XXXXXXXXXX XXXXXXXX CENTRÁLNÍ XXXXX (EU) 2021/1758
xx xxx 21.&xxxx;xxxx 2021,
xxxxxx xx xxxx rozhodnutí XXX/2007/7 o podmínkách XXXXXX2-XXX (XXX/2021/43)
XXXXXXX XXXX XXXXXXXX XXXXXXXXX XXXXX,
x&xxxx;xxxxxxx na Xxxxxxx x&xxxx;xxxxxxxxx Evropské xxxx, a zejména na xxxxx x&xxxx;xxxxxxx xxxxxxx xx.&xxxx;127 xxxx.&xxxx;2 této xxxxxxx,
x&xxxx;xxxxxxx na xxxxxx Xxxxxxxxxx xxxxxxx centrálních xxxx x&xxxx;Xxxxxxxx xxxxxxxxx xxxxx, x&xxxx;xxxxxxx xx xxxxxx&xxxx;11.6 x&xxxx;xxxxxx 17, 22 x&xxxx;23 tohoto xxxxxxx,
xxxxxxxx x&xxxx;xxxxx xxxxxxx:
|
(1) |
Xxxx xxxxxxxxx xxxxxxx&xxxx;(1) xxx 20.&xxxx;xxxxxxxx 2021 obecné xxxxxx Evropské xxxxxxxxx xxxxx ECB/2012/27 (2) x&xxxx;xxxxx: x) xxxxxxxx, xx xxxxxxxx TIPS XXX xxxxx x&xxxx;XXXXXX2 xxxxxxxxx xxxxxxxxxxxxxxx xxxxxxxxxx portálu xxxxx xxxxxxxxxxxxxx Xxxxxxxxxxx (Xxxxxxxxxx Single Xxxxxx Xxxxxxxxxxxxxx Gateway) od xxxxxxxxx 2021 x&xxxx;xxxxxxxx X2X XXX xxxxx x&xxxx;XXXXXX2 xxxxxxxxxxxxxxx xxxxxx xxxxxxx xxxxxxxxx xx xxxxxx 2022; b) xxxxxxxx x&xxxx;xxxxxxxx xxxxxxxx xxxxxxxx se xxxxxxxxxx xxxxxxxxx na xxxxxxxxxx xxxxxxxxx bodu XXXXXX2, xxx xx zajistilo, xx xx xxxxxx XXXXXX2 bude xxxx xxxxxxx tak, aby xxx xxxxxxx xxxxx xxxxxxx v oblasti kybernetické xxxxxxxxxxx; c) zavést xxxxxxxxx, xxx xxxxxxxx xxxx XX, xxxxxx xxxxxxx xxxxxxxxx x&xxxx;xxxxxxxxxxxxx xxxxxxxx xxxx BIC, xxxxx přistoupili x&xxxx;xxxxxxxxxxx xxxxxxx XXX Xxxx xxxxxxxx xxxxxx o dodržování xxxxxxx xxx xxxxxxxx xxxxxxxxxxxxx převody SEPA, xxxx x&xxxx;xxxxxxx trvale xxxxxxxxxxx xx platformě XXXX xxxxxxxxxxxxxxx XXXX XXX, tak xxx xx zajistila dostupnost xxxxxxxxxx xxxxxx v celé Xxxx; x) zavést xxxxxxxxxxxxxxx, xxxxx xxx x&xxxx;xxxxxxx převodu zůstatků x&xxxx;xxxx xxxxxxxxx x&xxxx;XXXXXX2 xx odpovídající xxxxxxxxxxx xxxx x&xxxx;xxxxxxxx xxxxxxx XXXXXX, xxx xxxx xxxxxxxxx právní xxxxxxx, x&xxxx;x) xxxxxxxx a aktualizovat xxxxxxx xxxxx xxxxxxx xxxxxxxx xxxxx ECB/2012/27. |
|
(2) |
Jakmile xxxx xxxxxxxxxx xxxxxxx xxxxxxxxxxx X2-X2X, xxxx x&xxxx;xxxxx xxxxxx xxxxxxx xxxxxx xxxxxxxx xxxxxxxx xxxxxxxxxxxxxxx, pokud xxx x&xxxx;xxxxxxx xxxxxxx zůstatků x&xxxx;xxxx xxxxxxxxx x&xxxx;XXXXXX2-XXX xx xxxxxxxxxxxx xxxxxxxxxxx xxxx. |
|
(3) |
Xxxxx xxxxxxxx xxxxx XXX/2012/27, xxxxx xxxx xxxx xx podmínky XXXXXX2-XXX, je třeba xxxxxxxxx x&xxxx;xxxxxxxxxx Evropské xxxxxxxxx banky ECB/2007/7 (3). |
|
(4) |
Rozhodnutí XXX/2007/7 xx proto xxxxx xxxxxxxxxxxxx xxxxxxxx xxxxxx, |
XXXXXXX XXXX XXXXXXXXXX:
Xxxxxx&xxxx;1
Xxxxx
Xxxxxxx X, XX x&xxxx;XXX xxxxxxxxxx XXX/2007/7 xx xxxx x&xxxx;xxxxxxx x&xxxx;xxxxxxxxx xxxxxx xxxxxxxxxx.
Xxxxxx&xxxx;2
Xxxxxxxxx ustanovení
Toto xxxxxxxxxx xxxxxxxx x&xxxx;xxxxxxxx pátým xxxx po zveřejnění x&xxxx;Xxxxxxx xxxxxxxx Evropské xxxx.
Xxxxxxx se xxx xxx 21. listopadu 2021, x&xxxx;xxxxxxxx xxxx.&xxxx;1 xxxx. x) a odstavců 7 x&xxxx;9 xxxxxxx XX xxxxxx xxxxxxxxxx, které xx xxxxxxx ode xxx 13.&xxxx;xxxxxx 2022.
Ve Xxxxxxxxxx xxx Xxxxxxx xxx 21. září 2021.
Xxxxxxxxxxx XXX
Xxxxxxxxx XXXXXXX
(1)&xxxx;&xxxx;Xxxxxx xxxxxx Xxxxxxxx xxxxxxxxx xxxxx (EU) 2021/1759 xx xxx 20.&xxxx;xxxxxxxx 2021, xxxxxxx se xxxx xxxxxx zásady XXX/2012/27 x&xxxx;xxxxxxxxxxxxxx xxxxxxxxx xxxxxxxxxxxxxxx xxxxxxx zúčtování xxxxxx x&xxxx;xxxxxxx xxxx (XXXXXX2) (ECB/2021/30) [(xxx xxxxxx 45 x&xxxx;xxxxx xxxxx Xxxxxxxx xxxxxxxx).
(2)&xxxx;&xxxx;Xxxxxx xxxxxx Xxxxxxxx centrální xxxxx XXX/2012/27 xx xxx 5. prosince 2012 x&xxxx;xxxxxxxxxxxxxx expresním xxxxxxxxxxxxxxx xxxxxxx zúčtování xxxxxx x&xxxx;xxxxxxx xxxx (TARGET2) (Xx. xxxx. X&xxxx;30, 30.1.2013, x. 1).
(3) Rozhodnutí Xxxxxxxx centrální xxxxx XXX/2007/7 xx xxx 24.&xxxx;xxxxxxxx 2007 o podmínkách XXXXXX2-XXX (Xx. xxxx. X&xxxx;237, 8.9.2007, x. 71).
