{"id":"circulars/faq-cssf-faq-related-to-circular-cssf-24-847-on-ict-related-incident-reporting-frame","title":"CSSF FAQ related to Circular CSSF 24/847 on ICT-related incident reporting framework","type":"circular","date":"2024-01-05","kind":"faq","html":"<p>CSSF FAQ related to Circular CSSF 24/847 on ICT-related incident reporting framework is a CSSF FAQ, published 5 January 2024.</p>\n<p>Legal basis: <a href=\"/lhoft?page=laws%2F2019-05-28-a372\" class=\"wikiLink\" data-target=\"laws/2019-05-28-a372\">Law of 28 May 2019 on network and information security (NIS)</a>, <a href=\"/lhoft?page=laws%2F1998-12-23-n2\" class=\"wikiLink\" data-target=\"laws/1998-12-23-n2\">Law of 23 December 1998 creating the CSSF</a>, <a href=\"/lhoft?page=laws%2F2009-04-20-n1\" class=\"wikiLink\" data-target=\"laws/2009-04-20-n1\">Law of 20 April 2009 (sur le dépôt par voie électronique auprès du registre de com)</a>, <a href=\"/lhoft?page=laws%2F2016-07-23-n19\" class=\"wikiLink\" data-target=\"laws/2016-07-23-n19\">Law of 23 July 2016 on non-financial and diversity information</a>.</p>\n<p>Relevant for: Management companies - Chapter 16, Payment institutions, Specialised PFS, Support PFS.</p>\n<p>Keywords: Cybersecurity, Information and communications technology (ICT), Information security, Operational risk.</p>\n<h2>Text</h2>\n<p>CSSF Regulation No 24-01 of 5 January 2024</p>\n<p>In case of discrepancies between the French and the English texts, the French text shall prevail.</p>\n<p>CSSF Regulation No 24-01 of 5 January 2024 relating to the notification of incidents according to the Law of 28 May 2019 transposing Directive (EU) 2016/1148 of the European Parliament and of the Council of 6 July 2016 concerning measures for a high common level of security of network and information systems across the European Union. (Mém. A 2024, No 3) The Executive Board of the Commission de Surveillance du Secteur Financier, Having regard to Article 129(2) of the Constitution; Having regard to the Law of 23 December 1998 establishing a financial sector supervisory commission (“Commission de surveillance du secteur financier”), as amended, and in particular Article 9(2) thereof; Having regard to the Law of 28 May 2019 transposing Directive (EU) 2016/1148 of the European Parliament and of the Council of 6 July 2016 concerning measures for a high common level of security of network and information systems across the European Union (the “NIS Law”) and amending the Law of 20 April 2009 establishing the Government IT Centre, as amended, and the Law of 23 July 2016 establishing a High Commission for National Protection; Having regard to Article 3 of the NIS Law designating the Commission de Surveillance du Secteur Financier (hereinafter, the “CSSF”), as the competent authority for the security of network and information systems covering the sectors of credit institutions and financial market infrastructures as defined in points (3) and (4) of the Annex to the NIS Law, as well as the digital services provided by an entity under the supervision of the CSSF; Having regard to Article 8(5) of the NIS Law under which the competent authority may specify, by way of a regulation, the parameters, modalities and timeframes for notifications of incidents having a significant impact on the continuity of the essential services that operators of essential services provide; Having regard to Article 11(3) of the NIS Law under which the competent authority shall determine, by way of a regulation, the modalities, format and timeframe for the notifications of incidents having a substantial impact on the provision of a digital service that digital service providers offer within the European Union; Having regard to the opinion of the of the Consultative Committee for Prudential Regulation; Decides:</p>\n<p>Article 1 Definitions 1) For the purposes of this regulation, the following definitions shall apply: a.</p>\n<p>“Credit institutions” means credit institutions as defined in point (12) of Article 1 of the Law of 5 April 1993 on the financial sector, as amended (the “LFS”).</p>\n<p>b. “Financial market infrastructures” means operators of trading venues as defined in point (43) of Article 1 of the Law of 30 May 2018 on markets in financial instruments and/or central counterparties as defined in point (1) of Article 2 of Regulation (EU) No 648/2012 of the European Parliament and of the Council of 4 July 2012 on OTC derivatives, central counterparties and trade repositories. c.</p>\n<p>“Support PFS” means professionals of the financial sector authorised in accordance with Article 293 of the LFS.</p>\n<p>d. “Operator of essential services” means, in accordance with point (3) of Article 2 of the NIS Law, a public or private entity of a type referred to in the Annex to the NIS Law, and which meets the criteria laid down in Article 7(2) of the NIS Law 1.</p>\n<p>In its competence as NIS authority, the CSSF already notified the relevant Supervised Entities of their identification as Operator of essential services (OES) when the NIS Law entered into force. The CSSF will reconfirm the relevant Supervised Entities of their status as OES at the latest by 1 March 2024. The Supervised Entities which will not have received this notification by that date are therefore not designated as OES, without prejudice to potential future designation.</p>\n<p>The text above is the opening of the document; the PDF carries the whole.</p>\n<p><a href=\"https://www.cssf.lu/en/Document/cssf-faq-related-to-circular-cssf-24-847-on-ict-related-incident-reporting-framework/\" target=\"_blank\" rel=\"noreferrer\">Document page</a>, <a href=\"https://www.cssf.lu/wp-content/uploads/RCSSF24_01eng.pdf\" target=\"_blank\" rel=\"noreferrer\">PDF</a>. Source: Commission de Surveillance du Secteur Financier (CSSF), reproduced with the CSSF's consent. The French text prevails.</p>"}