Source: OJ L, 2024/1774, 25.6.2024

Current language: EN

Article 4 ICT asset management policy


    1. As part of the ICT security policies, procedures, protocols, and tools referred to in Article 9(2) of Regulation (EU) 2022/2554, financial entities shall develop, document, and implement a policy on management of ICT assets.

    1. The policy on management of ICT assets referred to in paragraph 1 shall:

      1. prescribe the monitoring and management of the lifecycle of ICT assets identified and classified in accordance with Article 8(1) of Regulation (EU) 2022/2554;

      2. prescribe that the financial entity keeps records of all of the following:

        1. the unique identifier of each ICT asset;

        2. information on the location, either physical or logical, of all ICT assets;

        3. the classification of all ICT assets, as referred to in Article 8(1) of Regulation (EU) 2022/2254;

        4. the identity of ICT asset owners;

        5. the business functions or services supported by the ICT asset;

        6. the ICT business continuity requirements, including recovery time objectives and recovery point objectives;

        7. whether the ICT asset can be or is exposed to external networks, including the internet;

        8. the links and interdependencies among ICT assets and the business functions using each ICT asset;

        9. where applicable, for all ICT assets, the end dates of the ICT third-party service provider’s regular, extended, and custom support services after which those ICT assets are no longer supported by their supplier or by an ICT third-party service provider;

      3. for financial entities other than microenterprises, prescribe that those financial entities keep records of the information necessary to perform a specific ICT risk assessment on all legacy ICT systems referred to in Article 8(7) of Regulation (EU) 2022/2554.

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod