EBA欧洲银行-Guidelines-on-the-security-measures-under-PSD2-28EBA-GL-2017-1729_DA_15页_246kb
报告摘要
Summary of EBA/GL/2017/17 Guidelines on Security Measures for Payment Services under PSD2
1. Compliance and Reporting Obligations
- Status: The guidelines are issued under Article 16 of Regulation (EU) No 1093/2010. Competent authorities and financial institutions are required to implement them as best as possible.
- Reporting Requirements: Competent authorities must report to EBA by 12.03.2018 whether they have implemented or intend to implement the guidelines. Reports should be submitted using a specified form available on EBA's website to compliance@eba.europa.eu with reference "EBA/GL/2017/17".
- Implementation: Any changes in the status of compliance must be communicated to EBA. The guidelines are effective from 13.01.2018.
2. Scope and Definitions
2.1 Subject and Scope
- These guidelines are based on EBA's mandate under Article 95(3) of Directive (EU) 2015/2366 (PSD2).
- They apply to payment service providers (PSPs) and competent authorities as defined in Article 4 of Regulation (EU) 1093/2010.
2.2 Definitions
- Board of Directors: For credit institutions, it refers to the definition in Article 3(1)(7) of Directive 2013/36/EU. For payment institutions and e-money institutions, it refers to those responsible for the management of payment services.
- Operational and Security Incident: A single or series of related events that may have a negative impact on the integrity, availability, confidentiality, authenticity, or continuity of payment services.
- Risk Appetite: The level and types of risks an institution is willing to accept in order to achieve its strategic objectives within its risk capacity and business model.
- Operational and Security Risk: Risks arising from inadequate internal processes or external events that may affect the availability, integrity, or confidentiality of IT systems and information used in payment services.
3. Implementation
- Framework for Risk Management: PSPs must establish an effective risk management framework, which should be approved and reviewed at least annually by the board and, if relevant, by senior management.
- Security Policies: Must include a comprehensive security policy document.
- Roles and Responsibilities: Defined roles and responsibilities for reporting and managing risks.
- Procedures and Systems: Establish procedures and systems to identify, assess, monitor, and manage risks related to payment services.
4. Security Measures
4.1 General Security Principles
- PSPs must implement preventive security measures to address identified operational and security risks.
- These measures must ensure an adequate security level in line with the identified risks.
4.2 Defense-in-Depth Approach
- A multi-layered defense approach should be adopted, including firewalls, network segmentation, and access controls.
- This approach ensures that multiple controls are in place to protect against risks.
4.3 Protection of Data and Systems
- PSPs must ensure the confidentiality, integrity, and availability of their critical IT systems and payment data.
- If data contains personal information, it must comply with Regulation (EU) 2016/679 (GDPR) and, if relevant, Regulation (EC) No 45/2001.
4.4 Access Control
- Physical and logical access to IT systems must be restricted to authorized personnel.
- Access rights should be based on "need-to-know" principles and regularly reviewed.
- Access logs must be retained for a period consistent with the identified business functions and risks.
4.5 Security Monitoring
- PSPs must implement continuous monitoring to detect irregular activities and security threats.
- Monitoring should include transaction analysis, identification of potential threats, and regular testing of security measures.
4.6 Incident Response
- PSPs must classify incidents and establish procedures for reporting and handling them.
- They should report incidents to senior management and maintain a procedure for handling security-related customer complaints.
5. Business Continuity
- Business Continuity Plan: PSPs must develop and maintain a business continuity plan to ensure the continued operation of payment services and minimize disruption.
- Risk-Based Approach: Plans should prioritize critical functions and systems based on risk assessments.
- Testing Requirements: Business continuity plans must be tested at least annually and updated based on test results, new threats, and changes in risk appetite.
- Crisis Communication: Effective crisis communication mechanisms must be in place to inform relevant internal and external stakeholders in case of disruptions.
6. Testing of Security Measures
- Security Testing Framework: PSPs must establish a testing framework to ensure the robustness and effectiveness of security measures.
- Independent Testing: Testing should be conducted by independent testers with expertise in IT security and not involved in the development of the security measures.
- Regular Testing: Critical systems must be tested at least annually, while non-critical systems must be tested at least every three years.
- Test Scope: Includes vulnerability scanning, penetration testing, and scenario-based testing.
7. Awareness and Learning
- Threat Landscape Monitoring: PSPs must monitor and respond to security and operational threats continuously.
- Security Awareness Programs: Regular and targeted training programs must be implemented for all employees, especially those in key roles.
- Reporting Irregularities: Employees must be trained to report any unusual activities or incidents related to payment services.
8. Handling Relationships with Payment Service Users
- User Awareness: PSPs must provide guidance and support to users to enhance their awareness of security risks and risk mitigation measures.
- Customization of Limits: Users must be allowed to adjust transaction limits up to the agreed maximum.
- Alerts and Notifications: Users must be notified of failed or attempted transactions to detect fraudulent or harmful use of their accounts.
- Communication of Changes: Users must be kept informed of changes to security procedures that affect them.
展开完整摘要
试读结束,高清完整版pdf/doc/ppt,请点下载