EIOPA Guidelines on ICT Security and Governance (EIOPA-BoS-20/600)
What is EIOPA Guidelines on ICT Security and Governance (EIOPA-BoS-20/600)?
EIOPA Guidelines (EIOPA-BoS-20/600, issued 12 October 2020, applied from 1 July 2021) on how insurance and reinsurance undertakings should apply the Solvency II governance requirements (Directive 2009/138/EC and Delegated Regulation (EU) 2015/35) to information and communication technology (ICT) security and governance. 25 guidelines covering ICT governance and strategy, ICT and security risk management, information security, ICT operations and change management, business continuity, and outsourcing of ICT services. It comprises 25 controls organised across 5 domains, and applies in the European Union (EIOPA).
How EIOPA Guidelines on ICT Security and Governance (EIOPA-BoS-20/600) maps to other frameworks
All 25 controls, each one mapped to the equivalent requirement in other standards, with the evidence that carries across and the mappings that were judged and rejected shown alongside. No account needed to look.
See the control mappings →The 5 domains EIOPA Guidelines on ICT Security and Governance (EIOPA-BoS-20/600) groups its controls into
Where EIOPA Guidelines on ICT Security and Governance (EIOPA-BoS-20/600) overlaps with the standards you already hold
What EIOPA Guidelines on ICT Security and Governance (EIOPA-BoS-20/600) means in your sector
What EIOPA Guidelines on ICT Security and Governance (EIOPA-BoS-20/600) means for your job
Questions people ask about EIOPA Guidelines on ICT Security and Governance (EIOPA-BoS-20/600)
What is EIOPA Guidelines on ICT Security and Governance?
How many controls does EIOPA Guidelines on ICT Security and Governance have?
Where does EIOPA Guidelines on ICT Security and Governance apply?
What frameworks does EIOPA Guidelines on ICT Security and Governance map to?
How do I get started with EIOPA Guidelines on ICT Security and Governance compliance?
Query EIOPA Guidelines on ICT Security and Governance (EIOPA-BoS-20/600) programmatically
EIOPA Guidelines on ICT Security and Governance (EIOPA-BoS-20/600), its 25 controls and every mapping into other standards are available over a REST endpoint and an MCP server, so an agent can read them directly. The free tier is 10 calls a day and needs no signup.
EIOPA Guidelines on ICT Security and Governance (EIOPA-BoS-20/600) API reference and MCP config →What EIOPA Guidelines on ICT Security and Governance (EIOPA-BoS-20/600) requires, control by control
Each page carries the requirement text for one EIOPA Guidelines on ICT Security and Governance (EIOPA-BoS-20/600) control and what an assessor expects to see as evidence.
- EIOPA-ICTSG-GL-10 ICT operations security
- EIOPA-ICTSG-GL-11 Security monitoring
- EIOPA-ICTSG-GL-12 Information security reviews, assessment and testing
- EIOPA-ICTSG-GL-13 Information security training and awareness
- EIOPA-ICTSG-GL-14 ICT operations management
- EIOPA-ICTSG-GL-15 ICT incident and problem management
- EIOPA-ICTSG-GL-19 Business continuity management
- EIOPA-ICTSG-GL-2 ICT within the system of governance
- EIOPA-ICTSG-GL-20 Business impact analysis
- EIOPA-ICTSG-GL-21 Business continuity planning
How ready are you for EIOPA Guidelines on ICT Security and Governance (EIOPA-BoS-20/600)?
Answer 25 questions and get a professional readiness report with gap analysis, maturity scores, and prioritised action items. Results in 5 minutes.