EBA consults on Guidelines on security measures for operational and security risks under the PSD2

Autor:

Bancherul.ro
2017-05-08 10:16

The European Banking Authority (EBA) launched today a consultation on its draft Guidelines on security measures for operational and security risks under the revised Payment Services Directive (PSD2).

The Guidelines have been developed in close cooperation with the European Central Bank (ECB), and are in support of the objectives of PSD2, such as strengthening the integrated payments market in the EU, mitigating the increased security risks arising from electronic payments, and promoting equal conditions for competition. The consultation runs until 7 August 2017.

PSD2 requires payment service providers (PSPs) to establish a framework with appropriate mitigation measures and control mechanisms to manage operational and security risks arising from the payment services they provide, and has mandated the EBA to specify the details of these requirements.

In particular, these draft Guidelines cover the governance of the operational and security risk management framework, the risk management and control models, outsourcing, the identification, classification and risk assessment of functions, processes and assets, as well as the protection of the integrity of data, systems and confidentiality, physical security and asset control.

In addition, the draft Guidelines propose requirements in relation to the monitoring, detection and reporting of security incidents and risks, business continuity management, scenario-based continuity plans, incident management and crisis communication, the testing of security measures, and situational awareness and continuous learning.

Finally, in order to ensure that the security measures implemented by the PSPs are well communicated to payment service users (PSUs) the Guidelines also cover the management of the relationship with PSUs.

Consultation process

Responses to this consultation can be sent to the EBA by clicking on the “send your comments” button on the website. All contributions received will be published following the close of the consultation, unless requested otherwise. Please note that the deadline for the submission of comments is 7 August 2017 and that no attachments can be submitted. A public hearing will then take place at the EBA premises on 20 June 2017 from 13.00 to 16.00 UK time.

Legal basis and background

These Guidelines have been drafted in accordance with Article 95(3) of Directive (EU) 2015/2366 on payment services in the internal market (PSD2), which mandates the EBA, in close cooperation with the ECB, to issue Guidelines with regard to the establishment, implementation and monitoring of the security measures, including certification processes where relevant. The Guidelines are addressed to both competent authorities and PSPs.

The Guidelines are one of the 11 mandates conferred onto the EBA in PSD2, which entered into force on 12 January 2016 and which will apply from 13 January 2018.

Sursa: EBA statement

Comentarii

Adauga un comentariu

(nu se afiseaza pe site)
Turing Number

Alte stiri din categoria: Noutati EBA

Bancile romanesti detin cele mai multe titluri de stat din Europa

Bancile romanesti au cea mai mare pondere a titlurilor de stat din totalul activelor dintre bancile europene, conform datelor publicate de Autoritatea Bancara Europeana (ABE), in raportul anual privind evaluarea... detalii

Guidelines on legislative and non-legislative moratoria on loan repayments applied in the light of the COVID-19 crisis

Guidelines on legislative and non-legislative moratoria on loan repayments applied in the light of the COVID-19 crisis – Consolidated version updated on 2 December 20201. Executive summaryThe outbreak of the... detalii

The EBA reactivates its Guidelines on legislative and non-legislative moratoria

After closely monitoring the developments of the COVID-19 pandemic and, in particular, the impact of the second COVID-19 wave and the related government restrictions taken in many EU countries, the European Banking Authority (EBA) has decided to reactivate its Guidelines on legislative and non-legislative moratoria.This reactivation will ensure that loans, which had previously not benefitted from payment moratoria, can now also benefit from them.The role of banks to ensure the continued flow of lending to clients remains of utmost importance and with the reactivation of these Guidelines, the EBA recognises the exceptional circumstances of the second COVID-19 wave.The EBA revised Guidelines, which will apply until 31 March 2021, include additional safeguards against the risk of an undue increase in unrecognised losses on banks’ balance sheet.With the continued unfolding of the COVID-19 pandemic, it is crucial... detalii

EBA publishes 2018 EU-wide stress test results

The European Banking Authority (EBA) published today the results of the 2018 EU-wide stress test, which involved 48 banks from 15 EU and EEA countries, covering broadly 70% of total... detalii