XXXXXXX X
Xxxxxxx X&xxxx;xxxxxxxxxx XXX/2007/7 xx xxxx xxxxx:
|
1. |
Xxxxxx&xxxx;1 xx xxxx xxxxx:
|
|
2. |
V článku 2 xxxxxx odstavci se xxxxxxxx xxxx xxxx, xxxxx zní:
|
|
3. |
Xxxxxx&xxxx;3 xx xxxx takto:
|
|
4. |
Xxxxxx&xxxx;5 xx xxxxxxxxx xxxxx: „Xxxxxxx&xxxx;5 Xxxxxx xxxxxxxxxxxx XX account xxxxxxx xx TARGET2-ECB xxx direct xxxxxxxxxxxx xxx shall xxxxxx xxxx the xxxxxxxxxxxx xxx xxx xx Xxxxxxx&xxxx;8(1) xxx&xxxx;(2). Xxxx xxxxx xxxx at xxxxx one XX xxxxxxx xxxx xxx XXX. XX xxxxxxx xxxxxxx that xxxx xxxxxxx to xxx XXX Inst xxxxxx xx xxxxxxx xxx XXXX Xxxxxxx Xxxxxx Xxxxxxxx Adherence Xxxxxxxxx xxxxx xx and xxxxx remain xxxxxxxxx xx the XXXX Xxxxxxxx at xxx xxxxx, xxxxxx xx x&xxxx;XXXX XXX holder xx xx a reachable xxxxx via x&xxxx;XXXX XXX xxxxxx.“; |
|
5. |
Xxxxxx&xxxx;22 se xxxxxxxxx tímto: „Article 22 Security Xxxxxxxxxxxx xxx Control Xxxxxxxxxx 1.&xxxx;&xxxx;&xxxx;Xxxxxxxxxxxx xxxxx implement xxxxxxxx xxxxxxxx xxxxxxxx to xxxxxxx xxxxx xxxxxxx xxxx xxxxxxxxxxxx access xxx xxx. Xxxxxxxxxxxx xxxxx xx exclusively xxxxxxxxxxx for xxx xxxxxxxx xxxxxxxxxx xx xxx confidentiality, xxxxxxxxx xxx xxxxxxxxxxxx of xxxxx systems. 2. Participants shall xxxxxx the XXX xx any security-related xxxxxxxxx xx their xxxxxxxxx xxxxxxxxxxxxxx xxx, xxxxx appropriate, xxxxxxxx-xxxxxxx xxxxxxxxx that xxxxx xx xxx xxxxxxxxx xxxxxxxxxxxxxx xx xxx xxxxx party providers. Xxx XXX xxx xxxxxxx xxxxxxx xxxxxxxxxxx xxxxx xxx xxxxxxxx xxx, xx xxxxxxxxx, xxxxxxx xxxx the xxxxxxxxxxx xxxx xxxxxxxxxxx xxxxxxxx to xxxxxxx x&xxxx;xxxxxxxxxx xx xxxx xx xxxxx. 3.&xxxx;&xxxx;&xxxx;Xxx XXX xxx impose xxxxxxxxxx xxxxxxxx xxxxxxxxxxxx, xx xxxxxxxxxx xxxx regard xx cybersecurity xx xxx xxxxxxxxxx xx xxxxx, xx xxx xxxxxxxxxxxx xxx/xx xx xxxxxxxxxxxx xxxx xxx xxxxxxxxxx xxxxxxxx xx xxx ECB. 4. Participants xxxxx xxxxxxx xxx XXX xxxx: (i) permanent xxxxxx to xxxxx xxxxxxxxxxx xx adherence xx xxxxx xxxxxx xxxxxxx xxxxxxx provider’s xxxxxxxx security requirements, xxx (ii) on xx xxxxxx xxxxx xxx XXXXXX2 xxxx-xxxxxxxxxxxxx xxxxxxxxx xx xxxxxxxxx xx xxx XXX’x xxxxxxx in Xxxxxxx. 4x.&xxxx;&xxxx;&xxxx;Xxx XXX shall xxxxxx xxx xxxxxxxxxxx’x xxxx-xxxxxxxxxxxxx xxxxxxxxx(x) on the xxxxxxxxxxxx level xx xxxxxxxxxx with xxxx xx xxx requirements xxx xxx xx xxx XXXXXX2 xxxx-xxxxxxxxxxxxx xxxxxxxxxxxx. These xxxxxxxxxxxx xxx xxxxxx in Xxxxxxxx XXX, xxxxx xx addition xx xxx xxxxx Xxxxxxxxxx xxxxxx xx Xxxxxxx&xxxx;2(1), xxxxx xxxx xx xxxxxxxx xxxx xx xxxxx Xxxxxxxxxx. 4x.&xxxx;&xxxx;&xxxx;Xxx xxxxxxxxxxx’x xxxxx xx compliance xxxx xxx xxxxxxxxxxxx xx xxx XXXXXX2 xxxx-xxxxxxxxxxxxx shall xx xxxxxxxxxxx xx xxxxxxx, xx xxxxxxxxxx xxxxx xx xxxxxxxx: ‘xxxx xxxxxxxxxx’; ‘minor non-compliance’; xx ‘major xxx-xxxxxxxxxx’. Xxx following xxxxxxxx xxxxx: xxxx xxxxxxxxxx xx reached xxxxx xxxxxxxxxxxx xxxxxxx 100% xx the xxxxxxxxxxxx; xxxxx xxx-xxxxxxxxxx is xxxxx x&xxxx;xxxxxxxxxxx xxxxxxxxx xxxx than 100% xxx at xxxxx 66% xx xxx xxxxxxxxxxxx and major xxx-xxxxxxxxxx xxxxx x&xxxx;xxxxxxxxxxx xxxxxxxxx xxxx xxxx 66% of the xxxxxxxxxxxx. Xx x&xxxx;xxxxxxxxxxx xxxxxxxxxxxx xxxx x&xxxx;xxxxxxxx xxxxxxxxxxx xx xxx xxxxxxxxxx xx xx, xx shall be xxxxxxxxxx as xxxxxxxxx xxxx xxx respective xxxxxxxxxxx for the xxxxxxxx xx the xxxxxxxxxxxxxx. X&xxxx;xxxxxxxxxxx which xxxxx xx reach ‘xxxx xxxxxxxxxx’ xxxxx xxxxxx an xxxxxx xxxx demonstrating how xx xxxxxxx to xxxxx full compliance. Xxx XXX shall xxxxxx xxx relevant xxxxxxxxxxx xxxxxxxxxxx xx xxx status of xxxx xxxxxxxxxxx’x xxxxxxxxxx. 4x.&xxxx;&xxxx;&xxxx;Xx xxx participant refuses xx grant xxxxxxxxx xxxxxx to xxx xxxxxxxxxxx of xxxxxxxxx xx xxxxx chosen XXXx xxxxxxxx security xxxxxxxxxxxx xx xxxx xxx provide the XXXXXX2 xxxx-xxxxxxxxxxxxx the xxxxxxxxxxx’x level of xxxxxxxxxx xxxxx xx xxxxxxxxxxx xx ‘xxxxx xxx-xxxxxxxxxx’. 4x.&xxxx;&xxxx;&xxxx;Xxx XXX xxxxx xxxxxxxx xxxxxxxxxx xx xxxxxxxxxxxx xx xx xxxxxx xxxxx. 4x.&xxxx;&xxxx;&xxxx;Xxx XXX xxx xxxxxx xxx xxxxxxxxx xxxxxxxx of xxxxxxx xx xxxxxxxxxxxx xxxxx xxxxx xx xxxxxxxxxx xxx xxxxxxxx xx xxxxx xx xxxxx non-compliance, xx xxxxxxxxxx xxxxx xx xxxxxxxx:
|
|
6. |
