Lex Browse everything How it works For developers

What changed, Commission Delegated Regulation (EU) 2024/1774 of 13 March 2024 supplementing Regulation (EU) 2022/2554

2024-03-13 → 2024-06-25 · no interpretation, just the text delta

on 2024-03-13eu-eurlex:32024r1774:2024-03-13 (2024-03-13 → 2024-06-24) · official source ↗
on 2024-06-25eu-eurlex:32024r1774:2024-06-25 (2024-06-25 → open) · official source ↗

Open the structured article comparison → matched by provision anchor, with changed, added, removed and unchanged articles separated

1,415 line(s) in the old middle, 555 in the new; 1 unchanged leading and 1 trailing lines trimmed.

+ ### Article 1 — Overall risk profile and complexity
− ### art_1
− Article 1

+ (a) encryption and cryptography;
− | (a) | encryption and cryptography; |
− | --- | --- |
+ (b) ICT operations security;
− | (b) | ICT operations security; |
− | --- | --- |
+ (c) network security;
− | (c) | network security; |
− | --- | --- |
+ (d) ICT project and change management;
− | (d) | ICT project and change management; |
− | --- | --- |
+ (e) the potential impact of the ICT risk on confidentiality, integrity and availability of data, and of the disruptions on the continuity and availability of the financial entity’s activities.
− | (e) | the potential impact of the ICT risk on confidentiality, integrity and availability of data, and of the disruptions on the continuity and availability of the financial entity’s activities. |
− | --- | --- |
+ ### Article 2 — General elements of ICT security policies, procedures, protocols, and tools
− ### art_2
+ **1.** Financial entities shall ensure that their ICT security policies, information security, and related procedures, protocols, and tools as referred to in Article 9(2) of Regulation (EU) 2022/2554 are embedded in their ICT risk management framework. Financial entities shall establish the ICT secu…
− Article 2
+ **2.** Financial entities shall ensure that the ICT security policies referred to in paragraph 1:(a) are aligned to the financial entity’s information security objectives included in the digital operational resilience strategy referred to in Article 6(8) of Regulation (EU) 2022/2554;(b) indicate the…
− 1. Financial entities shall ensure that their ICT security policies, information security, and related procedures, protocols, and tools as referred to in Article 9(2) of Regulation (EU) 2022/2554 are embedded in their ICT risk management framework. Financial entities shall establish the ICT security…
+ ### Article 3 — ICT risk management
− | (a) | ensure the security of networks; |
− | --- | --- |

− | (b) | contain safeguards against intrusions and data misuse; |
− | --- | --- |

− | (c) | preserve the availability, authenticity, integrity, and confidentiality of data, including via the use of cryptographic techniques; |
− | --- | --- |

− | (d) | guarantee an accurate and prompt data transmission without major disruptions and undue delays. |
− | --- | --- |

− 2. Financial entities shall ensure that the ICT security policies referred to in paragraph 1:

− | (a) | are aligned to the financial entity’s information security objectives included in the digital operational resilience strategy referred to in Article 6(8) of Regulation (EU) 2022/2554; |
− | --- | --- |
− | (b) | indicate the date of the formal approval of the ICT security policies by the management body; |
− | --- | --- |

− | (c) | contain indicators and measures to:(i)monitor the implementation of the ICT security policies, procedures, protocols, and tools;(ii)record exceptions from that implementation;(iii)ensure that the digital operational resilience of the financial entity is ensured in case of exceptions as refer…
− | --- | --- |
− | (i) | monitor the implementation of the ICT security policies, procedures, protocols, and tools; |
− | (ii) | record exceptions from that implementation; |
− | (iii) | ensure that the digital operational resilience of the financial entity is ensured in case of exceptions as referred to in point (ii); |

− | (d) | specify the responsibilities of staff at all levels to ensure the financial entity’s ICT security; |
− | --- | --- |

− | (e) | specify the consequences of non-compliance by staff of the financial entity with the ICT security policies, where provisions to that effect are not laid down in other policies of the financial entity; |
− | --- | --- |

− | (f) | list the documentation to be maintained; |
− | --- | --- |

− | (g) | specify the segregation of duties arrangements in the context of the three lines of defence model or other internal risk management and control model, as applicable, to avoid conflicts of interest; |
− | --- | --- |

− | (h) | consider leading practices and, where applicable, standards as defined in Article 2, point (1), of Regulation (EU) No 1025/2012; |
− | --- | --- |

− | (i) | identify the roles and responsibilities for the development, implementation and maintenance of ICT security policies, procedures, protocols, and tools; |
− | --- | --- |

− | (j) | are reviewed in accordance with Article 6(5) of Regulation (EU) 2022/2554; |
− | --- | --- |

− | (k) | take into account material changes concerning the financial entity, including material changes to the activities or processes of the financial entity, to the cyber threat landscape, or to applicable legal obligations. |
− | --- | --- |

