Open Banking Security
Incident + BCM

Open Banking Security OPENBANK-8: Incident Detection, Response, Customer Notification, Post-Incident Review, BCM

Operate incident detection + response + customer notification + post-incident review + BCM per scheme + applicable regulation. Incident detection and classification must (a) implement SIEM + EDR + fraud detection + with open banking-aware correlation rules + (b) classify incidents per scheme requirements (cyber + operational + customer impact + payment fraud + similar) + (c) integrate with broader security operations. Incident response and containment must (a) maintain IR plan with open banking scenarios (TPP compromise + API abuse + customer credential theft + transaction fraud + scheme infrastructure attack), (b) coordinate with scheme operator + national CERT + payment brand + regulator per applicable obligation. Regulatory reporting requirements must (a) report incidents within scheme + regulatory timeframes (varying 2 hours + 4 hours + 24 hours + 72 hours + 5 days per scheme + incident category), (b) provide complete + accurate + timely reports. Customer notification procedures must (a) notify affected customers per applicable regulation + (b) coordinate with TPPs for customer-facing communication + (c) maintain customer support capacity during incidents. Post-incident review and improvement must (a) conduct lessons-learned post-incident + (b) implement remediation tracking through closure + (c) feed lessons into broader open banking programme. Business continuity planning and testing must (a) maintain ISCP covering open banking services + (b) test annually with technical recovery + tabletop + (c) coordinate with scheme operator + TPPs. Disaster recovery procedures must (a) maintain DR capability per scheme RTO/RPO + (b) test recovery + (c) maintain alternate site + capacity.

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.