X&xxxx;xxxxxx&xxxx;33 xx xxxxxxxx 1 xxxxxxxxx xxxxx: „1.&xxxx;&xxxx;&xxxx;Xxxxxxxxxxxx xxxxx xx xxxxxx xx be xxxxx xx, xxxxx xxxxxx xxxx, and shall xx xxxx xx xxxxxxxxxxx that xxxxxxxxxx xx the xxxxxxxx xxxxxxxxx xxxxxxxxxxx xxxx xxx xxxxxxxxxxx xx xxxx xxxxxxxx xx xxxxxxxxxxx xx data xxxxxxxxxx. Xxxx shall xx xxxxxx to xx aware xx, xxx xxxxx xxxxxx xxxx xxx xxxxxxxxxxx xx xxxx xxxxxxxx xx xxxxxxxxxxx on xxxxxxxxxx xx xxxxx xxxxxxxxxx xxx the xxxxxxxxx of xxxxxxxxx, xxxxxxxxxxxxx-xxxxxxxxx nuclear activities xxx the xxxxxxxxxxx xx nuclear weapons xxxxxxxx systems, xx xxxxxxxxxx xx terms xx xxxxxxxxxxxx xxxxxxxxxxx xxxxxxxx xxxxxxxxxx xxx xxxxxxxx xxxxxxx or xxxxxxxx xx their XX accounts. Participants xxxxx xxxxxx xxxx xxxx xxx xxxxxxxx xxxxx xxx XXXXXX2 xxxxxxx xxxxxxx xxxxxxxx’x xxxx xxxxxxxxx policy xxxxx to entering xxxx xxx xxxxxxxxxxx xxxxxxxxxxxx xxxx xxx XXXXXX2 network service xxxxxxxx.“; |
|
7. |
Xxxxxx xx nový xxxxxx&xxxx;39x, který xxx: „Xxxxxxx&xxxx;39x Xxxxxxxxxxxx xxxxxxxxxx 1.&xxxx;&xxxx;&xxxx;Xxxx xxx XXXXXX xxxxxx xx xxxxxxxxxxx xxx TARGET2 has xxxxxx operation, XX xxxxxxx xxxxxxxx xxxxx xx xxxxxxxxxxx to xxx xxxxxxx holder’s xxxxxxxxxxxxx xxxxxxxxx xxxxxxxx xx the XXXXXX xxxxxx. 2.&xxxx;&xxxx;&xxxx;Xxx xxxxxxxxxxx xxxx XX account holders, xxxxxxxx Participants xxx xxxxxxxxxxx XXX holders xxxxxxxx xx xxx XXX Inst xxxxxx xx xxxxxxxxx xx xxx XXXX Platform xxxxxxxx xx Xxxxxxx&xxxx;5 xxxxx xxxxx xx xx 25 Xxxxxxxx 2022.“; |
|
8. |
X&xxxx;xxxxxxx X&xxxx;xx x&xxxx;xxxx.&xxxx;8 xxxxxxx. 4 xxxxxxxxx xxxxxxx b) xxxxx:
|
|
9. |
X&xxxx;xxxxxxx XX se v odstavci 6 xxxxxxxxx xxxxxxx x) xxxxx:
|
|
10. |
Xxxxxxxx xx xxxx xxxxxxx VII, který xxx: „Xxxxxxxx XXX Xxxxxxxxxxxx regarding xxxxxxxxxxx xxxxxxxx xxxxxxxxxx xxx business xxxxxxxxxx xxxxxxxxxx Xxxxxxxxxxx security xxxxxxxxxx Xxxxx xxxxxxxxxxxx xxx xxxxxxxxxx xx xxxx xxxxxxxxxxx, xxxxxx xxx xxxxxxxxxxx xxxxxxxxxxxx that x&xxxx;xxxxxxxx xxxxxxxxxxx xx xxx xxxxxxxxxx xx xx. Xx establishing xxx xxxxx xx xxxxxxxxxxx xx xxx xxxxxxxxxxxx xxxxxx xxx xxxxxxxxxxxxxx, xxx xxxxxxxxxxx xxxxxx xxxxxxxx the xxxxxxxx xxxx xxx xxxx xx xxx Xxxxxxx Xxxxxxxxxxx Chain (PTC). Xxxxxxxxxxxx, the PTC xxxxxx xx x&xxxx;Xxxxx xx Xxxxx (PoE), x.x. a system xxxxxxxx xx xxx xxxxxxxx xx transactions (e.g. xxxxxxxxxxxx, front-office xxx xxxx-xxxxxx xxxxxxxxxxxx, middleware), xxx xxxx xx xxx system responsible xx xxxx xxx xxxxxxx xx XXXXX (x.x. XXXXX XXX Xxx) or Xxxxxxxx (xxxx xxx xxxxxx xxxxxxxxxx to Internet-based Xxxxxx). Xxxxxxxxxxx 1.1: Information xxxxxxxx policy The xxxxxxxxxx xxxxx xxx x&xxxx;xxxxx xxxxxx direction xx xxxx xxxx xxxxxxxx xxxxxxxxxx xxx demonstrate xxxxxxx for xxx xxxxxxxxxx to information xxxxxxxx xxxxxxx xxx xxxxxxxx, approval xxx xxxxxxxxxxx of an xxxxxxxxxxx security xxxxxx xxxxxx xx xxxxxxxx xxxxxxxxxxx xxxxxxxx and xxxxx xxxxxxxxxx xxxxxx xxx xxxxxxxxxxxx in xxxxx xx xxxxxxxxxxxxxx, xxxxxxxxxx xxx xxxxxxxxx xx xxxxxxxxxxx xxxxxxxx xxx xxxxx xxxxxxxxxx xxxxx. Xxx xxxxxx xxxxxx contain xx xxxxx xxx xxxxxxxxx xxxxxxxx: objectives, xxxxx (xxxxxxxxx domains xxxx xx xxxxxxxxxxxx, xxxxx xxxxxxxxx, xxxxx management xxx.), principles xxx xxxxxxxxxx xx responsibilities. Requirement 1.2: Xxxxxxxx organisation An xxxxxxxxxxx security xxxxxxxxx xxxxx xx xxxxxxxxxxx xx xxxxxxxxx xxx xxxxxxxxxxx xxxxxxxx xxxxxx xxxxxx xxx organisation. Xxx management shall xxxxxxxxxx xxx xxxxxx xxx xxxxxxxxxxxxx of xxx xxxxxxxxxxx xxxxxxxx xxxxxxxxx to xxxxxx xxx xxxxxxxxxxxxxx xx xxx xxxxxxxxxxx xxxxxxxx xxxxxx (xx xxx Xxxxxxxxxxx 1.1) xxxxxx xxx organisation, xxxxxxxxx xxx allocation xx xxxxxxxxxx xxxxxxxxx xxx xxxxxxxxxx xx xxxxxxxx xxxxxxxxxxxxxxxx xxx this xxxxxxx. Xxxxxxxxxxx 1.3: Xxxxxxxx xxxxxxx Xxx security xx xxx organisation’s information xxx information xxxxxxxxxx xxxxxxxxxx xxxxxx xxx xx xxxxxxx by xxx introduction xx, xxx/xx xxx xxxxxxxxxx xx, an xxxxxxxx xxxxx/xxxxxxx xx products/services xxxxxxxx xx them. Xxx xxxxxx to xxx xxxxxxxxxxxx’x xxxxxxxxxxx xxxxxxxxxx facilities xx xxxxxxxx xxxxxxx xxxxx xx xxxxxxxxxx. Xxxx xxxxxxxx parties xx xxxxxxxx/xxxxxxxx xx xxxxxxxx xxxxxxx xxx xxxxxxxx xx xxxxxx xxx xxxxxxxxxxxx’x xxxxxxxxxxx xxxxxxxxxx xxxxxxxxxx, x&xxxx;xxxx assessment xxxxx xx xxxxxxx xxx xx determine xxx security xxxxxxxxxxxx xxx xxxxxxx xxxxxxxxxxxx. Xxxxxxxx shall xx xxxxxx and defined xx an agreement xxxx xxxx xxxxxxxx xxxxxxxx xxxxx. Xxxxxxxxxxx 1.4: Xxxxx xxxxxxxxxx Xxx information xxxxxx, xxx business xxxxxxxxx xxx xxx xxxxxxxxxx xxxxxxxxxxx xxxxxxx, xxxx as xxxxxxxxx xxxxxxx, xxxxxxxxxxxxxxx, xxxxxxxx xxxxxxxxxxxx, xxx-xxx-xxxxx xxxxxxxx, xxxxxxxx xxx xxxx-xxxxxxxxx xxxxxxxxxxxx, xx the xxxxx of the Xxxxxxx Xxxxxxxxxxx Xxxxx xxxxx xx accounted xxx xxx xxxx x&xxxx;xxxxxxxxx xxxxx. Xxx xxxxxxxxxxxxxx xxx xxx xxxxxxxxxxx xxx the xxxxxxxxx xx xxxxxxxxxxx xxxxxxxx in xxx xxxxxxxx xxxxxxxxx xxx xxx related XX xxxxxxxxxx xx xxxxxxxxx xxx xxxxxxxxxxx assets xxxxx xx assigned. Xxxx: the xxxxx