− ### art_3

− Article 3

+ (a) an indication of the approval of the risk tolerance level for ICT risk established in accordance with Article 6(8), point (b), of Regulation (EU) 2022/2554;
− | (a) | an indication of the approval of the risk tolerance level for ICT risk established in accordance with Article 6(8), point (b), of Regulation (EU) 2022/2554; |
− | --- | --- |
+ (b) a procedure and a methodology to conduct the ICT risk assessment, identifying: (i) vulnerabilities and threats that affect or may affect the supported business functions, the ICT systems and ICT assets supporting those functions; (ii) the quantitative or qualitative indicators to measure the imp…
− | (b) | a procedure and a methodology to conduct the ICT risk assessment, identifying:(i)vulnerabilities and threats that affect or may affect the supported business functions, the ICT systems and ICT assets supporting those functions;(ii)the quantitative or qualitative indicators to measure the imp…
− | --- | --- |
− | (i) | vulnerabilities and threats that affect or may affect the supported business functions, the ICT systems and ICT assets supporting those functions; |
− | (ii) | the quantitative or qualitative indicators to measure the impact and likelihood of the vulnerabilities and threats referred to in point (i); |
+ (c) the procedure to identify, implement, and document ICT risk treatment measures for the ICT risks identified and assessed, including the determination of ICT risk treatment measures necessary to bring ICT risk within the risk tolerance level referred to in point (a);
− | (c) | the procedure to identify, implement, and document ICT risk treatment measures for the ICT risks identified and assessed, including the determination of ICT risk treatment measures necessary to bring ICT risk within the risk tolerance level referred to in point (a); |
− | --- | --- |
+ (d) for the residual ICT risks that are still present following the implementation of the ICT risk treatment measures referred to in point (c): (i) provisions on the identification of those residual ICT risks; (ii) the assignment of roles and responsibilities regarding: (1) the acceptance of the res…
− | (d) | for the residual ICT risks that are still present following the implementation of the ICT risk treatment measures referred to in point (c):(i)provisions on the identification of those residual ICT risks;(ii)the assignment of roles and responsibilities regarding:(1)the acceptance of the resid…
− | --- | --- |
− | (i) | provisions on the identification of those residual ICT risks; |
− | (ii) | the assignment of roles and responsibilities regarding:(1)the acceptance of the residual ICT risks that exceed the financial entity’s risk tolerance level referred to in point (a);(2)for the review process referred to in point (iv) of this point (d); |
− | (1) | the acceptance of the residual ICT risks that exceed the financial entity’s risk tolerance level referred to in point (a); |
− | (2) | for the review process referred to in point (iv) of this point (d); |
− | (iii) | the development of an inventory of the accepted residual ICT risks, including a justification for their acceptance; |
− | (iv) | provisions on the review of the accepted residual ICT risks at least once a year, including:(1)the identification of any changes to the residual ICT risks;(2)the assessment of available mitigation measures;(3)the assessment of whether the reasons justifying the acceptance of residual ICT ri…
− | (1) | the identification of any changes to the residual ICT risks; |
− | (2) | the assessment of available mitigation measures; |
− | (3) | the assessment of whether the reasons justifying the acceptance of residual ICT risks are still valid and applicable at the date of the review; |
+ (e) provisions on the monitoring of: (i) any changes to the ICT risk and cyber threat landscape; (ii) internal and external vulnerabilities and threats: (iii) ICT risk of the financial entity that enables promp detection of changes that could affect its ICT risk profile;
− | (e) | provisions on the monitoring of:(i)any changes to the ICT risk and cyber threat landscape;(ii)internal and external vulnerabilities and threats:(iii)ICT risk of the financial entity that enables promp detection of changes that could affect its ICT risk profile; |
− | --- | --- |
− | (i) | any changes to the ICT risk and cyber threat landscape; |
− | (ii) | internal and external vulnerabilities and threats: |
− | (iii) | ICT risk of the financial entity that enables promp detection of changes that could affect its ICT risk profile; |
+ (f) provisions on a process to ensure that any changes to the business strategy and the digital operational resilience strategy of the financial entity are taken into account.
− | (f) | provisions on a process to ensure that any changes to the business strategy and the digital operational resilience strategy of the financial entity are taken into account. |
− | --- | --- |
+ (a) the monitoring of the effectiveness of the ICT risk treatment measures implemented;
− | (a) | the monitoring of the effectiveness of the ICT risk treatment measures implemented; |
− | --- | --- |
+ (b) the assessment of whether the established risk tolerance levels of the financial entity have been attained;
− | (b) | the assessment of whether the established risk tolerance levels of the financial entity have been attained; |
− | --- | --- |
+ (c) the assessment of whether the financial entity has taken actions to correct or improve those measures where necessary.
− | (c) | the assessment of whether the financial entity has taken actions to correct or improve those measures where necessary. |
− | --- | --- |
+ ### Article 4 — ICT asset management policy
− ### art_4
+ **1.** As part of the ICT security policies, procedures, protocols, and tools referred to in Article 9(2) of Regulation (EU) 2022/2554, financial entities shall develop, document, and implement a policy on management of ICT assets.
− Article 4
+ **2.** The policy on management of ICT assets referred to in paragraph 1 shall:(a) prescribe the monitoring and management of the lifecycle of ICT assets identified and classified in accordance with Article 8(1) of Regulation (EU) 2022/2554;(b) prescribe that the financial entity keeps records of al…
− 1. As part of the ICT security policies, procedures, protocols, and tools referred to in Article 9(2) of Regulation (EU) 2022/2554, financial entities shall develop, document, and implement a policy on management of ICT assets.
+ ### Article 5 — ICT asset management procedure
− 2. The policy on management of ICT assets referred to in paragraph 1 shall:
+ **1.** Financial entities shall develop, document, and implement a procedure for the management of ICT assets.
− | (a) | prescribe the monitoring and management of the lifecycle of ICT assets identified and classified in accordance with Article 8(1) of Regulation (EU) 2022/2554; |
− | --- | --- |
+ **2.** The procedure for management of ICT assets referred to in paragraph 1 shall specify the criteria to perform the criticality assessment of information assets and ICT assets supporting business functions. That assessment shall take into account:(a) the ICT risk related to those business functio…
− | (b) | prescribe that the financial entity keeps records of all of the following:(i)the unique identifier of each ICT asset;(ii)information on the location, either physical or logical, of all ICT assets;(iii)the classification of all ICT assets, as referred to in Article 8(1) of Regulation (EU) 202…
− | --- | --- |
− | (i) | the unique identifier of each ICT asset; |
− | (ii) | information on the location, either physical or logical, of all ICT assets; |
− | (iii) | the classification of all ICT assets, as referred to in Article 8(1) of Regulation (EU) 2022/2254; |
− | (iv) | the identity of ICT asset owners; |
− | (v) | the business functions or services supported by the ICT asset; |
− | (vi) | the ICT business continuity requirements, including recovery time objectives and recovery point objectives; |
− | (vii) | whether the ICT asset can be or is exposed to external networks, including the internet; |
− | (viii) | the links and interdependencies among ICT assets and the business functions using each ICT asset; |
− | (ix) | where applicable, for all ICT assets, the end dates of the ICT third-party service provider’s regular, extended, and custom support services after which those ICT assets are no longer supported by their supplier or by an ICT third-party service provider; |
+ ### Article 6 — Encryption and cryptographic controls
− | (c) | for financial entities other than microenterprises, prescribe that those financial entities keep records of the information necessary to perform a specific ICT risk assessment on all legacy ICT systems referred to in Article 8(7) of Regulation (EU) 2022/2554. |
− | --- | --- |

