procedure

Update Q&A en Good Practice Informatiebeveiliging: de belangrijkste wijzigingen

ID 26393

DNB has released updated Q&A and Good Practice Information Security 2023 on Open Book Supervision.
The Good Practice provides supervised institutions with current guidelines and control measures to comply with legal requirements, ensuring the continuous availability, integrity, confidentiality, and authenticity of automated data processing.
The update is motivated by DNB’s findings in supervision investigations and the TIBER program, where they encountered effective control measure examples for managing information security risks. Additionally, input from various financial sectors contributed to improvements in the Good Practice Information Security 2019/2020.
The Good Practice Information Security 2023 follows the same structure as the 2019/2020 version but represents a deeper and more stringent approach in response to increasing and evolving cyber threats.
The key changes include:
– Focus on the digital operational resilience strategy in the short, medium, and long term, outlining the execution of the Risk Management Framework, including oversight of third parties
– Risk-based implementation for each control, allowing institutions to tailor information security measures to their specific needs
– Conducting a business impact analysis to assess an institution’s exposure to severe business disruptions and their potential consequences
– Emphasizing the desired role of the board in information security, explicitly naming the role in certain controls
– Developing and maintaining knowledge for daily management, boards, supervisory boards, and key function holders through targeted training to understand and address key IT and cyber risks
– Addressing opportunities and risks related to technological developments such as quantum computing and artificial intelligence
For ongoing investigations and the sector-wide analysis of information security in 2024, the Good Practice Information Security 2019/2020 remains the basis. However, from the second quarter of 2024 onwards, DNB will generally apply the Good Practice Information Security 2023 for new investigations and supervision activities.
The updated Q&A addresses the question: “How can institutions under DNB’s supervision comply with the statutory requirements regarding the integrity, continuous availability and security of electronic data processing?”
The answer provided is, that institutions supervised by DNB must implement measures to control IT risks, ensuring the integrity and security of electronic data. These measures, guided by risk analysis, cover technology, human actions, processes, and facilities. Regular assessments and adjustments are made to address evolving information security risks. Governance and organizational structures guide this process, encompassing outsourced activities and resilience testing. The associated Good Practices offer practical guidance, recommending control measures in various areas to meet regulatory requirements.
The answer has been amended to include sections on (sub)outsourcing, governance & key functions, training & education and a definition of information security & cybersecurity.

Other Features
AI
assessment
automation
banks
best practice
companies
compliance
cyber security
financial stability
fund management
governance
insurance
operational
outsourcing
pension funds
process
professional competence
regulatory
resilience
risk
risk management
securities
statistics
Date Published: 2023-12-19
Regulatory Framework: Digital Operational Resilience Act (DORA)
Regulatory Type: procedure
Asset Management
information

ESG-risico’s hoog op de agenda van pensioenfondsbesturen, maar meer actie en ...

ID 26517
There’s an increasing urgency to manage ESG risks due to rapid climate change, biodi ...

DNB handhaaft Contracyclische Kapitaalbuffer op 2 procent – december 2023

ID 26484
The Dutch Central Bank (DNB) published a news release stating to maintain the 2% countercy ...
Asset Management
information

TRANSITIENIEUWS – Gesprekken tussen DNB en pensioenfondsen bieden inzichten ...

ID 26483
DNB published a news article sharing information from a DNB seminar held for smaller pensi ...
Asset Management
report / study

TRANSITIENIEUWS – Uitkomst onderzoeken over beheersing datakwaliteit bij ...

ID 26464
DNB publishes an artcle with the outcome of an investigation, conducted in 2023, into the ...
  • Topic Filter

    Top Tag Search
    Top Tag Search
    Top Tag Search
    Top Tag Search
You are on the training version of RISP core with limited functions and data. Please subscribe to RISP core for professional or academic use. We supply free real time datasets for approved academic research; professional subscriptions start at 950€ plus VAT per annum.

Compare Listings