Authentic statutory obligations decomposed into atomic machine-actionable conditions, actions, and verification standards.
Financial entities shall have mechanisms to promptly detect anomalous activities, including ICT network performance issues and ICT-related incidents (Article 10).
Statutory verification and compliance logging required.
{
"24_7_siem_soc": true,
"automated_anomaly_detection": true
}Financial entities shall have in place an internal governance and control framework that ensures effective and prudent management of ICT risk (Article 5).
Statutory verification and compliance logging required.
{
"annual_review": true,
"management_body_approval": true
}Entities shall carry out advanced digital operational resilience testing, including Threat-Led Penetration Testing (TLPT) at least every 3 years for critical functions (Article 26).
Statutory verification and compliance logging required.
{
"production_scope_tested": true,
"crested_testers_mandated": true
}Continuous monitoring and security tooling to prevent unauthorized access, mitigate data tampering, and ensure network segregation (Article 9).
Statutory verification and compliance logging required.
{
"edr_deployed": true,
"microsegmentation": true,
"multi_factor_authentication": true
}Financial entities shall use and maintain updated ICT systems, protocols and tools that are appropriate, reliable, technologically resilient and have adequate capacity (Article 6).
Statutory verification and compliance logging required.
{
"capacity_monitoring": true,
"supported_software_versions": true
}Financial entities shall manage ICT third-party risk as an integral component of ICT risk, maintaining a full Register of Information for all ICT service providers (Article 28).
Statutory verification and compliance logging required.
{
"vendor_register_updated": true,
"audit_rights_in_contracts": true
}Financial entities shall identify, classify and adequately document all ICT supported business functions, the information assets and the ICT assets fulfilling those functions (Article 8).
Statutory verification and compliance logging required.
{
"interdependency_mapping": true,
"critical_function_tagging": true
}Comprehensive business continuity plans and disaster recovery arrangements subjected to regular testing and audit validation (Article 11).
Statutory verification and compliance logging required.
{
"rpo_rto_defined": true,
"annual_failover_test": true
}