EBA欧洲银行-Guidelines-on-the-security-measures-under-PSD2-28EBA-GL-2017-1729_EN_14页_246kb
报告摘要
EBA/GL/2017/17 Guidelines Summary
Core Content
These Guidelines, issued under Article 16 of Regulation (EU) No 1093/2010, provide supervisory guidance for payment service providers (PSPs) on managing operational and security risks in compliance with Directive (EU) 2015/2366 (PSD2). They emphasize the need for a comprehensive and proportionate approach to risk management, security measures, and business continuity planning.
Main Requirements and Key Points
1. Compliance and Reporting Obligations
- Compliance Deadline: PSPs and competent authorities (CAs) must notify the EBA of compliance or non-compliance with the Guidelines by 12 March 2018.
- Notification Process: Notifications must be submitted via the EBA’s form and sent to compliance@eba.europa.eu with the reference 'EBA/GL/2017/17'. Changes in compliance status must also be reported.
- Publication: Notifications will be published on the EBA website.
2. Subject Matter, Scope and Definitions
- Scope: These Guidelines apply to all PSPs and CAs, including those under the repealed Directive 2007/64/EC.
- Definitions:
- Management Body: Defined differently based on the type of PSP (credit institutions, payment institutions, etc.).
- Operational or Security Incident: An unplanned event that may affect the integrity, availability, confidentiality, authenticity, and continuity of payment services.
- Security Risk: Risk arising from internal or external factors affecting the security of ICT systems and information used in payment services.
- Risk Appetite: The level and types of risk an institution is willing to take to achieve its strategic objectives.
Implementation Requirements
3. Date of Application
- These Guidelines became effective on 13 January 2018.
Guideline 1: General Principle
- All PSPs must comply with the Guidelines.
- The level of detail should be proportionate to the size, complexity, and riskiness of the services provided.
Guideline 2: Governance
Risk Management Framework
- PSPs must establish and maintain an effective operational and security risk management framework, approved and reviewed annually.
- The framework should:
- Include a comprehensive security policy document.
- Be consistent with the PSP’s risk appetite.
- Define roles and responsibilities.
- Establish procedures to identify, measure, monitor, and manage risks, including business continuity arrangements.
Lines of Defence
- PSPs should establish three lines of defense or an equivalent internal control model.
- Audits should be conducted by IT security and payment experts and be operationally independent.
Outsourcing
- PSPs must ensure that outsourced functions (including IT systems) maintain appropriate security.
- Contracts and service-level agreements should include security objectives, measures, and performance targets.
- PSPs must monitor and ensure compliance of providers with these standards.
Guideline 3: Risk Assessment
Identification and Classification
- PSPs should maintain an inventory of business functions, processes, and information assets.
- Assets and functions should be classified based on criticality.
Risk Assessment Process
- Risk assessments should be conducted at least annually or more frequently as required.
- They should cover threats, vulnerabilities, and potential impacts on payment services.
- Risk assessments should be performed before major changes in infrastructure or processes.
Guideline 4: Protection
Security Measures
- PSPs must implement preventive security measures based on identified risks.
- A 'defence-in-depth' approach with multi-layered controls (people, processes, technology) is required.
Data Integrity and Confidentiality
- Sensitive payment data must be protected at all stages (rest, transit, use).
- Compliance with GDPR and other data protection regulations is required.
Physical and Logical Access Control
- Access to ICT systems should be limited to authorized individuals and based on their roles.
- Strong controls must be in place for privileged access, including authentication, logging, and monitoring.
- Access rights should be periodically reviewed.
Access Logs and Secure Communication
- Access logs should be retained based on the criticality of functions and assets.
- Remote administrative access to critical systems should be on a need-to-know basis and use strong authentication.
Guideline 5: Detection
Continuous Monitoring
- PSPs must implement continuous monitoring to detect anomalous activities.
- They should monitor internal and external factors, transactions, and threats.
Incident Classification and Reporting
- PSPs must define criteria and thresholds for classifying incidents.
- They should establish processes for monitoring, handling, and reporting incidents and related customer complaints to senior management.
Guideline 6: Business Continuity
Business Continuity Management
- PSPs should develop and maintain business continuity plans (BCPs) to ensure continued service during disruptions.
- BCPs should be based on risk assessments and scenario analyses.
Testing and Updating
- BCPs should be tested at least annually and updated based on lessons learned, new threats, and changes in recovery objectives.
- Testing should include plausible scenarios and challenge assumptions in the BCPs.
Crisis Communication
- PSPs must ensure timely and effective communication with stakeholders during disruptions or emergencies.
Guideline 7: Testing of Security Measures
- A testing framework must be established to validate the effectiveness of security measures.
- Testing should be conducted during changes in infrastructure, processes, or after major incidents.
- Testing should include vulnerability scans and penetration tests, and be carried out by independent testers.
- Critical systems must be tested annually; non-critical systems at least every three years.
- Test results should be monitored and used to update security measures.
Guideline 8: Situational Awareness and Continuous Learning
Threat Monitoring
- PSPs should monitor security and operational threats continuously.
- They should analyze incidents and update security measures accordingly.
Training and Awareness
- All staff should receive regular training on security policies and procedures.
- Key personnel should receive targeted information security training annually.
- Periodic security awareness programs should be implemented to educate staff and encourage reporting of suspicious activities.
Guideline 9: Payment Service User Relationship Management
Security Awareness for PSUs
- PSPs should provide PSUs with guidance on security risks and mitigating actions.
- Updates on security procedures should be communicated to PSUs.
User Control and Alerts
- PSUs should be allowed to disable certain payment functionalities if possible.
- PSPs should provide PSUs with the ability to adjust spending limits.
- Alerts should be sent for initiated or failed payment transactions to detect fraud.
Support and Communication
- PSPs should assist PSUs with all security-related questions, requests, and notifications.
- PSUs should be informed about how to obtain support in case of anomalies or issues.
展开完整摘要
试读结束,高清完整版pdf/doc/ppt,请点下载