− ### art_5
+ **1.** As part of their ICT security policies, procedures, protocols, and tools referred to in Article 9(2) of Regulation (EU) 2022/2554, financial entities shall develop, document, and implement a policy on encryption and cryptographic controls.
− Article 5

− 1. Financial entities shall develop, document, and implement a procedure for the management of ICT assets.

− 2. The procedure for management of ICT assets referred to in paragraph 1 shall specify the criteria to perform the criticality assessment of information assets and ICT assets supporting business functions. That assessment shall take into account:
+ **2.** Financial entities shall design the policy on encryption and cryptographic controls referred to in paragraph 1 on the basis of the results of an approved data classification and ICT risk assessment. That policy shall contain rules for all of the following:(a) the encryption of data at rest an…
− | (a) | the ICT risk related to those business functions and their dependencies on the information assets or ICT assets; |
− | --- | --- |

− | (b) | how the loss of confidentiality, integrity, and availability of such information assets and ICT assets would impact the business processes and activities of the financial entities. |
− | --- | --- |

− ### art_6

− Article 6
− 1. As part of their ICT security policies, procedures, protocols, and tools referred to in Article 9(2) of Regulation (EU) 2022/2554, financial entities shall develop, document, and implement a policy on encryption and cryptographic controls.

− 2. Financial entities shall design the policy on encryption and cryptographic controls referred to in paragraph 1 on the basis of the results of an approved data classification and ICT risk assessment. That policy shall contain rules for all of the following:

− | (a) | the encryption of data at rest and in transit; |
− | --- | --- |

− | (b) | the encryption of data in use, where necessary; |
− | --- | --- |

− | (c) | the encryption of internal network connections and traffic with external parties; |
− | --- | --- |

− | (d) | the cryptographic key management referred to in Article 7, laying down rules on the correct use, protection, and lifecycle of cryptographic keys. |
− | --- | --- |

