XXXXXXXXXX EVROPSKÉ CENTRÁLNÍ XXXXX (XX) 2021/1758
ze xxx 21.&xxxx;xxxx 2021,
xxxxxx xx xxxx rozhodnutí XXX/2007/7 o podmínkách TARGET2-ECB (XXX/2021/43)
XXXXXXX XXXX XXXXXXXX XXXXXXXXX XXXXX,
x&xxxx;xxxxxxx xx Xxxxxxx x&xxxx;xxxxxxxxx Xxxxxxxx xxxx, x&xxxx;xxxxxxx xx xxxxx a čtvrtou odrážku xx.&xxxx;127 xxxx.&xxxx;2 této xxxxxxx,
x&xxxx;xxxxxxx xx xxxxxx Xxxxxxxxxx xxxxxxx xxxxxxxxxxx xxxx x&xxxx;Xxxxxxxx xxxxxxxxx xxxxx, a zejména xx xxxxxx&xxxx;11.6 x&xxxx;xxxxxx 17, 22 x&xxxx;23 xxxxxx xxxxxxx,
xxxxxxxx x&xxxx;xxxxx xxxxxxx:
|
(1) |
Xxxx xxxxxxxxx xxxxxxx&xxxx;(1) xxx 20.&xxxx;xxxxxxxx 2021 xxxxxx xxxxxx Xxxxxxxx centrální xxxxx XXX/2012/27&xxxx;(2) s cílem: x) vyjasnit, xx xxxxxxxx TIPS XXX xxxxx x&xxxx;XXXXXX2 xxxxxxxxx xxxxxxxxxxxxxxx xxxxxxxxxx xxxxxxx xxxxx xxxxxxxxxxxxxx Xxxxxxxxxxx (Xxxxxxxxxx Single Xxxxxx Xxxxxxxxxxxxxx Gateway) xx xxxxxxxxx 2021 x&xxxx;xxxxxxxx X2X XXX budou x&xxxx;XXXXXX2 xxxxxxxxxxxxxxx xxxxxx xxxxxxx xxxxxxxxx od xxxxxx 2022; x) xxxxxxxx a rozšířit pravidla xxxxxxxx xx xxxxxxxxxx xxxxxxxxx na bezpečnost xxxxxxxxx xxxx TARGET2, xxx se xxxxxxxxx, xx se systém XXXXXX2 xxxx xxxx xxxxxxx tak, xxx xxx schopen xxxxx xxxxxxx x&xxxx;xxxxxxx xxxxxxxxxxxx xxxxxxxxxxx; x) xxxxxx xxxxxxxxx, aby majitelé xxxx XX, xxxxxx xxxxxxx xxxxxxxxx a adresovatelní xxxxxxxx kódu XXX, xxxxx xxxxxxxxxxx x&xxxx;xxxxxxxxxxx xxxxxxx XXX Inst xxxxxxxx xxxxxx x&xxxx;xxxxxxxxxx xxxxxxx pro xxxxxxxx xxxxxxxxxxxxx xxxxxxx SEPA, xxxx a zůstali xxxxxx xxxxxxxxxxx xx xxxxxxxxx XXXX xxxxxxxxxxxxxxx XXXX XXX, tak xxx xx xxxxxxxxx xxxxxxxxxx xxxxxxxxxx xxxxxx v celé Xxxx; x) zavést xxxxxxxxxxxxxxx, xxxxx xxx x&xxxx;xxxxxxx xxxxxxx xxxxxxxx x&xxxx;xxxx účastníků x&xxxx;XXXXXX2 xx odpovídající nástupnické xxxx x&xxxx;xxxxxxxx xxxxxxx XXXXXX, xxx xxxx xxxxxxxxx právní xxxxxxx, x&xxxx;x) xxxxxxxx a aktualizovat xxxxxxx xxxxx xxxxxxx xxxxxxxx zásad XXX/2012/27. |
|
(2) |
Xxxxxxx xxxx xxxxxxxxxx projekt xxxxxxxxxxx X2-X2X, bude x&xxxx;xxxxx právní jistoty xxxxxx xxxxxxxx xxxxxxxx xxxxxxxxxxxxxxx, pokud xxx x&xxxx;xxxxxxx xxxxxxx zůstatků x&xxxx;xxxx xxxxxxxxx v TARGET2-ECB xx xxxxxxxxxxxx nástupnické xxxx. |
|
(3) |
Xxxxx obecných xxxxx XXX/2012/27, xxxxx mají xxxx xx podmínky XXXXXX2-XXX, je xxxxx xxxxxxxxx x&xxxx;xxxxxxxxxx Xxxxxxxx xxxxxxxxx banky XXX/2007/7&xxxx;(3). |
|
(4) |
Xxxxxxxxxx XXX/2007/7 xx xxxxx xxxxx odpovídajícím způsobem xxxxxx, |
XXXXXXX XXXX XXXXXXXXXX:
Xxxxxx&xxxx;1
Xxxxx
Xxxxxxx I, XX x&xxxx;XXX xxxxxxxxxx XXX/2007/7 xx xxxx x&xxxx;xxxxxxx x&xxxx;xxxxxxxxx tohoto xxxxxxxxxx.
Článek 2
Závěrečná ustanovení
Toto rozhodnutí xxxxxxxx x&xxxx;xxxxxxxx xxxxx xxxx xx xxxxxxxxxx x&xxxx;Xxxxxxx xxxxxxxx Evropské xxxx.
Xxxxxxx xx xxx xxx 21.&xxxx;xxxxxxxxx 2021, x&xxxx;xxxxxxxx odst. 1 písm. x) x&xxxx;xxxxxxxx 7 x&xxxx;9 xxxxxxx XX xxxxxx xxxxxxxxxx, xxxxx xx xxxxxxx xxx xxx 13.&xxxx;xxxxxx 2022.
Xx Frankfurtu xxx Xxxxxxx xxx 21.&xxxx;xxxx 2021.
Xxxxxxxxxxx XXX
Xxxxxxxxx XXXXXXX
(1)&xxxx;&xxxx;Xxxxxx xxxxxx Xxxxxxxx xxxxxxxxx xxxxx (XX) 2021/1759 xx xxx 20. července 2021, xxxxxxx xx xxxx xxxxxx xxxxxx XXX/2012/27 x&xxxx;xxxxxxxxxxxxxx expresním xxxxxxxxxxxxxxx xxxxxxx xxxxxxxxx xxxxxx x&xxxx;xxxxxxx čase (XXXXXX2) (XXX/2021/30) [(xxx xxxxxx 45 x&xxxx;xxxxx xxxxx Úředního xxxxxxxx).
(2)&xxxx;&xxxx;Xxxxxx xxxxxx Xxxxxxxx centrální xxxxx XXX/2012/27 xx xxx 5. prosince 2012 x&xxxx;xxxxxxxxxxxxxx expresním xxxxxxxxxxxxxxx xxxxxxx xxxxxxxxx xxxxxx x&xxxx;xxxxxxx čase (XXXXXX2) (Xx. xxxx. X&xxxx;30, 30.1.2013, s. 1).
(3)&xxxx;&xxxx;Xxxxxxxxxx Xxxxxxxx centrální xxxxx XXX/2007/7 xx xxx 24.&xxxx;xxxxxxxx 2007 x&xxxx;xxxxxxxxxx XXXXXX2-XXX (Xx. xxxx. X&xxxx;237, 8.9.2007, x. 71).
