European Union (EBA)

EBA Guidelines on ICT and Security Risk Management (EBA/GL/2019/04)

43 controls. 14 other frameworks in our corpus share controls with it. Here is all of it, and how much of it you are already doing.

Page built . This page is derived from the framework corpus, which changes when the corpus is extended rather than daily.

43 controls 14 frameworks share controls with it European Union (EBA) verified against its source document

Every control below is one this framework asks for. The right hand column counts how many other frameworks in our corpus carry the same control, which is the difference between doing this work once and doing it again for the next standard.

There is no implementation kit for this framework yet. The control list and the overlap above are free and complete.

What you already have

Frameworks whose controls overlap this one, most first. If you run any of them, the count is roughly what you have already evidenced.

Every control

CodeControlAlso in
EBA-GL-3.1Proportionality0
EBA-GL-3.2Governance and strategy0
EBA-GL-3.2.1Governance2
EBA-GL-3.2.2Strategy0
EBA-GL-3.2.3Use of third party providers1
EBA-GL-3.3ICT and security risk management framework0
EBA-GL-3.3.1Organisation and objectives1
EBA-GL-3.3.2Identification of functions, processes and assets2
EBA-GL-3.3.3Classification and risk assessment1
EBA-GL-3.3.4Risk mitigation0
EBA-GL-3.3.5Reporting4
EBA-GL-3.3.6Audit1
EBA-GL-3.4Information security0
EBA-GL-3.4.1Information security policy0
EBA-GL-3.4.2Logical security1
EBA-GL-3.4.3Physical security2
EBA-GL-3.4.4ICT operations security0
EBA-GL-3.4.5Security monitoring2
EBA-GL-3.4.6Information security reviews, assessment and testing3
EBA-GL-3.4.7Information security training and awareness1
EBA-GL-3.5ICT operations management0
EBA-GL-3.5.1ICT incident and problem management2
EBA-GL-3.6ICT project and change management0
EBA-GL-3.6.1ICT project management0
EBA-GL-3.6.2ICT systems acquisition and development0
EBA-GL-3.6.3ICT change management0
EBA-GL-3.7Business continuity management0
EBA-GL-3.7.1Business impact analysis2
EBA-GL-3.7.2Business continuity planning0
EBA-GL-3.7.3Response and recovery plans2
EBA-GL-3.7.4Testing of plans0
EBA-GL-3.7.5Crisis communications0
EBA-GL-3.8Payment service user relationship management0
EBA-GL-92Awareness of security risks through assistance and guidance0
EBA-GL-93Updating guidance for new threats0
EBA-GL-94Option to disable payment functionalities0
EBA-GL-95Adjustable spending limits0
EBA-GL-96Alerts on initiated and failed payment transactions0
EBA-GL-97Informing users of updates to security procedures0
EBA-GL-98Assistance on security questions and anomaly notifications0
EBA-GL-ADDRESSEESAddressees (as amended)0
EBA-GL-STATUSStatus and history0
EBA-GL-SUBJECTSubject matter and scope (as amended)0

Tell me when EBA Guidelines on ICT and Security Risk Management (EBA/GL/2019/04) files something new

One email when a public company newly discloses something this framework governs, naming the company and what our corpus says it puts in scope. Nothing else, and one click to stop.

What this page is

A control-level reference for EBA Guidelines on ICT and Security Risk Management (EBA/GL/2019/04), drawn from our framework corpus. Control codes and titles are references to the standard, not reproductions of it. The overlap counts and the auditor artefacts are our own work and are the part you will not find elsewhere.

Measure this against what you already run · All frameworks · Today's edition