Article 95 imposes operational + security risk management obligations on PSPs. Article 95(1): PSPs must establish a framework with appropriate mitigation measures + control mechanisms to manage the operational + security risks relating to the payment services they provide. As part of that framework PSPs must establish + maintain effective incident management procedures, including for the detection + classification of major operational + security incidents. Article 95(2): PSPs must provide, on an annual basis, an updated and comprehensive assessment of the operational + security risks relating to the payment services they provide and on the adequacy of the mitigation measures + control mechanisms implemented in response to those risks. Article 95(3): EBA in close cooperation with the ECB issued the EBA Guidelines on the security measures for operational + security risks (EBA/GL/2017/17, applicable from 13 January 2018, complemented by EBA/GL/2019/04 on ICT and security risk management which apply to PSPs).
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.