XXXXXXX X
Xxxxxxx X&xxxx;xxxxxxxxxx XXX/2007/7 xx mění xxxxx:
|
1. |
Xxxxxx&xxxx;1 xx xxxx xxxxx:
|
|
2. |
X&xxxx;xxxxxx&xxxx;2 xxxxxx odstavci xx xxxxxxxx nový xxxx, xxxxx xxx:
|
|
3. |
Xxxxxx&xxxx;3 se xxxx xxxxx:
|
|
4. |
Xxxxxx&xxxx;5 xx xxxxxxxxx xxxxx: „Xxxxxxx&xxxx;5 Xxxxxx xxxxxxxxxxxx XX account xxxxxxx in XXXXXX2-XXX xxx direct xxxxxxxxxxxx xxx xxxxx comply xxxx xxx xxxxxxxxxxxx xxx xxx in Xxxxxxx&xxxx;8(1) xxx&xxxx;(2). They xxxxx xxxx xx xxxxx one PM xxxxxxx xxxx the XXX. PM xxxxxxx xxxxxxx xxxx xxxx xxxxxxx xx xxx XXX Inst xxxxxx xx signing the XXXX Xxxxxxx Xxxxxx Xxxxxxxx Adherence Xxxxxxxxx xxxxx xx xxx xxxxx remain reachable xx xxx TIPS Xxxxxxxx xx xxx xxxxx, either xx x&xxxx;XXXX DCA xxxxxx xx xx x&xxxx;xxxxxxxxx xxxxx via x&xxxx;XXXX XXX xxxxxx.“; |
|
5. |
Xxxxxx&xxxx;22 se xxxxxxxxx xxxxx: „Xxxxxxx&xxxx;22 Xxxxxxxx Requirements xxx Xxxxxxx Procedures 1. Participants xxxxx xxxxxxxxx xxxxxxxx xxxxxxxx xxxxxxxx xx xxxxxxx their xxxxxxx xxxx xxxxxxxxxxxx xxxxxx xxx use. Xxxxxxxxxxxx xxxxx xx xxxxxxxxxxx xxxxxxxxxxx xxx xxx xxxxxxxx xxxxxxxxxx of xxx confidentiality, integrity xxx availability xx xxxxx xxxxxxx. 2.&xxxx;&xxxx;&xxxx;Xxxxxxxxxxxx xxxxx xxxxxx xxx XXX xx xxx security-related xxxxxxxxx xx xxxxx xxxxxxxxx infrastructure and, xxxxx xxxxxxxxxxx, xxxxxxxx-xxxxxxx xxxxxxxxx xxxx xxxxx xx the technical xxxxxxxxxxxxxx xx xxx xxxxx xxxxx xxxxxxxxx. Xxx XXX may xxxxxxx xxxxxxx xxxxxxxxxxx xxxxx xxx xxxxxxxx xxx, xx necessary, xxxxxxx xxxx xxx xxxxxxxxxxx take xxxxxxxxxxx xxxxxxxx xx xxxxxxx x&xxxx;xxxxxxxxxx of such xx xxxxx. 3.&xxxx;&xxxx;&xxxx;Xxx XXX xxx xxxxxx additional xxxxxxxx xxxxxxxxxxxx, xx xxxxxxxxxx with regard xx cybersecurity or xxx xxxxxxxxxx of xxxxx, xx xxx xxxxxxxxxxxx and/or xx xxxxxxxxxxxx that xxx xxxxxxxxxx xxxxxxxx xx xxx XXX. 4.&xxxx;&xxxx;&xxxx;Xxxxxxxxxxxx xxxxx xxxxxxx the ECB xxxx: (x) permanent xxxxxx xx their xxxxxxxxxxx xx adherence xx xxxxx xxxxxx xxxxxxx xxxxxxx provider’s xxxxxxxx xxxxxxxx requirements, xxx (xx) xx xx xxxxxx xxxxx xxx XXXXXX2 self-certification xxxxxxxxx xx xxxxxxxxx xx xxx XXX’x xxxxxxx in Xxxxxxx. 4x.&xxxx;&xxxx;&xxxx;Xxx XXX shall xxxxxx xxx xxxxxxxxxxx’x xxxx-xxxxxxxxxxxxx xxxxxxxxx(x) xx xxx xxxxxxxxxxxx level xx xxxxxxxxxx xxxx each xx xxx xxxxxxxxxxxx xxx xxx xx xxx XXXXXX2 self-certification xxxxxxxxxxxx. Xxxxx xxxxxxxxxxxx xxx listed xx Xxxxxxxx XXX, which xx xxxxxxxx xx xxx other Appendices xxxxxx xx Xxxxxxx&xxxx;2(1), xxxxx xxxx an xxxxxxxx xxxx xx xxxxx Conditions. 4b. The xxxxxxxxxxx’x xxxxx xx xxxxxxxxxx xxxx xxx requirements xx xxx TARGET2 xxxx-xxxxxxxxxxxxx shall be xxxxxxxxxxx xx xxxxxxx, xx xxxxxxxxxx order xx severity: ‘xxxx xxxxxxxxxx’; ‘minor non-compliance’; xx ‘xxxxx xxx-xxxxxxxxxx’. Xxx xxxxxxxxx criteria xxxxx: full compliance xx xxxxxxx xxxxx xxxxxxxxxxxx xxxxxxx 100% xx xxx requirements; xxxxx non-compliance xx xxxxx a participant satisfies xxxx xxxx 100% xxx at xxxxx 66% xx xxx xxxxxxxxxxxx xxx xxxxx xxx-xxxxxxxxxx where x&xxxx;xxxxxxxxxxx xxxxxxxxx xxxx xxxx 66% of xxx xxxxxxxxxxxx. Xx x&xxxx;xxxxxxxxxxx xxxxxxxxxxxx xxxx x&xxxx;xxxxxxxx xxxxxxxxxxx xx xxx xxxxxxxxxx xx xx, xx xxxxx xx xxxxxxxxxx xx xxxxxxxxx xxxx xxx xxxxxxxxxx xxxxxxxxxxx xxx xxx xxxxxxxx xx the xxxxxxxxxxxxxx. A participant which xxxxx xx reach ‘xxxx xxxxxxxxxx’ xxxxx xxxxxx an xxxxxx xxxx xxxxxxxxxxxxx xxx xx xxxxxxx xx xxxxx xxxx xxxxxxxxxx. Xxx ECB shall xxxxxx xxx xxxxxxxx xxxxxxxxxxx xxxxxxxxxxx xx xxx status xx xxxx xxxxxxxxxxx’x compliance. 4c. If xxx participant xxxxxxx xx grant xxxxxxxxx xxxxxx xx xxx xxxxxxxxxxx of xxxxxxxxx xx their chosen XXXx xxxxxxxx security xxxxxxxxxxxx or does xxx provide xxx XXXXXX2 self-certification the xxxxxxxxxxx’x xxxxx xx xxxxxxxxxx xxxxx be xxxxxxxxxxx as ‘major xxx-xxxxxxxxxx’. 4x.&xxxx;&xxxx;&xxxx;Xxx XXX xxxxx xxxxxxxx xxxxxxxxxx of xxxxxxxxxxxx xx an xxxxxx xxxxx. 4x.&xxxx;&xxxx;&xxxx;Xxx ECB xxx xxxxxx xxx xxxxxxxxx xxxxxxxx xx xxxxxxx on xxxxxxxxxxxx xxxxx level xx xxxxxxxxxx xxx assessed xx xxxxx xx xxxxx xxx-xxxxxxxxxx, xx xxxxxxxxxx order of xxxxxxxx:
|
|
6. |
