Article 1

Chapitre 1 - : Définitions et champ d’application

CSSF Circular 24/847 on the ICT-related incident reporting framework · CSSF 24/847

Chapitre 1 : Définitions et champ d’application ....................................................................... 5

Section 1.1 : Définitions .................................................................................................... 5 Section 1.2 : Champ d’application ...................................................................................... 7

Chapitre 2 : Exigences générales .......................................................................................... 8

Section 2.1 : Incidents à notifier ........................................................................................ 8 Section 2.2 : Classification des incidents liés aux TIC ............................................................ 9 Section 2.3 : Notification d’incidents majeurs liés aux TIC ..................................................... 9

Luxembourg specificity
loi du 18 decembre 2015 relative a la securite des reseaux et des systemes d'information; reglement CSSF N 24-01

In Luxembourg, CSSF Circular 24/847 covers a broad range of supervised entities: credit institutions, PSFs, payment institutions, e-money institutions, UCIs, management companies, AIFs and their managers. It interacts with the law of 18 December 2015 on the security of network and information systems (NIS transposition) for OES/DSPs, and with CSSF Regulation 24-01. The initial notification deadline for a major incident is 4 hours after classification, with an intermediate report within 72 hours and a final report within 1 month.

Luxgap practice: pre-configure today in your SIEM (Sentinel, Wazuh, Splunk) the detection rules that automatically start the CSSF 4-hour countdown, and embed the CSSF eDesk form into your on-call runbook. Without this automation, the initial deadline is practically impossible to meet.