2024-06-25
Added · Updated
Financial entities must embed specific ICT security policies, procedures, protocols, and tools into their ICT risk management framework, ensuring network security, data integrity, and availability. The regulation mandates detailed requirements for ICT risk management, including risk tolerance levels, assessment methodologies, and the annual review of residual risks. Entities are required to implement comprehensive ICT asset management policies that track asset lifecycles, classifications, and dependencies, while also establishing encryption policies and cryptographic key management controls. Furthermore, the text imposes obligations for ICT operations security, capacity management, and rigorous vulnerability and patch management procedures, including weekly automated scanning for critical assets.