2023-12-18 | C609The Cyprus Securities and Exchange Commission issued Circular C609 to clarify the application of EBA Guidelines on ICT and security risks management for Cyprus Investment Firms. The circular specifies that CIFs must assign ICT risk oversight to a control function, which may be outsourced, and mandates that the internal audit function independently reviews compliance with ICT policies. Furthermore, it requires periodic audits of ICT governance and systems by qualified auditors to provide independent assurance to the management body on the effectiveness of risk controls.
TO : Cyprus Investment Firms (CIFs) FROM : Cyprus Securities and Exchange Commission DATE : 18 December 2023 CIRCULAR NO. : C609 SUBJECT : ΕΒΑ Guidelines on Information and Communication Technology (ICT) and security risks management (EBA/GL/2019/04) Following the Cyprus Securities and Exchange Commission (the “CySEC”) Circular C571 regarding the EBA Guidelines on Information and Communication Technology (ICT) and security risks management (EBA/GL/2019/04) (the “Guidelines”), CySEC would like to clarify the following:
The internal audit function mentioned above is the appointed internal auditor of the CIF and it is anticipated that it has the capability to comprehensively assess the ICT and security aspects of the CIF within the scope of its audit responsibilities and prepare the internal audit report accordingly. 3. Paragraph 25 of the Guidelines states that: «A CIF’s governance, systems and processes for its ICT and security risks should be audited on a periodic basis by auditors with sufficient knowledge, skills and expertise in ICT and security risks to provide independent assurance of their effectiveness to the management body. The auditors should be independent within or from the CIF. The frequency and focus of such audits should be commensurate with the relevant ICT and security risks». The audit mentioned above may be performed by the internal auditor of the CIF or another auditor appointed by the CIF. An independent assurance report conducted either by the internal auditor or another auditor should be generated. This separate report aims to provide independent assurance of the effectiveness of the CIF's governance, systems, and processes in addressing ICT and security risks, providing valuable insights to the management body. Sincerely, Dr. George Theocharides Chairman Cyprus Securities and Exchange Commission