+ **3.** Financial entities shall include in the policy on encryption and cryptographic controls referred to in paragraph 1 criteria for the selection of cryptographic techniques and use practices, taking into account leading practices, and standards as defined in Article 2, point (1), of Regulation (…
− 3. Financial entities shall include in the policy on encryption and cryptographic controls referred to in paragraph 1 criteria for the selection of cryptographic techniques and use practices, taking into account leading practices, and standards as defined in Article 2, point (1), of Regulation (EU) …
+ **4.** Financial entities shall include in the policy on encryption and cryptographic controls referred to in paragraph 1 provisions for updating or changing, where necessary, the cryptographic technology on the basis of developments in cryptanalysis. Those updates or changes shall ensure that the c…
− 4. Financial entities shall include in the policy on encryption and cryptographic controls referred to in paragraph 1 provisions for updating or changing, where necessary, the cryptographic technology on the basis of developments in cryptanalysis. Those updates or changes shall ensure that the crypt…
+ **5.** Financial entities shall include in the policy on encryption and cryptographic controls referred to in paragraph 1 a requirement to record the adoption of mitigation and monitoring measures adopted in accordance with paragraphs 3 and 4 and to provide a reasoned explanation for doing so.
− 5. Financial entities shall include in the policy on encryption and cryptographic controls referred to in paragraph 1 a requirement to record the adoption of mitigation and monitoring measures adopted in accordance with paragraphs 3 and 4 and to provide a reasoned explanation for doing so.
+ ### Article 7 — Cryptographic key management
− ### art_7
+ **1.** Financial entities shall include in the cryptographic key management policy referred to in Article 6(2), point (d), requirements for managing cryptographic keys through their whole lifecycle, including generating, renewing, storing, backing up, archiving, retrieving, transmitting, retiring, r…
− Article 7
+ **2.** Financial entities shall identify and implement controls to protect cryptographic keys through their whole lifecycle against loss, unauthorised access, disclosure, and modification. Financial entities shall design those controls on the basis of the results of the approved data classification …
− 1. Financial entities shall include in the cryptographic key management policy referred to in Article 6(2), point (d), requirements for managing cryptographic keys through their whole lifecycle, including generating, renewing, storing, backing up, archiving, retrieving, transmitting, retiring, revok…
+ **3.** Financial entities shall develop and implement methods to replace the cryptographic keys in the case of loss, or where those keys are compromised or damaged.
− 2. Financial entities shall identify and implement controls to protect cryptographic keys through their whole lifecycle against loss, unauthorised access, disclosure, and modification. Financial entities shall design those controls on the basis of the results of the approved data classification and …
+ **4.** Financial entities shall create and maintain a register for all certificates and certificate-storing devices for at least ICT assets supporting critical or important functions. Financial entities shall keep that register up to date.
− 3. Financial entities shall develop and implement methods to replace the cryptographic keys in the case of loss, or where those keys are compromised or damaged.

− 4. Financial entities shall create and maintain a register for all certificates and certificate-storing devices for at least ICT assets supporting critical or important functions. Financial entities shall keep that register up to date.
+ **5.** Financial entities shall ensure the prompt renewal of certificates in advance of their expiration.
− 5. Financial entities shall ensure the prompt renewal of certificates in advance of their expiration.
+ ### Article 8 — Policies and procedures for ICT operations
− ### art_8
+ **1.** As part of the ICT security policies, procedures, protocols, and tools referred to in Article 9(2) of Regulation (EU) 2022/2554, financial entities shall develop, document, and implement policies and procedures to manage the ICT operations. Those policies and procedures shall specify how fina…
− Article 8
+ **2.** The policies and procedures for ICT operations referred to in paragraph 1 shall contain all of the following:(a) an ICT assets description, including all of the following:(i) requirements regarding secure installation, maintenance, configuration, and deinstallation of an ICT system;(ii) requi…
− 1. As part of the ICT security policies, procedures, protocols, and tools referred to in Article 9(2) of Regulation (EU) 2022/2554, financial entities shall develop, document, and implement policies and procedures to manage the ICT operations. Those policies and procedures shall specify how financia…

− 2. The policies and procedures for ICT operations referred to in paragraph 1 shall contain all of the following:

− | (a) | an ICT assets description, including all of the following:(i)requirements regarding secure installation, maintenance, configuration, and deinstallation of an ICT system;(ii)requirements regarding the management of information assets used by ICT assets, including their processing and handling…
− | --- | --- |
− | (i) | requirements regarding secure installation, maintenance, configuration, and deinstallation of an ICT system; |
− | (ii) | requirements regarding the management of information assets used by ICT assets, including their processing and handling, both automated and manual; |
− | (iii) | requirements regarding the identification and control of legacy ICT systems; |

− | (b) | controls and monitoring of ICT systems, including all of the following:(i)backup and restore requirements of ICT systems;(ii)scheduling requirements, taking into consideration interdependencies among the ICT systems;(iii)protocols for audit-trail and system log information;(iv)requirements t…
− | --- | --- |
− | (i) | backup and restore requirements of ICT systems; |
− | (ii) | scheduling requirements, taking into consideration interdependencies among the ICT systems; |
− | (iii) | protocols for audit-trail and system log information; |
− | (iv) | requirements to ensure that the performance of internal audit and other testing minimises disruptions to business operations; |
− | (v) | requirements on the separation of ICT production environments from the development, testing, and other non-production environments; |
− | (vi) | requirements to conduct the development and testing in environments which are separated from the production environment; |
− | (vii) | requirements to conduct the development and testing in production environments; |

