Guidelines on ICT and security risk management

  • Status: Final and translated into the EU official languages

These draft Guidelines establish requirements for credit institutions, investment firms and payment service providers (PSPs) on the mitigation and management of their information and communication technology (ICT) risks and aim to ensure a consistent and robust approach across the Single market. Once into force, these Guidelines will replace those on security measures for operational and security risks (EBA GL/2017/17), which will then be repealed.

Summary of document history

Current version Ongoing versions

Consultation on the Guidelines on security measures for operational and security risks of payment services under PSD2

  • Status: Closed
  • Deadline: 7 AUGUST 2017
Documents
Consultation Paper on the security measures for operational and security risks of payment services under PSD2 (EBA-CP-2017-04)

(294.23 KB - PDF) Last update 5 May 2017

Responses

The form is now closed.

Public hearings

Public hearing on Guidelines on security measures for operational and security risks under the PSD2

Presentation

(796.99 KB - PDF) Last update 22 June 2017

Press contacts

Franca Rosa Congiu