EBA欧洲银行-Guidelines-on-the-security-measures-under-PSD2-28EBA-GL-2017-1729_MT_14页_306kb
报告摘要
Summary of EBA/GL/2017/17
Core Content
The document EBA/GL/2017/17 outlines the guidelines for operational risk and payment services security under the Directive (EU) 2015/2366 (PSD2). It provides a comprehensive framework for payment service providers (PSPs) to ensure compliance with the European Banking Authority (EBA) requirements, focusing on risk management, incident response, continuity of operations, and security measures.
Main Points
1. Compliance and Reporting Obligations
- The guidelines are based on Article 16 of Regulation (EU) No 1093/2010.
- Competent authorities must ensure that the guidelines are incorporated into their supervisory practices.
- PSPs must report all non-compliance or changes in compliance status to the EBA by 12 March 2018.
- Reports must be submitted using the EBA template and must include relevant information from the competent authorities.
- Non-compliance must be reported promptly, and changes in risk management practices must also be communicated.
2. Scope and Definitions
- The guidelines apply to PSPs as defined in Article 4(11) of PSD2 and Article 4(1) of Regulation (EU) 1093/2010.
- Key definitions include:
- Corporate governance: Refers to the board of directors and senior management.
- Operational risk and security incidents: Events that may have a negative impact on the integrity, availability, confidentiality, authenticity, and continuity of payment services.
- Risk management: Involves identifying, assessing, and mitigating risks.
- Security controls: Must be appropriate and proportional to the risk level.
- Security breaches: Include unauthorized access, data leaks, and other incidents affecting payment services.
3. Implementation
- The guidelines came into effect on 13 January 2018.
- PSPs must establish and implement effective risk management frameworks, including:
- Comprehensive security policies.
- Alignment with the institution’s risk appetite.
- Integration into overall risk management processes.
- Externalization of payment services must be monitored, and contractual agreements must define security requirements.
4. Security Measures
- PSPs must ensure the integrity, confidentiality, and availability of critical systems and data.
- Physical and technical security measures must be implemented to protect sensitive data and ICT systems.
- Access control must be strictly managed, with:
- Physical and logical access limited to authorized individuals.
- Monitoring and logging of access activities.
- Authentication mechanisms for privileged access.
- Incident monitoring and reporting must be established, including:
- Classification criteria for operational and security incidents.
- Alert systems for early detection.
- Procedures for reporting incidents to senior management.
5. Business Continuity
- PSPs must establish business continuity plans (BCPs) to ensure continuous service delivery during disruptions.
- BCPs must:
- Address potential risks such as cyber attacks or system failures.
- Include recovery plans for critical functions, systems, and transactions.
- Be tested regularly, with annual testing for critical systems.
- Testing procedures must cover:
- Various scenarios, including extreme events.
- Communication protocols during crises.
- Involvement of relevant internal and external parties.
6. Testing and Evaluation
- PSPs must implement testing frameworks to validate the effectiveness of security measures.
- Testing includes:
- Penetration testing and vulnerability scanning.
- Independent testing by qualified experts.
- Testing before implementing security measures.
- Continuous testing is required for all security measures, especially for critical systems, with more frequent testing for high-risk areas.
7. Risk Awareness and Continuous Training
- PSPs must maintain awareness of operational and security risks.
- They must:
- Identify and monitor changes in risk profiles.
- Provide regular training to staff on security risks and mitigation actions.
- Ensure that training is tailored to specific roles and updated based on risk assessments.
- Training programs should cover:
- Human error, fraud, misuse, and breaches.
- Roles and responsibilities related to security.
- Periodic updates to ensure staff are aware of new threats and procedures.
8. User Security Awareness and Support
- PSPs must provide security awareness and support to users (PSUs).
- This includes:
- Guidance and support on how to manage security risks.
- Regular updates on changes in security procedures.
- Notification of security incidents and fraud attempts.
- Support for users in identifying and responding to threats.
Key Information
- The guidelines apply to all PSPs, including credit institutions, payment institutions, and electronic money institutions.
- Compliance is mandatory, and non-compliance must be reported.
- Security measures must be proportional to the risk level and aligned with the institution's risk appetite.
- Testing and evaluation are required to ensure the effectiveness of security controls.
- Training and awareness are essential for both staff and users to prevent and respond to security incidents.
- Business continuity plans must be tested regularly and updated to reflect new risks and technologies.
Conclusion
EBA/GL/2017/17 sets out a clear and detailed framework for operational risk and payment services security. It emphasizes the importance of compliance, risk assessment, incident management, business continuity, and continuous training to ensure the security, reliability, and continuity of payment services in the European Union.
试读结束,高清完整版pdf/doc/ppt,请点下载