EBA Guidelines on ICT and Security Risk Management (EBA/GL/2024/07)
What is EBA Guidelines on ICT and Security Risk Management (EBA/GL/2024/07)?
The European Banking Authority Guidelines on ICT and security risk management (EBA/GL/2019/04, 28 November 2019, applied from 30 June 2020), addressed to financial institutions and payment service providers. (Reference corrected from a mislabelled 'EBA/GL/2024/07'.) Cover governance and strategy, the ICT and security risk management framework (identification, classification/risk assessment, mitigation, reporting, audit), information security (policy, logical and physical security, ICT operations security, monitoring, testing, training), ICT operations management and incident/problem management, ICT project and change management, business continuity management, and payment service user relationship management. It comprises 28 controls organised across 7 domains, and applies in the European Union (EBA).
How EBA Guidelines on ICT and Security Risk Management (EBA/GL/2024/07) maps to other frameworks
All 28 controls, each one mapped to the equivalent requirement in other standards, with the evidence that carries across and the mappings that were judged and rejected shown alongside. No account needed to look.
See the control mappings →The 7 domains EBA Guidelines on ICT and Security Risk Management (EBA/GL/2024/07) groups its controls into
Where EBA Guidelines on ICT and Security Risk Management (EBA/GL/2024/07) overlaps with the standards you already hold
What EBA Guidelines on ICT and Security Risk Management (EBA/GL/2024/07) means in your sector
What EBA Guidelines on ICT and Security Risk Management (EBA/GL/2024/07) means for your job
Questions people ask about EBA Guidelines on ICT and Security Risk Management (EBA/GL/2024/07)
What is EBA Guidelines on ICT and Security Risk Management?
How many controls does EBA Guidelines on ICT and Security Risk Management have?
Where does EBA Guidelines on ICT and Security Risk Management apply?
What frameworks does EBA Guidelines on ICT and Security Risk Management map to?
How do I get started with EBA Guidelines on ICT and Security Risk Management compliance?
Query EBA Guidelines on ICT and Security Risk Management (EBA/GL/2024/07) programmatically
EBA Guidelines on ICT and Security Risk Management (EBA/GL/2024/07), its 28 controls and every mapping into other standards are available over a REST endpoint and an MCP server, so an agent can read them directly. The free tier is 10 calls a day and needs no signup.
EBA Guidelines on ICT and Security Risk Management (EBA/GL/2024/07) API reference and MCP config →What EBA Guidelines on ICT and Security Risk Management (EBA/GL/2024/07) requires, control by control
Each page carries the requirement text for one EBA Guidelines on ICT and Security Risk Management (EBA/GL/2024/07) control and what an assessor expects to see as evidence.
- EBA-GL-3-2-1 Governance
- EBA-GL-3-2-3 Use of third party providers
- EBA-GL-3-3-1 Organisation and objectives
- EBA-GL-3-3-2 Identification of functions, processes and assets
- EBA-GL-3-3-3 Classification and risk assessment
- EBA-GL-3-3-5 Reporting
- EBA-GL-3-3-6 Audit
- EBA-GL-3-4-2 Logical security
- EBA-GL-3-4-3 Physical security
- EBA-GL-3-4-5 Security monitoring
How ready are you for EBA Guidelines on ICT and Security Risk Management (EBA/GL/2024/07)?
Answer 25 questions and get a professional readiness report with gap analysis, maturity scores, and prioritised action items. Results in 5 minutes.