− | (c) | error handling concerning ICT systems, including all of the following:(i)procedures and protocols for handling errors;(ii)support and escalation contacts, including external support contacts in case of unexpected operational or technical issues;(iii)ICT system restart, rollback, and recovery…
− | --- | --- |
− | (i) | procedures and protocols for handling errors; |
− | (ii) | support and escalation contacts, including external support contacts in case of unexpected operational or technical issues; |
− | (iii) | ICT system restart, rollback, and recovery procedures for use in the event of ICT system disruption. |
+ ### Article 9 — Capacity and performance management
− ### art_9
+ **1.** As part of the ICT security policies, procedures, protocols, and tools referred to in Article 9(2) of Regulation (EU) 2022/2554, financial entities shall develop, document, and implement capacity and performance management procedures for the following:(a) the identification of capacity requir…
− Article 9
+ **2.** The capacity and performance management procedures referred to in paragraph 1 shall ensure that financial entities take measures that are appropriate to cater for the specificities of ICT systems with long or complex procurement or approval processes or ICT systems that are resource-intensive…
− 1. As part of the ICT security policies, procedures, protocols, and tools referred to in Article 9(2) of Regulation (EU) 2022/2554, financial entities shall develop, document, and implement capacity and performance management procedures for the following:
+ ### Article 10 — Vulnerability and patch management
− | (a) | the identification of capacity requirements of their ICT systems; |
− | --- | --- |
+ **1.** As part of the ICT security policies, procedures, protocols, and tools referred to in Article 9(2) of Regulation (EU) 2022/2554, financial entities shall develop, document, and implement vulnerability management procedures.
− | (b) | the application of resource optimisation; |
− | --- | --- |
+ **2.** The vulnerability management procedures referred to in paragraph 1 shall:(a) identify and update relevant and trustworthy information resources to build and maintain awareness about vulnerabilities;(b) ensure the performance of automated vulnerability scanning and assessments on ICT assets, w…
− | (c) | the monitoring procedures for maintaining and improving:(i)the availability of data and ICT systems;(ii)the efficiency of ICT systems;(iii)the prevention of ICT capacity shortages. |
− | --- | --- |
− | (i) | the availability of data and ICT systems; |
− | (ii) | the efficiency of ICT systems; |
− | (iii) | the prevention of ICT capacity shortages. |
− 2. The capacity and performance management procedures referred to in paragraph 1 shall ensure that financial entities take measures that are appropriate to cater for the specificities of ICT systems with long or complex procurement or approval processes or ICT systems that are resource-intensive.

− ### art_10

− Article 10

− 1. As part of the ICT security policies, procedures, protocols, and tools referred to in Article 9(2) of Regulation (EU) 2022/2554, financial entities shall develop, document, and implement vulnerability management procedures.

− 2. The vulnerability management procedures referred to in paragraph 1 shall:

− | (a) | identify and update relevant and trustworthy information resources to build and maintain awareness about vulnerabilities; |
− | --- | --- |

− | (b) | ensure the performance of automated vulnerability scanning and assessments on ICT assets, whereby the frequency and scope of those activities shall be commensurate to the classification established in accordance with Article 8(1) of Regulation (EU) 2022/2554 and the overall risk profile of t…
− | --- | --- |

− | (c) | verify whether:(i)ICT third-party service providers handle vulnerabilities related to the ICT services provided to the financial entity;(ii)whether those service providers report to the financial entity at least the critical vulnerabilities and statistics and trends in a timely manner; |
− | --- | --- |
− | (i) | ICT third-party service providers handle vulnerabilities related to the ICT services provided to the financial entity; |
− | (ii) | whether those service providers report to the financial entity at least the critical vulnerabilities and statistics and trends in a timely manner; |

− | (d) | track the usage of:(i)third-party libraries, including open-source libraries, used by ICT services supporting critical or important functions;(ii)ICT services developed by the financial entity itself or specifically customised or developed for the financial entity by an ICT third-party servi…
− | --- | --- |
− | (i) | third-party libraries, including open-source libraries, used by ICT services supporting critical or important functions; |
− | (ii) | ICT services developed by the financial entity itself or specifically customised or developed for the financial entity by an ICT third-party service provider; |

− | (e) | establish procedures for the responsible disclosure of vulnerabilities to clients, counterparties, and to the public; |
− | --- | --- |

− | (f) | prioritise the deployment of patches and other mitigation measures to address the vulnerabilities identified; |
− | --- | --- |

− | (g) | monitor and verify the remediation of vulnerabilities; |
− | --- | --- |

− | (h) | require the recording of any detected vulnerabilities affecting ICT systems and the monitoring of their resolution. |
− | --- | --- |

+ **3.** As part of the ICT security policies, procedures, protocols, and tools referred to in Article 9(2) of Regulation (EU) 2022/2554, financial entities shall develop, document and implement patch management procedures.
− 3. As part of the ICT security policies, procedures, protocols, and tools referred to in Article 9(2) of Regulation (EU) 2022/2554, financial entities shall develop, document and implement patch management procedures.
+ **4.** The patch management procedures referred to in paragraph 3 shall:(a) to the extent possible identify and evaluate available software and hardware patches and updates using automated tools;(b) identify emergency procedures for the patching and updating of ICT assets;(c) test and deploy the sof…
− 4. The patch management procedures referred to in paragraph 3 shall:
+ ### Article 11 — Data and system security
− | (a) | to the extent possible identify and evaluate available software and hardware patches and updates using automated tools; |
− | --- | --- |
+ **1.** As part of the ICT security policies, procedures, protocols, and tools referred to in Article 9(2) of Regulation (EU) 2022/2554, financial entities shall develop, document, and implement a data and system security procedure.
− | (b) | identify emergency procedures for the patching and updating of ICT assets; |
− | --- | --- |
+ **2.** The data and system security procedure referred to in paragraph 1 shall contain all of the following elements related to data and ICT system security, in accordance with the classification established in accordance with Article 8(1) of Regulation (EU) 2022/2554:(a) the access restrictions ref…
− | (c) | test and deploy the software and hardware patches and the updates referred to in Article 8(2), points (b)(v), (vi) and (vii); |
− | --- | --- |

− | (d) | set deadlines for the installation of software and hardware patches and updates and escalation procedures in case those deadlines cannot be met. |
− | --- | --- |

− ### art_11

− Article 11

− 1. As part of the ICT security policies, procedures, protocols, and tools referred to in Article 9(2) of Regulation (EU) 2022/2554, financial entities shall develop, document, and implement a data and system security procedure.

