2020-08-25

Added · Updated

Circular CSSF 20/750 on ICT and Security Risk Management Requirements

The circular establishes requirements for ICT and security risk management for support postal financial services, specialised postal financial services, POST Luxembourg, and branches in Luxembourg of third-country credit institutions, investment firms, payment institutions, and e-money institutions. It mandates that management bodies ensure adequate internal governance, approve an ICT strategy aligned with business objectives, and maintain a documented risk management framework that is reviewed at least annually. Financial institutions must implement specific controls including logical access management based on least privilege, physical security measures, and periodic independent audits of ICT systems and processes.

Commission de Surveillance du Secteur Financier logo

Luxembourg

Commission de Surveillance du Secteur Financier

Scan of the document's first page
Share

CSSF published 3 documents in the last 30 days — get each new one by email the day it lands.

Read the rest free

Lineage: Amended

CSSF Circular No. 22/828 of 2022CSSF Circular No. 22/828 of 2022CSSF Circular No. 25/881 of 2025CSSF Circular No. 25/881 of 2025Circular CSSF 20/750 on ICTand Security Risk Management …2020-08-25 · this documentCircular CSSF 20/750 on ICT and Security Risk Management Requirements (2020-08-25)Circular CSSF 22/807 Update of …2022Circular CSSF 22/807 Update of Circular CSSF 12/552 on Central Administration, Internal Governance and Risk Management (2022-04-22)Authorisation and organisation …2022Authorisation and organisation of entities acting as UCI administrators (2022-05-16)Amendment of Circular CSSF 20/7…2022Amendment of Circular CSSF 20/750 on ICT and Security Risk Management (2022-12-29)Circular CSSF 24/860 Update of …2024Circular CSSF 24/860 Update of Circular CSSF 12/552 on central administration, internal governance and risk management (2024-08-29)Circular CSSF 25/880 on relatio…2025Circular CSSF 25/880 on relationship management of payment service users and PSP ICT assessment (2025-04-09)Circular CSSF 25/881 amending C…2025Circular CSSF 25/881 amending Circular CSSF 20/750 on ICT and security risk management (2025-04-09)Circular CSSF 25/900 amending C…2025Circular CSSF 25/900 amending Circular CSSF 22/811 on Authorisation and organisation of entities acting as UCI administrators (2025-12-16)Circular CSSF 26/915 — on the a…2026Circular CSSF 26/915 — on the applicability of the Digital Operational Resilience Act (DORA) to third-country branches in Luxembourg (2026-08-27)
amendssupersedesissued underrefers toproposed or not in RegAlertarrows run from the older text to the one that changes it

Source: Commission de Surveillance du Secteur Financier — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works

More like this from CSSF

CSSF published 3 documents in the last 30 days. We email you each new one the day it's published.