EBA欧洲银行-2017-06-20-28Public-hearing-on-EBA-Recommendations-on-Cloud-Outsourcing29_13页_1mb
报告摘要
EBA Recommendations on Outsourcing to Cloud Service Providers Summary
Core Content
The European Banking Authority (EBA) published recommendations on outsourcing to cloud service providers in June 2017. These recommendations aim to provide specific guidance to credit institutions on the use of cloud services, building upon the existing general outsourcing guidelines introduced in 2006. The goal is to harmonise supervisory expectations across the EU and ensure that institutions can benefit from cloud computing while managing the associated risks effectively.
Main Objectives
- To offer more detailed guidance on cloud outsourcing beyond the general outsourcing guidelines.
- To promote a common EU-wide approach to the use of cloud services by financial institutions.
- To harmonise supervisory expectations across the EU for institutions adopting cloud computing.
- To ensure that institutions can leverage the benefits of cloud services while adequately identifying and managing related risks.
Link with General Outsourcing Guidelines
- The recommendations clarify and explain how to apply the existing general outsourcing guidelines in the specific context of cloud outsourcing.
- They should be read in parallel with the general guidelines.
- They address the unique risks and characteristics of cloud outsourcing, such as data security, governance, and concentration risk.
- They bridge the gap until the finalisation of the planned review of the general outsourcing guidelines.
Outline of the Draft Recommendations
The draft recommendations cover the following key areas:
-
Materiality Assessment
- Determine which activities are critical to business continuity and regulatory compliance.
- Consider the impact of disruptions on revenue, legal, and reputational aspects.
-
Duty to Adequately Inform Supervisors
- Institutions must ensure transparency with supervisors regarding their cloud outsourcing arrangements.
-
Access and Audit Rights
- Access rights must be contractually ensured for both the institution and the competent authority.
- Full access to business premises, devices, systems, and data is required.
- Audit rights should be exercised in a risk-based manner, possibly through pooled audits, third-party certifications, or audit reports.
-
Security of Data and Systems
- Conduct a risk-based assessment to identify and classify sensitive data and systems.
- Define appropriate levels of protection for data confidentiality, integrity, and traceability.
- Implement specific security measures such as encryption and key management.
-
Location of Data and Data Processing
- Consider the geographical location of data and processing activities, especially in relation to data protection and regulatory compliance.
-
Chain Outsourcing
- Institutions must assess risks associated with multiple layers of outsourcing.
- The cloud service provider retains full responsibility for subcontracted services.
- Institutions should monitor the overall service performance and ensure prior notification of significant changes in subcontracting.
-
Contingency Plans and Exit Strategies
- Develop contingency plans to ensure business continuity in case of service failure.
- Establish exit strategies to facilitate the orderly transfer of data and activities when the outsourcing agreement is terminated.
Key Elements
- Materiality Assessment: Focus on the criticality of activities and their impact on business and regulatory obligations.
- Access and Audit Rights: Ensure both the institution and supervisory authorities have contractual access and audit rights.
- Security of Data and Systems: Implement risk-based security measures and define appropriate protection levels.
- Chain Outsourcing: Monitor and assess risks across the outsourcing chain, with the cloud provider maintaining oversight.
- Contingency and Exit Plans: Prepare for service failures and ensure a smooth transition in case of termination.
Next Steps
- Public Consultation: Ends on 18 August 2017.
- Finalisation: The recommendations will be finalised following the standard procedure.
- Expected Issuance: Final recommendations are expected to be issued in the second half of 2017.
- Application Date: Envisaged to be mid-2018.
试读结束,高清完整版pdf/doc/ppt,请点下载