EBA Guidelines on ICT and Security Risk Management (EBA/GL/2024/07)
EBA GL 3.3: ICT and Security Risk Management Framework

EBA Guidelines on ICT and Security Risk Management (EBA/GL/2024/07) EBA-GL-3.3.4: Risk mitigation

Institutions shall take measures to mitigate identified ICT and security risks, including the protection measures in the information security section, and address residual risk in line with their risk appetite.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Other controls in EBA GL 3.3: ICT and Security Risk Management Framework

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.