− 2. The data and system security procedure referred to in paragraph 1 shall contain all of the following elements related to data and ICT system security, in accordance with the classification established in accordance with Article 8(1) of Regulation (EU) 2022/2554:
− | (a) | the access restrictions referred to in Article 21 of this Regulation, supporting the protection requirements for each level of classification; |
− | --- | --- |

− | (b) | the identification of a secure configuration baseline for ICT assets that minimise exposure of those ICT assets to cyber threats and measures to verify regularly that those baselines are effectively deployed; |
− | --- | --- |

− | (c) | the identification of security measures to ensure that only authorised software is installed in ICT systems and endpoint devices; |
− | --- | --- |

− | (d) | the identification of security measures against malicious codes; |
− | --- | --- |

− | (e) | the identification of security measures to ensure that only authorised data storage media, systems, and endpoint devices are used to transfer and store data of the financial entity; |
− | --- | --- |

− | (f) | the following requirements to secure the use of portable endpoint devices and private non-portable endpoint devices:(i)the requirement to use a management solution to remotely manage the endpoint devices and remotely wipe the financial entity’s data;(ii)the requirement to use security mechan…
− | --- | --- |
− | (i) | the requirement to use a management solution to remotely manage the endpoint devices and remotely wipe the financial entity’s data; |
− | (ii) | the requirement to use security mechanisms that cannot be modified, removed or bypassed by staff members or ICT third-party service providers in an unauthorised manner; |
− | (iii) | the requirement to use removable data storage devices only where the residual ICT risk remains within the financial entity’s risk tolerance level referred to in Article 3, first subparagraph, point (a); |

− | (g) | the process to securely delete data, present on premises of the financial entity or stored externally, that the financial entity no longer needs to collect or to store; |
− | --- | --- |

− | (h) | the process to securely dispose or decommission of data storage devices present on premises of the financial entity or stored externally containing confidential information; |
− | --- | --- |

− | (i) | the identification and implementation of security measures to prevent data loss and leakage for systems and endpoint devices; |
− | --- | --- |

− | (j) | the implementation of security measures to ensure that teleworking and the use of private endpoint devices does not adversely impact the ICT security of the financial entity; |
− | --- | --- |

− | (k) | for ICT assets or services operated by an ICT third-party service provider, the identification and implementation of requirements to maintain digital operational resilience, in accordance with the results of the data classification and ICT risk assessment. |
− | --- | --- |

+ (a) the implementation of vendor recommended settings on the elements operated by the financial entity;
− | (a) | the implementation of vendor recommended settings on the elements operated by the financial entity; |
− | --- | --- |
+ (b) a clear allocation of information security roles and responsibilities between the financial entity and the ICT third-party service provider, in accordance with the principle of full responsibility of the financial entity over its ICT third-party service provider referred to in Article 28(1), poi…
− | (b) | a clear allocation of information security roles and responsibilities between the financial entity and the ICT third-party service provider, in accordance with the principle of full responsibility of the financial entity over its ICT third-party service provider referred to in Article 28(1),…
− | --- | --- |
+ (c) the need to ensure and maintain adequate competences within the financial entity in the management and security of the service used;
− | (c) | the need to ensure and maintain adequate competences within the financial entity in the management and security of the service used; |
− | --- | --- |
+ (d) technical and organisational measures to minimise the risks related to the infrastructure used by the ICT third-party service provider for its ICT services, considering leading practices, and standards as defined in Article 2, point (1), of Regulation (EU) No 1025/2012.
− | (d) | technical and organisational measures to minimise the risks related to the infrastructure used by the ICT third-party service provider for its ICT services, considering leading practices, and standards as defined in Article 2, point (1), of Regulation (EU) No 1025/2012. |
− | --- | --- |
+ ### Article 12 — Logging
− ### art_12
+ **1.** Financial entities shall, as part of the safeguards against intrusions and data misuse, develop, document, and implement logging procedures, protocols and tools.
− Article 12
+ **2.** The logging procedures, protocols, and tools referred to in paragraph 1 shall contain all of the following:(a) the identification of the events to be logged, the retention period of the logs, and the measures to secure and handle the log data, considering the purpose for which the logs are cr…
− 1. Financial entities shall, as part of the safeguards against intrusions and data misuse, develop, document, and implement logging procedures, protocols and tools.

