|
Principles of Corporate Governance for Supervised InstitutionsKNF
|
Financial institutions supervised by KNF within the principles’ scope |
Management and supervisory-board responsibilities, risk governance, internal controls, compliance, internal audit and transparent reporting. |
|
Source
|
|
Recommendation D on Information Technology and ICT Environment SecurityKNF
|
Banks operating within the recommendation’s scope |
ICT strategy, security governance, risk assessment, outsourcing, continuity, incident response, monitoring and independent assurance. |
|
Source
|
|
Digital Operational Resilience ActEuropean Union and KNF
|
Financial entities and ICT third-party providers within DORA’s scope |
ICT risk governance, major incident reporting, resilience testing, third-party registers, recovery and management-body accountability. |
|
Source
|
|
National Cybersecurity System Act, 2026 AmendmentMinistry of Digital Affairs and national CSIRTs
|
Essential and important entities within the amended national regime |
Information-security management, incident reporting to CSIRTs, accountable contacts, cybersecurity audits and documented remediation. |
|
Source
|
|
GDPR Personal Data Breach NotificationUODO
|
Controllers and processors handling personal data within the GDPR’s scope |
Breach logging, risk assessment, notification without undue delay, affected-person communication, root-cause analysis and corrective action. |
|
Source
|