2020-05-06
Added
The European Banking Authority (EBA) published "Guidelines on the management of ICT and security risks" (EBA/GL/2019/04) on November 28, 2019, which revoke and incorporate prior guidelines. These Guidelines specify risk management measures for credit institutions, payment service providers, and investment firms to manage ICT and security risks across all activities, including specific measures for payment service providers regarding payment services and requirements for outsourced systems and cybersecurity incidents. Banco de Portugal expects these entities to observe the requirements of the Guidelines from June 30, 2020, and will consider them in its supervisory activity from that date. The requirements will be subject to future regulation by Banco de Portugal.
Circular Letter No. CC/2020/00000029 Sent to: Credit Institutions; Payment Institutions; Electronic Money Institutions and Investment Firms. Mod. 40000375/T – 01/14 Subject: Guidelines on the management of ICT and security risks On November 28, 2019, the European Banking Authority (EBA) published the “Guidelines on the management of ICT and security risks” (EBA/GL/2019/04) (hereinafter “Guidelines”) 1. These Guidelines revoke and incorporate the previous “Guidelines on security measures for managing operational and security risks under Directive (EU) 2015/2366” (EBA/GL/2017/17). Given the matters concerned, the Guidelines complement the “Guidelines on the assessment of ICT risk in the supervisory review and evaluation process (SREP)” (EBA/GL/2017/05), which were integrated by Banco de Portugal into its assessment of information and communication technology (ICT) risk within the scope of SREP. The Guidelines are addressed to payment service providers, credit institutions, and investment firms. In general terms, they specify the risk management measures that institutions must adopt to manage their ICT and security risks for all activities, and, in particular, the measures that payment service providers must take to manage operational and security risks related to the payment services they provide. The guidelines also include requirements aimed at mitigating security risks associated with outsourced systems and/or exposed to cybersecurity incidents. Given their importance for strengthening the operational resilience of the financial sector, Banco de Portugal informed the EBA of its intention to comply with these Guidelines from June 30, 2020, which will imply that the underlying requirements will be taken into consideration in the exercise of supervisory activity from that date. In this context, Banco de Portugal, in the exercise of the competence attributed to it by Articles 14 and 17 of its Organic Law, approved by Law No. 5/98, of January 31, hereby conveys its expectation that, in accordance with their scope of application, the requirements set out in the Guidelines will be observed from June 30, 2020, by: payment service providers, as defined in Article 4, No. 11, of Directive (EU) 2015/2366 of the European Parliament and of the Council, of November 25, 2015 (PSD2), and credit institutions and investment firms, as defined in Article 4, No. 1, point 3, of Regulation (EU) No 575/2013 of the European Parliament and of the Council, of June 26, 2013 (CRR). The requirements set out in the Guidelines will be subject to regulation by Banco de Portugal in due course. 1 https://eba.europa.eu/eba-publishes-guidelines-ict-and-security-risk-management
More like this from BDP
BDP published 5 documents in the last 30 days. We email you each new one the day it's published.