2024-06-25

Added · Updated

Commission Delegated Regulation (EU) 2024/1774 on ICT risk management standards

Financial entities must embed specific ICT security policies, procedures, protocols, and tools into their ICT risk management framework, ensuring network security, data integrity, and availability. The regulation mandates detailed requirements for ICT risk management, including risk tolerance levels, assessment methodologies, and the annual review of residual risks. Entities are required to implement comprehensive ICT asset management policies that track asset lifecycles, classifications, and dependencies, while also establishing encryption policies and cryptographic key management controls. Furthermore, the text imposes obligations for ICT operations security, capacity management, and rigorous vulnerability and patch management procedures, including weekly automated scanning for critical assets.

European Commission logo

European Union

European Commission

Scan of the document's first page
Share

Get EC alerts — same-day email on every new publication.

Read the rest free, and get an email when EC publishes again

Lineage: In force

Regulation (EU) 2022/2554 of th…2022Regulation (EU) No 1025/2012 of…2012Commission Delegated Regulation…2024Commission DelegatedRegulation (EU) 2024/1774 on …2024-06-25 · this document
amendssupersedesissued underrefers toproposed or not in RegAlertarrows run from the older text to the one that changes it

Source: European Commission — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works

More like this from EC

We email you every new EC publication the day it's published.