2024-03-13
Added · Updated
The European Commission adopts regulatory technical standards supplementing Regulation (EU) 2022/2554 by specifying ICT risk management tools, methods, processes, and policies for financial entities. The regulation mandates detailed requirements for ICT asset management, cryptographic controls, vulnerability and patch management, change management, and incident detection, while requiring the segregation of duties and the maintenance of ICT business continuity plans. It establishes a simplified ICT risk management framework for smaller entities, limiting their obligations to a single information security policy and essential governance elements. The act enters into force on 25 June 2024 and applies to the financial entities covered by the Digital Operational Resilience Act.