EIOPA Guidelines on ICT Security and Governance (EIOPA-BoS-20/600)
Evidence request list. 25 controls, 25 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
EIOPA ICT - Business Continuity Management
As part of the overall business continuity policy, the AMSB sets and approves the ICT continuity policy, communicated appropriately within the undertaking and to relevant service providers.
- AMSB-approved ICT continuity policy
- Evidence of communication to staff/providers
- No board-approved ICT continuity policy
Undertakings conduct a business impact analysis assessing exposure to severe business disruptions and their quantitative/qualitative impact using internal/external data and scenario analysis, considering criticality and interdependencies per Guideline 4, and design/align ICT systems and services with the BIA (e.g. redundancy of critical components).
- Business impact analysis covering ICT criticality and interdependencies
- Evidence systems are designed around the BIA
- No BIA
- BIA not linked to asset criticality
Business continuity plans should consider material risks to ICT systems/services and support protection and re-establishment of CIA, coordinated with stakeholders, and ensure reaction to failure scenarios within a Recovery Time Objective and Recovery Point Objective, considering a range of extreme-but-plausible and cyber-attack scenarios.
- Business continuity plans with RTO/RPO
- Scenario analysis incl. cyber-attack scenarios
- No defined RTO/RPO
- Plans omit cyber scenarios
Based on the BIA and plausible scenarios, undertakings develop response and recovery plans specifying activation conditions and actions to ensure integrity, availability, continuity and recovery of at least critical ICT systems/services/data, considering short- and long-term options, documented and accessible with clear roles, continuously updated from lessons learned, and including measures to mitigate failure of key service providers.
- Response and recovery plans with activation criteria and roles
- Provider-failure continuity measures
- Update records from lessons learned
- Plans not documented/accessible in emergency
- No provider-failure mitigation
Undertakings test their BCPs and the operation of critical processes/functions/assets and interdependencies (including provider-supplied) regularly based on the risk profile; update BCPs from testing results, threat intelligence and lessons learned; demonstrate the plans sustain business viability until critical operations are re-established at a predefined level; and document results, analysing, addressing and reporting deficiencies to the AMSB.
- BCP test plans and results
- Deficiency remediation and AMSB reporting
- BCPs not tested regularly
- Test deficiencies not remediated
In a disruption or emergency and during BCP implementation, undertakings should have effective crisis communication measures so all relevant internal and external stakeholders, including supervisory authorities (where required) and relevant service providers, are informed in a timely and appropriate manner.
- Crisis communication plan and stakeholder/contact lists
- Records of notifications during incidents
- No crisis communication plan
- Supervisory notification path undefined
EIOPA ICT - Governance and Risk Management
Undertakings should apply the Guidelines in a manner proportionate to the nature, scale and complexity of the risks inherent in their business.
- Documented proportionality rationale for the ICT/security control set
- One-size-fits-all controls with no proportionality justification
The administrative, management or supervisory body (AMSB) should ensure the system of governance, in particular risk management and internal control, adequately manages ICT and security risks; that staff numbers and skills are adequate and trained; and that allocated resources are appropriate.
- AMSB oversight records for ICT/security risk
- Evidence of adequate ICT staffing/skills and resourcing
- No AMSB-level ownership of ICT risk
- Under-resourced ICT/security function
The AMSB sets and approves a written ICT strategy aligned with business strategy, defining how ICT evolves to support the business, the ICT architecture evolution and service-provider dependencies, and clear information security objectives; the strategy is implemented, communicated and its effectiveness monitored and reviewed.
- Approved written ICT strategy with information security objectives
- Evidence of communication and effectiveness monitoring
- No board-approved ICT strategy
- Strategy not reviewed/updated
The AMSB establishes an effective system for managing ICT and security risks within the overall risk management system, including risk tolerance and regular reporting. Undertakings map business processes/functions/assets and interdependencies, identify and measure ICT and security risks, classify assets by criticality and assess confidentiality/integrity/availability protection requirements with identified asset owners, and define and implement measures (incl. residual risk) approved by the AMSB.
- ICT/security risk assessment and register
- Asset inventory with criticality and CIA classification + asset owners
- AMSB approval of the risk results
- No asset classification or owners
- Risk assessment not refreshed before major changes
Governance, systems and processes for ICT and security risks should be audited periodically, in line with the audit plan, by auditors with sufficient ICT/security knowledge to provide independent assurance to the AMSB, with frequency and focus commensurate with the risks.
- ICT/security audit plan and reports
- Auditor competence evidence
- No independent ICT/security audit
- Audit scope not risk-based
EIOPA ICT - ICT Operations and Change Management
Undertakings manage ICT operations based on the ICT strategy, documenting critical processes/procedures; implement logging and monitoring for error detection/correction; maintain an up-to-date ICT asset inventory (location, classification, ownership); manage the ICT asset lifecycle (vendor support, patching, decommissioning); implement performance and capacity planning; and define and regularly test data/ICT backup and restoration procedures, storing backups in secure, sufficiently remote off-site locations.
- ICT asset inventory and lifecycle records
- Backup and restoration procedures with test evidence
- Capacity/performance monitoring
- Outdated/unsupported ICT assets
- Backups untested or not off-site
Undertakings establish an incident and problem management process to monitor and log operational/security incidents and resume critical functions, with classification criteria/thresholds and early-warning indicators, and processes/structures ensuring consistent monitoring, handling, root-cause analysis, corrective actions, escalation, communication and post-incident review.
