On 17 May, 2017 the Luxembourg Financial Regulator (CSSF) published four new circulars concerning cloud computing and IT outsourcing. The new regulations will immediately affect credit institutions, professionals of the financial sector, payment service providers, and electronic money issuers (Entities). The four CSSF circulars, which came into effect on the date of their publication, introduce new rules and replace existing requirements set out in existing circulars.
This circular addresses the obligations that Entities must meet when their IT infrastructure uses or will rely on a cloud computing infrastructure.
The circular applies to the partial or full transfer of the activities and does not make many differences between an external provider and an internal provider within a group of companies.
The CSSF defines the term of material activity as any activity that, when not properly performed, reduces the ability of an Entity to meet regulatory requirements or continue its operations, and any activities that are necessary for the sound and prudent risk management.
Three different IT service models are described:
For each of the above service models, the CSSF provides an interpretation of the levels of control on the systems and the software that an Entity must respect when applying such model.
Within these service models the CSSF differentiates four different cloud types:
An Entitys outsourcing of IT matters will qualify for particular regulatory treatment, if it meets specific criteria set out by the CSSF and will be excluded from the scope of other existing regulations relating the Entitys central administration, accounting organization, internal governance and risk management (e.g. Circulars 12/552 or 17/656).
The criteria that the CSSF uses to define the specific regulatory treatment are:
If the above criteria are fulfilled an Entity must obtain the CSSFs prior approval (if a material activity is concerned). In case a Luxembourg based professional of the financial sector is used, an Entity must only file a prior notification to the CSSF.
Once the outsourcing is implemented, all the changes to the set-up and the service providers as well as the in-sourcing must be notified to the regulator before an Entity enacts them.
Entities under the supervision of the CSSF that would like to offer cloud computing services or related operating services to their clients must submit a program description to the CSSF to obtain its prior approval.
This circular amends the requirements applicable to credit institutions, investment firms and professional lenders. The amendments introduce Circular 17/654 and clarify that Circular 05/178 is repealed.
In addition, the amendments clarify that every time specific infrastructures are used or changed, authorized entities must observe data protection and professional secrecy rules.
The circular clarifies the conditions for the use of other group entities that are not authorized by the CSSF. The systems of such group entities may be used under the condition that no confidential information is stored in a readable manner on those systems. If this is the case, the supervised entity must inform its clients and, if required, collect their consent.
This circular aligns the IT outsourcing requirements for professionals of the financial sector other than investment firms, payment service providers and electronic money issuers to those applicable to credit institutions and investment firms. It copies the wording of the relevant sections of Circular 12/552 to ensure consistency and ease further alignments.
Finally, the circular introduces Circular 17/564 and clarifies that professionals of the financial sector that offer IT services to their clients, may use the infrastructure of a third party or sub-delegate a part of their services only with the prior consent of the concerned clients.
This circular amends Circular 06/240 and is applicable to all credit institutions and professionals of the financial sector. One important clarification of this circular consists of providing that only the production environment should contain confidential data, whereas the test and development environment(s) (that as per applicable regulation may be accessed by third parties) should not contain confidential data.
As the four circulars came into effect on the date of their publication, the Entities auditors are expected to pay particular attention to the new requirements when carrying out their audits.
Entities supervised by the CSSF will have to carefully study the new circulars and analyze the impact on their existing administrative organization and IT infrastructure, because if affected, theymust be aligned to the new requirements. Therefore, changes may need to be implemented at multiple levels:
As service providers located outside of Luxembourg will be required to accept contractual provisions that they have never been requested to comply with before, (for instance, amendments to certifications and controls), the time to implement the changes should not be underestimated.
