Element 6: Cross-sector Coordination Cyber risks associated with third-party dependencies across sectors are identified and managed across those sectors. The financial sector is dependent on third parties in other sectors. A disruptive cyber incident in one of these sectors could affect the ability of entities to deliver their core business functions. Appropriate steps should be taken to facilitate cross-sector coordination in order to identify and manage these cyber risks. Efforts to improve information sharing across sectors on cyber risk should be encouraged, so that entities can monitor and manage cyber risks stemming from third parties in other sectors. Entities and relevant authorities should continue to seek opportunities to work with their respective counterparts in other sectors and critical infrastructure forums to promote sound cyber risk management, improve cyber resilience, support the sharing of effective practices and, if appropriate, pursue coordinated responses. Element 7: Third Parties to the Financial Sector Third parties that enter into contractual relationships with an entity should be aware that risk management requirements of these entities might have implications for their provision of services and goods. Entities remain responsible for ensuring the safe and sound operation of services provided to them by third parties. However, third parties should support entities in identifying, assessing, monitoring, and mitigating cyber risks and in complying with relevant risk management requirements. This especially applies to third parties that support ICT and cybersecurity services. To this extent, third parties should make available information necessary to facilitate effective management of cyber risk, including third-party cyber risk. This includes information potentially affecting an entity and its customers such as that related to material incidents, the intent to terminate a service or the support for a service or product, and the intent to enter into a critical third-party relationship with another party in the ICT supply chain. Where applicable, third parties are encouraged to use these Fundamental Elements to address thirdparty risk emanating from their respective third parties in the ICT supply chain. TLP WHITE: Subject to standard copyright rules, this document may be distributed freely, without restriction. 6

Select target paragraph3