Article M.5

Amendment 3 — the EBA Guidelines moved into Chapters 2 and 3

CSSF Circular 25/881 amending CSSF 20/750 on ICT and security risk management (as amended by Circular CSSF 26/915) · CSSF 25/881

3. The requirements that were listed in EBA Guidelines EBA/GL/2019/04 have been introduced directly in Circular CSSF 20/750 as follows:

a. The text of the EBA Guidelines in the section “Definitions” can now be found in Chapter 2;

b. The text of the EBA Guidelines in the section “Guidelines on ICT and security risk management” can now be found in Chapter 3.

The amendments to the EBA Guidelines, which are now in Chapters 2 and 3 are shown in track changes. They relate to requirements or references which were primarily relevant for entities which are now out of scope of this circular. In addition, some definitions were modified to align them with recent definitions in this area.