Link:
- Roundup Of Cloud Computing Forecasts, 2017 - Forbes - May 3rd, 2017 [May 3rd, 2017]
- RCom arm in tie-up for cloud computing - Moneycontrol.com - May 3rd, 2017 [May 3rd, 2017]
- How Do You Define Cloud Computing? - Data Center Knowledge - May 3rd, 2017 [May 3rd, 2017]
- 5 Cloud Computing Stocks to Buy - TheStreet.com - May 3rd, 2017 [May 3rd, 2017]
- Cloud Computing Continues to Influence HPC - insideHPC - May 3rd, 2017 [May 3rd, 2017]
- Red Hat's New Products Centered Around Cloud Computing, Containers - Virtualization Review - May 3rd, 2017 [May 3rd, 2017]
- Adobe bets big on cloud computing for marketing, creative professionals - Livemint - May 3rd, 2017 [May 3rd, 2017]
- Verizon sells cloud services to IBM in 'unique cooperation between ... - Cloud Tech - May 3rd, 2017 [May 3rd, 2017]
- How Cloud Computing Is Turning the Tide on Heart Attacks - Fortune - May 3rd, 2017 [May 3rd, 2017]
- Hospital CIOs see benefits of healthcare cloud computing - TechTarget - May 3rd, 2017 [May 3rd, 2017]
- Trends In Cloud Computing - Business Solutions Magazine - June 6th, 2017 [June 6th, 2017]
- A deeper dive into cloud security as a service: Advantages and issues - Cloud Tech - June 6th, 2017 [June 6th, 2017]
- OpenText buys cloud computing firm for US$103 million - TheRecord.com - June 6th, 2017 [June 6th, 2017]
- Belfast IT firm celebrates cloud computing success in 57 countries ... - Belfast Telegraph - June 6th, 2017 [June 6th, 2017]
- Meet The Cloud Wars Top 10: The World's Most-Powerful Cloud-Computing Vendors - Forbes - June 6th, 2017 [June 6th, 2017]
- How to approach cloud computing and cyber security in 2017 - Information Age - June 6th, 2017 [June 6th, 2017]
- CFOs have discovered the big stick of cloud computing - InfoWorld - June 6th, 2017 [June 6th, 2017]
- Belmont Stakes Odds 2017: Latest Vegas Betting Lines Before Post Positions Draw - Bleacher Report - June 7th, 2017 [June 7th, 2017]
- Cloudistics Announces New Cloud Computing Program That Enables High Margin Reoccurring Revenue Models for ... - Marketwired (press release) - June 7th, 2017 [June 7th, 2017]
- CloudCheckr, cloud computing company expects rapid growth in Rochester - WXXI News - June 7th, 2017 [June 7th, 2017]
- IBM Losing Facebook's WhatsApp as Cloud Customer, says CNBC - Barron's - June 7th, 2017 [June 7th, 2017]
- What My Father Taught Me About Cloud Computing - Virtualization Review - June 7th, 2017 [June 7th, 2017]
- Workday Phenomenon Goes Global As Cloud Computing Goes Mainstream - Forbes - June 7th, 2017 [June 7th, 2017]
- 3 Things You Should Know About Cloud Computing Right Now - Fortune - June 9th, 2017 [June 9th, 2017]
- Learning in the Sky: Collaborative Robots Embrace Cloud Computing - Machine Design - June 9th, 2017 [June 9th, 2017]
- Best Practices To Manage Your Hybrid Cloud - Forbes - June 9th, 2017 [June 9th, 2017]
- Here's how venture capitalists are thinking about cloud computing companies and technologies - GeekWire - June 9th, 2017 [June 9th, 2017]
- Amazon is helping veterans find jobs in cloud computing - Marketplace - Marketplace.org - June 9th, 2017 [June 9th, 2017]
- New Cloud Computing and IT Outsourcing Requirements in the Financial Sector - Lexology (registration) - June 9th, 2017 [June 9th, 2017]
- Growing Patent Claim Risks in Cloud Computing - Lexology (registration) - June 9th, 2017 [June 9th, 2017]
- The benefits of cloud computing, Rust 1.18, and intelligent tracking prevention in WebKit SD Times news digest ... - SDTimes.com - June 9th, 2017 [June 9th, 2017]
- Edge Computing Is New Cloud Computing Tech Investors Should Track - GuruFocus.com - June 9th, 2017 [June 9th, 2017]
- Real Estate Weekly: Digital Realty Becomes A Cloud Computing Giant - Seeking Alpha - June 9th, 2017 [June 9th, 2017]
- Virtualization admin? Pivot -- pivot now -- to a cloud computing career - TechTarget - June 10th, 2017 [June 10th, 2017]
- Why isn't Cloud Computing in the 2017 Belmont Stakes? - FanSided - June 11th, 2017 [June 11th, 2017]
- Cloud Computing Companies Move Into Medical Diagnosis (GOOG, IBM) - Investopedia - June 11th, 2017 [June 11th, 2017]
- China's cloud industry moving to new era with emergence of unicorns - TechNode (blog) - June 12th, 2017 [June 12th, 2017]
- Terry Crews Is On Crackdown 3 Trailer, No Cloud Computing For Single Player - EconoTimes - June 12th, 2017 [June 12th, 2017]
- The Risks and Perquisites of Cloud Computing - DATAQUEST - June 12th, 2017 [June 12th, 2017]
- Alibaba Cloud announces launch of data centres in India and Indonesia - Cloud Tech - June 12th, 2017 [June 12th, 2017]
