EIOPA Guidelines on ICT Security and Governance (EIOPA-BoS-20/600)
EIOPA ICT - ICT Operations and Change Management

EIOPA Guidelines on ICT Security and Governance (EIOPA-BoS-20/600) EIOPA-ICTSG-GL.17: ICT systems acquisition and development

Undertakings implement a risk-based process governing ICT systems acquisition, development and maintenance ensuring CIA and defined protection requirements: clear functional/non-functional (incl. security) requirements; measures preventing alteration/manipulation during development; a testing/approval methodology; security testing; segregation of production from non-production; source-code integrity and documentation; and the process extends to end-user-developed applications with a register of those supporting critical functions.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Other controls in EIOPA ICT - ICT Operations and Change Management

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.