xxx xxxxxxxx the xxxxxxxxxxxxxx xx specific xxxxxxxx xx appropriate, xxx xxxxxxx xxxxxxxxxxx xxx the proper xxxxxxxxxx of the xxxxxx. Xxxxxxxxxxx 1.5: Xxxxxxxxxxx xxxxxx xxxxxxxxxxxxxx Xxxxxxxxxxx xxxxxx xxxxx xx classified xx xxxxx xx xxxxx xxxxxxxxxxx xx xxx smooth xxxxxxxx xx xxx service xx xxx xxxxxxxxxxx. Xxx xxxxxxxxxxxxxx shall xxxxxxxx xxx need, xxxxxxxxxx xxx xxxxxx xx protection xxxxxxxx xxxx xxxxxxxx xxx xxxxxxxxxxx xxxxx xx xxx xxxxxxxx xxxxxxxx xxxxxxxxx xxx xxxxx xxxx take into xxxxxxxxxxxxx the xxxxxxxxxx XX xxxxxxxxxx. Xx xxxxxxxxxxx xxxxx classification xxxxxx approved by xxx xxxxxxxxxx xxxxx xx xxxx to xxxxxx xx xxxxxxxxxxx xxx of xxxxxxxxxx xxxxxxxx xxxxxxxxxx the xxxxxxxxxxx asset lifecycle (xxxxxxxxx xxxxxxx xxx xxxxxxxxxxx xx xxxxxxxxxxx xxxxxx) and xx xxxxxxxxxxx the xxxx xxx xxxxxxxx xxxxxxxx xxxxxxxx. Xxxxxxxxxxx 1.6: Xxxxx xxxxxxxxx xxxxxxxx Xxxxxxxx xxxxxxxxxxxxxxxx xxxxx xx xxxxxxxxx xxxxx to employment xx xxxxxxxx xxx xxxxxxxxxxxx xxx in xxxxx and xxxxxxxxxx xx employment. Xxx xxxxxxxxxx xxx xxxxxxxxxx, xxxxxxxxxxx and xxxxx xxxxx xxxxx xxxxx xx xxxxxxxxxx screened, xxxxxxxxxx xxx xxxxxxxxx xxxx. Xxxxxxxxx, contractors xxx xxxxx party xxxxx of xxxxxxxxxxx xxxxxxxxxx facilities xxxxx xxxx xx agreement xx their xxxxxxxx xxxxx and xxxxxxxxxxxxxxxx. Xx xxxxxxxx xxxxx xx xxxxxxxxx xxxxx xx xxxxxxx among xxx xxxxxxxxx, xxxxxxxxxxx xxx xxxxx xxxxx xxxxx, and education xxx xxxxxxxx in xxxxxxxx procedures and xxx xxxxxxx use xx information xxxxxxxxxx xxxxxxxxxx shall xx xxxxxxxx xx xxxx xx xxxxxxxx possible xxxxxxxx xxxxx. X&xxxx;xxxxxx xxxxxxxxxxxx process for xxxxxxxx security xxxxxxxx xxxxx xx xxxxxxxxxxx xxx xxxxxxxxx. Responsibilities xxxxx xx xx xxxxx to ensure xxxx xx employee’s, xxxxxxxxxx’x xx xxxxx xxxxx xxxx’x xxxx xxxx xx transfer xxxxxx xxx xxxxxxxxxxxx xx xxxxxxx, xxx xxxx the xxxxxx xx all xxxxxxxxx xxx the xxxxxxx xx xxx xxxxxx xxxxxx are completed. Requirement 1.7: Xxxxxxxx and xxxxxxxxxxxxx security Critical xx xxxxxxxxx xxxxxxxxxxx xxxxxxxxxx xxxxxxxxxx shall xx xxxxxx xx secure xxxxx, xxxxxxxxx by xxxxxxx xxxxxxxx perimeters, xxxx xxxxxxxxxxx xxxxxxxx xxxxxxxx xxx xxxxx xxxxxxxx. Xxxx xxxxx xx xxxxxxxxxx xxxxxxxxx xxxx xxxxxxxxxxxx access, xxxxxx and xxxxxxxxxxxx. Xxxxxx xxxxx be xxxxxxx xxxx xx xxxxxxxxxxx who xxxx xxxxxx xxx xxxxx xx Xxxxxxxxxxx 1.6. Xxxxxxxxxx xxx standards xxxxx xx xxxxxxxxxxx xx protect xxxxxxxx xxxxx xxxxxxxxxx information xxxxxx when in xxxxxxx. Xxxxxxxxx xxxxx be xxxxxxxxx from xxxxxxxx xxx xxxxxxxxxxxxx xxxxxxx. Xxxxxxxxxx xx xxxxxxxxx (xxxxxxxxx xxxxxxxxx xxxx xxx-xxxx) xxx xxxxxxx xxx removal xx xxxxxxxx is xxxxxxxxx xx xxxxxx xxx xxxx xx xxxxxxxxxxxx xxxxxx xx information xxx to xxxxx xxxxxxx xxxx xx xxxxxx xx xxxxxxxxx xx xxxxxxxxxxx. Special xxxxxxxx xxx xx xxxxxxxx xx xxxxxxx xxxxxxx xxxxxxxx xxxxxxx xxx xx xxxxxxxxx xxxxxxxxxx xxxxxxxxxx xxxx xx xxx xxxxxxxxxx xxxxxx and cabling xxxxxxxxxxxxxx. Xxxxxxxxxxx 1.8: Xxxxxxxxxx xxxxxxxxxx Xxxxxxxxxxxxxxxx and xxxxxxxxxx xxxxx xx xxxxxxxxxxx xxx the xxxxxxxxxx xxx xxxxxxxxx xx xxxxxxxxxxx xxxxxxxxxx xxxxxxxxxx xxxxxxxx xxx xxx xxxxxxxxxx systems xx xxx Xxxxxxx Xxxxxxxxxxx Xxxxx end-to-end. As regards xxxxxxxxx xxxxxxxxxx, xxxxxxxxx xxxxxxxxx xxxxxxxxxxxxxx xx XX xxxxxxx, xxxxxxxxxxx xx duties xxxxx xx xxxxxxxxxxx, xxxxx xxxxxxxxxxx, xx xxxxxx xxx xxxx of xxxxxxxxx xx xxxxxxxxxx xxxxxx xxxxxx. Xxxxx xxxxxxxxxxx xx duties xxxxxx xx xxxxxxxxxxx xxx xx xxxxxxxxxx xxxxxxxxx xxxxxxx, xxxxxxxxxxxx xxxxxxxx xxxxx be xxxxxxxxxxx xxxxxxxxx x&xxxx;xxxxxx xxxx analysis. Xxxxxxxx xxxxx xx established xx xxxxxxx xxx xxxxxx the xxxxxxxxxxxx xx xxxxxxxxx code xxx xxxxxxx in xxx Payment Xxxxxxxxxxx Xxxxx. Xxxxxxxx xxxxx xx xxxx established (xxxxxxxxx xxxx xxxxxxxxx) xx xxxxxxx, xxxxxx xxx remove xxxxxxxxx xxxx. Xxxxxx xxxx xxxxx xx xxxx xxxx xxxx xxxxxxx xxxxxxx (x.x. signed Xxxxxxxxx XXX components xxx Java Xxxxxxx). Xxx configuration xx xxx xxxxxxx (x.x. xxx xxx xx xxxxxxxxxx and xxxxxxx) xxxxx be xxxxxxxx xxxxxxxxxx. Xxxx xxxxxx and xxxxxxxx xxxxxxxx shall xx xxxxxxxxxxx xx xxx xxxxxxxxxx; xxxxx xxxxxxxx policies xxxxx xxxxxxx x&xxxx;xxxx of xxx xxxxxxxxxxx xxxxxxx xxxxx xx xxxxxx xx regular xxxxxxxxx xx least xxxxxxxx. Xxxxxxx xxxx are xxxxxxxx xxx the xxxxxxxx xx xxxxxxxx xxxxx xx monitored xxx xxxxxx xxxxxxxx xx xxxxxxxxxxx security shall xx xxxxxxxx. Xxxxxxxx xxxx shall xx xxxx xx xxxxxx xxxx xxxxxxxxxxx xxxxxx xxxxxxxx xxx identified. Xxxxxxxx xxxx xxxxx xx xxxxxxxxx reviewed xx x&xxxx;xxxxxx xxxxx, xxxxx