− 2. The logging procedures, protocols, and tools referred to in paragraph 1 shall contain all of the following:

− | (a) | the identification of the events to be logged, the retention period of the logs, and the measures to secure and handle the log data, considering the purpose for which the logs are created; |
− | --- | --- |

− | (b) | the alignment of the level of detail of the logs with their purpose and usage to enable the effective detection of anomalous activities as referred to in Article 24; |
− | --- | --- |
− | (c) | the requirement to log events related to all of the following:(i)logical and physical access control, as referred to in Article 21, and identity management;(ii)capacity management;(iii)change management;(iv)ICT operations, including ICT system activities;(v)network traffic activities, includ…
− | --- | --- |
− | (i) | logical and physical access control, as referred to in Article 21, and identity management; |
− | (ii) | capacity management; |
− | (iii) | change management; |
− | (iv) | ICT operations, including ICT system activities; |
− | (v) | network traffic activities, including ICT network performance; |

− | (d) | measures to protect logging systems and log information against tampering, deletion, and unauthorised access at rest, in transit, and, where relevant, in use; |
− | --- | --- |

− | (e) | measures to detect a failure of logging systems; |
− | --- | --- |

− | (f) | without prejudice to any applicable regulatory requirements under Union or national law, the synchronisation of the clocks of each of the financial entity’s ICT systems upon a documented reliable reference time source. |
− | --- | --- |

+ ### Article 13 — Network security management
− ### art_13

− Article 13
+ (a) the segregation and segmentation of ICT systems and networks taking into account: (i) the criticality or importance of the function those ICT systems and networks support; (ii) the classification established in accordance with Article 8(1) of Regulation (EU) 2022/2554; (iii) the overall risk pro…
− | (a) | the segregation and segmentation of ICT systems and networks taking into account:(i)the criticality or importance of the function those ICT systems and networks support;(ii)the classification established in accordance with Article 8(1) of Regulation (EU) 2022/2554;(iii)the overall risk profi…
− | --- | --- |
− | (i) | the criticality or importance of the function those ICT systems and networks support; |
− | (ii) | the classification established in accordance with Article 8(1) of Regulation (EU) 2022/2554; |
− | (iii) | the overall risk profile of ICT assets using those ICT systems and networks; |
+ (b) the documentation of all of the financial entity’s network connections and data flows;
− | (b) | the documentation of all of the financial entity’s network connections and data flows; |
− | --- | --- |
+ (c) the use of a separate and dedicated network for the administration of ICT assets;
− | (c) | the use of a separate and dedicated network for the administration of ICT assets; |
− | --- | --- |
+ (d) the identification and implementation of network access controls to prevent and detect connections to the financial entity’s network by any unauthorised device or system, or any endpoint not meeting the financial entity’s security requirements;
− | (d) | the identification and implementation of network access controls to prevent and detect connections to the financial entity’s network by any unauthorised device or system, or any endpoint not meeting the financial entity’s security requirements; |
− | --- | --- |
+ (e) the encryption of network connections passing over corporate networks, public networks, domestic networks, third-party networks, and wireless networks, for communication protocols used, taking into account the results of the approved data classification, the results of the ICT risk assessment an…
− | (e) | the encryption of network connections passing over corporate networks, public networks, domestic networks, third-party networks, and wireless networks, for communication protocols used, taking into account the results of the approved data classification, the results of the ICT risk assessmen…
− | --- | --- |
+ (f) the design of networks in line with the ICT security requirements established by the financial entity, taking into account leading practices to ensure the confidentiality, integrity, and availability of the network;
− | (f) | the design of networks in line with the ICT security requirements established by the financial entity, taking into account leading practices to ensure the confidentiality, integrity, and availability of the network; |
− | --- | --- |
+ (g) the securing of network traffic between the internal networks and the internet and other external connections;
− | (g) | the securing of network traffic between the internal networks and the internet and other external connections; |
− | --- | --- |
+ (h) the identification of the roles and responsibilities and steps for the specification, implementation, approval, change, and review of firewall rules and connections filters;
− | (h) | the identification of the roles and responsibilities and steps for the specification, implementation, approval, change, and review of firewall rules and connections filters; |
− | --- | --- |
+ (i) the performance of reviews of the network architecture and of the network security design once a year, and periodically for microenterprises, to identify potential vulnerabilities;
− | (i) | the performance of reviews of the network architecture and of the network security design once a year, and periodically for microenterprises, to identify potential vulnerabilities; |
− | --- | --- |
+ (j) the measures to temporarily isolate, where necessary, subnetworks, and network components and devices;
− | (j) | the measures to temporarily isolate, where necessary, subnetworks, and network components and devices; |
− | --- | --- |
+ (k) the implementation of a secure configuration baseline of all network components, and the hardening of the network and of network devices in line with any vendor instructions, where applicable standards, as defined in Article 2, point (1), of Regulation (EU) No 1025/2012, and leading practices;
− | (k) | the implementation of a secure configuration baseline of all network components, and the hardening of the network and of network devices in line with any vendor instructions, where applicable standards, as defined in Article 2, point (1), of Regulation (EU) No 1025/2012, and leading practice…
− | --- | --- |
+ (l) the procedures to limit, lock, and terminate system and remote sessions after a specified period of inactivity;
− | (l) | the procedures to limit, lock, and terminate system and remote sessions after a specified period of inactivity; |
− | --- | --- |
+ (m) for network services agreements: (i) the identification and specification of ICT and information security measures, service levels, and management requirements of all network services; (ii) whether those services are provided by an ICT intra-group service provider or by ICT third-party service p…
− | (m) | for network services agreements:(i)the identification and specification of ICT and information security measures, service levels, and management requirements of all network services;(ii)whether those services are provided by an ICT intra-group service provider or by ICT third-party service p…
− | --- | --- |
− | (i) | the identification and specification of ICT and information security measures, service levels, and management requirements of all network services; |
− | (ii) | whether those services are provided by an ICT intra-group service provider or by ICT third-party service providers. |
+ ### Article 14 — Securing information in transit
− ### art_14
+ **1.** As part of the safeguards to preserve the availability, authenticity, integrity and confidentiality of data, financial entities shall develop, document, and implement the policies, procedures, protocols, and tools to protect information in transit. Financial entities shall in particular ensur…
− Article 14
+ **2.** Financial entities shall design the policies, procedures, protocols, and tools to protect the information in transit referred to in paragraph 1 on the basis of the results of the approved data classification and of the ICT risk assessment.
− 1. As part of the safeguards to preserve the availability, authenticity, integrity and confidentiality of data, financial entities shall develop, document, and implement the policies, procedures, protocols, and tools to protect information in transit. Financial entities shall in particular ensure al…
+ ### Article 15 — ICT project management
− | (a) | the availability, authenticity, integrity and confidentiality of data during network transmission, and the establishment of procedures to assess compliance with those requirements; |
− | --- | --- |
+ **1.** As part of the safeguards to preserve the availability, authenticity, integrity, and confidentiality of data, financial entities shall develop, document, and implement an ICT project management policy.
− | (b) | the prevention and detection of data leakages and the secure transfer of information between the financial entity and external parties; |
− | --- | --- |
+ **2.** The ICT project management policy referred to in paragraph 1 shall specify the elements that ensure the effective management of the ICT projects related to the acquisition, maintenance and, where applicable, development of the financial entity’s ICT systems.
− | (c) | that requirements on confidentiality or non-disclosure arrangements reflecting the financial entity’s needs for the protection of information for both the staff of the financial entity and of third parties are implemented, documented, and regularly reviewed. |
− | --- | --- |
+ **3.** The ICT project management policy referred to in paragraph 1 shall contain all of the following:(a) ICT project objectives;(b) ICT project governance, including roles and responsibilities;(c) ICT project planning, timeframe, and steps;(d) ICT project risk assessment;(e) relevant milestones;(f…
− 2. Financial entities shall design the policies, procedures, protocols, and tools to protect the information in transit referred to in paragraph 1 on the basis of the results of the approved data classification and of the ICT risk assessment.
+ **4.** The ICT project management policy referred to in paragraph 1 shall ensure the secure ICT project implementation through the provision of the necessary information and expertise from the business area or functions impacted by the ICT project.
− ### art_15
+ **5.** In accordance with the ICT project risk assessment referred to in paragraph 3, point (d), the ICT project management policy referred to in paragraph 1 shall provide that the establishment and progress of ICT projects impacting critical or important functions of the financial entity and their …
− Article 15
+ ### Article 16 — ICT systems acquisition, development, and maintenance
− 1. As part of the safeguards to preserve the availability, authenticity, integrity, and confidentiality of data, financial entities shall develop, document, and implement an ICT project management policy.
+ **1.** As part of the safeguards to preserve the availability, authenticity, integrity, and confidentiality of data, financial entities shall develop, document and implement a policy governing the acquisition, development, and maintenance of ICT systems. That policy shall:(a) identify security pract…
− 2. The ICT project management policy referred to in paragraph 1 shall specify the elements that ensure the effective management of the ICT projects related to the acquisition, maintenance and, where applicable, development of the financial entity’s ICT systems.
+ **2.** Financial entities shall develop, document, and implement an ICT systems’ acquisition, development, and maintenance procedure for the testing and approval of all ICT systems prior to their use and after maintenance, in accordance with Article 8(2), point (b), points (v), (vi) and (vii). The l…
− 3. The ICT project management policy referred to in paragraph 1 shall contain all of the following:

