EBA欧洲银行-Public-Hearing-on-Guidelines-on-the-security-measures-for-operational-and-security-risks-of-payment-services-under-PSD2-200617_26页_1mb
报告摘要
Summary of EBA Public Hearing on the CP on the Guidelines on the Security Measures for Operational and Security Risks of Payment Services under PSD2
Core Content
The European Banking Authority (EBA) held a public hearing on the Consultation Paper (CP) regarding the Guidelines on security measures for operational and security risks of payment services under the Payment Services Directive 2 (PSD2). The hearing aimed to gather feedback from stakeholders on the proposed guidelines, which were developed in close cooperation with the European Central Bank (ECB) and after consulting all relevant parties.
Main Purpose of the Public Hearing
- To allow interested parties to ask clarification questions on the draft guidelines.
- To present a summary of the CP and re-produce its questions.
- To collect input on whether additional explanations or clarifications are needed.
- To ensure that stakeholder views are considered in the final guidelines.
The public hearing does not replace written responses but complements them by providing an opportunity for direct engagement.
EBA's Mandate under PSD2
Under Article 95(3) of PSD2, the EBA is tasked with:
- Issuing guidelines on the establishment, implementation, and monitoring of security measures for payment services by 13 July 2017.
- Reviewing these guidelines regularly, at least every 2 years, in close cooperation with the ECB.
Approach to Developing the Guidelines
The EBA and ECB drew upon various existing standards and guidance, including:
- EU: EBA Guidelines on the Security of Internet Payments, earlier SecuRe Pay Guidance, and the NIS Directive.
- International: BCBS principles on operational risk, US NIST Framework, and CPMI-IOSCO Guidance on cyber resilience for financial market infrastructures (FMIs).
Key Threats and Vulnerabilities Identified
The EBA and ECB identified the following main threats and vulnerabilities affecting payment service providers (PSPs):
- Inadequate protection of communication channels.
- Insecure systems and devices.
- Unsafe user and staff behavior.
- Increased complexity of the payments environment.
- Technological tools available to fraudsters and attackers.
Main Findings of the Risk Assessment
- The nature and type of security threats and vulnerabilities are evolving rapidly.
- Guidelines must remain flexible to adapt to the changing risk landscape.
- PSPs should implement security measures to prevent, detect, and correct unauthorized use, disclosure, access, modification, or damage to their ICT systems and information.
- Security measures should be integrated into overall risk management and continuously monitored through periodic reviews and reporting.
Structure of the Guidelines
The EBA proposed eight guidelines to address the security and operational risks faced by PSPs:
| Guideline | Title |
|---|---|
| GL 1 | Governance |
| GL 2 | Risk Assessment |
| GL 3 | Protection |
| GL 4 | Detection |
| GL 5 | Business Continuity |
| GL 6 | Testing of Security Measures |
| GL 7 | Situational Awareness and Continuous Learning |
| GL 8 | Payment Service User (PSU) Relationship Management |
Additional Categories
- Testing: Ensures the robustness and effectiveness of security measures.
- Situational Awareness and Continuous Learning: Enhances the ability to detect and respond to threats.
- PSU Relationship Management: Focuses on user communication and secure reporting procedures.
Key Requirements of the Guidelines
Guideline 1: Governance
- Establish a clear and comprehensive operational and security risk management framework.
- Implement a three lines of defence model or equivalent.
- Ensure security objectives are included in contracts and SLAs with outsourcing providers.
Guideline 2: Risk Assessment
- Identify, classify, and assess functions, processes, and assets.
- Maintain an updated inventory of business functions and information assets.
- Regularly review and update risk assessments based on threat intelligence.
Guideline 3: Protection
- Apply a 'defence-in-depth' approach with multi-layered controls.
- Protect sensitive data and ensure access control based on the principle of least privilege.
- Limit physical access to systems and regularly review it.
Guideline 4: Detection
- Implement continuous monitoring and detection processes.
- Define thresholds and early warning indicators for security incidents.
- Establish procedures for handling and reporting security incidents to senior management.
Guideline 5: Business Continuity
- Develop and implement business continuity management and planning.
- Test plans annually and update them based on threat intelligence and lessons learned.
Guideline 6: Testing of Security Measures
- Conduct tests during infrastructure and procedure changes or after major incidents.
- Ensure tests are performed by independent parties.
- Include vulnerability scans and penetration tests.
Guideline 7: Situational Awareness and Continuous Learning
- Proactively monitor the threat landscape and use actionable threat intelligence.
- Participate in information-sharing and collaborate with external stakeholders.
- Foster a culture of continuous learning and security awareness.
Guideline 8: PSU Relationship Management
- Inform users about security breach reporting procedures.
- Provide guidance on blocking or unblocking transactions.
- Enhance user awareness of security risks and measures.
Next Steps
- 7 August 2017: Consultation period ends.
- Q3/Q4 2017: EBA assesses responses to decide on any necessary changes.
- Q4 2017: Final Guidelines and Final Report are published in English.
- December 2017: Translations in all official EU languages are published.
- February 2018: National authorities have two months to submit compliance notifications.
- 13 January 2018: Guidelines become applicable.
Key Information
- The EBA has issued over 200 legal instruments since 2011.
- The guidelines are based on the principle of proportionality, meaning all PSPs must comply, but the steps may vary based on their size and complexity.
- A new definition of "security risk" was introduced, encompassing both internal and external threats.
- No new definition of "operational risk" or "security measures" was provided, as these are already defined in other regulations.
Conclusion
The EBA and ECB have developed a comprehensive and flexible framework for security measures in payment services, with a focus on risk management, continuous monitoring, and stakeholder engagement. The guidelines aim to ensure that PSPs are well-prepared to handle evolving security threats and maintain the integrity and safety of payment services.
试读结束,高清完整版pdf/doc/ppt,请点下载