Source: OJ L, 2024/1774, 25.6.2024

Current language: EN

Article 8 Policies and procedures for ICT operations


Summary What does Article 8 of the RTS on ICT risk management framework say?

This article sits within the broader ICT security framework established under Article 9(2) of DORA and focuses specifically on the operational management of ICT systems.

It requires financial entities to develop, document, and implement policies and procedures that govern how they operate, monitor, control, and restore their ICT assets.

The article covers three core operational areas: asset description and lifecycle management, system controls and monitoring, and error handling.

Notably, it addresses the sensitive topic of testing in production environments, imposing strict conditions on when and how this is permitted, linking directly to requirements set out in Article 16(6) of this regulation.

Important points:

  • Develop, document, and implement ICT operations policies covering asset management, system controls and monitoring, and error handling procedures.
  • Separate production environments from development and testing environments across all components, including accounts, data, and connections.
  • Testing in production environments is only permitted in clearly identified and reasoned instances, for limited periods, and must be approved by the relevant function.

Springlex's summary of the article, a reading aid, not a substitute for the legal text.

    1. As part of the ICT security policies, procedures, protocols, and tools referred to in Article 9(2) of Regulation (EU) 2022/2554, financial entities shall develop, document, and implement policies and procedures to manage the ICT operations. Those policies and procedures shall specify how financial entities operate, monitor, control, and restore their ICT assets, including the documentation of ICT operations.

    1. The policies and procedures for ICT operations referred to in paragraph 1 shall contain all of the following:

      1. an ICT assets description, including all of the following:

        1. requirements regarding secure installation, maintenance, configuration, and deinstallation of an ICT system;

        2. requirements regarding the management of information assets used by ICT assets, including their processing and handling, both automated and manual;

        3. requirements regarding the identification and control of legacy ICT systems;

      2. controls and monitoring of ICT systems, including all of the following:

        1. backup and restore requirements of ICT systems;

        2. scheduling requirements, taking into consideration interdependencies among the ICT systems;

        3. protocols for audit-trail and system log information;

        4. requirements to ensure that the performance of internal audit and other testing minimises disruptions to business operations;

        5. requirements on the separation of ICT production environments from the development, testing, and other non-production environments;

        6. requirements to conduct the development and testing in environments which are separated from the production environment;

        7. requirements to conduct the development and testing in production environments;

      3. error handling concerning ICT systems, including all of the following:

        1. procedures and protocols for handling errors;

        2. support and escalation contacts, including external support contacts in case of unexpected operational or technical issues;

        3. ICT system restart, rollback, and recovery procedures for use in the event of ICT system disruption.

    2. For the purposes of point (b)(v), the separation shall consider all of the components of the environment, including accounts, data or connections, as required by Article 13, first subparagraph, point (a).

    3. For the purposes of point (b)(vii), the policies and procedures referred to in paragraph 1 shall provide that the instances in which testing is performed in a production environment are clearly identified, reasoned, are for limited periods of time, and are approved by the relevant function in accordance with Article 16(6). Financial entities shall ensure the availability, confidentiality, integrity, and authenticity of ICT systems and production data during development and test activities in the production environment.

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod