Element 6: Cross-sector Coordination
Cyber risks associated with third-party dependencies across sectors are identified and managed
across those sectors.
The financial sector is dependent on third parties in other sectors. A disruptive cyber incident in
one of these sectors could affect the ability of entities to deliver their core business functions.
Appropriate steps should be taken to facilitate cross-sector coordination in order to identify and
manage these cyber risks.
Efforts to improve information sharing across sectors on cyber risk should be encouraged, so that
entities can monitor and manage cyber risks stemming from third parties in other sectors.
Entities and relevant authorities should continue to seek opportunities to work with their respective
counterparts in other sectors and critical infrastructure forums to promote sound cyber risk
management, improve cyber resilience, support the sharing of effective practices and, if
appropriate, pursue coordinated responses.
Element 7: Third Parties to the Financial Sector
Third parties that enter into contractual relationships with an entity should be aware that risk
management requirements of these entities might have implications for their provision of services
and goods.
Entities remain responsible for ensuring the safe and sound operation of services provided to them
by third parties. However, third parties should support entities in identifying, assessing,
monitoring, and mitigating cyber risks and in complying with relevant risk management
requirements. This especially applies to third parties that support ICT and cybersecurity services.
To this extent, third parties should make available information necessary to facilitate effective
management of cyber risk, including third-party cyber risk. This includes information potentially
affecting an entity and its customers such as that related to material incidents, the intent to
terminate a service or the support for a service or product, and the intent to enter into a critical
third-party relationship with another party in the ICT supply chain.
Where applicable, third parties are encouraged to use these Fundamental Elements to address thirdparty risk emanating from their respective third parties in the ICT supply chain.
TLP WHITE: Subject to standard copyright rules, this document may be distributed freely, without restriction.
6