
Roadmap: building your GRC framework step by step
An effective GRC framework is built progressively, from the diagnosis of the existing state to consolidation, by adapting each step to the maturity, size and priorities of the organisation.
Circular CSSF 21/769 introduces Cumulative conditions for defining the concept of teleworking :
The work must be provided as part of the’normal company activity. Any task carried out as part of the activation of a BCP/DRP or in exceptional circumstances (such as the Covid-19 pandemic) does not fall within the definition of remote working and is therefore not covered by CSSF Circular 21/769.
In order to comply with the requirements for’Central administration :
The supervised entity must perform a Risk analysis to identify the risks inherent in the implementation of teleworking. It must also implement mitigation measures aimed at keeping residual risks within acceptable limits based on its Risk appetite (Risk Appetite). Risk analysis and the implementation of mitigation measures must be formalised and regularly reviewed by the entity.
The Board of Directors must formalise a Remote working policy which must be reviewed annually based on risk analysis. Point 32 of CSSF Circular 21/769 indicates a de minimis list that must be included in this policy.
The entity must formalise a Security policy This policy, which must be approved by the Board of Directors, defines the principles and rules applicable to teleworking in order to protect the confidentiality, integrity and availability of data, information and ICT.
The access rights Access rights granted to teleworkers must be in line with the risk analysis and security policy. These access rights must be reviewed at least annually (semi-annually for privileged users).
Furthermore, the entity must ensure that it keeps the control on the devices for remote connection to ICT systems. In this context, the use of personal devices must be restricted to low-risk activities and must be subject to specific risk analysis.
The components of the’Remote working infrastructure must, at all times, be secure and controlled. Thus, mechanisms must be put in place by the entity to detect and block any abnormal connection. Two-factor authentication must also be implemented to remotely connect to the company's ICT systems.
The entity must retain all elements permitting the control of conformity to the teleworking policy, as well as CSSF Circular 21/769. This information will need to be updated CSSF's disposition As requested.
The internal control functions (compliance, risk management, internal audit…) must to include The review of compliance with the requirements relating to teleworking within their Multiannual work plans. Furthermore, the Reports synthèse annuelle doit to include elements Statistics on the use of remote working as well as a mention of the Incidents significant ones that have taken place.
The Good functioning of the communication channel between the remote device and the company's infrastructure as well as the’effectiveness of security measures implementations must be audited by an independent security control function (Information security officer, internal audit or specialised external third party) before the launch of remote working and regularly thereafter. Scan tests and penetration tests must also be carried out regularly.
Furthermore, the entity must implement a Journalisation in order to ensure that all connections and technical information relating to remote working are recorded for security audit purposes.
The Staff awareness The risks and best practices associated with remote working must also be ensured by the entity through periodic training, newsletters or other communications.
Discover our other publications:

An effective GRC framework is built progressively, from the diagnosis of the existing state to consolidation, by adapting each step to the maturity, size and priorities of the organisation.

A useful GRC reporting consolidates the work of control functions into a readable view allowing the board to identify developments, areas of concern and decisions to be made.

A credible monitoring system relies on reliable data, structured evidence and an audit trail making it possible to reconstruct decisions and actions throughout the activity.
| Cookie | Durée | Description |
|---|---|---|
| cookielawinfo-checkbox-analytics | 11 months | This cookie is set by the GDPR Cookie Consent plugin. The cookie is used to store the user's consent for their cookies under the "Analytics" category. |
| cookielawinfo-checkbox-functional | 11 months | The cookie is set by GDPR cookie consent to record the user's consent for cookies in the "Functional" category. |
| Necessary cookies | 11 months | This cookie is set by the GDPR Cookie Consent plugin. The cookie is used to store the user's consent for the cookies in the "Necessary" category. |
| cookielawinfo-checkbox-others | 11 months | This cookie is set by the GDPR Cookie Consent plugin. The cookie is used to store the user's consent for the cookies in the "Other" category. |
| cookielawinfo-checkbox-performance | 11 months | This cookie is set by the GDPR Cookie Consent plugin. The cookie is used to store the user's consent for the cookies in the "Performance" category. |
| viewed_cookie_policy | 11 months | The cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not the user has consented to the use of cookies. It does not store any personal data. |
Once the form has been validated, a clean version of the article will open in a new tab. You can print it or save it as a PDF from the print window.