The ICT risk-management framework
The ICT risk-management framework requires financial entities to establish a robust, documented system of governance and controls to manage ICT risks. It mandates that the management body takes ultimate responsibility for defining, approving, and overseeing a strategy that ensures operational resilience against ICT disruptions.
What it means
In practice, this is not merely a technical security requirement but a governance mandate. The framework must shift ICT risk from being an "IT department issue" to a core business priority overseen by the board of directors or equivalent management body. This involves creating a structured lifecycle for managing risks: identifying threats, implementing protections, detecting anomalies, and ensuring rapid recovery.
The scope is comprehensive, covering all ICT systems, including those provided by third parties. The framework must be proportional to the size, risk profile, and complexity of the organization, meaning larger entities with complex infrastructures will face more stringent expectations regarding the granularity of their controls.
Ultimately, the goal is "digital operational resilience," which means the entity should not only prevent failures but also possess the documented capability to withstand, respond to, and recover from ICT-related incidents without compromising critical business functions.
How to meet it
- Establish a formal governance structure where the management body approves the ICT risk-management framework and is regularly updated on its effectiveness.
- Create an ICT Risk Management Strategy that aligns technical security goals with overall business objectives and risk appetite.
- Maintain a comprehensive inventory of all ICT assets, including hardware, software, and data, categorized by their criticality to business functions.
- Implement a continuous risk identification process that analyzes threat landscapes, vulnerabilities, and the potential impact of ICT failures on critical services.
- Develop documented policies for protection and prevention (e.g., identity management, network security) and detection (e.g., monitoring tools, alerting mechanisms).
- Formalize Business Continuity Plans (BCP) and Disaster Recovery Plans (DRP) that specifically address the restoration of ICT systems after a severe disruption.
- Set up a recurring review cycle to update the framework based on changes in the threat environment or organizational structure.
Evidence an auditor asks for
- The approved ICT Risk Management Framework document, accompanied by Board meeting minutes proving its review and approval.
- A current asset register that maps critical business functions to their underlying ICT dependencies.
- An ICT risk register documenting identified risks, their assessed impact/likelihood, and the specific controls implemented to mitigate them.
- Evidence of BCP/DRP testing (e.g., test reports, post-mortem analyses) showing that recovery time objectives are achievable.
- Documented policies for change management, access control, and incident response.
Common pitfalls
- "Paper Compliance": Creating comprehensive policy documents that look good on paper but are not actually operationalized or followed by staff.
- Lack of Board Engagement: Treating the framework as a technical checklist managed solely by the CISO/CTO without active oversight from senior management.
- Static Assessments: Performing risk assessments as a one-time annual exercise rather than integrating them into a continuous monitoring process.