X&xxxx;xxxxxx&xxxx;33 se xxxxxxxx 1 nahrazuje xxxxx: „1.&xxxx;&xxxx;&xxxx;Xxxxxxxxxxxx xxxxx xx xxxxxx xx be aware xx, shall comply xxxx, xxx shall xx xxxx to xxxxxxxxxxx xxxx xxxxxxxxxx xx xxx xxxxxxxx xxxxxxxxx xxxxxxxxxxx xxxx xxx xxxxxxxxxxx on xxxx relating to xxxxxxxxxxx on xxxx xxxxxxxxxx. They shall xx xxxxxx to xx xxxxx of, xxx xxxxx xxxxxx xxxx xxx obligations xx them relating xx legislation xx xxxxxxxxxx of xxxxx xxxxxxxxxx and xxx xxxxxxxxx of xxxxxxxxx, xxxxxxxxxxxxx-xxxxxxxxx xxxxxxx activities xxx the xxxxxxxxxxx xx nuclear xxxxxxx xxxxxxxx systems, in xxxxxxxxxx xx xxxxx xx xxxxxxxxxxxx xxxxxxxxxxx xxxxxxxx concerning xxx xxxxxxxx xxxxxxx or xxxxxxxx on xxxxx XX xxxxxxxx. Xxxxxxxxxxxx xxxxx xxxxxx that xxxx xxx xxxxxxxx xxxxx the XXXXXX2 xxxxxxx xxxxxxx xxxxxxxx’x xxxx retrieval xxxxxx xxxxx xx entering xxxx the contractual xxxxxxxxxxxx xxxx xxx XXXXXX2 xxxxxxx xxxxxxx xxxxxxxx.“; |
|
7. |
Xxxxxx xx xxxx xxxxxx&xxxx;39x, který xxx: „Xxxxxxx&xxxx;39x Xxxxxxxxxxxx xxxxxxxxxx 1.&xxxx;&xxxx;&xxxx;Xxxx xxx XXXXXX xxxxxx xx operational xxx XXXXXX2 has xxxxxx xxxxxxxxx, PM xxxxxxx balances xxxxx xx transferred to xxx account xxxxxx’x xxxxxxxxxxxxx xxxxxxxxx xxxxxxxx xx the XXXXXX xxxxxx. 2.&xxxx;&xxxx;&xxxx;Xxx xxxxxxxxxxx xxxx XX account xxxxxxx, xxxxxxxx Xxxxxxxxxxxx xxx xxxxxxxxxxx BIC xxxxxxx xxxxxxxx xx the XXX Xxxx xxxxxx xx xxxxxxxxx xx xxx XXXX Xxxxxxxx xxxxxxxx to Article 5 xxxxx apply xx xx 25 Xxxxxxxx 2022.“; |
|
8. |
X&xxxx;xxxxxxx X&xxxx;xx v odst. 8 xxxxxxx. 4 xxxxxxxxx xxxxxxx b) xxxxx:
|
|
9. |
V dodatku XX xx x&xxxx;xxxxxxxx 6 xxxxxxxxx xxxxxxx x) tímto:
|
|
10. |
Xxxxxxxx xx nový xxxxxxx VII, xxxxx xxx: „Xxxxxxxx XXX Xxxxxxxxxxxx xxxxxxxxx xxxxxxxxxxx security xxxxxxxxxx xxx business continuity xxxxxxxxxx Xxxxxxxxxxx security management These xxxxxxxxxxxx are applicable xx xxxx xxxxxxxxxxx, xxxxxx xxx xxxxxxxxxxx xxxxxxxxxxxx that x&xxxx;xxxxxxxx xxxxxxxxxxx is xxx xxxxxxxxxx xx xx. Xx xxxxxxxxxxxx xxx xxxxx xx xxxxxxxxxxx xx xxx xxxxxxxxxxxx xxxxxx xxx xxxxxxxxxxxxxx, xxx xxxxxxxxxxx xxxxxx xxxxxxxx the xxxxxxxx xxxx xxx part xx the Payment Xxxxxxxxxxx Xxxxx (XXX). Xxxxxxxxxxxx, xxx XXX xxxxxx xx a Point xx Entry (XxX), x.x. x&xxxx;xxxxxx xxxxxxxx xx xxx creation xx xxxxxxxxxxxx (x.x. xxxxxxxxxxxx, xxxxx-xxxxxx xxx xxxx-xxxxxx applications, xxxxxxxxxx), xxx xxxx xx xxx xxxxxx responsible xx xxxx xxx xxxxxxx xx SWIFT (x.x. SWIFT XXX Xxx) xx Xxxxxxxx (xxxx xxx latter xxxxxxxxxx xx Xxxxxxxx-xxxxx Xxxxxx). Xxxxxxxxxxx 1.1: Information xxxxxxxx xxxxxx Xxx xxxxxxxxxx xxxxx xxx a clear xxxxxx xxxxxxxxx in xxxx with xxxxxxxx xxxxxxxxxx xxx xxxxxxxxxxx xxxxxxx xxx xxx xxxxxxxxxx to xxxxxxxxxxx xxxxxxxx xxxxxxx xxx xxxxxxxx, xxxxxxxx xxx xxxxxxxxxxx xx xx xxxxxxxxxxx security xxxxxx xxxxxx at xxxxxxxx xxxxxxxxxxx xxxxxxxx xxx xxxxx xxxxxxxxxx across xxx organisation xx xxxxx xx xxxxxxxxxxxxxx, xxxxxxxxxx xxx xxxxxxxxx xx information xxxxxxxx xxx xxxxx xxxxxxxxxx xxxxx. Xxx xxxxxx xxxxxx xxxxxxx xx xxxxx xxx following xxxxxxxx: xxxxxxxxxx, xxxxx (xxxxxxxxx xxxxxxx xxxx xx organisation, xxxxx xxxxxxxxx, xxxxx management xxx.), xxxxxxxxxx and xxxxxxxxxx of responsibilities. Requirement 1.2: Internal xxxxxxxxxxxx Xx xxxxxxxxxxx xxxxxxxx xxxxxxxxx xxxxx be xxxxxxxxxxx xx xxxxxxxxx the xxxxxxxxxxx xxxxxxxx xxxxxx xxxxxx xxx organisation. Xxx xxxxxxxxxx shall xxxxxxxxxx xxx xxxxxx xxx xxxxxxxxxxxxx xx xxx xxxxxxxxxxx xxxxxxxx xxxxxxxxx to ensure xxx implementation xx xxx information xxxxxxxx xxxxxx (xx xxx Xxxxxxxxxxx 1.1) xxxxxx xxx xxxxxxxxxxxx, xxxxxxxxx xxx xxxxxxxxxx of xxxxxxxxxx xxxxxxxxx xxx xxxxxxxxxx of xxxxxxxx xxxxxxxxxxxxxxxx for this xxxxxxx. Xxxxxxxxxxx 1.3: External xxxxxxx Xxx xxxxxxxx xx xxx organisation’s xxxxxxxxxxx xxx xxxxxxxxxxx xxxxxxxxxx xxxxxxxxxx xxxxxx xxx xx xxxxxxx xx xxx introduction xx, xxx/xx xxx dependence xx, an xxxxxxxx xxxxx/xxxxxxx xx xxxxxxxx/xxxxxxxx xxxxxxxx xx xxxx. Xxx xxxxxx xx xxx organisation’s xxxxxxxxxxx xxxxxxxxxx xxxxxxxxxx xx xxxxxxxx xxxxxxx xxxxx xx xxxxxxxxxx. Xxxx xxxxxxxx xxxxxxx or xxxxxxxx/xxxxxxxx of xxxxxxxx xxxxxxx xxx xxxxxxxx xx access xxx xxxxxxxxxxxx’x xxxxxxxxxxx xxxxxxxxxx xxxxxxxxxx, x&xxxx;xxxx xxxxxxxxxx xxxxx be xxxxxxx xxx to xxxxxxxxx xxx xxxxxxxx xxxxxxxxxxxx xxx xxxxxxx requirements. Xxxxxxxx shall xx xxxxxx xxx defined xx an xxxxxxxxx xxxx xxxx xxxxxxxx xxxxxxxx party. Requirement 1.4: Xxxxx xxxxxxxxxx Xxx information xxxxxx, the xxxxxxxx xxxxxxxxx xxx xxx xxxxxxxxxx xxxxxxxxxxx xxxxxxx, xxxx xx xxxxxxxxx xxxxxxx, xxxxxxxxxxxxxxx, business xxxxxxxxxxxx, xxx-xxx-xxxxx xxxxxxxx, xxxxxxxx xxx xxxx-xxxxxxxxx xxxxxxxxxxxx, in xxx xxxxx xx xxx Xxxxxxx Transaction Xxxxx xxxxx xx xxxxxxxxx xxx xxx xxxx x&xxxx;xxxxxxxxx xxxxx. Xxx xxxxxxxxxxxxxx xxx xxx xxxxxxxxxxx and xxx xxxxxxxxx of appropriate xxxxxxxx xx xxx xxxxxxxx xxxxxxxxx xxx xxx xxxxxxx XX xxxxxxxxxx xx xxxxxxxxx xxx xxxxxxxxxxx xxxxxx xxxxx be xxxxxxxx. Xxxx: xxx xxxxx xxx xxxxxxxx the xxxxxxxxxxxxxx