Article 15
Use of internal testers
1. Financial entities shall establish all of the following arrangements for the use of internal testers:
(a) |
the establishment and implementation of a policy for the management of internal testers in a TLPT; |
(b) |
measures to ensure that the use of internal testers to perform a TLPT does not negatively impact the financial entity’s general defensive or resilience capabilities regarding ICT-related incidents or significantly impacts the availability of resources devoted to ICT-related tasks during a TLPT; |
(c) |
measures to ensure that internal testers have sufficient resources and capabilities to perform a TLPT. |
The policy referred to in point (a) shall:
(a) |
contain criteria to assess suitability, competence, potential conflicts of interest of the internal testers and specify management responsibilities in the testing process; |
(b) |
be documented and periodically reviewed; |
(c) |
provide that the internal testing team includes a test lead, and at least two additional members; |
(d) |
require that all members of the test team have been employed by the financial entity or by an ICT intra-group service provider for the preceding 12 months; |
(e) |
include provisions on training on how to perform penetration testing and red team testing of the internal testers. |
2. Where a TLPT authority approves the use of internal testers in accordance with Article 27(2), point (a), of Regulation (EU) 2022/2554, the TLPT authority shall consider the requirements laid down in Article 7(1) of this Regulation.
3. When using internal testers, the financial entity shall ensure that such use is mentioned in the following documents:
(a) |
the test initiation information referred to in Article 9; |
(b) |
the red team test report referred to in Article 12(2); |
(c) |
the report summarising the relevant findings of the TLPT referred to in Article 26(6) of Regulation (EU) 2022/2554. |
4. Testers employed by an ICT intra-group service provider shall be considered as internal testers of the financial entity.