EBA欧洲银行-EBA-BS-2018-431-28Draft-CP-on-Guidelines-on-ICT-and-security-risk-management29_35页_653kb
报告摘要
EBA Draft Guidelines on ICT and Security Risk Management Summary
Core Content
The European Banking Authority (EBA) has issued a Consultation Paper on draft Guidelines on ICT and Security Risk Management, aiming to enhance the risk management practices of financial institutions in the context of increasing ICT risks and cybersecurity threats. These guidelines are intended to be proportionate to the size, complexity, and risk profile of each institution, ensuring a level-playing field across the EU financial sector.
Main Objectives
- To provide a comprehensive framework for managing ICT risks, including security risks, across financial institutions.
- To align with Article 74 of CRD and Article 95 of PSD2, which mandate the management of operational and security risks.
- To repeal the previous EBA/GL/2017/17 guidelines on security measures for payment services, replacing them with a broader scope that applies to all activities of financial institutions.
Key Points
1. Scope of Application
- PSPs (Payment Service Providers): Apply to their payment services, including electronic money issuance.
- Credit Institutions and Investment Firms: Apply to all their activities.
- Competent Authorities: Include the European Central Bank and other regulatory bodies under PSD2 and CRD.
2. Definitions
| Term | Definition |
|---|---|
| ICT Risk | Risk of loss due to breach of confidentiality, failure of integrity, inappropriateness or unavailability of systems and data, or inability to change IT within a reasonable time and cost when business requirements change. This includes security risks such as cyber-attacks and inadequate physical security. |
| Management Body | For credit institutions and investment firms, refers to the board or management; for PSPs, refers to directors or persons responsible for the management of the institution. |
| Operational or Security Incident | A single unplanned event or a series of linked unplanned events that may have an adverse impact on the integrity, availability, confidentiality, authenticity, and/or continuity of ICT systems and services. |
| Risk Tolerance | The level and types of risk that an institution is willing to assume within its risk capacity, in line with its business model. |
| Audit Function | For credit institutions and investment firms, refers to the internal audit function; for PSPs, it may be internal or external. |
| ICT Projects | Any project involving changes, replacements, or implementations of ICT systems and services. |
| Third Party | An organisation that provides a product or service through a business relationship or contract. |
| Information Asset | A collection of information, tangible or intangible, that is worth protecting. |
| ICT Asset | Software and hardware assets in the business environment. |
| ICT Systems and Services | Systems and services that support the operations of an institution. |
3. Main Requirements
- Proportionality: Institutions must apply the guidelines in a manner that is proportionate to their size, complexity, and risk profile.
- ICT Governance and Strategy:
- Management bodies must ensure the establishment of an internal governance and control framework.
- They must define and approve an ICT strategy that aligns with the overall business strategy.
- Staff should be appropriately trained, and budgets allocated for ICT should be sustainable.
- Risk Management Framework:
- Institutions should implement a three lines of defence model to identify, assess, and mitigate ICT risks.
- The internal control function should have sufficient authority, independence, and resources.
- The internal audit function must provide independent assurance on the effectiveness of the first and second lines of defence.
- Third Party Management:
- Contracts and service-level agreements must include information security objectives and measures.
- Financial institutions should monitor and ensure compliance with these requirements.
- Risk Identification and Assessment:
- Financial institutions should map and classify their business functions, processes, and information assets based on criticality.
- They must assess the associated ICT risks and define mitigation measures.
- Information Security:
- A high level of information security must be implemented.
- This includes an independent information security function, an information security policy, testing of security measures, and training for all staff.
- ICT Operations:
- Financial institutions must automate ICT operations, implement logging and monitoring, and maintain an updated inventory of ICT assets.
- They should also monitor and manage the lifecycle of ICT assets and have backup and recovery plans.
- Incident Management:
- An incident and problem management process must be established.
- Business Continuity:
- Institutions must develop and test response and recovery plans.
- They should have effective crisis communication mechanisms to inform internal and external stakeholders.
4. Implementation and Compliance
- The guidelines are issued pursuant to Article 16 of Regulation (EU) No 1093/2010.
- Competent authorities must notify the EBA of their compliance status by a specified deadline.
- If no notification is received, the EBA will consider the authority as non-compliant.
- The guidelines will replace EBA/GL/2017/17 and will be repealed once they come into force.
5. Cybersecurity Considerations
- Cybersecurity is a subset of ICT risk and is implicitly covered by the guidelines.
- Cyber-attacks have specific characteristics that must be considered, such as:
- Difficulty in identification and eradication.
- Potential to render business continuity and disaster recovery ineffective.
- Risk of data propagation through third-party channels.
- Therefore, cybersecurity must be integrated into the overall ICT risk management framework.
Conclusion
These guidelines aim to enhance the resilience of financial institutions against ICT and cybersecurity threats. They promote proportionality, governance, and risk management across all activities and entities within the EU financial sector, ensuring consistency and clarity in supervisory expectations.
试读结束,高清完整版pdf/doc/ppt,请点下载