- Indonesia banks have yet to implement cloud computing - Jakarta Post - June 13th, 2017 [June 13th, 2017]
- 'Sweden is heaven for cloud computing': Amazon Nordic chief - The ... - The Local Sweden - June 14th, 2017 [June 14th, 2017]
- Amazon.com to open second government cloud-computing region ... - The Seattle Times - June 14th, 2017 [June 14th, 2017]
- Shadow raises $57 million for its cloud computing service for ... - TechCrunch - June 14th, 2017 [June 14th, 2017]
- Amazon Still Leads Cloud Rankings, But Competition Is Coming On Strong - Fortune - June 16th, 2017 [June 16th, 2017]
- Alibaba to enter European cloud computing market in mid-2017 | Air ... - Air Cargo World (registration) - June 17th, 2017 [June 17th, 2017]
- Alibaba to enter European cloud computing market in mid-2017 - Air Cargo World (registration) - June 17th, 2017 [June 17th, 2017]
- Pressing Tech Issue: Enterprise Software Vs. Cloud Computing? - Credit Union Times - June 17th, 2017 [June 17th, 2017]
- 7 Tips for Securely Moving Data to the Cloud - Government Technology (blog) - June 20th, 2017 [June 20th, 2017]
- Chinese tech giant Alibaba joins key open-source cloud computing foundation - GeekWire - June 20th, 2017 [June 20th, 2017]
- Microsoft Could Surpass Amazon in Cloud Computing This Year (AMZN, MSFT) - Investopedia - June 20th, 2017 [June 20th, 2017]
- GDS Holdings Limited (GDS) Announces Strategic Partnership with Tencent Cloud - StreetInsider.com - June 20th, 2017 [June 20th, 2017]
- Cloud first - Philippine Star - June 20th, 2017 [June 20th, 2017]
- Three Considerations for Reducing Risk in Cloud Computing - CIOReview - June 21st, 2017 [June 21st, 2017]
- Cloud Computing and Digital Divide 2.0 - CircleID - CircleID - June 21st, 2017 [June 21st, 2017]
- Microsoft will ride artificial intelligence, cloud computing to higher ... - CNBC - June 21st, 2017 [June 21st, 2017]
- Cloud-Computing Business Lifts Oracle's Profit -- Update - Fox Business - June 21st, 2017 [June 21st, 2017]
- Report affirms continued cloud spend for US businesses in 2017 - Cloud Tech - June 22nd, 2017 [June 22nd, 2017]
- Catching up with an interconnected federal cloud - GCN.com - June 22nd, 2017 [June 22nd, 2017]
- Cloud-Computing Business Lifts Oracle's Profit -- 2nd Update - Fox Business - June 22nd, 2017 [June 22nd, 2017]
- Cisco adapts to the rise of cloud computing - The Economist - June 22nd, 2017 [June 22nd, 2017]
- Amazon accuses Walmart of bullying in cloud computing clash - BBC News - June 22nd, 2017 [June 22nd, 2017]
- Companies plan to spend more on cloud computing services this year, higher prices among drivers: Clutch - Canadian Underwriter - June 23rd, 2017 [June 23rd, 2017]
- Survey: businesses ramp up spending on cloud computing DC ... - DC Velocity - June 24th, 2017 [June 24th, 2017]
- Morgan Stanley: Cloud computing is at 'an inflection point' but how big will it get? - GeekWire - June 26th, 2017 [June 26th, 2017]
- How the cloud has changed education and training - TNW - June 26th, 2017 [June 26th, 2017]
- Cloud computing key to 4th industrial revolution - News VietNamNet - VietNamNet Bridge - June 26th, 2017 [June 26th, 2017]
- Lady Eli, Cloud Computing Among Workers for Brown - BloodHorse.com (press release) (registration) (blog) - June 26th, 2017 [June 26th, 2017]
- Microsoft signs cloud-computing partnership with Box - The Seattle Times - June 27th, 2017 [June 27th, 2017]
- Microsoft Signs Cloud Computing Partnership with Box - CIO Today - June 30th, 2017 [June 30th, 2017]
- US action on Microsoft email case could devastate cloud computing - Irish Times - June 30th, 2017 [June 30th, 2017]
- Cloud computing challenges today: Planning, process and people - TechTarget - July 2nd, 2017 [July 2nd, 2017]
- Five podcasts to catch up on the latest trends in cloud computing - TechTarget - July 2nd, 2017 [July 2nd, 2017]
- Microsoft reportedly set to lay off thousands as part of massive sales reorganization - GeekWire - July 3rd, 2017 [July 3rd, 2017]
- VMware to surge more than 20 percent because the Amazon cloud ... - CNBC - August 25th, 2017 [August 25th, 2017]
- Google Unveils Custom Hardware Chip for Cloud - Investopedia - August 25th, 2017 [August 25th, 2017]
- Cloud Computing Confirmed for Travers | TDN | Thoroughbred Daily ... - Thoroughbred Daily News - August 25th, 2017 [August 25th, 2017]
- Why 2017 Is The Year To Understand Cloud Computing - Nasdaq - August 25th, 2017 [August 25th, 2017]
- Biz Cloud Computing - Four States Homepage - August 25th, 2017 [August 25th, 2017]
- The Benefits of Multi-Cloud Computing Architectures for MSPs - MSPmentor - August 25th, 2017 [August 25th, 2017]