xx xxx xxxxxxxxxxx xx xxx xxxxxxxxxx. Xxxxxx monitoring xxxxx xx used xx xxxxx the xxxxxxxxxxxxx xx xxxxxxxx xxxxx xxx xxxxxxxxxx xx xxxxxxxx xxx xxx xxxxxxxx xx xxxxxxxx and xx xxxxxx xxxxxxxxxx xx xx access policy xxxxx. Xxxxxxxxx xx xxxxxxxxxxx xxxxxxx organisations xxxxx xx xxxxx on x&xxxx;xxxxxx exchange policy, xxxxxxx out xx xxxx xxxx exchange xxxxxxxxxx xxxxx xxx xxxxxxxx parties and xxxxx xx xxxxxxxxx xxxx any relevant xxxxxxxxxxx. Xxxxx xxxxx xxxxxxxx components xxxxxxxx xx xxx xxxxxxxx xx information xxxx XXXXXX2 (like xxxxxxxx xxxxxxxx from a Service Xxxxxx xx xxxxxxxx 2 of xxx xxxxx xxxxxxx xx xxx XXXXXX2 xxxx-xxxxxxxxxxxxx xxxxxxxxxxx xxxxxxxx) xxxx xx xxxx xxxxx x&xxxx;xxxxxx xxxxxxxxx with xxx third party. Requirement 1.9: Xxxxxx control Access xx xxxxxxxxxxx xxxxxx xxxxx be xxxxxxxxx xx xxx xxxxx xx business requirements (xxxx-xx-xxxx&xxxx;(1)) xxx xxxxxxxxx xx the established xxxxxxxxx of xxxxxxxxx xxxxxxxx (including the xxxxxxxxxxx security policy). Xxxxx xxxxxx xxxxxxx xxxxx shall xx xxxxxxx xxxxx xx xxx xxxxxxxxx xx xxxxx xxxxxxxxx&xxxx;(2) xx xxxxxxx xxxxxxx xxx xxxxx of xxx xxxxxxxxxxxxx business xxx XX xxxxxxxxx. Where xxxxxxxx (e.g. xxx xxxxxx management) logical xxxxxx control xxxxxx xx xxxxxxxxxx xxxx xxxxxxxx xxxxxx xxxxxxx xxxxxx xxxxx xxx xxxxxxxx xxxxxxxxxxxx controls xx xxxxx (e.g. xxxxxxxxxx, xxxxxxxx data xxxxxxxxxxxxx). Xxxxxx and xxxxxxxxxx xxxxxxxxxx shall be xx xxxxx to xxxxxxx the xxxxxxxxxx xx access xxxxxx xx information xxxxxxx xxx services that xxxx within xxx xxxxx xx the Xxxxxxx Xxxxxxxxxxx Chain. Xxx xxxxxxxxxx shall xxxxx xxx xxxxxx xx the xxxxxxxxx xx xxxx xxxxxx, xxxx the xxxxxxx xxxxxxxxxxxx xx xxx xxxxx xx the xxxxx deregistration of xxxxx xxxx xx xxxxxx xxxxxxx access. Special xxxxxxxxx shall xx xxxxx, xxxxx xxxxxxxxxxx, xx xxx xxxxxxxxxx xx access rights xx xxxx criticality xxxx xxx abuse xx xxxxx access xxxxxx xxxxx xxxx xx x&xxxx;xxxxxx adverse xxxxxx xx xxx xxxxxxxxxx of xxx xxxxxxxxxxx (x.x. xxxxxx xxxxxx xxxxxxxx xxxxxx xxxxxxxxxxxxxx, xxxxxxxx xx xxxxxx xxxxxxxx, xxxxxx xxxxxx to xxxxxxxx xxxx). Xxxxxxxxxxx xxxxxxxx xxxxx xx xxx xx xxxxx xx identify, xxxxxxxxxxxx xxx authorise xxxxx xx specific xxxxxx in the xxxxxxxxxxxx’x xxxxxxx, e.g. xxx xxxxx xxx xxxxxx xxxxxx to xxxxxxx in xxx Xxxxxxx Xxxxxxxxxxx Chain. Xxxxxxxx xxxxxxxx xxxxx xxx xx xxxxxx xx xxxxx xx xxxxxx xxxxxxxxxxxxxx. Xxx passwords, xxxxx shall xx xxxxxxxxxxx and xxxxxxxx xx xxxxxxxx xxxxxxxx xx ensure xxxx xxxxxxxxx xxxxxx xx xxxxxx xxxxxxx, x.x. xxxxxxxxxx rules xxx xxxxxxx-xxxx xxxxxxxx. A safe xxxxxxxx xxxxxxxx and/or xxxxx protocol xxxxx xx xxxxxxxxxxx. X&xxxx;xxxxxx xxxxx xx xxxxxxxxx xxx xxxxxxxxxxx on xxx xxx xx xxxxxxxxxxxxx xxxxxxxx xx protect xxx xxxxxxxxxxxxxxx, xxxxxxxxxxxx xxx xxxxxxxxx xx xxxxxxxxxxx. A key management xxxxxx shall xx xxxxxxxxxxx to xxxxxxx xxx xxx of xxxxxxxxxxxxx controls. There shall xx xxxxxx for xxxxxxx xxxxxxxxxxxx information xx xxxxxx xx xx xxxxx (x.x. x&xxxx;xxxxx xxxxxx, a clear xxxx xxxxxx) to xxxxxx the xxxx xx xxxxxxxxxxxx xxxxxx. Xxxx xxxxxxx xxxxxxxx, the xxxxx xx xxxxxxx xx xx xxxxxxxxxxx xxxxxxxxxxx xxxxx xx xxxxxxxxxx xxx xxxxxxxxxxx xxxxxxxxx xxx xxxxxxxxxxxxxx xxxxxxxx xxxxx xx xxxxxxx. Xxxxxxxxxxx 1.10: Xxxxxxxxxxx xxxxxxx xxxxxxxxxxx, xxxxxxxxxxx xxx xxxxxxxxxxx Xxxxxxxx requirements xxxxx xx identified xxx xxxxxx xxxxx xx xxx development xxx/xx xxxxxxxxxxxxxx xx xxxxxxxxxxx xxxxxxx. Xxxxxxxxxxx xxxxxxxx xxxxx be built xxxx applications, xxxxxxxxx xxxx-xxxxxxxxx xxxxxxxxxxxx, xx xxxxxx correct processing. Xxxxx controls shall xxxxxxx xxx validation xx xxxxx xxxx, xxxxxxxx xxxxxxxxxx and xxxxxx xxxx. Xxxxxxxxxx xxxxxxxx xxx xx xxxxxxxx xxx xxxxxxx xxxx xxxxxxx, or xxxx xx xxxxxx xx, sensitive, xxxxxxxx xx xxxxxxxx xxxxxxxxxxx. Xxxx controls xxxxx xx xxxxxxxxxx on xxx basis xx xxxxxxxx requirements xxx xxxx assessment according xx xxx xxxxxxxxxxx xxxxxxxx (x.x. xxxxxxxxxxx xxxxxxxx xxxxxx, xxxxxxxxxxxxx xxxxxxx xxxxxx). Xxx xxxxxxxxxxx xxxxxxxxxxxx xx xxx xxxxxxx shall xx xxxxxxxxxxx, documented and xxxxxx xxxxx to xxxxx xxxxxxxxxx xxx xxx. Xx xxxxxxx xxxxxxx xxxxxxxx, xxxxxxxxxxx xxxxxxxx, xxxxxxxxx segmentation xxx xxxxxx xxxxxxxxxx, xxxxxx xx xxxxxxxxxxx xxxxx on xxx xxxxxxxxxxx xx xxxx xxxxx xxx xxx xxxxx of risk xx xxx xxxxxxx xxxxx xx xxx xxxxxxxxxxxx. Xxxxx xxxxx xx specific xxxxxxxx xx protect xxxxxxxxx xxxxxxxxxxx xxxxxxx xxxx xxxxxx xxxxxxxx. Xxxxxx xx xxxxxx files and xxxxxxx xxxxxx code xxxxx be xxxxxxxxxx xxx XX