2020-08-25

Added · Updated

Circular CSSF 20/750 on ICT and Security Risk Management Requirements

The circular establishes requirements for ICT and security risk management for support postal financial services, specialised postal financial services, POST Luxembourg, and branches in Luxembourg of third-country credit institutions, investment firms, payment institutions, and e-money institutions. It mandates that management bodies ensure adequate internal governance, approve an ICT strategy aligned with business objectives, and maintain a documented risk management framework that is reviewed at least annually. Financial institutions must implement specific controls including logical access management based on least privilege, physical security measures, and periodic independent audits of ICT systems and processes.

Commission de Surveillance du Secteur Financier logo

Luxembourg

Commission de Surveillance du Secteur Financier

Click to view full text

More like this from CSSF

We email you every new CSSF publication the day it's published.

Share