Recital 45

Recital 45

Digital Operational Resilience Act · UE 2022/2554

(45)

To ensure full alignment and overall consistency between financial entities’ business strategies, on the one hand, and the conduct of ICT risk management, on the other hand, the financial entities’ management bodies should be required to maintain a pivotal and active role in steering and adapting the ICT risk management framework and the overall digital operational resilience strategy. The approach to be taken by management bodies should not only focus on the means of ensuring the resilience of the ICT systems, but should also cover people and processes through a set of policies which cultivate, at each corporate layer, and for all staff, a strong sense of awareness about cyber risks and a commitment to observe a strict cyber hygiene at all levels. The ultimate responsibility of the management body in managing a financial entity’s ICT risk should be an overarching principle of that comprehensive approach, further translated into the continuous engagement of the management body in the control of the monitoring of the ICT risk management.

Luxembourg specificity
Circulaires CSSF 20/750 et 22/806

In Luxembourg, the CSSF clarified in its Circular CSSF 22/806 on outsourcing arrangements and its Circular CSSF 20/750 on governance of ICT and security risks that the management body must designate by name a member responsible for ICT risk oversight, and that board minutes must explicitly state the decisions taken on operational resilience. The CSSF systematically checks for these traces during on-site inspections and annual SREP exercises.

Luxgap practice: we configure the cockpit to automatically produce the reporting format expected by the CSSF (Circular 20/750 matrix) and feed your ICAAP/ILAAP file with the corresponding DORA indicators, with no double entry.