2021-07-07 | NBB_2021_15Added · Updated
The National Bank of Belgium integrates the EIOPA Guidelines on ICT security and governance into its supervisory practices, requiring insurance and reinsurance companies to establish adequate ICT risk management, strategy, and security measures. The document mandates that administrative, management, or supervisory bodies ensure appropriate governance, allocate sufficient resources, and implement written ICT strategies aligned with business objectives. It further requires the establishment of information security policies, logical and physical security controls, and regular auditing of ICT systems to protect confidentiality, integrity, and availability of information assets.