Source: OJ L, 2024/1774, 25.6.2024Current language: EN
- Digital operational resilience in the financial sector
ICT risk management
- RTS on ICT risk management framework
Article 26 ICT response and recovery plans
Summary What does Article 26 of the RTS on ICT risk management framework say?
This article sets out the detailed requirements for ICT response and recovery plans, building directly on the ICT business continuity policy framework established in Article 24.
It requires financial entities to ground these plans in their business impact analysis and covers everything from the conditions triggering plan activation, to the range of disruption scenarios that must be accounted for.
Notably, the article provides an extensive and explicit list of scenarios that plans must address, ranging from cyber-attacks and insider threats to natural disasters, political instability, and widespread power outages, reflecting the broad threat landscape financial entities must prepare for.
Important points:
- Develop ICT response and recovery plans that are rooted in the business impact analysis, cover both short- and long-term recovery options, and are documented and accessible to relevant staff with clearly assigned roles and responsibilities.
- Ensure your plans account for a wide range of defined disruption scenarios, including cyber-attacks, ICT third-party service provider failures, staff unavailability, and physical or environmental disasters.
- Implement continuity measures within your plans to specifically mitigate failures of ICT third-party service providers supporting critical or important functions.
Springlex's summary of the article, a reading aid, not a substitute for the legal text.
When developing the ICT response and recovery plans referred to in Article 11(3) of Regulation (EU) 2022/2554, financial entities shall take into account the results of the financial entity’s business impact analysis (BIA). Those ICT response and recovery plans shall:
specify the conditions prompting their activation or deactivation, and any exceptions for such activation or deactivation;
describe what actions are to be taken to ensure the availability, integrity, continuity, and recovery of at least ICT systems and services supporting critical or important functions of the financial entity;
be designed to meet the recovery objectives of the operations of the financial entities;
be documented and made available to the staff involved in the execution of ICT response and recovery plans and be readily accessible in case of emergency;
provide for both short-term and long-term recovery options, including partial systems recovery;
lay down the objectives of ICT response and recovery plans and the conditions to declare a successful execution of those plans.
For the purposes of point (d), financial entities shall clearly specify roles and responsibilities.
The ICT response and recovery plans referred to in paragraph 1 shall identify relevant scenarios, including scenarios of severe business disruptions and increased likelihood of occurrence of disruption. Those plans shall develop scenarios based on current information on threats and on lessons learned from previous occurrences of business disruptions. Financial entities shall duly take into account all of the following scenarios:
cyber-attacks and switchovers between the primary ICT infrastructure and the redundant capacity, backups, and redundant facilities;
scenarios in which the quality of the provision of a critical or important function deteriorates to an unacceptable level or fails, and duly consider the potential impact of the insolvency, or other failures, of any relevant ICT third-party service provider;
partial or total failure of premises, including office and business premises, and data centres;
substantial failure of ICT assets or of the communication infrastructure;
the non-availability of a critical number of staff or staff members in charge of guaranteeing the continuity of operations;
impact of climate change and environment degradation related events, natural disasters, pandemics, and physical attacks, including intrusions and terrorist attacks;
insider attacks;
political and social instability, including, where relevant, in the ICT third-party service provider’s jurisdiction and the location where the data are stored and processed;
widespread power outages.
Where the primary recovery measures may not be feasible in the short term because of costs, risks, logistics, or unforeseen circumstances, the ICT response and recovery plans referred to in paragraph 1 shall consider alternative options.
As part of the ICT response and recovery plans referred to in paragraph 1, financial entities shall consider and implement continuity measures to mitigate failures of ICT third-party service providers of ICT services supporting critical or important functions of the financial entity.
Relevant recitals
Recital 23 Business continuity scenarios
It is necessary to set out the set of scenarios that financial entities referred to in Title II of this Regulation should take into account both for the implementation of ICT response and recovery plans and for the testing of ICT business continuity plans. Those scenarios should serve as a starting point for financial entities to analyse both the relevance and plausibility of each scenario and the need to develop alternative scenarios. Financial entities should focus on those scenarios in which investment in resilience measures could be more efficient and effective. By testing switchovers between the primary ICT infrastructure and any redundant capacity, backups and redundant facilities, financial institutions should assess whether that capacity, backup, and those facilities operate effectively for a sufficient period of time and ensure that the normal functioning of the primary ICT infrastructure is restored in accordance with the recovery objectives.
Springlex and this text is meant purely as a documentation tool and has no legal effect. No liability is assumed for its content. The authentic version of this act is the one published in the Official Journal of the European Union.
Definition
ICT third-party service provider
Definition
ICT asset
Definition
network and information system
Definition
cyber-attack
Definition
ICT services
Definition
ICT-related incident
Definition
critical or important function