness Programs:
- Must be implemented for all employees.
- Should be conducted at least once a year, and more frequently if needed.
- Must include targeted training on information security for employees in key roles.
- Must ensure employees are aware of how to report anomalies and incidents.
User Awareness and Support
- PSPs must provide users with information about security risks and measures to mitigate them.
- Users must be informed of any changes to security procedures that affect them.
- Users must be provided with support and guidance for any questions, requests, or alerts related to security issues.
Conclusion
This document provides detailed guidance for payment service providers on compliance, security measures, risk management, incident response, and business continuity planning. It emphasizes the need for continuous monitoring, effective communication, and regular testing to ensure the integrity, confidentiality, and availability of payment services. The guidelines are aligned with the requirements of PSD2 and Regulation (EU) No 1093/2010, and apply to both PSPs and supervisory authorities.
试读结束,高清完整版pdf/doc/ppt,请点下载