projects xxx support xxxxxxxxxx xxxxxxxxx xx x&xxxx;xxxxxx xxxxxx. Xxxx xxxxx xx taken xx xxxxx xxxxxxxx of xxxxxxxxx xxxx xx xxxx xxxxxxxxxxxx. Project xxx xxxxxxx xxxxxxxxxxxx xxxxx xx xxxxxxxx xxxxxxxxxx. Xxxxxxxxxx xx xxxxxxx xx xxxxxxxxxx xxxxx xx xxxxxxxx xxxxxxxxxx. A risk xxxxxxxxxx xx xxx major xxxxxxx xx xx xxxxxxxx xx xxxxxxxxxx xxxxx xx xxxxxxxxx. Xxxxxxx xxxxxxxx xxxxxxx xxxxxxxxxx xx xxxxxxx in xxxxxxxxxx shall also xx xxxxxxxxx according xx x&xxxx;xxxxxxxxxx xxxx xxxxx xx the xxxxxxx xx a risk xxxxxxxxxx, xxx xxxxxxxx xxxxxxx shall include, xx xxxxx, xxxxxxxxxxxxx xxxxxxxxxxx. All xx xxx xxxxxxxxxxxx highlighted xxxxxx the xxxxxxxx xxxxxxx xxxxxxxxxx xxxxx xx xxxxxxxx xxx xxxxxx xxxxx to xxxxx xxx identified xxx xxxxx xx xxxxxxxx and followed xx in x&xxxx;xxxxxx xxxxxxx. Xxxxxxxxxxx 1.11: Information xxxxxxxx in xxxxxxxx&xxxx;(3) xxxxxxxxxxxxx Xx xxxxxx protection xx xxx xxxxxxxxxxx’x xxxxxxxx information xxxxxxx xxxx xxx accessible xx suppliers, xxxxxxxxxxx xxxxxxxx requirements for xxxxxxxxxx xxx risks xxxxxxxxxx xxxx supplier’s xxxxxx shall be xxxxxxxxxx xxx formally xxxxxx upon xxxx xxx xxxxxxxx. Xxxxxxxxxxx 1.12: Xxxxxxxxxx xx xxxxxxxxxxx xxxxxxxx incidents and xxxxxxxxxxxx Xx xxxxxx a consistent xxx xxxxxxxxx approach xx xxx xxxxxxxxxx xx information xxxxxxxx xxxxxxxxx, xxxxxxxxx xxxxxxxxxxxxx xx xxxxxxxx events xxx weaknesses, roles, xxxxxxxxxxxxxxxx xxx xxxxxxxxxx, xx xxxxxxxx and xxxxxxxxx level, xxxxx xx xxxxxxxxxxx xxx xxxxxx to xxxxxx x&xxxx;xxxxx, xxxxxxxxx and xxxxxxx xxx safely xxxxxxx xxxx xxxxxxxxxxx xxxxxxxx incidents xxxxxxxxx xxxxxxxxx xxxxxxx xx x&xxxx;xxxxx-xxxxxxx xxxxx (e.g. x&xxxx;xxxxx pursued xx xx external xxxxxxxx xx by xx xxxxxxx). Xxxxxxxxx xxxxxxxx xx xxxxx procedures xxxxx be xxxxxxxxxx xxxxxxx. Xxxxxxxxxxx 1.13: Xxxxxxxxx xxxxxxxxxx xxxxxx X&xxxx;xxxxxxxxxxx’x xxxxxxxx xxxxxxxxxxx systems (x.x. xxxx office systems, xxxxxxxx xxxxxxxx xxx xxxxxxxx network xxxxxxxxxxxx) xxxxx be regularly xxxxxxxx for xxxxxxxxxx xxxx the organisation’s xxxxxxxxxxx xxxxxxxxx xx xxxxxxxx (x.x. xxxxxxxxxxx xxxxxxxx xxxxxx, cryptographic xxxxxxx xxxxxx). Xxxxxxxxxxx 1.14: Xxxxxxxxxxxxxx Xxxxx virtual xxxxxxxx xxxxx comply with xxx xxx xxxxxxxx xxxxxxxx xxxx xxx xxx xxx xxxxxxxx xxxxxxxx xxx systems (x.x. xxxxxxxxx, xxxxxxx). Xxxxxxxx xxxxxxxx xx xxxxxxxxxxx xxxx xxxxxxx: xxxxxxxxx xx xxx xxxxxxxxxx xxx xxx xxxxxxx xxxxxxxxx system, xxxxxxx xxxxxxxx, xxxxxx xxxxxxxxxx xx xxxxxxxxx xxxxxxxxxxxx (x.x. production xxx xxxxxxxxxxx). Xxxxxxxxxxx xxxxxxxxxx, xxxxxxx xxx xxxxxxxxxx xx xxxx xx xxxxxxxx xx xxxxxx xxxxxx, xx xxxxxxxxxx xxx high xxxxxxxxxx xxxxxxxx, xxxxx xx implemented xxxxx xx a risk assessment. Xxxxx xxxxxxx xxxxxxxx xxxxxxx xx the xxxx xxxxxxxxxx xxxxx xxxx a similar xxxx xxxxxxx. Xxxxxxxxxxx 1.15: Cloud xxxxxxxxx Xxx xxxxx xx xxxxxx and/or hybrid xxxxx xxxxxxxxx xx xxx Xxxxxxx Xxxxxxxxxxx Xxxxx must be xxxxx xx x&xxxx;xxxxxx xxxx xxxxxxxxxx, xxxxxx xxxx xxxxxxx the xxxxxxxxx xxxxxxxx xxx xxx xxxxxxxxxxx xxxxxxx xxxxxxx to xxx xxxxx xxxxxxxx. Xx xxxxxx xxxxx solutions are xxxx, xx xx xxxxxxxxxx that xxx xxxxxxxxxxx level of xxx xxxxxxx system xx xxx xxxxxxx xxx of the xxxxxxxxx systems. Xxx xx-xxxxxxxx xxxxxxxxxx xx xxx xxxxxx xxxxxxxxx xxxx xx xxxxxxxxxx xxxx xxx xxxxx xx-xxxxxxxx systems. Business xxxxxxxxxx xxxxxxxxxx (xxxxxxxxxx xxxx xx xxxxxxxx participants) The xxxxxxxxx xxxxxxxxxxxx (2.1 xx 2.6) xxxxxx xx xxxxxxxx continuity xxxxxxxxxx. Xxxx XXXXXX2 xxxxxxxxxxx xxxxxxxxxx xx xxx Xxxxxxxxxx as xxxxx xxxxxxxx xxx xxx xxxxxx xxxxxxxxxxx xx the TARGET2 xxxxxx xxxxx xxxx x&xxxx;xxxxxxxx xxxxxxxxxx xxxxxxxx xx xxxxx xxxxxxxxxx xxx following elements.
|
(1) The xxxx-xx-xxxx xxxxxxxxx refers xx the xxxxxxxxxxxxxx xx the set xx information xxxx xx xxxxxxxxxx xxxxx xxxxxx xx in xxxxx xx xxxxx xxx xxx/xxx duties.
(2) The xxxxxxxxx xx xxxxx xxxxxxxxx refers xx xxxxxxxxx x&xxxx;xxxxxxx’x xxxxxx xxxxxxx xx xx XX xxxxxx xx xxxxx to xxxxx xxx corresponding xxxxxxxx xxxx.
(3)&xxxx;&xxxx;X&xxxx;xxxxxxxx xx xxx xxxxxxx of xxxx xxxxxxxx should xx xxxxxxxxxx as xxx xxxxx xxxxx (xxx xxx xxxxxxxxx) which xx under xxxxxxxx (xxxxxxxxx), xxxx xxx xxxxxxxxxxx, xx xxxxxxx x&xxxx;xxxxxxx xxx xxxxx xxx xxxxxxx xxxxxxxxx xxx xxxxx xxxxx (xxx xxx xxxxxxxxx) xx xxxxxxx access, xxxxxx xxxxxxxx xx xx-xxxx, xx information xxx/xx xxxxxxxxxxx xxxxxxx xxx/xx xxxxxxxxxxx processing xxxxxxxxxx xx the xxxxxxxxxxx xx xxxxx xx associated to xxx scope xxxxxxx xxxxx xxx exercise xx the XXXXXX2 xxxx-xxxxxxxxxxxxx.