− | (a) | ICT project objectives; |
− | --- | --- |

− | (b) | ICT project governance, including roles and responsibilities; |
− | --- | --- |

− | (c) | ICT project planning, timeframe, and steps; |
− | --- | --- |

− | (d) | ICT project risk assessment; |
− | --- | --- |

− | (e) | relevant milestones; |
− | --- | --- |
− | (f) | change management requirements; |
− | --- | --- |

− | (g) | the testing of all requirements, including security requirements, and the respective approval process when deploying an ICT system in the production environment. |
− | --- | --- |

− 4. The ICT project management policy referred to in paragraph 1 shall ensure the secure ICT project implementation through the provision of the necessary information and expertise from the business area or functions impacted by the ICT project.

− 5. In accordance with the ICT project risk assessment referred to in paragraph 3, point (d), the ICT project management policy referred to in paragraph 1 shall provide that the establishment and progress of ICT projects impacting critical or important functions of the financial entity and their asso…

− | (a) | individually or in aggregation, depending on the importance and size of the ICT projects; |
− | --- | --- |

− | (b) | periodically and, where necessary, on an event-driven basis. |
− | --- | --- |

− ### art_16

− Article 16

− 1. As part of the safeguards to preserve the availability, authenticity, integrity, and confidentiality of data, financial entities shall develop, document and implement a policy governing the acquisition, development, and maintenance of ICT systems. That policy shall:
… diff truncated at 500 changed lines …
tierA, publisher-supplied validity dates
history beginspublisher
index built2026-08-07T19:46:23Z · corpus 8d5e859
stamp signaturevalid (ECDSA-P256)