xx xxxxxxxx xxxxxxxx xx xxxxxxxxxxx, xxx xxxxxxx xxxxxxxxxxx xxx xxx xxxxxx xxxxxxxxxx of the xxxxxx. Xxxxxxxxxxx 1.5: Information xxxxxx classification Information xxxxxx xxxxx xx xxxxxxxxxx xx xxxxx xx xxxxx criticality xx xxx xxxxxx xxxxxxxx xx xxx xxxxxxx xx xxx participant. Xxx xxxxxxxxxxxxxx xxxxx xxxxxxxx xxx xxxx, xxxxxxxxxx xxx degree xx xxxxxxxxxx xxxxxxxx xxxx xxxxxxxx the xxxxxxxxxxx asset in xxx relevant business xxxxxxxxx xxx xxxxx xxxx xxxx into xxxxxxxxxxxxx the underlying XX xxxxxxxxxx. Xx xxxxxxxxxxx asset xxxxxxxxxxxxxx xxxxxx xxxxxxxx by xxx xxxxxxxxxx xxxxx xx xxxx xx xxxxxx xx xxxxxxxxxxx xxx xx xxxxxxxxxx xxxxxxxx throughout the xxxxxxxxxxx asset lifecycle (xxxxxxxxx xxxxxxx and xxxxxxxxxxx xx xxxxxxxxxxx xxxxxx) and xx xxxxxxxxxxx the xxxx xxx xxxxxxxx handling xxxxxxxx. Xxxxxxxxxxx 1.6: Human xxxxxxxxx xxxxxxxx Xxxxxxxx xxxxxxxxxxxxxxxx xxxxx be xxxxxxxxx xxxxx to xxxxxxxxxx xx xxxxxxxx xxx xxxxxxxxxxxx xxx xx xxxxx xxx xxxxxxxxxx xx xxxxxxxxxx. All xxxxxxxxxx xxx xxxxxxxxxx, xxxxxxxxxxx xxx third xxxxx xxxxx xxxxx xx adequately xxxxxxxx, xxxxxxxxxx for sensitive xxxx. Employees, xxxxxxxxxxx xxx third party xxxxx of information xxxxxxxxxx xxxxxxxxxx xxxxx xxxx xx xxxxxxxxx xx their xxxxxxxx xxxxx xxx responsibilities. Xx xxxxxxxx level xx xxxxxxxxx shall xx xxxxxxx xxxxx xxx xxxxxxxxx, xxxxxxxxxxx xxx xxxxx xxxxx xxxxx, and education xxx xxxxxxxx xx xxxxxxxx xxxxxxxxxx xxx xxx xxxxxxx xxx xx xxxxxxxxxxx xxxxxxxxxx xxxxxxxxxx xxxxx be xxxxxxxx xx xxxx xx xxxxxxxx xxxxxxxx xxxxxxxx risks. X&xxxx;xxxxxx xxxxxxxxxxxx xxxxxxx xxx xxxxxxxx xxxxxxxx xxxxxxxx xxxxx xx established xxx xxxxxxxxx. Xxxxxxxxxxxxxxxx xxxxx be xx xxxxx xx xxxxxx xxxx an xxxxxxxx’x, xxxxxxxxxx’x or xxxxx xxxxx xxxx’x xxxx xxxx xx xxxxxxxx xxxxxx the xxxxxxxxxxxx xx xxxxxxx, xxx xxxx xxx xxxxxx xx xxx equipment xxx xxx removal xx xxx access xxxxxx xxx completed. Requirement 1.7: Xxxxxxxx xxx xxxxxxxxxxxxx xxxxxxxx Xxxxxxxx or xxxxxxxxx information xxxxxxxxxx xxxxxxxxxx xxxxx xx xxxxxx xx secure xxxxx, xxxxxxxxx xx xxxxxxx security xxxxxxxxxx, xxxx appropriate security xxxxxxxx and entry xxxxxxxx. Xxxx xxxxx xx physically xxxxxxxxx xxxx unauthorised access, xxxxxx xxx xxxxxxxxxxxx. Xxxxxx shall xx xxxxxxx only xx xxxxxxxxxxx xxx xxxx xxxxxx xxx xxxxx xx Xxxxxxxxxxx 1.6. Xxxxxxxxxx and xxxxxxxxx xxxxx xx established xx protect physical xxxxx xxxxxxxxxx information xxxxxx xxxx xx xxxxxxx. Xxxxxxxxx xxxxx xx xxxxxxxxx xxxx xxxxxxxx xxx environmental xxxxxxx. Xxxxxxxxxx of equipment (xxxxxxxxx xxxxxxxxx xxxx xxx-xxxx) xxx xxxxxxx xxx xxxxxxx xx xxxxxxxx xx xxxxxxxxx xx xxxxxx the xxxx of xxxxxxxxxxxx xxxxxx xx information xxx xx xxxxx xxxxxxx xxxx xx xxxxxx xx equipment xx xxxxxxxxxxx. Xxxxxxx xxxxxxxx xxx xx xxxxxxxx to xxxxxxx xxxxxxx xxxxxxxx xxxxxxx xxx xx xxxxxxxxx xxxxxxxxxx xxxxxxxxxx xxxx xx the xxxxxxxxxx xxxxxx xxx xxxxxxx xxxxxxxxxxxxxx. Xxxxxxxxxxx 1.8: Xxxxxxxxxx xxxxxxxxxx Xxxxxxxxxxxxxxxx xxx xxxxxxxxxx xxxxx xx established xxx the management xxx xxxxxxxxx xx xxxxxxxxxxx xxxxxxxxxx xxxxxxxxxx xxxxxxxx all xxx xxxxxxxxxx xxxxxxx xx xxx Payment Xxxxxxxxxxx Xxxxx xxx-xx-xxx. Xx regards xxxxxxxxx procedures, xxxxxxxxx xxxxxxxxx administration xx XX xxxxxxx, segregation xx xxxxxx xxxxx xx xxxxxxxxxxx, where xxxxxxxxxxx, to xxxxxx xxx risk xx xxxxxxxxx or xxxxxxxxxx xxxxxx xxxxxx. Xxxxx xxxxxxxxxxx xx xxxxxx xxxxxx xx xxxxxxxxxxx xxx xx xxxxxxxxxx xxxxxxxxx xxxxxxx, xxxxxxxxxxxx xxxxxxxx xxxxx xx xxxxxxxxxxx xxxxxxxxx x&xxxx;xxxxxx xxxx xxxxxxxx. Xxxxxxxx xxxxx be established xx xxxxxxx xxx xxxxxx the xxxxxxxxxxxx xx xxxxxxxxx xxxx xxx systems xx xxx Xxxxxxx Transaction Xxxxx. Controls xxxxx xx xxxx xxxxxxxxxxx (xxxxxxxxx xxxx xxxxxxxxx) xx xxxxxxx, detect xxx xxxxxx malicious xxxx. Xxxxxx xxxx xxxxx be xxxx xxxx xxxx xxxxxxx xxxxxxx (x.x. xxxxxx Xxxxxxxxx XXX xxxxxxxxxx xxx Xxxx Xxxxxxx). Xxx xxxxxxxxxxxxx xx xxx xxxxxxx (e.g. xxx xxx xx xxxxxxxxxx and plugins) xxxxx xx xxxxxxxx xxxxxxxxxx. Xxxx backup and xxxxxxxx xxxxxxxx shall xx xxxxxxxxxxx xx xxx xxxxxxxxxx; those xxxxxxxx xxxxxxxx xxxxx xxxxxxx a plan of xxx xxxxxxxxxxx xxxxxxx xxxxx xx xxxxxx xx regular intervals xx xxxxx xxxxxxxx. Xxxxxxx xxxx are xxxxxxxx xxx xxx xxxxxxxx xx xxxxxxxx xxxxx xx xxxxxxxxx xxx xxxxxx relevant xx xxxxxxxxxxx xxxxxxxx xxxxx xx recorded. Operator xxxx shall xx xxxx to xxxxxx xxxx information xxxxxx xxxxxxxx are xxxxxxxxxx. Xxxxxxxx logs xxxxx xx regularly xxxxxxxx xx x&xxxx;xxxxxx xxxxx, xxxxx on xxx xxxxxxxxxxx xx xxx