2020-06-16 | NBB_2020_23

Added · Updated

Circular NBB_2020_23 / EBA Guidelines on ICT and security risk management

This circular implements the European Banking Authority Guidelines on ICT and security risk management (EBA/GL/2019/04) into Belgian supervisory practice, applying from 30 June 2020. It mandates that credit institutions, stockbroking firms, payment institutions, electronic money institutions, and relevant holding companies establish sound ICT and security risk management arrangements in compliance with the Banking Law of 25 April 2014 and the Payment Services Law of 11 March 2018. The document replaces Circular NBB_2018_13 and requires adherence to specific provisions regarding governance, information security, ICT operations, and business continuity. It also clarifies that these requirements apply on a consolidated basis to Belgian parent credit institutions and holding companies.

National Bank of Belgium logo

Belgium

National Bank of Belgium

Click to view thumbnail

Boulevard de Bedaimont 14-BE-1000 Brussels Phone +32 2 221 48 66 Company number: 0203. 201. 340 RPM (Trade Register) Bmssels www. nbb. be rtl BanqueNatipnaleBank DEBELCIQUE VAN BELGtE Eurosystem Circular Brussels, 16 June 2020 Reference: Contact person: Thomas Plomteux Phone +32 2 221 21 97 thomas. plomteux@nbb. be NBB 2020 23 European Banking Authority (EBA) Guidelines of 29 November 2019 on ICT1 and security risk management (EBA/GL/2019/04) . Credit institutions and stockbroking firms governed by Belgian law; . branches established in Belgium of credit institutions and stockbroking firms governed by the law of a non-EEA Member State; . payment institutions and electronic money institutions governed by Belgian law; . branches established in Belgium of payment institutions and electronic money institutions governed by the law of a non-EEA Member State2: . in the context of consolidated supervision, group supen/ision or supplementary conglomerate supervision, financial holding companies and mixed financial holding companies. Summarv/Obiectives This Circular implements the Guidelines of the European Banking Authority (hereinafter referred to as the "EBA") on ICT and security risk management (EBA/GL/2019/04)3 and applies from 30 June 2020. This Circular replaces Circular NBB_2018_13, which ceases to apply from that date. 1 Information and communication technology. 2 Assuming that the legal provision of which the content is specified here is made applicable to the branches concerned. 3 httDs://eba. euroDa. eu/requlation-and-policv/intemal-aovemance/Quidelines-on-ict-and-securitv-risk-management. NBB 2020 23 - 16062020 Circular - Page 1/3

m Dear Sir, Dear Madam,

  1. Introduction and motivation Through this Circular, the NBB indicates that the EBA Guidelines on ICT and security risk management have been integrated in its supervisory practices. These Guidelines aim to guarantee adequate ICT and security management in the financial sector in the European Union and to ensure a level playing field in this area for financial institutions. Among other things, these Guidelines include provisions on governance and strategy, ICT and security risk management, information security, ICT operations management, ICT project and change management, and business continuity management. Thus, this Circular clarifies the National Bank of Belgium's expectations regarding the implementation of the following provisions: . Articles 21 of the Law of 25 April 2014 on the legal status and supervision of credit institutions and stockbroking firms ("the Banking Law of 25 April 2014") and 21 and 176 of the Law of 11 March 2018 on the legal status and supervision of payment institutions and electronic money institutions, access to the activity of payment service provider and the activity of issuing electronic money, and access to payment systems ("the Payment Services Law of 11 March 2018") in relation to the obligation to have a sound and appropriate arrangement for the organisation of the business4; . Articles 50 through 53 and 145 of the Law of 11 March 20185 in relation to the security risks for the provision of payment sen/ices and the issuance of electronic money. Pursuant to Article 168 of the Banking Law, these requirements also apply on a consolidated basis to Belgian parent credit institutions and to credit institution governed by Belgian law that are controlled by a parent financial holding company or a parent mixed financial holding company. In this context, financial holding companies and mixed financial holding companies governed by Belgian law are therefore also expected to comply with this Circular on a consolidated basis. 4 Among other things, these Articles mention: . an appropriate management structure, including a clear, transparent and coherent arrangement for allocating responsibilities; . effective procedures for the identification, measurement, management, monitoring and internal reporting of the financial institution's risks; . an appropriate independent risk management function and internal audit function; . appropriate IT control and security measures; . the introduction of appropriate measures for business continuity to guarantee that the critical/essential business functions can be preserved or restored as quickly as possible and that the normal provision of services and activities can be resumed within a reasonable timeframe. 5 Articles 50 through 53 and Article 145 of the Payment Services Law clarify that each payment service provider is expected to establish a security policy as well as procedures for reporting incidents. Circular - Page 213 NBB_2020^23 - 16062020

m 2. Clarifications on the scope and implementation When referring to "financial institutions", the EBA Guidelines and this Circular apply to: . payment service providers (payment institutions, electronic money institutions and credit institutions) with respect to the provision of payment services; . credit institutions with respect to any of their activities other than payment services; . stockbroking firms with respect to any of their activities. Some provisions and clarifications in the Guidelines are aimed exclusively at payment service providers, credit institutions or "investment firms", For the scope of this Circular, "investment firms" should be read as stockbroking firms. This Circular applies from 30 June 2020 and replaces Circular NBB_2018_13, which is repealed from that date. The EBA Guidelines should be read and applied in conjunction with the provisions of the following Circulars: . Circular NBB_2019_19, which defines the general expectations regarding outsourcing for this scope; » Circular NBB_2015_32, which applies specifically to systemically important financial institutions; . Circular CBFA_2009_17, which includes additional provisions for offering financial services (excluding payment services) via the Internet (inter alia for credit institutions and stockbroking firms); . Circular PPB 2005/2, which includes additional provisions for business continuity management (inter alia for credit institutions and stockbroking firms); . Circular NBB_2019_09, which establishes the reporting on operational and security risks of payment services to be submitted by credit institutions and branches of credit institutions; . Circular NBB_2020_24, which establishes the reporting on operational and security risks of payment services to be submitted by payment institutions and electronic money institutions. A copy of this Circular will be sent to your institution's accredited statutory auditor(s). Yours faithfully, NBB 2020 23 - 16062020 Circular - Page 3/3