Chapitre 1 - : Définitions et champ d’application
CSSF Circular 24/847 on the ICT-related incident reporting framework · CSSF 24/847
Chapitre 1 : Définitions et champ d’application ....................................................................... 5
Section 1.1 : Définitions .................................................................................................... 5 Section 1.2 : Champ d’application ...................................................................................... 7
Chapitre 2 : Exigences générales .......................................................................................... 8
Section 2.1 : Incidents à notifier ........................................................................................ 8 Section 2.2 : Classification des incidents liés aux TIC ............................................................ 9 Section 2.3 : Notification d’incidents majeurs liés aux TIC ..................................................... 9
In Luxembourg, CSSF Circular 24/847 covers a broad range of supervised entities: credit institutions, PSFs, payment institutions, e-money institutions, UCIs, management companies, AIFs and their managers. It interacts with the law of 18 December 2015 on the security of network and information systems (NIS transposition) for OES/DSPs, and with CSSF Regulation 24-01. The initial notification deadline for a major incident is 4 hours after classification, with an intermediate report within 72 hours and a final report within 1 month.
Luxgap practice: pre-configure today in your SIEM (Sentinel, Wazuh, Splunk) the detection rules that automatically start the CSSF 4-hour countdown, and embed the CSSF eDesk form into your on-call runbook. Without this automation, the initial deadline is practically impossible to meet.