Article 95 imposes operational + security risk management obligations on PSPs. Article 95(1): PSPs must establish a framework with appropriate mitigation measures + control mechanisms to manage the operational + security risks relating to the payment services they provide. As part of that framework PSPs must establish + maintain effective incident management procedures, including for the detection + classification of major operational + security incidents. Article 95(2): PSPs must provide, on an annual basis, an updated and comprehensive assessment of the operational + security risks relating to the payment services they provide and on the adequacy of the mitigation measures + control mechanisms implemented in response to those risks. Article 95(3): EBA in close cooperation with the ECB issued the EBA Guidelines on the security measures for operational + security risks (EBA/GL/2017/17, applicable from 13 January 2018, complemented by EBA/GL/2019/04 on ICT and security risk management which apply to PSPs).
This control maps to 5 controls across 2 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 5 it maps to, and the evidence behind each claim, over MCP and REST.