2024-06-25
Added · Updated
Financial entities must embed specific ICT security policies, procedures, protocols, and tools into their ICT risk management framework, ensuring network security, data integrity, and availability. The regulation mandates detailed requirements for ICT risk management, including risk tolerance levels, assessment methodologies, and the annual review of residual risks. Entities are required to implement comprehensive ICT asset management policies that track asset lifecycles, classifications, and dependencies, while also establishing encryption policies and cryptographic key management controls. Furthermore, the text imposes obligations for ICT operations security, capacity management, and rigorous vulnerability and patch management procedures, including weekly automated scanning for critical assets.
Get EC alerts — same-day email on every new publication.
Skip to main content
EUR-Lex
Access to European Union law
This document is an excerpt from the EUR-Lex website
You are here
EUROPA
EUR-Lex home
EUR-Lex - 02024R1774-20240625 - EN
Help
Quick search
Use quotation marks to search for an "exact phrase". Append an asterisk ( * ) to a search term to find variations of it (transp * , 32019R * ). Use a question mark ( ? ) instead of a single character in your search term to find variations of it (ca ? e finds case, cane, care).
Search tips
Need more search options? Use the
Read the rest free, and get an email when EC publishes again
Source: European Commission — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works
More like this from EC
We email you every new EC publication the day it's published.