[stock-market-ticker symbols="FB;BABA;AMZN;AXP;AAPL;DBD;EEFT;GTO.AS;ING.PA;MA;MGI;NPSNY;NCR;PYPL;005930.KS;SQ;HO.PA;V;WDI.DE;WU;WP" width="100%" palette="financial-light"]

European Supervisory Authorities publish first set of rules under DORA for ICT and third-party risk management and incident classification

18 ianuarie 2024

The three European Supervisory Authorities (EBA, EIOPA and ESMA – the ESAs) published the first set of final draft technical standards under the Digital Operational Resilience Act (DORA) aimed at enhancing the digital operational resilience of the EU financial sector by strengthening financial entities’ Information and Communication Technology (ICT) and third-party risk management and incident reporting frameworks.

The joint final draft technical standards include:

. Regulatory Technical Standards (RTS) on ICT risk management framework and on simplified ICT risk management framework;
. RTS on criteria for the classification of ICT-related incidents;
. RTS to specify the policy on ICT services supporting critical or important functions provided by ICT third-party service providers (TPPs); and
. Implementing Technical Standards (ITS) to establish the templates for the register of information.

RTS on ICT risk management framework and on simplified ICT risk management framework
The draft RTS on ICT risk management framework identify further elements related to ICT risk management with a view to harmonise tools, methods, processes and policies. These elements are complementary to those identified in DORA. The RTS identify the key elements that financial entities subject to the simplified regime and of lower scale, risk, size and complexity would need to have in place, setting out a simplified ICT risk management framework. The RTS ensure the ICT risk management requirements are harmonised among the different financial sectors.

RTS on criteria for the classification of ICT-related incidents
These RTS specify the criteria for the classification of major ICT-related incidents, the approach for the classification of major incidents, the materiality thresholds of each classification criterion, the criteria and materiality thresholds for determining significant cyber threats, the criteria for competent authorities to assess the relevance of incidents to competent authorities in other Member States and the details of the incidents to be shared in this regard. The RTS ensure a harmonised and simple process of classifying incident reports throughout the financial sector.

RTS on ICT TPP policy
These RTS specify parts of the governance arrangements, risk management and internal control framework that financial entities should have in place regarding the use of ICT third-party service providers. They aim to ensure financial entities remain in control of their operational risks, information security and business continuity throughout the life cycle of contractual arrangements with such ICT third-party service providers.

ITS on the register of information
Finally, the ITS set out the templates to be maintained and updated by financial entities in relation to their contractual arrangements with ICT third-party service providers. The register of information will play a crucial role in the ICT third-party risk management framework of the financial entities and will be used by competent authorities and ESAs in the context of supervising financial entities’ compliance with DORA and to designate critical ICT third-party service providers that will be subject to the DORA oversight regime.

Next steps

The final draft technical standards have been submitted to the European Commission, who will now start working on their review with the objective to adopt these first standards in the coming months.

______________

Documents

Draft RTS on ICT Risk Management Framework and on simplified ICT Risk Management Framework (1.74 MB – PDF) – Download

Draft RTS to specify the policy on ICT services supporting critical or important functions (754.99 KB – PDF) – Download

Draft RTS on classification of major incidents and significant cyber threats (1.02 MB – PDF) – Download

Draft ITS on Register of Information (2.92 MB – PDF) – Download

Related content

Regulatory activity – Final draft RTS/ITS adopted by the EBA and submitted to the European Commission

Implementing Technical Standards to establish the templates for the register of information

Regulatory Technical Standards on the policy on ICT services supporting critical or important functions provided by ICT third-party service providers

Regulatory Technical Standards on criteria for the classification of ICT-related incidents

Regulatory Technical Standards on ICT risk management framework and on simplified ICT risk management framework

Noutăți
Cifra/Declaratia zilei

Anders Olofsson – former Head of Payments Finastra

Banking 4.0 – „how was the experience for you”

So many people are coming here to Bucharest, people that I see and interact on linkedin and now I get the change to meet them in person. It was like being to the Football World Cup but this was the World Cup on linkedin in payments and open banking.”

Many more interesting quotes in the video below:

Sondaj

In 23 septembrie 2019, BNR a anuntat infiintarea unui Fintech Innovation Hub pentru a sustine inovatia in domeniul serviciilor financiare si de plata. In acest sens, care credeti ca ar trebui sa fie urmatorul pas al bancii centrale?