EBA Guidelines on ICT and Security Risk Management (EBA/GL/2024/07)
EBA GL 3.4: Information Security

EBA Guidelines on ICT and Security Risk Management (EBA/GL/2024/07) EBA-GL-3.4.1: Information security policy

Institutions shall establish an information security policy approved by the management body, defining the high-level principles and rules to protect the confidentiality, integrity and availability of information.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Other controls in EBA GL 3.4: Information Security

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.