Source: OJ L, 2024/1774, 25.6.2024
EN- Digital operational resilience in the financial sector
ICT risk management
- RTS on ICT risk management framework
Article 9 Capacity and performance management
As part of the ICT security policies, procedures, protocols, and tools referred to in Article 9(2) of Regulation (EU) 2022/2554, financial entitiesas defined in Article 2, points (a) to (t) shall develop, document, and implement capacity and performance management procedures for the following:
the identification of capacity requirements of their ICT systems;
the application of resource optimisation;
the monitoring procedures for maintaining and improving:
the availability of data and ICT systems;
the efficiency of ICT systems;
the prevention of ICT capacity shortages.
The capacity and performance management procedures referred to in paragraph 1 shall ensure that financial entitiesas defined in Article 2, points (a) to (t) take measures that are appropriate to cater for the specificities of ICT systems with long or complex procurement or approval processes or ICT systems that are resource-intensive.
Springlex and this text is meant purely as a documentation tool and has no legal effect. No liability is assumed for its content. The authentic version of this act is the one published in the Official Journal of the European Union.