Fundamental Elements To help address cyber risks, the G7 Fundamental Elements of Cybersecurity for the Financial Sector were issued in October 2016, and the G7 Fundamental Elements for Effective Assessment of Cybersecurity in the Financial Sector were issued in October 2017. To further support the development of third-party cyber risk management in the financial sector, the G7 issued the Fundamental Elements for Third Party Cyber Risk Management in the Financial Sector in 2018. To address industry developments since 2018, the G7 has revised the 2018 Fundamental Elements so as to focus not only on the management of third-party relationships but also on ICT supply chain management. The updated Fundamental Elements stress the importance of extensive information sharing and transparency to cope with an ever-changing threat landscape. To draw attention to the increasingly important role of third parties in the financial sector, a new fundamental element (Element 7) has been added. Entities should tailor the Fundamental Elements, as appropriate, to their specific risk profiles, operational and threat landscapes, roles in the sector, and legal and regulatory frameworks. The elements are non-binding and do not invalidate existing frameworks or prevent their continuous adaptation. The following Fundamental Elements consider the Third-Party Cyber Risk Management Life Cycle within an individual entity, the role of a third party to the financial sector, as well as system-wide monitoring of cyber risk. Moreover, these Fundamental Elements consider the Third-Party Cyber Risk Management within the entire ICT supply chain of an individual entity. Entities and third parties can use these Fundamental Elements as part of their cyber risk management toolkit. In doing so, entities should apply a proportionate approach that takes into account the size, nature, scope, complexity and potential systemic significance of the third-party relationship. Authorities within and across jurisdictions can use the Fundamental Elements to inform their public policy, regulatory, and supervisory efforts to address third-party cyber risks. Third-Party Cyber Risk Management Life Cycle Element 1: Governance Entities’ governing bodies are responsible and accountable for effective oversight and implementation of third-party cyber risk management. Entities’ governing bodies, such as boards of directors and senior management, are ultimately responsible and accountable for overseeing and implementing the management of the entities’ cyber risks, including those posed by its third-party relationships. This oversight and implementation includes: a documented strategy addressing the reliance on third parties; thirdparty and cyber risk policies; setting a risk tolerance for third-party relationships; and clear roles, responsibilities, and accountabilities for third-party cyber risk management integrated into the enterprise risk control functions, managed in proportion to the level of risk and criticality of a given activity. It also includes appropriate communication and escalation processes as a normal course of business at all levels within the entity, and between the entity, the third party and relevant authorities. TLP WHITE: Subject to standard copyright rules, this document may be distributed freely, without restriction. 2

Select target paragraph3