xxxxxxxxxx. Xxxxxx xxxxxxxxxx xxxxx be xxxx xx xxxxx xxx xxxxxxxxxxxxx of xxxxxxxx xxxxx xxx identified xx xxxxxxxx for xxx xxxxxxxx xx xxxxxxxx xxx to xxxxxx conformity xx xx xxxxxx xxxxxx xxxxx. Xxxxxxxxx of xxxxxxxxxxx xxxxxxx xxxxxxxxxxxxx xxxxx xx xxxxx on x&xxxx;xxxxxx exchange xxxxxx, xxxxxxx xxx xx xxxx xxxx xxxxxxxx xxxxxxxxxx among xxx xxxxxxxx xxxxxxx xxx xxxxx xx compliant xxxx xxx relevant xxxxxxxxxxx. Xxxxx party xxxxxxxx components xxxxxxxx xx the exchange xx xxxxxxxxxxx xxxx XXXXXX2 (like software xxxxxxxx xxxx x&xxxx;Xxxxxxx Xxxxxx in xxxxxxxx 2 xx xxx xxxxx section of xxx XXXXXX2 xxxx-xxxxxxxxxxxxx xxxxxxxxxxx xxxxxxxx) xxxx xx xxxx xxxxx x&xxxx;xxxxxx xxxxxxxxx xxxx xxx xxxxx xxxxx. Xxxxxxxxxxx 1.9: Xxxxxx xxxxxxx Xxxxxx xx information xxxxxx xxxxx be xxxxxxxxx xx xxx basis xx xxxxxxxx xxxxxxxxxxxx (xxxx-xx-xxxx&xxxx;(1)) xxx according xx xxx xxxxxxxxxxx xxxxxxxxx xx xxxxxxxxx xxxxxxxx (xxxxxxxxx the xxxxxxxxxxx xxxxxxxx xxxxxx). Xxxxx xxxxxx xxxxxxx xxxxx shall xx xxxxxxx xxxxx xx xxx xxxxxxxxx xx xxxxx xxxxxxxxx&xxxx;(2) xx xxxxxxx xxxxxxx xxx xxxxx xx the xxxxxxxxxxxxx business and XX xxxxxxxxx. Xxxxx xxxxxxxx (x.x. xxx xxxxxx xxxxxxxxxx) logical xxxxxx control should xx xxxxxxxxxx xxxx xxxxxxxx access xxxxxxx xxxxxx xxxxx xxx xxxxxxxx xxxxxxxxxxxx xxxxxxxx xx place (e.g. xxxxxxxxxx, xxxxxxxx xxxx xxxxxxxxxxxxx). Xxxxxx xxx documented xxxxxxxxxx shall be xx place xx xxxxxxx the xxxxxxxxxx xx xxxxxx xxxxxx xx xxxxxxxxxxx xxxxxxx xxx xxxxxxxx that xxxx xxxxxx xxx xxxxx xx xxx Xxxxxxx Transaction Xxxxx. Xxx xxxxxxxxxx shall xxxxx xxx stages xx the xxxxxxxxx xx user xxxxxx, xxxx the initial xxxxxxxxxxxx of xxx xxxxx xx the xxxxx deregistration xx xxxxx that xx xxxxxx require xxxxxx. Xxxxxxx xxxxxxxxx xxxxx be xxxxx, where xxxxxxxxxxx, xx xxx allocation xx access rights xx xxxx criticality xxxx xxx xxxxx xx xxxxx access xxxxxx xxxxx xxxx xx x&xxxx;xxxxxx xxxxxxx xxxxxx on xxx xxxxxxxxxx xx xxx xxxxxxxxxxx (x.x. xxxxxx xxxxxx xxxxxxxx system xxxxxxxxxxxxxx, xxxxxxxx of xxxxxx xxxxxxxx, xxxxxx xxxxxx to business xxxx). Xxxxxxxxxxx controls xxxxx xx xxx in xxxxx xx xxxxxxxx, xxxxxxxxxxxx and authorise xxxxx xx xxxxxxxx xxxxxx in the xxxxxxxxxxxx’x xxxxxxx, x.x. xxx local and xxxxxx xxxxxx xx xxxxxxx xx the Xxxxxxx Transaction Chain. Xxxxxxxx xxxxxxxx xxxxx xxx be xxxxxx xx order xx xxxxxx accountability. For passwords, xxxxx shall be xxxxxxxxxxx xxx xxxxxxxx xx xxxxxxxx controls xx ensure xxxx xxxxxxxxx xxxxxx xx xxxxxx xxxxxxx, x.x. xxxxxxxxxx xxxxx xxx xxxxxxx-xxxx validity. X&xxxx;xxxx xxxxxxxx xxxxxxxx and/or xxxxx protocol shall xx established. A policy xxxxx xx xxxxxxxxx and xxxxxxxxxxx on xxx xxx xx xxxxxxxxxxxxx xxxxxxxx xx xxxxxxx xxx confidentiality, xxxxxxxxxxxx xxx xxxxxxxxx xx xxxxxxxxxxx. X&xxxx;xxx xxxxxxxxxx xxxxxx xxxxx xx xxxxxxxxxxx xx xxxxxxx xxx xxx of xxxxxxxxxxxxx xxxxxxxx. Xxxxx xxxxx xx xxxxxx xxx xxxxxxx confidential xxxxxxxxxxx xx screen or xx xxxxx (x.x. x&xxxx;xxxxx screen, x&xxxx;xxxxx xxxx xxxxxx) to xxxxxx xxx xxxx xx unauthorised access. When xxxxxxx xxxxxxxx, xxx xxxxx xx working xx xx unprotected xxxxxxxxxxx xxxxx be xxxxxxxxxx and appropriate xxxxxxxxx xxx xxxxxxxxxxxxxx xxxxxxxx shall xx xxxxxxx. Xxxxxxxxxxx 1.10: Information xxxxxxx acquisition, xxxxxxxxxxx xxx xxxxxxxxxxx Xxxxxxxx xxxxxxxxxxxx xxxxx be xxxxxxxxxx xxx xxxxxx xxxxx xx xxx xxxxxxxxxxx xxx/xx xxxxxxxxxxxxxx xx xxxxxxxxxxx xxxxxxx. Xxxxxxxxxxx xxxxxxxx xxxxx xx built xxxx xxxxxxxxxxxx, xxxxxxxxx xxxx-xxxxxxxxx xxxxxxxxxxxx, xx xxxxxx correct xxxxxxxxxx. Xxxxx xxxxxxxx xxxxx xxxxxxx xxx xxxxxxxxxx xx input xxxx, xxxxxxxx processing xxx xxxxxx data. Xxxxxxxxxx xxxxxxxx xxx xx xxxxxxxx xxx xxxxxxx xxxx process, xx xxxx an xxxxxx xx, xxxxxxxxx, xxxxxxxx xx xxxxxxxx xxxxxxxxxxx. Xxxx controls xxxxx xx determined xx xxx xxxxx xx xxxxxxxx requirements and xxxx assessment xxxxxxxxx xx xxx xxxxxxxxxxx xxxxxxxx (x.x. xxxxxxxxxxx xxxxxxxx xxxxxx, cryptographic xxxxxxx policy). The xxxxxxxxxxx xxxxxxxxxxxx xx xxx xxxxxxx shall xx xxxxxxxxxxx, xxxxxxxxxx xxx xxxxxx prior to xxxxx xxxxxxxxxx and xxx. Xx xxxxxxx xxxxxxx security, appropriate xxxxxxxx, xxxxxxxxx xxxxxxxxxxxx xxx secure xxxxxxxxxx, xxxxxx xx implemented xxxxx on xxx xxxxxxxxxxx xx data xxxxx and xxx xxxxx xx xxxx xx the xxxxxxx xxxxx xx xxx xxxxxxxxxxxx. Xxxxx shall xx xxxxxxxx xxxxxxxx xx xxxxxxx xxxxxxxxx xxxxxxxxxxx passing xxxx xxxxxx xxxxxxxx. Xxxxxx xx xxxxxx files xxx xxxxxxx xxxxxx xxxx xxxxx be xxxxxxxxxx xxx XX xxxxxxxx xxx support xxxxxxxxxx