2020-08-25
Added · Updated
The circular establishes requirements for ICT and security risk management for support postal financial services, specialised postal financial services, POST Luxembourg, and branches in Luxembourg of third-country credit institutions, investment firms, payment institutions, and e-money institutions. It mandates that management bodies ensure adequate internal governance, approve an ICT strategy aligned with business objectives, and maintain a documented risk management framework that is reviewed at least annually. Financial institutions must implement specific controls including logical access management based on least privilege, physical security measures, and periodic independent audits of ICT systems and processes.
More like this from CSSF
We email you every new CSSF publication the day it's published.