CHAPTER III of the Regulation introduces requirements related to the ICT-related Incident Management, Classification and Reporting which focus on the following actions:
- Management
Development and implementation of an ICT-related incident detection, management and notification process.
- Classification
Assessment of the ICT-related incident impacts and classification based on defined criteria.
- Reporting
Reporting of ICT-related incidents, which are classified as major, to the Bank of Greece based on the requirements of the Regulation regarding:
- The reporting deadlines (initial, intermediate and final notification).
- The content of each notification.
In the event of a major ICT-related incident, in accordance with the criteria of the Regulation, supervised institutions must send a completed relevant template, using a secure communication channel, to the following email address: ICTIncidentReporting@bankofgreece.gr. Additionally, significant cyber threats may be reported through the same secure communication channel, by sending the corresponding template. The above templates as well as the corresponding validation rules are available at the end of the website.
For the process of implementing the secure communication channel, supervised institutions may contact ict.supervision@bankofgreece.gr for instructions.
Further details regarding these requirements are also included in the following documents related to the Regulation:
Regulatory Technical Standards (RTS) specifying the criteria for the classification of ICT-related incidents and cyber threats, setting out materiality thresholds and specifying the details of reports of major incidents
Regulatory Technical Standards (RTS) specifying the content and time limits for the initial notification of, and intermediate and final report on, major ICT-related incidents, and the content of the voluntary notification for significant cyber threats
Implementing Technical Standards (ITS) with regard to the standard forms, templates, and procedures for financial entities to report a major ICT-related incident and to notify a significant cyber threat