+RTS ICT Risk Management T. II Ch. II Art. 19 Human resources policy
---+RTS ICT Risk Management T. II Ch. II Art. 19 , 1

1. Overview

RTS ICT Risk Management T. II Ch. II Art. 19 Human resources policy

Human resources policy
Summary Regulation
RTS ICT Risk Management T. II Ch. II Art. 19 , 1

Financial entities shall include in their human resource policy or other relevant policies all of the following ICT security related elements:

  • (a) the identification and assignment of any specific ICT security responsibilities;
  • (b) requirements for staff of the financial entity and of the ICT third-party service providers using or accessing ICT assets of the financial entity to:
    • (i) be informed about, and adhere to, the financial entity’s ICT security policies, procedures, and protocols;
    • (ii) be aware of the reporting channels put in place by the financial entity for the detection of anomalous behaviour, including, where applicable, the reporting channels established in line with Directive (EU) 2019/1937 of the European Parliament and of the Council (11);
    • (iii) for the staff, to return to the financial entity, upon termination of employment, all ICT assets and tangible information assets in their possession that belong to the financial entity."

1.1 References

1.2 Identified Requirements

1.3 Related Standards

2. Identified Requirements

Requirements
Source Requirement

3. Related Standards

Standards
Source Requirement
Impressum