- Incident and problem management process
- Incident classification criteria and logs
- Root-cause and corrective-action records
- No incident classification thresholds
- No root-cause/problem management
Undertakings implement an ICT project methodology (with independent security requirement consideration) and governance to support the ICT strategy, and monitor and mitigate risks across the ICT project portfolio, including interdependencies and shared-resource dependencies.
- ICT project methodology with security gates
- Project portfolio risk monitoring
- Security requirements not built into projects
- No portfolio-level project risk view
Undertakings implement a risk-based process governing ICT systems acquisition, development and maintenance ensuring CIA and defined protection requirements: clear functional/non-functional (incl. security) requirements; measures preventing alteration/manipulation during development; a testing/approval methodology; security testing; segregation of production from non-production; source-code integrity and documentation; and the process extends to end-user-developed applications with a register of those supporting critical functions.
- Secure SDLC process and security requirements
- Environment segregation and source-code integrity controls
- Register of end-user-developed critical applications
- No security in the SDLC
- Production not segregated from dev/test
Undertakings establish an ICT change management process so all changes are recorded, assessed, tested, approved, authorised and implemented in a controlled manner, with urgent/emergency changes traceable and notified ex-post; and assess whether changes impact existing security measures or require additional ones.
- Change management process and change records
- Emergency-change traceability and ex-post review
- Untracked/unapproved changes
- Security impact of changes not assessed
EIOPA ICT - Information Security
Undertakings implement procedures ensuring CIA of ICT systems and services: vulnerability identification and remediation (patching, antivirus, compensating controls); secure configuration baselines; network segmentation, data leakage prevention and network traffic encryption; endpoint protection; integrity-checking mechanisms; and encryption of data at rest and in transit per asset classification.
- Patch and vulnerability management records
- Secure configuration baselines
- Encryption (at rest/in transit) and network segmentation evidence
- Unpatched critical systems
- No secure baselines or endpoint protection
Undertakings establish procedures to continuously monitor activities impacting information security (internal/external factors, provider and user transactions, internal/external threats) and implement capabilities to detect, report and respond to anomalous activities and threats; monitoring reports support understanding incidents, identifying trends and decision-making.
- Security monitoring procedures and tooling
- Anomaly detection and reporting records
- No continuous security monitoring
- Monitoring not covering provider/threat activity
Undertakings perform varied information security reviews/assessments/testing to identify vulnerabilities, establish an information security testing framework validating the robustness of measures, with tests by independent competent testers, performed regularly (scope/frequency/method commensurate with risk, incl. penetration testing; critical systems and vulnerability scans annually) and on changes/major incidents, monitoring results and updating measures without undue delay.
- Security testing framework and schedule
- Penetration test / vulnerability scan reports (annual for critical)
- Remediation tracking from test results
- No regular security testing of critical systems
- Testers not independent/competent
Undertakings establish information security training programmes for all staff (including the AMSB) to reduce human error, theft, fraud, misuse or loss, provided regularly, and implement periodic security awareness programmes.
- Security training and awareness programme records
- Completion/coverage evidence incl. AMSB
- No regular security training
- AMSB excluded from awareness
Undertakings establish a written, AMSB-approved information security policy defining principles and rules to protect confidentiality, integrity and availability of information, with roles and responsibilities, communicated to all staff (and relevant service providers); and implement more specific information security procedures and measures covering the processes in the Guidelines.
- AMSB-approved information security policy
- Supporting information security procedures
- Evidence of communication to staff/providers
- No board-approved information security policy
- Policy not operationalised into procedures
Undertakings establish an information security function with responsibilities assigned to a designated person, independent and segregated from ICT development and operations and reporting to the AMSB, tasked with supporting the policy, advising the AMSB, monitoring implementation, ensuring provider compliance, awareness, and incident coordination.
- Designated information security officer/function
- Segregation from ICT dev/ops evidence
- Reporting line to the AMSB
- Information security function not independent of ICT operations
- No designated owner
Undertakings define, document and implement logical access control (identity and access management): need-to-know, least privilege and segregation of duties; user accountability (limit generic/shared accounts); strong control of privileged access; secure remote access with strong authentication; logging and monitoring of user activity; timely granting/modification/revocation and periodic access review; documented access changes; and robust authentication methods (strong passwords or stronger, e.g. two-factor) commensurate with criticality.
- IAM policy and procedures
- Privileged-access controls and access reviews
- Authentication standards (incl. MFA) and access logs
- Excessive/standing privileges
- No periodic access recertification
- Weak authentication on critical systems
Undertakings define, document and implement physical security measures (against power failure, fire, water, unauthorised access) to protect premises, data centres and sensitive areas; permit physical access to ICT systems only to authorised, trained, monitored individuals with regular review; and protect against environmental hazards commensurate with criticality.
- Physical access controls and authorisation records
- Environmental protection measures for data centres
- Unrestricted physical access to ICT systems
- No environmental hazard protection
EIOPA ICT - Outsourcing of ICT Services
Without prejudice to the EIOPA cloud-outsourcing guidelines, where ICT services/systems are outsourced undertakings ensure the relevant requirements are met; for outsourcing of critical or important functions, contractual obligations (contract, SLAs, termination) must include at least appropriate information security objectives/measures (incl. minimum security requirements, data lifecycle, audit/access rights, data-centre location, encryption, network security and monitoring), SLAs ensuring continuity and performance, and operational/security incident handling with escalation and reporting; and undertakings monitor and seek assurance on provider compliance.
- ICT outsourcing contracts/SLAs with security, audit/access and incident clauses
- Provider assurance/monitoring records
- Critical outsourcing without audit/access or security clauses
- No ongoing provider assurance
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.