Source: OJ L, 2024/1774, 25.6.2024
EN- Digital operational resilience in the financial sector
ICT risk management
- RTS on ICT risk management framework
Article 26 ICT response and recovery plans
When developing the ICT response and recovery plans referred to in Article 11(3) of Regulation (EU) 2022/2554, financial entitiesas defined in Article 2, points (a) to (t) shall take into account the results of the financial entity means a natural or legal person created and recognised as such under the national law of its place of establishment, which may, acting under its own name, exercise rights and be subject to obligations;’s business impact analysis (BIAbusiness impact analysis). Those ICT response and recovery plans shall:
specify the conditions prompting their activation or deactivation, and any exceptions for such activation or deactivation;
describe what actions are to be taken to ensure the availability, integrity, continuity, and recovery of at least ICT systems and services supporting critical or important functions means a function, the disruption of which would materially impair the financial performance of a financial entity, or the soundness or continuity of its services and activities, or the discontinued, defective or failed performance of that function would materially impair the continuing compliance of a financial entity with the conditions and obligations of its authorisation, or with its other obligations under applicable financial services law; of the financial entity means a natural or legal person created and recognised as such under the national law of its place of establishment, which may, acting under its own name, exercise rights and be subject to obligations;;
be designed to meet the recovery objectives of the operations of the financial entitiesas defined in Article 2, points (a) to (t);
be documented and made available to the staff involved in the execution of ICT response and recovery plans and be readily accessible in case of emergency;
provide for both short-term and long-term recovery options, including partial systems recovery;
lay down the objectives of ICT response and recovery plans and the conditions to declare a successful execution of those plans.
For the purposes of point (d), financial entitiesas defined in Article 2, points (a) to (t) shall clearly specify roles and responsibilities.
The ICT response and recovery plans referred to in paragraph 1 shall identify relevant scenarios, including scenarios of severe business disruptions and increased likelihood of occurrence of disruption. Those plans shall develop scenarios based on current information on threats and on lessons learned from previous occurrences of business disruptions. Financial entitiesas defined in Article 2, points (a) to (t) shall duly take into account all of the following scenarios:
cyber-attacks means a malicious ICT-related incident caused by means of an attempt perpetrated by any threat actor to destroy, expose, alter, disable, steal or gain unauthorised access to, or make unauthorised use of, an asset; and switchovers between the primary ICT infrastructure and the redundant capacity, backups, and redundant facilities;
scenarios in which the quality of the provision of a critical or important function means a function, the disruption of which would materially impair the financial performance of a financial entity, or the soundness or continuity of its services and activities, or the discontinued, defective or failed performance of that function would materially impair the continuing compliance of a financial entity with the conditions and obligations of its authorisation, or with its other obligations under applicable financial services law; deteriorates to an unacceptable level or fails, and duly consider the potential impact of the insolvency, or other failures, of any relevant ICT third-party service provider means an undertaking providing ICT services;;
partial or total failure of premises, including office and business premises, and data centres;
substantial failure of ICT assets means a software or hardware asset in the network and information systems used by the financial entity; or of the communication infrastructure;
the non-availability of a critical number of staff or staff members in charge of guaranteeing the continuity of operations;
impact of climate change and environment degradation related events, natural disasters, pandemics, and physical attacks, including intrusions and terrorist attacks;
insider attacks;
political and social instability, including, where relevant, in the ICT third-party service provider means an undertaking providing ICT services;’s jurisdiction and the location where the data are stored and processed;
widespread power outages.
Where the primary recovery measures may not be feasible in the short term because of costs, risks means the potential for loss or disruption caused by an incident and is to be expressed as a combination of the magnitude of such loss or disruption and the likelihood of occurrence of the incident;, logistics, or unforeseen circumstances, the ICT response and recovery plans referred to in paragraph 1 shall consider alternative options.
As part of the ICT response and recovery plans referred to in paragraph 1, financial entitiesas defined in Article 2, points (a) to (t) shall consider and implement continuity measures to mitigate failures of ICT third-party service providers means an undertaking providing ICT services; of ICT services means digital and data services provided through ICT systems to one or more internal or external users on an ongoing basis, including hardware as a service and hardware services which includes the provision of technical support via software or firmware updates by the hardware provider, excluding traditional analogue telephone services; supporting critical or important functions means a function, the disruption of which would materially impair the financial performance of a financial entity, or the soundness or continuity of its services and activities, or the discontinued, defective or failed performance of that function would materially impair the continuing compliance of a financial entity with the conditions and obligations of its authorisation, or with its other obligations under applicable financial services law; of the financial entity means a natural or legal person created and recognised as such under the national law of its place of establishment, which may, acting under its own name, exercise rights and be subject to obligations;.
Springlex and this text is meant purely as a documentation tool and has no legal effect. No liability is assumed for its content. The authentic version of this act is the one published in the Official Journal of the European Union.