PŘÍLOHA II
Příloha XX xxxxxxxxxx XXX/2007/7 xx xxxx xxxxx:
|
1. |
Xxxxxx&xxxx;1 xx xxxx xxxxx:
|
|
2. |
X&xxxx;xx.&xxxx;4 odst. 2 xx xxxxxxx xx) xxxxxxxxx xxxxx:
|
|
3. |
X&xxxx;xx.&xxxx;4 xxxx.&xxxx;2 xx xxxxxx nové xxxxxxx xx), xxxxx xxx:
|
|
4. |
X&xxxx;xxxxxx&xxxx;4 xx xxxxxxxx 3 xxxxxxxxx tímto: „3. TARGET2 provides xxxx-xxxx xxxxx settlement xxx payments xx xxxx, xxxx xxxxxxxxxx xx xxxxxxx xxxx xxxxx xxxxxx XX xxxxxxxx, X2X XXXx xxx TIPS XXXx. XXXXXX2 is xxxxxxxxxxx xxx xxxxxxxxx on xxx xxxxx xx xxx XXX xxxxxxx xxxxx xxxxxxx orders xxx xxxxxxxxx xxx xxxxxxxxx xxx xxxxxxx xxxxx payments xxx xxxxxxxxxx received xx xxx xxxx xxxxxxxxx xxxxxx. Xx far xx xxx xxxxxxxxx xxxxxxxxx of xxx X2X XXXx xx xxxxxxxxx, XXXXXX2 xx xxxxxxxxxxx xxxxxxxxxxx and xxxxxxxxx xx xxx xxxxx xx xxx X2X Xxxxxxxx. Xx xxx as xxx xxxxxxxxx xxxxxxxxx xx xxx XXXX XXXx xxx XXXX XX xxxxxxxxx accounts xx xxxxxxxxx, XXXXXX2 is xxxxxxxxxxx established xxx xxxxxxxxx xx xxx xxxxx xx the XXXX Platform. Xxx XXX xx xxx xxxxxxxx xx services xxxxx xxxxx Xxxxxxxxxx. Xxxx xxx omissions xx the SSP-providing XXXx and xxx 4XXx shall xx xxxxxxxxxx xxxx xxx xxxxxxxxx of xxx XXX, xxx which xx xxxxx xxxxxx xxxxxxxxx xx accordance xxxx Xxxxxxx&xxxx;21 of xxxx Xxxxx. Xxxxxxxxxxxxx xxxxxxxx to xxxxx Xxxxxxxxxx xxxxx not xxxxxx a contractual relationship xxxxxxx X2X DCA xxxxxxx and the XXX-xxxxxxxxx NCBs or xxx 4XXx xxxx xxx xx xxx xxxxxx xxxx in xxxx xxxxxxxx. Xxxxxxxxxxxx, xxxxxxxx xx xxxxxxxxxxx xxxxx x&xxxx;X2X DCA xxxxxx xxxxxxxx from, xx xxxxx xx, xxx XXX xx X2X Platform xx xxxxxxxx to xxx xxxxxxxx provided xxxxx xxxxx Conditions xxx xxxxxx xx be xxxxxxxx from, or xxxx to, xxx XXX.“; |
|
5. |
X&xxxx;xxxxxx&xxxx;8 xx xxxxxxxx 3 nahrazuje xxxxx: „3.&xxxx;&xxxx;&xxxx;Xxxxx xxx ECB xxx xxxxxxx a request xx x&xxxx;X2X XXX xxxxxx xxxxxxxx xx xxxxxxxxx 1, that T2S XXX xxxxxx xx xxxxxx to xxxx xxxxx xxx participating XXX(x) x&xxxx;xxxxxxx xx xxxxx xxx T2S XXX xxxx the xxxxxxx xxxxxxxx xx xxxxxxxxxx transactions xxxxxxxx xx those xxxxxxxxxx xxxxxxxx.“; |
|
6. |
X&xxxx;xxxxxx&xxxx;28 se xxxxxxxx 1 nahrazuje xxxxx: „1.&xxxx;&xxxx;&xxxx;X2X XXX xxxxxxx xxxxx xx xxxxxx xx xx aware xx, xxxxx xxxxxx with, xxx xxxxx xx xxxx to xxxxxxxxxxx xxxx xxxxxxxxxx xx xxx xxxxxxxx xxxxxxxxx xxxxxxxxxxx with xxx xxxxxxxxxxx xx them xxxxxxxx to xxxxxxxxxxx xx data xxxxxxxxxx. Xxxx xxxxx xx xxxxxx xx xx xxxxx xx, xxx xxxxx xxxxxx xxxx xxx obligations on xxxx relating to xxxxxxxxxxx xx xxxxxxxxxx xx xxxxx laundering xxx xxx financing xx terrorism, xxxxxxxxxxxxx-xxxxxxxxx xxxxxxx activities and xxx xxxxxxxxxxx xx xxxxxxx xxxxxxx xxxxxxxx xxxxxxx, xx particular xx xxxxx xx xxxxxxxxxxxx appropriate xxxxxxxx xxxxxxxxxx xxx xxxxxxxx xxxxxxx or credited xx xxxxx X2X XXXx. Xxxxx xx xxxxxxxx xxxx xxx xxxxxxxxxxx xxxxxxxxxxxx xxxx xxx X2X xxxxxxx xxxxxxx provider, X2X XXX xxxxxxx xxxxx xxxxxx xxxx xxxx xxx xxxxxxxx xxxxx xxx xxxx xxxxxxxxx xxxxxx.“; |
|
7. |
Xxxxxx&xxxx;30 xx xxxxxxxxx xxxxx: „Xxxxxxx&xxxx;30 Xxxxxxxxxxx xxxxxxxxxxxx xxxx xx XXX 1.&xxxx;&xxxx;&xxxx;X2X XXX xxxxxxx xxxxx xxxxxx:
2. The xxxxx xxxxxxxxxxxx xxxxxxx x&xxxx;X2X DCA holder xxx xxx XXX xxxxx be exclusively xxxxxxxx by xxx xxxxx xxx xxxxxxxxxx xx xxx xxxxxxxx xxxxxxxx xxxxxxxxx xxxx xx NSP xx xxxxxxxx to xx xxxxxxxxx 1(x). 3.&xxxx;&xxxx;&xxxx;Xxx xxxxxxxx xx be xxxxxxxx xx the XXX xxxxx not form xxxx of the xxxxxxxx xx xx xxxxxxxxx xx xxx XXX xx respect xx XXXXXX2. 4.&xxxx;&xxxx;&xxxx;Xxx ECB xxxxx not xx xxxxxx xxx xxx xxxx, xxxxxx xx xxxxxxxxx xx xxx XXX (xxxxxxxxx its xxxxxxxxx, staff xxx xxxxxxxxxxxxxx), xx for xxx acts, xxxxxx xx omissions xx xxxxx parties xxxxxxxx xx xxxxxxxxxxxx to xxxx xxxxxx xx xxx NSP’s network.“; |
|
8. |
Vkládá xx xxxx článek 34a, xxxxx xxx: „Xxxxxxx&xxxx;34x Xxxxxxxxxxxx provisions Once xxx TARGET system xx xxxxxxxxxxx and XXXXXX2 xxx ceased xxxxxxxxx, X2X XXX xxxxxxx shall xxxxxx X2X DCA holders xx the XXXXXX xxxxxx.“; |
|
9. |
Xxxxxx xx pojem „X2X network xxxxxxx xxxxxxxx“ (v jednotném xxxx xxxxxxx xxxxx) x&xxxx;xx.&xxxx;6 xxxx.&xxxx;1 písm. a) xxxx i), xx.&xxxx;9 xxxx.&xxxx;5, xx.&xxxx;10 xxxx.&xxxx;6, xx.&xxxx;14 odst. 1 xxxx. x), xx.&xxxx;22 xxxx.&xxxx;1, xx.&xxxx;22 xxxx.&xxxx;2, čl. 22 xxxx.&xxxx;3, čl. 27 odst. 5, xx.&xxxx;28 xxxx.&xxxx;1, xx.&xxxx;29 xxxx.&xxxx;1 přílohy XX x&xxxx;x&xxxx;xxxxxxxx 1 dodatku X&xxxx;xx xxxxxxxxx xxxxxxx „XXX“; |
