Open Banking Security OPENBANK-7: Logging, Monitoring, Regulatory Reporting, SLA, Availability
Operate logging + monitoring + regulatory reporting + SLA + availability per scheme + applicable regulation. Logging Monitoring and Reporting to Regulators must (a) collect comprehensive API audit logs covering authentication + authorisation + transactions + admin actions + (b) maintain regulator reporting per scheme requirements (UK OBIE + EU PSD2/3 incident reporting + Brazilian Open Finance + Australian CDR + similar), (c) report incidents + SLA breaches + customer complaints + fraud metrics + (d) integrate with broader regulatory reporting function. Service Level Agreement and Availability must (a) maintain scheme-required SLAs (typically 99.5%+ availability for in-scope APIs) + (b) monitor + measure + report SLA conformance + (c) maintain incident management + remediation + customer notification + (d) align with broader BCM + DR programme. Communication and escalation procedures must (a) maintain regulator + scheme operator + TPP communication channels + (b) escalate incidents per scheme procedures + (c) maintain on-call coverage + executive escalation + (d) integrate with broader crisis management.
Maintained by Gerard Blokdyk·Verified against the published standard ·Control text last updated
What else in your programme already covers this
This control maps to 105 controls across 55 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
PIPA-CPO-DPO-Privacy-Officer-PIA-Personal-Information-Impact-Assessment-Articles-31-33 Korea PIPA CPO + DPO + Privacy Officer + PIA + Personal Information Impact Assessment + Articles 31-33
PIPA-Sensitive-Information-Unique-ID-Resident-Registration-Numbers-CCTV-Articles-23-24-25 Korea PIPA Sensitive Information + Unique ID + RRN + CCTV + Articles 23-25