Skip to content

ICT Risk Framework RTS

COMMISSION DELEGATED REGULATION (EU) 2024/1774

of 13 March 2024

supplementing Regulation (EU) 2022/2554 of the European Parliament and of the Council with regard to regulatory technical standards specifying ICT risk management tools, methods, processes, and policies and the simplified ICT risk management framework

(Text with EEA relevance)

THE EUROPEAN COMMISSION,

Having regard to the Treaty on the Functioning of the European Union,

Having regard to Regulation (EU) 2022/2554 of the European Parliament and of the Council of 14 December 2022 on digital operational resilience for the financial sector and amending Regulations (EC) No 1060/2009, (EU) No 648/2012, (EU) No 600/2014, (EU) No 909/2014 and (EU) 2016/1011 1, and in particular Article 15, fourth subparagraph, and Article 16(3), fourth subparagraph, thereof,

Whereas:

Recitals

HAS ADOPTED THIS REGULATION:

TITLE I General principle
Article 1 Overall risk profile and complexity
TITLE II Further harmonisation of ICT risk management tools, methods, processes, and policies in accordance with Article 15 of regulation (EU) 2022/2554
Chapter I ICT Security policies, procedures, protocols, and tools
Article 2 General elements of ICT security policies, procedures, protocols, and tools
Article 3 ICT risk management
Section III ICT asset management
Article 4 ICT asset management policy
Article 5 ICT asset management procedure
Section IV Encryption and cryptography
Article 6 Encryption and cryptographic controls
Article 7 Cryptographic key management
Section V ICT operations security
Article 8 Policies and procedures for ICT operations
Article 9 Capacity and performance management
Article 10 Vulnerability and patch management
Article 11 Data and system security
Article 12 Logging
Section VI Network security
Article 13 Network security management
Article 14 Securing information in transit
Section VII ICT project and change management
Article 15 ICT project management
Article 16 ICT systems acquisition, development, and maintenance
Article 17 ICT change management
Article 18 Physical and environmental security
Chapter II Human resources policy and access control
Article 19 Human resources policy
Article 20 Identity management
Article 21 Access control
Chapter III ICT-related incident detection and response
Article 22 ICT-related incident management policy
Article 23 Anomalous activities detection and criteria for ICT-related incidents detection and response
Chapter IV ICT business continuity management
Article 24 Components of the ICT business continuity policy
Article 25 Testing of the ICT business continuity plans
Article 26 ICT response and recovery plans
Chapter V Report on the ICT risk management framework review
Article 27 Format and content of the report on the review of the ICT risk management framework
TITLE III Simplified ICT risk management framework for financial entities referred to in Article 16(1) of Regulation (EU) 2022/2554
Chapter I Simplified ICT risk management framework
Article 28 Governance and organisation
Article 29 Information security policy and measures
Article 30 Classification of information assets and ICT assets
Article 31 ICT risk management
Article 32 Physical and environmental security
Chapter II ICT business continuity management
Article 33 Access Control
Article 34 ICT operations security
Article 35 Data, system and network security
Article 36 ICT security testing
Article 37 ICT systems acquisition, development, and maintenance
Article 38 ICT project and change management
Chapter III ICT business continuity management
Article 39 Components of the ICT business continuity plan
Article 40 Testing of business continuity plans
Chapter IV Report on the review of the simplified ICT risk management framework
Article 41 Format and content of the report on the review of the simplified ICT risk management framework
TITLE IV Final provisions
Article 42 Entry into force

This Regulation shall be binding in its entirety and directly applicable in all Member States.

Done at Brussels, 13 March 2024.

  • For the Commission

    The President

    Ursula VON DER LEYEN


Footnotes
  1. OJ L 333, 27.12.2022, p. 1, ELI: http://data.europa.eu/eli/reg/2022/2554/oj.