xxxxxxxxx in a secure xxxxxx. Care xxxxx xx xxxxx xx xxxxx exposure xx xxxxxxxxx xxxx xx xxxx environments. Xxxxxxx xxx xxxxxxx xxxxxxxxxxxx xxxxx xx strictly xxxxxxxxxx. Xxxxxxxxxx xx xxxxxxx xx xxxxxxxxxx xxxxx be xxxxxxxx xxxxxxxxxx. X&xxxx;xxxx assessment xx the xxxxx xxxxxxx to xx xxxxxxxx xx xxxxxxxxxx xxxxx xx xxxxxxxxx. Xxxxxxx xxxxxxxx xxxxxxx xxxxxxxxxx xx xxxxxxx in xxxxxxxxxx xxxxx xxxx xx xxxxxxxxx xxxxxxxxx xx x&xxxx;xxxxxxxxxx plan xxxxx xx xxx xxxxxxx of x&xxxx;xxxx xxxxxxxxxx, xxx xxxxxxxx xxxxxxx xxxxx xxxxxxx, xx xxxxx, vulnerability xxxxxxxxxxx. Xxx xx xxx xxxxxxxxxxxx xxxxxxxxxxx xxxxxx xxx security xxxxxxx activities shall xx assessed xxx xxxxxx xxxxx to xxxxx xxx xxxxxxxxxx xxx xxxxx be xxxxxxxx and followed xx in x&xxxx;xxxxxx xxxxxxx. Xxxxxxxxxxx 1.11: Xxxxxxxxxxx xxxxxxxx xx xxxxxxxx&xxxx;(3) xxxxxxxxxxxxx Xx xxxxxx xxxxxxxxxx xx the xxxxxxxxxxx’x xxxxxxxx xxxxxxxxxxx systems xxxx xxx xxxxxxxxxx xx xxxxxxxxx, information xxxxxxxx requirements xxx xxxxxxxxxx the xxxxx xxxxxxxxxx xxxx xxxxxxxx’x xxxxxx xxxxx xx xxxxxxxxxx and formally xxxxxx xxxx xxxx xxx xxxxxxxx. Xxxxxxxxxxx 1.12: Xxxxxxxxxx of xxxxxxxxxxx xxxxxxxx xxxxxxxxx and xxxxxxxxxxxx Xx xxxxxx a consistent xxx effective approach xx xxx management xx xxxxxxxxxxx xxxxxxxx xxxxxxxxx, xxxxxxxxx xxxxxxxxxxxxx xx xxxxxxxx xxxxxx xxx xxxxxxxxxx, roles, xxxxxxxxxxxxxxxx and xxxxxxxxxx, xx xxxxxxxx and xxxxxxxxx xxxxx, xxxxx xx established and xxxxxx to xxxxxx x&xxxx;xxxxx, xxxxxxxxx xxx xxxxxxx xxx safely xxxxxxx xxxx xxxxxxxxxxx xxxxxxxx incidents xxxxxxxxx xxxxxxxxx xxxxxxx xx x&xxxx;xxxxx-xxxxxxx xxxxx (e.g. x&xxxx;xxxxx xxxxxxx by xx xxxxxxxx xxxxxxxx xx by an xxxxxxx). Personnel involved xx xxxxx xxxxxxxxxx xxxxx be xxxxxxxxxx xxxxxxx. Xxxxxxxxxxx 1.13: Xxxxxxxxx xxxxxxxxxx xxxxxx X&xxxx;xxxxxxxxxxx’x xxxxxxxx xxxxxxxxxxx xxxxxxx (e.g. xxxx xxxxxx xxxxxxx, xxxxxxxx networks xxx xxxxxxxx network xxxxxxxxxxxx) xxxxx xx xxxxxxxxx xxxxxxxx for xxxxxxxxxx xxxx xxx xxxxxxxxxxxx’x xxxxxxxxxxx framework xx xxxxxxxx (e.g. xxxxxxxxxxx xxxxxxxx xxxxxx, xxxxxxxxxxxxx xxxxxxx xxxxxx). Xxxxxxxxxxx 1.14: Xxxxxxxxxxxxxx Xxxxx xxxxxxx xxxxxxxx xxxxx comply xxxx xxx xxx xxxxxxxx xxxxxxxx xxxx xxx xxx xxx xxxxxxxx xxxxxxxx xxx systems (x.x. xxxxxxxxx, xxxxxxx). Xxxxxxxx xxxxxxxx xx xxxxxxxxxxx xxxx xxxxxxx: xxxxxxxxx xx xxx xxxxxxxxxx xxx xxx xxxxxxx xxxxxxxxx xxxxxx, xxxxxxx patching, xxxxxx xxxxxxxxxx xx xxxxxxxxx xxxxxxxxxxxx (e.g. xxxxxxxxxx xxx xxxxxxxxxxx). Centralised xxxxxxxxxx, xxxxxxx xxx xxxxxxxxxx xx xxxx xx managing xx xxxxxx xxxxxx, xx xxxxxxxxxx for high xxxxxxxxxx xxxxxxxx, xxxxx xx xxxxxxxxxxx based xx a risk xxxxxxxxxx. Xxxxx xxxxxxx xxxxxxxx xxxxxxx by the xxxx xxxxxxxxxx shall xxxx x&xxxx;xxxxxxx xxxx xxxxxxx. Xxxxxxxxxxx 1.15: Xxxxx xxxxxxxxx Xxx xxxxx of xxxxxx xxx/xx xxxxxx xxxxx xxxxxxxxx in xxx Xxxxxxx Transaction Xxxxx xxxx be xxxxx on a formal xxxx xxxxxxxxxx, taking xxxx xxxxxxx xxx xxxxxxxxx controls and xxx contractual xxxxxxx xxxxxxx xx the xxxxx xxxxxxxx. Xx xxxxxx xxxxx xxxxxxxxx xxx xxxx, xx xx xxxxxxxxxx xxxx the xxxxxxxxxxx level of xxx xxxxxxx xxxxxx xx the xxxxxxx xxx xx xxx xxxxxxxxx xxxxxxx. Xxx xx-xxxxxxxx xxxxxxxxxx of xxx hybrid xxxxxxxxx xxxx xx segregated xxxx xxx xxxxx xx-xxxxxxxx xxxxxxx. Xxxxxxxx continuity xxxxxxxxxx (xxxxxxxxxx only xx xxxxxxxx xxxxxxxxxxxx) Xxx xxxxxxxxx xxxxxxxxxxxx (2.1 xx 2.6) xxxxxx xx business continuity xxxxxxxxxx. Each TARGET2 xxxxxxxxxxx classified by xxx Xxxxxxxxxx as xxxxx critical xxx xxx xxxxxx functioning xx xxx XXXXXX2 xxxxxx xxxxx have x&xxxx;xxxxxxxx xxxxxxxxxx xxxxxxxx xx xxxxx xxxxxxxxxx xxx xxxxxxxxx xxxxxxxx.
|
(1)&xxxx;&xxxx;Xxx xxxx-xx-xxxx xxxxxxxxx xxxxxx xx the identification xx xxx set xx information that xx xxxxxxxxxx xxxxx xxxxxx xx xx xxxxx xx carry xxx her/his xxxxxx.
(2)&xxxx;&xxxx;Xxx xxxxxxxxx xx xxxxx xxxxxxxxx xxxxxx to xxxxxxxxx x&xxxx;xxxxxxx’x xxxxxx xxxxxxx to xx XX xxxxxx xx xxxxx to xxxxx xxx xxxxxxxxxxxxx xxxxxxxx xxxx.
(3)&xxxx;&xxxx;X&xxxx;xxxxxxxx xx the xxxxxxx xx xxxx xxxxxxxx should xx xxxxxxxxxx xx xxx xxxxx party (and xxx xxxxxxxxx) xxxxx xx under contract (xxxxxxxxx), with xxx xxxxxxxxxxx, xx xxxxxxx x&xxxx;xxxxxxx and xxxxx xxx xxxxxxx agreement xxx third xxxxx (xxx its personnel) xx granted xxxxxx, xxxxxx xxxxxxxx or xx-xxxx, to xxxxxxxxxxx xxx/xx information xxxxxxx xxx/xx xxxxxxxxxxx xxxxxxxxxx xxxxxxxxxx of xxx xxxxxxxxxxx xx xxxxx xx xxxxxxxxxx xx xxx xxxxx covered xxxxx xxx xxxxxxxx xx the XXXXXX2 xxxx-xxxxxxxxxxxxx.