|
10. |
X&xxxx;xxxxxxx X&xxxx;xx x&xxxx;xxxx.&xxxx;8 xxxxxxx. 4 nahrazuje xxxxxxx x) tímto:
|
PŘÍLOHA XXX
Xxxxxxx XXX xxxxxxxxxx ECB/2007/7 xx xxxx xxxxx:
|
1. |
Xxxxxx xx xxxxx „TIPS xxxxxxx xxxxxxx xxxxxxxx“ (v jednotném xxxx xxxxxxx xxxxx) x&xxxx;xxxx xxxxxxx se xxxxxxxxx xxxxxxx „NSP“; |
|
2. |
Článek 1 xx mění xxxxx:
|
|
3. |
X&xxxx;xx.&xxxx;3 xxxx.&xxxx;1 xx xxxxxxx xxxxx na „Appendix X: XXXX xxxxxxxxxxxx xxxxxxxxx requirements“; |
|
4. |
Článek 4 xx xxxx xxxxx:
|
|
5. |
X&xxxx;xx.&xxxx;6 xxxx.&xxxx;1 xxxx. x) xx xxx x) xxxxxxxxx xxxxx:
|
|
6. |
Xxxxxx&xxxx;9 se xxxxxxxxx xxxxx: „Xxxxxxx&xxxx;9 Xxxxxxxxxxx xxxxxxxxxxxx xxxx xx XXX 1.&xxxx;&xxxx;&xxxx;Xxxxxxxxxxxx shall xxxxxx:
2. The legal xxxxxxxxxxxx between x&xxxx;xxxxxxxxxxx xxx xxx XXX xxxxx xx xxxxxxxxxxx xxxxxxxx xx xxx xxxxx xxx xxxxxxxxxx xx their xxxxxxxx xxxxxxxx xx xxxxxxxx xx xx xxxxxxxxx 1(x). 3.&xxxx;&xxxx;&xxxx;Xxx services xx xx xxxxxxxx by xxx NSP xxxxx xxx form part xx xxx services xx xx xxxxxxxxx xx the XXX xx xxxxxxx xx XXXXXX2. 4.&xxxx;&xxxx;&xxxx;Xxx ECB xxxxx xxx xx xxxxxx xxx xxx xxxx, xxxxxx or xxxxxxxxx xx xxx XXX (xxxxxxxxx its xxxxxxxxx, xxxxx and xxxxxxxxxxxxxx), xx xxx xxx xxxx, xxxxxx or xxxxxxxxx by xxxxx xxxxxxx selected by xxxxxxxxxxxx xx xxxx xxxxxx to xxx XXX’x xxxxxxx.“; |
|
7. |
Xxxxxx&xxxx;10 xx xxxxxxx; |
|
8. |
Xxxxxx xx xxxx xxxxxx&xxxx;11x, který xxx: „Xxxxxxx&xxxx;11x XXX xxxxxxxxxx 1.&xxxx;&xxxx;&xxxx;Xxx xxxxxxx XXX xxxxxxxxxx xxxxxxxx xxx xxxxx – XXXX xxxxxxx table xxx xxx xxxxxxxx xx xxx MPL xxxxxxx. 2.&xxxx;&xxxx;&xxxx;Xxxx xxxxx xxx be xxxxxx xx xxxx xxx IBAN. Xx XXXX xxx xx xxxxxx xx xxx xx multiple proxies. 3. Article 29 xxxxx xxxxx xx xxx xxxx contained xx the XXX xxxxxxxxxx.“; |
|
9. |
X&xxxx;xxxxxx&xxxx;12 xx zrušuje xxxxxxxx 9; |
|
10. |
Xxxxxx&xxxx;16 xx xxxxxxxxx tímto: „Article 16 Types of xxxxxxx xxxxxx xx XXXX DCA The xxxxxxxxx xxx xxxxxxxxxx xx xxxxxxx orders xxx xxx xxxxxxxx xx xxx XXXX xxxxxxx:
|
|
11. |
X&xxxx;xxxxxx&xxxx;18 xx xxxxxxxx 6 nahrazuje xxxxx: „6.&xxxx;&xxxx;&xxxx;Xxxxx x&xxxx;XXXX XXX xx PM xxxxxxxxx xxxxxxxx xxxxx, x&xxxx;XXXX XXX to XXXX XX xxxxxxxxx xxxxxxx xxxxxxxxx xxxxxxxx order xx x&xxxx;XXXX AS xxxxxxxxx xxxxxxx to XXXX XXX xxxxxxxxx xxxxxxxx xxxxx xxx xxxx accepted as xxxxxxxx to in Xxxxxxx&xxxx;17, xxx XXXXXX2-XXX xxxxx xxxxx xxxxxxx xxxxxxxxxx xxxxx are xxxxxxxxx xx xxx xxxxx'x xxxxxxx. Xx xxxxxxxxxx xxxxx xxx xxx xxxxxxxxx xxx xxxxxxxxx xxxxxxxx xxxxx xxxxx be rejected. Xx sufficient funds xxx available the xxxxxxxxx xxxxxxxx xxxxx xxxxx xx xxxxxxx xxxxxxxxxxx.“; |
|
12. |
X&xxxx;xx.&xxxx;20 odst. 1 se xxxxxxx x) xxxxxxxxx xxxxx:
|
|
13. |
X&xxxx;xxxxxx&xxxx;30 xx xxxxxxxx 1 xxxxxxxxx xxxxx: „1.&xxxx;&xxxx;&xxxx;XXXX XXX xxxxxxx xxxxx xx deemed xx xx xxxxx of, xxxxx xxxxxx with xxx xxxxx be xxxx to xxxxxxxxxxx xxxx xxxxxxxxxx xx xxx xxxxxxxx xxxxxxxxx xxxxxxxxxxx with xxx xxxxxxxxxxx xx xxxx xxxxxxxx to legislation xx data protection. Xxxx shall xx xxxxxx to xx xxxxx xx, and xxxxx comply xxxx xxx obligations xx xxxx xxxxxxxx xx xxxxxxxxxxx xx xxxxxxxxxx xx money xxxxxxxxxx xxx xxx xxxxxxxxx xx xxxxxxxxx, xxxxxxxxxxxxx-xxxxxxxxx xxxxxxx xxxxxxxxxx xxx xxx development xx xxxxxxx xxxxxxx delivery xxxxxxx, xx particular xx xxxxx xx xxxxxxxxxxxx xxxxxxxxxxx measures xxxxxxxxxx xxx xxxxxxxx xxxxxxx xx xxxxxxxx xx their TIPS XXXx. XXXX XXX xxxxxxx xxxxxx xxxx xxxx xxx xxxxxxxx xxxxx xxxxx chosen XXX'x xxxx xxxxxxxxx xxxxxx xxxxx xx xxxxxxxx into x&xxxx;xxxxxxxxxxx xxxxxxxxxxxx xxxx xxxx XXX.“; |
|
14. |
Xxxxxx xx nový xxxxxx&xxxx;35x, xxxxx xxx: „Xxxxxxx&xxxx;35x Xxxxxxxxxxxx xxxxxxxxx Xxxx xxx TARGET xxxxxx xx operational xxx xxx XXXXXX2 xxx ceased operation, XXXX XXX xxxxxxx xxxxx xxxxxx XXXX XXX holders xx xxx XXXXXX xxxxxx.“; |
|
15. |
X&xxxx;xxxxxxx X&xxxx;xx tabulka x&xxxx;xxxxxxxx 2 nahrazuje tímto:
|
|
16. |
X&xxxx;xxxxxxx X&xxxx;xx x&xxxx;xxxx.&xxxx;6 xxxxxxx. 1 xxxxxxxxx xxxxxxx x) xxxxx:
|
|
17. |
X&xxxx;xxxxxxx XX xx xxxxxxx xxxxxxxx 2; |
|
18. |
Xxxxxxx X&xxxx;xx xxxxxxx. |