{"id":"circulars/cssf-24-847","title":"Circular CSSF 24/847","type":"circular","date":"2024-01-05","kind":"circular","html":"<p>Circular CSSF 24/847 is a CSSF circular on ICT-related incident reporting framework, published 5 January 2024.</p>\n<p>Legal basis: <a href=\"/lhoft?page=laws%2F1993-04-05-n1\" class=\"wikiLink\" data-target=\"laws/1993-04-05-n1\">Law of 5 April 1993 on the financial sector</a>, <a href=\"/lhoft?page=laws%2F2000-12-15-n1\" class=\"wikiLink\" data-target=\"laws/2000-12-15-n1\">Law of 15 December 2000 on postal services and postal financial services</a>, <a href=\"/lhoft?page=laws%2F2009-11-10-n1\" class=\"wikiLink\" data-target=\"laws/2009-11-10-n1\">Law of 10 November 2009 on payment services and electronic money</a>, <a href=\"/lhoft?page=laws%2F2010-12-17-n9\" class=\"wikiLink\" data-target=\"laws/2010-12-17-n9\">Law of 17 December 2010 on undertakings for collective investment</a>, <a href=\"/lhoft?page=laws%2F2013-07-12-n1\" class=\"wikiLink\" data-target=\"laws/2013-07-12-n1\">Law of 12 July 2013 on alternative investment fund managers</a>, <a href=\"/lhoft?page=laws%2F2016-03-15-n3\" class=\"wikiLink\" data-target=\"laws/2016-03-15-n3\">Law of 15 March 2016 on OTC derivatives and central counterparties</a>, Loi du 17 avril 2018, Loi du 6 juin 2018 relative aux dépositaires centraux de titres, <a href=\"/lhoft?page=laws%2F2019-05-28-a372\" class=\"wikiLink\" data-target=\"laws/2019-05-28-a372\">Law of 28 May 2019 on network and information security (NIS)</a>, <a href=\"/lhoft?page=laws%2F2019-07-16-a514\" class=\"wikiLink\" data-target=\"laws/2019-07-16-a514\">Law of 16 July 2019 implementing the EuVECA, EuSEF and ELTIF regulations</a>, <a href=\"/lhoft?page=laws%2F2019-07-16-a513\" class=\"wikiLink\" data-target=\"laws/2019-07-16-a513\">Law of 16 July 2019 on prospectuses for securities</a>, Loi du 17 décembre 2021, <a href=\"/lhoft?page=laws%2F2004-11-12-n1\" class=\"wikiLink\" data-target=\"laws/2004-11-12-n1\">Law of 12 November 2004 on anti-money laundering</a>, <a href=\"/lhoft?page=laws%2F2018-05-30-a446\" class=\"wikiLink\" data-target=\"laws/2018-05-30-a446\">Law of 30 May 2018 on markets in financial instruments</a>.</p>\n<p>Relevant for: AIFMs, Central Securities Depositories (CSDs), Credit institutions, Crowdfunding service providers, Data Reporting Service Providers (DRSPs), E-money institutions, Investment firms, Investment fund managers, Management companies - Chapter 15, Management companies - Chapter 16, Payment institutions, Specialised PFS, Support PFS.</p>\n<p>Keywords: Cybersecurity, Information and communications technology (ICT), Information security, Operational risk.</p>\n<h2>Text</h2>\n<p>Circular CSSF 24/847 ICT-related incident reporting framework To all Supervised Entities within the meaning of the following laws, as amended, and regulations as further specified in point 2: -</p>\n<p>Law of 5 April 1993 on the financial sector</p>\n<p>Law of 15 December 2000 on postal financial services</p>\n<p>Law of 10 November 2009 on payment services</p>\n<p>Law of 17 December 2010 relating to undertakings for collective investment</p>\n<p>Law of 12 July 2013 on alternative investment fund managers</p>\n<p>Law of 15 March 2016 on OTC derivatives, central counterparties and trade repositories</p>\n<p>Law of 17 April 2018 on benchmarks</p>\n<p>Law of 6 June 2018 on Central Securities Depositories</p>\n<p>Law of 28 May 2019 on Network and Information Systems</p>\n<p>Law of 16 July 2019 on the operationalisation of European regulations in the area of financial services</p>\n<p>Luxembourg, 5 January 2024 Ladies and Gentlemen, The purpose of this Circular is to introduce a new ICT-related incident reporting framework in order to acquire a better and more structured overview of the nature, frequency, significance and impact of ICT-related incidents, also considering the growing ICT and security risk in the context of a highly interconnected global financial system. The provisions of this Circular are based on Article 53(1) of the Law of 5 April 1993 on the financial sector, as amended (hereafter “LFS”), Article 31(4) of the Law of 10 November 2009 on payment services, as amended (hereafter “LPS”), Article 2 of the Law of 15 December 2000 on postal financial services, as amended, Article 147 of the Law of 17 December 2010 relating to undertakings for collective investment, as amended (hereafter “UCITS Law”), Article 50 of the Law of 12 July 2013 on alternative investment fund managers, as amended (hereafter “AIFM Law”), Article 2(1) of the Law of 15 March 2016 on OTC derivatives, central counterparties and trade repositories, as amended (hereafter “EMIR Law”), Article 2(1) of the Law of 17 April 2018 on benchmarks (hereafter “Benchmark Law”), Article 2 of the Law of 6 June 2018 on Central Securities Depositories (hereafter “CSD Law”), and Article 20-16 of the Law of 16 July 2019 on the operationalisation of European regulations in the area of financial services. According to Article 3 of the Law of 28 May 2019 on Network and Information Systems (hereafter “NIS Law”), the CSSF is also the competent authority in terms of network and information security for the credit institutions and the financial market infrastructures that have been identified as Operators of Essential Services (hereafter “OES”), as well as for Digital Service Providers (hereafter “DSP”) which are already under the supervision of the CSSF (“NIS authority”). The objective of this circular is to lay down the practical details and modalities for the reporting obligations set forth in Articles 8(4), 8(5), 9(1), 11(3) and 11(4) and 12 of the NIS Law and in CSSF Regulation No 24-01</p>\n<p>relating to the notification of incidents according to the Law of 28 May 2019 1 (hereafter “CSSF Regulation No 24-01”) regarding specifically Articles 8(5) and 11(3) of the NIS Law. This Circular brings the following changes to the current incident reporting mechanism: •</p>\n<p>Increases the incident coverage, currently limited to fraud and incidents due to external computer attacks as per Circular CSSF 11/504, by covering more broadly ICT operational and security incidents while avoiding double reporting for incidents to be notified under other incident notification frameworks.</p>\n<p>Introduces reporting based on classification. Supervised Entities will be required to classify ICTrelated incidents based on the criteria indicated in this Circular and to notify to the CSSF the cases where ICT-related incidents are classified as major or significant incidents.</p>\n<p>Introduces a new incident reporting notification form.</p>\n<p>The text above is the opening of the document; the PDF carries the whole.</p>\n<p><a href=\"https://www.cssf.lu/en/Document/circular-cssf-24-847/\" target=\"_blank\" rel=\"noreferrer\">Document page</a>, <a href=\"https://www.cssf.lu/wp-content/uploads/cssf24_847eng.pdf\" target=\"_blank\" rel=\"noreferrer\">PDF</a>. Source: Commission de Surveillance du Secteur Financier (CSSF), reproduced with the CSSF's consent. The French text prevails.</p>"}