PŘÍLOHA II
Příloha II xxxxxxxxxx ECB/2007/7 xx xxxx takto:
|
1. |
Článek 1 xx xxxx takto:
|
|
2. |
X&xxxx;xx.&xxxx;4 xxxx.&xxxx;2 xx písmeno xx) xxxxxxxxx tímto:
|
|
3. |
X&xxxx;xx.&xxxx;4 xxxx.&xxxx;2 xx xxxxxx nové xxxxxxx xx), xxxxx xxx:
|
|
4. |
X&xxxx;xxxxxx&xxxx;4 xx odstavec 3 xxxxxxxxx xxxxx: „3.&xxxx;&xxxx;&xxxx;XXXXXX2 provides xxxx-xxxx xxxxx xxxxxxxxxx xxx payments xx xxxx, with settlement xx xxxxxxx xxxx xxxxx xxxxxx PM xxxxxxxx, X2X XXXx xxx XXXX XXXx. XXXXXX2 is xxxxxxxxxxx xxx xxxxxxxxx on xxx xxxxx xx xxx XXX xxxxxxx xxxxx xxxxxxx xxxxxx xxx submitted xxx xxxxxxxxx and xxxxxxx xxxxx xxxxxxxx xxx xxxxxxxxxx received in xxx xxxx xxxxxxxxx xxxxxx. Xx xxx xx xxx xxxxxxxxx xxxxxxxxx xx xxx X2X XXXx is xxxxxxxxx, XXXXXX2 xx xxxxxxxxxxx xxxxxxxxxxx xxx xxxxxxxxx on the xxxxx xx the X2X Platform. As xxx as xxx xxxxxxxxx xxxxxxxxx xx xxx TIPS DCAs xxx XXXX XX xxxxxxxxx xxxxxxxx xx xxxxxxxxx, XXXXXX2 xx xxxxxxxxxxx xxxxxxxxxxx xxx xxxxxxxxx xx xxx xxxxx of the XXXX Platform. Xxx XXX xx xxx xxxxxxxx xx xxxxxxxx xxxxx xxxxx Xxxxxxxxxx. Xxxx xxx xxxxxxxxx xx xxx SSP-providing XXXx xxx xxx 4XXx xxxxx xx xxxxxxxxxx xxxx and xxxxxxxxx xx the XXX, xxx xxxxx xx xxxxx assume xxxxxxxxx xx xxxxxxxxxx xxxx Article 21 xx xxxx Annex. Xxxxxxxxxxxxx xxxxxxxx to these Xxxxxxxxxx xxxxx not xxxxxx a contractual xxxxxxxxxxxx xxxxxxx X2X DCA xxxxxxx and xxx XXX-xxxxxxxxx XXXx xx xxx 4XXx xxxx xxx of xxx xxxxxx xxxx xx xxxx xxxxxxxx. Xxxxxxxxxxxx, xxxxxxxx xx xxxxxxxxxxx xxxxx x&xxxx;X2X DCA xxxxxx xxxxxxxx xxxx, xx xxxxx xx, xxx XXX or X2X Xxxxxxxx xx xxxxxxxx xx the xxxxxxxx xxxxxxxx xxxxx xxxxx Xxxxxxxxxx are xxxxxx to be xxxxxxxx xxxx, xx xxxx xx, xxx XXX.“; |
|
5. |
X&xxxx;xxxxxx&xxxx;8 xx xxxxxxxx 3 xxxxxxxxx tímto: „3. Where xxx ECB has xxxxxxx a request xx x&xxxx;X2X DCA holder xxxxxxxx xx paragraph 1, xxxx X2X XXX xxxxxx is xxxxxx xx xxxx xxxxx the xxxxxxxxxxxxx XXX(x) x&xxxx;xxxxxxx to xxxxx xxx X2X XXX xxxx the xxxxxxx relating to xxxxxxxxxx transactions xxxxxxxx xx xxxxx securities xxxxxxxx.“; |
|
6. |
X&xxxx;xxxxxx&xxxx;28 xx xxxxxxxx 1 nahrazuje xxxxx: „1.&xxxx;&xxxx;&xxxx;X2X XXX holders xxxxx xx deemed xx xx aware xx, xxxxx xxxxxx with, xxx xxxxx xx xxxx xx xxxxxxxxxxx xxxx xxxxxxxxxx xx xxx relevant xxxxxxxxx xxxxxxxxxxx xxxx xxx xxxxxxxxxxx xx them xxxxxxxx to legislation xx xxxx xxxxxxxxxx. Xxxx shall xx xxxxxx xx be xxxxx xx, and xxxxx xxxxxx xxxx xxx obligations on xxxx relating xx xxxxxxxxxxx on xxxxxxxxxx xx money xxxxxxxxxx xxx xxx financing xx terrorism, proliferation-sensitive xxxxxxx xxxxxxxxxx and xxx xxxxxxxxxxx xx xxxxxxx weapons delivery xxxxxxx, xx xxxxxxxxxx xx terms xx xxxxxxxxxxxx appropriate measures xxxxxxxxxx xxx payments xxxxxxx xx xxxxxxxx xx xxxxx T2S XXXx. Xxxxx xx xxxxxxxx xxxx xxx xxxxxxxxxxx relationship xxxx xxx X2X xxxxxxx xxxxxxx xxxxxxxx, T2S XXX xxxxxxx xxxxx xxxxxx xxxx xxxx xxx xxxxxxxx about xxx data xxxxxxxxx xxxxxx.“; |
|
7. |
Xxxxxx&xxxx;30 xx xxxxxxxxx xxxxx: „Xxxxxxx&xxxx;30 Xxxxxxxxxxx xxxxxxxxxxxx xxxx xx NSP 1. T2S XXX xxxxxxx shall xxxxxx:
2. The xxxxx xxxxxxxxxxxx xxxxxxx x&xxxx;X2X DCA xxxxxx xxx the NSP xxxxx xx xxxxxxxxxxx xxxxxxxx xx xxx xxxxx xxx xxxxxxxxxx xx xxx xxxxxxxx xxxxxxxx concluded with xx NSP xx xxxxxxxx xx xx xxxxxxxxx 1(x). 3.&xxxx;&xxxx;&xxxx;Xxx services xx xx xxxxxxxx xx xxx XXX xxxxx not form xxxx of xxx xxxxxxxx xx be xxxxxxxxx xx the XXX xx respect xx XXXXXX2. 4.&xxxx;&xxxx;&xxxx;Xxx XXX xxxxx xxx be xxxxxx xxx any xxxx, xxxxxx xx xxxxxxxxx xx xxx XXX (including xxx xxxxxxxxx, xxxxx and xxxxxxxxxxxxxx), or for xxx xxxx, xxxxxx xx omissions xx xxxxx xxxxxxx xxxxxxxx xx participants xx xxxx xxxxxx xx xxx NSP’s xxxxxxx.“; |
|
8. |
Xxxxxx xx nový xxxxxx&xxxx;34x, xxxxx xxx: „Xxxxxxx&xxxx;34x Xxxxxxxxxxxx provisions Once xxx XXXXXX system xx operational and XXXXXX2 xxx xxxxxx xxxxxxxxx, T2S XXX xxxxxxx shall xxxxxx X2X DCA xxxxxxx xx xxx TARGET xxxxxx.“; |
|
9. |
Xxxxxx na pojem „X2X xxxxxxx service xxxxxxxx“ (x&xxxx;xxxxxxxxx nebo xxxxxxx xxxxx) x&xxxx;xx.&xxxx;6 xxxx.&xxxx;1 xxxx. x) xxxx i), xx.&xxxx;9 xxxx.&xxxx;5, čl. 10 xxxx.&xxxx;6, xx.&xxxx;14 odst. 1 xxxx. x), xx.&xxxx;22 odst. 1, xx.&xxxx;22 xxxx.&xxxx;2, xx.&xxxx;22 xxxx.&xxxx;3, xx.&xxxx;27 xxxx.&xxxx;5, xx.&xxxx;28 xxxx.&xxxx;1, xx.&xxxx;29 xxxx.&xxxx;1 xxxxxxx XX x&xxxx;x&xxxx;xxxxxxxx 1 xxxxxxx X&xxxx;xx xxxxxxxxx odkazem „XXX“; |
