TÜRKIYE Law and Practice Contributed by: Bora Yazıcıoğlu, Alper Işık, Emre Öntekin and Ferat Gümüş, YAZICIOGLU Legal
3.2 ICT Service Provider Contractual Requirements
• provisions ensuring that the outsourcing provider is also subject to inspection/audit of the respective regulator; • terms for changes and termination; • data destruction obligations for the outsourcing provider in case of termination; and • provisions regarding the management of risks related to unexpected termination. Banks must also follow the conditions set under the By-Law on Support Services for Banks, which covers the banks’ outsourcing of any type of support ser - vices. Classification of ICT Services The Financial NIS does not define any ICT services as “critical”. While the By-Law ISBEBS and the Communiqué on Payment Services regulate “critical information systems” without defining the term, the By-Law on Remote Identity Verification Methods to be Used by Banks and the Establishment of Contractual Relation - ships in Electronic Environment classifies the systems used for remote identity verification as critical informa - tion systems in terms of the By-Law ISBEBS. The CMB Communiqué also does not define “critical information systems”, but it does define “criticality” as “the quality of the information asset that indicates its importance or necessity in achieving the business objectives of the institution, organisation or compa - ny”. It also sets specific requirements, such as real- time monitoring of unauthorised access. 3.3 Key Operational Resilience Obligations Aiming to establish the standards for strengthening financial institutions’ information systems, the Finan - cial NIS imposes several obligations on institutions within their respective areas to increase the resilience of information systems. It provides measures to be taken for information security as well as the manage - ment of cyber incidents. Risk Management Obligations Financial sector institutions are required to prepare a plan and policy for the detection, analysis and man - agement of risks related to information systems. They
There is no legal definition for ICT or cloud service providers. However, several sectoral regulations indi - cate different service providers for ICT services. The By-Law ISBEBS defines “outsourcing” as sup - port services that banks acquire from external sourc - es, which may potentially affect the confidentiality, integrity and availability of banking data, continuity of banking services, and services involving access to or sharing of banking data. Requirements Under the By-Law ISBEBS, the Communiqué on Payment Services, and the CMB Communiqué (“Financial NIS”) The Financial NIS regulates the outsourcing of ICT services by the financial sector institutions. It aims to guarantee that financial sector institutions retain their control over outsourced information systems and remain accountable to the relevant parties (eg, their customers). For the scope of Financial NIS, see 3.1 Scope of Financial Sector Operation Resilience Regulation . Outsourcing requirements include: • assessing service provider access risks; • determining exit strategies; and • in case of procuring cloud services for primary and secondary systems, ensuring that the sys - tems used for these cloud services are located in Türkiye. The Financial NIS requires outsourcing contracts to include certain clauses, including: • the scope of the contract and the responsibilities of the parties; • the liability of the external outsourcing provider with regard to information security; • the liability of the sub-contractors of the outsourc - ing provider, which must be equivalent; • provisions granting the respective financial institu - tion the right to request necessary documents and information regarding the outsourced services;
426 CHAMBERS.COM
Powered by FlippingBook