|
10. |
X&xxxx;xxxxxxx I se v odst. 8 xxxxxxx. 4 xxxxxxxxx xxxxxxx x) xxxxx:
|
XXXXXXX III
Příloha XXX xxxxxxxxxx XXX/2007/7 xx xxxx xxxxx:
|
1. |
Xxxxxx xx xxxxx „XXXX network xxxxxxx xxxxxxxx“ (v jednotném xxxx množném xxxxx) x&xxxx;xxxx příloze xx xxxxxxxxx xxxxxxx „XXX“; |
|
2. |
Xxxxxx&xxxx;1 xx xxxx xxxxx:
|
|
3. |
X&xxxx;xx.&xxxx;3 xxxx.&xxxx;1 xx zrušuje xxxxx xx „Xxxxxxxx X: XXXX xxxxxxxxxxxx xxxxxxxxx xxxxxxxxxxxx“; |
|
4. |
Xxxxxx&xxxx;4 xx xxxx takto:
|
|
5. |
X&xxxx;xx.&xxxx;6 xxxx.&xxxx;1 xxxx. x) xx xxx x) xxxxxxxxx xxxxx:
|
|
6. |
Xxxxxx&xxxx;9 se nahrazuje xxxxx: „Xxxxxxx&xxxx;9 Xxxxxxxxxxx relationship xxxx xx XXX 1.&xxxx;&xxxx;&xxxx;Xxxxxxxxxxxx xxxxx xxxxxx:
2.&xxxx;&xxxx;&xxxx;Xxx xxxxx xxxxxxxxxxxx xxxxxxx x&xxxx;xxxxxxxxxxx xxx xxx NSP xxxxx be xxxxxxxxxxx xxxxxxxx xx xxx xxxxx xxx conditions xx their xxxxxxxx xxxxxxxx xx xxxxxxxx xx in xxxxxxxxx 1(x). 3.&xxxx;&xxxx;&xxxx;Xxx services xx xx provided by xxx XXX shall xxx form xxxx xx the xxxxxxxx xx be xxxxxxxxx xx xxx XXX xx respect xx XXXXXX2. 4.&xxxx;&xxxx;&xxxx;Xxx XXX xxxxx xxx be xxxxxx xxx xxx xxxx, xxxxxx or xxxxxxxxx xx xxx XXX (xxxxxxxxx xxx xxxxxxxxx, xxxxx xxx xxxxxxxxxxxxxx), xx xxx xxx xxxx, xxxxxx xx xxxxxxxxx xx xxxxx xxxxxxx xxxxxxxx xx xxxxxxxxxxxx to xxxx xxxxxx xx xxx XXX’x network.“; |
|
7. |
Článek 10 xx xxxxxxx; |
|
8. |
Xxxxxx xx xxxx xxxxxx&xxxx;11x, xxxxx xxx: „Xxxxxxx&xxxx;11x XXX xxxxxxxxxx 1.&xxxx;&xxxx;&xxxx;Xxx xxxxxxx MPL xxxxxxxxxx xxxxxxxx xxx xxxxx – IBAN xxxxxxx table xxx xxx xxxxxxxx xx xxx MPL xxxxxxx. 2.&xxxx;&xxxx;&xxxx;Xxxx xxxxx xxx be xxxxxx to xxxx xxx IBAN. Xx XXXX xxx xx xxxxxx xx xxx xx xxxxxxxx xxxxxxx. 3.&xxxx;&xxxx;&xxxx;Xxxxxxx&xxxx;29 xxxxx apply to xxx xxxx xxxxxxxxx xx the MPL xxxxxxxxxx.“; |
|
9. |
X&xxxx;xxxxxx&xxxx;12 se zrušuje xxxxxxxx 9; |
|
10. |
Článek 16 xx xxxxxxxxx xxxxx: „Xxxxxxx&xxxx;16 Xxxxx xx xxxxxxx orders xx XXXX XXX Xxx xxxxxxxxx xxx classified xx xxxxxxx orders xxx xxx xxxxxxxx xx xxx XXXX xxxxxxx:
|
|
11. |
V článku 18 se xxxxxxxx 6 xxxxxxxxx xxxxx: „6.&xxxx;&xxxx;&xxxx;Xxxxx a TIPS XXX xx XX liquidity xxxxxxxx order, x&xxxx;XXXX XXX xx TIPS XX xxxxxxxxx xxxxxxx xxxxxxxxx transfer xxxxx xx a TIPS AS xxxxxxxxx account xx XXXX XXX xxxxxxxxx xxxxxxxx xxxxx xxx xxxx accepted as xxxxxxxx to xx Xxxxxxx&xxxx;17, xxx XXXXXX2-XXX xxxxx xxxxx xxxxxxx xxxxxxxxxx funds are xxxxxxxxx on xxx xxxxx'x account. Xx xxxxxxxxxx xxxxx xxx xxx xxxxxxxxx xxx xxxxxxxxx xxxxxxxx order xxxxx xx rejected. Xx xxxxxxxxxx xxxxx xxx xxxxxxxxx xxx xxxxxxxxx xxxxxxxx order xxxxx be xxxxxxx xxxxxxxxxxx.“; |
|
12. |
X&xxxx;xx.&xxxx;20 odst. 1 xx xxxxxxx x) xxxxxxxxx xxxxx:
|
|
13. |
X&xxxx;xxxxxx&xxxx;30 xx xxxxxxxx 1 xxxxxxxxx xxxxx: „1.&xxxx;&xxxx;&xxxx;XXXX XXX xxxxxxx xxxxx xx xxxxxx xx xx aware xx, xxxxx xxxxxx xxxx xxx xxxxx be xxxx xx demonstrate xxxx compliance xx xxx xxxxxxxx competent xxxxxxxxxxx xxxx xxx xxxxxxxxxxx xx xxxx xxxxxxxx to xxxxxxxxxxx xx data xxxxxxxxxx. Xxxx shall xx xxxxxx to xx xxxxx xx, xxx xxxxx xxxxxx xxxx xxx obligations xx xxxx relating xx xxxxxxxxxxx xx prevention xx money xxxxxxxxxx xxx xxx xxxxxxxxx xx xxxxxxxxx, xxxxxxxxxxxxx-xxxxxxxxx xxxxxxx xxxxxxxxxx and xxx xxxxxxxxxxx of xxxxxxx weapons delivery xxxxxxx, in xxxxxxxxxx xx terms of xxxxxxxxxxxx xxxxxxxxxxx measures xxxxxxxxxx xxx xxxxxxxx xxxxxxx or xxxxxxxx xx their TIPS XXXx. XXXX XXX xxxxxxx xxxxxx that xxxx xxx xxxxxxxx xxxxx xxxxx xxxxxx XXX'x xxxx retrieval xxxxxx prior to xxxxxxxx xxxx a contractual xxxxxxxxxxxx with xxxx XXX.“; |
|
14. |
Xxxxxx xx xxxx xxxxxx&xxxx;35x, xxxxx zní: „Article 35a Transitional xxxxxxxxx Xxxx xxx XXXXXX xxxxxx xx xxxxxxxxxxx xxx xxx XXXXXX2 xxx xxxxxx xxxxxxxxx, XXXX XXX xxxxxxx xxxxx become XXXX XXX xxxxxxx in xxx XXXXXX system.“; |
|
15. |
V dodatku X&xxxx;xx xxxxxxx v odstavci 2 xxxxxxxxx xxxxx:
|
|
16. |
X&xxxx;xxxxxxx I se x&xxxx;xxxx.&xxxx;6 xxxxxxx. 1 xxxxxxxxx xxxxxxx x) xxxxx:
|
|
17. |
X&xxxx;xxxxxxx XX xx zrušuje xxxxxxxx 2; |
|
18. |
Dodatek X&xxxx;xx xxxxxxx. |