EBA Guidelines on ICT and Security Risk Management (EBA/GL/2024/07)
The European Banking Authority Guidelines on ICT and security risk management (EBA/GL/2019/04, 28 November 2019, applied from 30 June 2020), addressed to financial institutions and payment service providers. (Reference corrected from a mislabelled 'EBA/GL/2024/07'.) Cover governance and strategy, the ICT and security risk management framework (identification, classification/risk assessment, mitigation, reporting, audit), information security (policy, logical and physical security, ICT operations security, monitoring, testing, training), ICT operations management and incident/problem management, ICT project and change management, business continuity management, and payment service user relationship management. Largely superseded for EU financial entities by DORA from January 2025.
EBA Guidelines on ICT and Security Risk Management (EBA/GL/2024/07) is a compliance framework from European Union (EBA) with 7 domains and 28 controls that map to 14 other frameworks. The largest domains are EBA GL 3.4: Information Security (7 controls), EBA GL 3.3: ICT and Security Risk Management Framework (6 controls), EBA GL 3.7: Business Continuity Management (5 controls). Every control below carries what it requires and what an assessor expects to see.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (7)
EBA GL 3.1/3.8: Proportionality and Payment Service User Relationship
| Code | Title |
|---|---|
| EBA-GL-3.1 | Proportionality |
| EBA-GL-3.8 | Payment service user relationship management |
EBA GL 3.2: Governance and Strategy
| Code | Title |
|---|---|
| EBA-GL-3.2.1 | Governance |
| EBA-GL-3.2.2 | Strategy |
| EBA-GL-3.2.3 | Use of third party providers |
EBA GL 3.3: ICT and Security Risk Management Framework
| Code | Title |
|---|---|
| EBA-GL-3.3.1 | Organisation and objectives |
| EBA-GL-3.3.2 | Identification of functions, processes and assets |
| EBA-GL-3.3.3 | Classification and risk assessment |
| EBA-GL-3.3.4 | Risk mitigation |
| EBA-GL-3.3.5 | Reporting |
| EBA-GL-3.3.6 | Audit |
EBA GL 3.4: Information Security
| Code | Title |
|---|---|
| EBA-GL-3.4.1 | Information security policy |
| EBA-GL-3.4.2 | Logical security |
| EBA-GL-3.4.3 | Physical security |
| EBA-GL-3.4.4 | ICT operations security |
| EBA-GL-3.4.5 | Security monitoring |
| EBA-GL-3.4.6 | Information security reviews, assessment and testing |
| EBA-GL-3.4.7 | Information security training and awareness |
EBA GL 3.5: ICT Operations Management
| Code | Title |
|---|---|
| EBA-GL-3.5 | ICT operations management |
| EBA-GL-3.5.1 | ICT incident and problem management |
EBA GL 3.6: ICT Project and Change Management
| Code | Title |
|---|---|
| EBA-GL-3.6.1 | ICT project management |
| EBA-GL-3.6.2 | ICT systems acquisition and development |
| EBA-GL-3.6.3 | ICT change management |
EBA GL 3.7: Business Continuity Management
| Code | Title |
|---|---|
| EBA-GL-3.7.1 | Business impact analysis |
| EBA-GL-3.7.2 | Business continuity planning |
| EBA-GL-3.7.3 | Response and recovery plans |
| EBA-GL-3.7.4 | Testing of plans |
| EBA-GL-3.7.5 | Crisis communications |
Your Compliance Coverage
If you comply with EBA Guidelines on ICT and Security Risk Management (EBA/GL/2024/07), you already cover:
DORA
32%
9 controls mapped
Compare →NIST Cybersecurity Framework 2.0
14%
4 controls mapped
Compare →ISO 27002:2022
7%
2 controls mapped
Compare →+ 11 more: ISO 27018:2019 (7%), ISO 22301:2019 (4%)
See all 14 mapped frameworks ↓Maps to 14 other frameworks
Coverage is not the same as your position
This page shows what EBA Guidelines on ICT and Security Risk Management (EBA/GL/2024/07) overlaps with in general. Where your organisation actually stands, against the standard you are going for and the certifications you already hold, is a different question. Same graph and the same recorded refutations, scoped to you rather than to a pair.
The Compliance Position Diagnostic, $5,000 fixed, ten business daysWhat is EBA Guidelines on ICT and Security Risk Management (EBA/GL/2024/07) and who does it apply to?
EBA Guidelines on ICT and Security Risk Management (EBA/GL/2024/07) is a compliance framework from European Union (EBA) with 7 domains and 28 controls. The European Banking Authority Guidelines on ICT and security risk management (EBA/GL/2019/04, 28 November 2019, applied from 30 June 2020), addressed to financial institutions and payment service providers. (Reference corrected from a mislabelled 'EBA/GL/2024/07'.) Cover governance and strategy, the ICT and security risk management framework (identification, classification/risk assessment, mitigation, reporting, audit), information security (policy, logical and physical security, ICT operations security, monitoring, testing, training), ICT operations management and incident/problem management, ICT project and change management, business continuity management, and payment service user relationship management. Largely superseded for EU financial entities by DORA from January 2025. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
What does EBA Guidelines on ICT and Security Risk Management (EBA/GL/2024/07) actually require?
EBA Guidelines on ICT and Security Risk Management (EBA/GL/2024/07) has 28 controls organised across 7 domains. The largest domains are EBA GL 3.4: Information Security (7 controls), EBA GL 3.3: ICT and Security Risk Management Framework (6 controls), EBA GL 3.7: Business Continuity Management (5 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
If I already comply with another framework, how much of EBA Guidelines on ICT and Security Risk Management (EBA/GL/2024/07) do I already cover?
EBA Guidelines on ICT and Security Risk Management (EBA/GL/2024/07) maps to 14 other compliance frameworks. The top mapping partners are DORA (32% coverage), NIST Cybersecurity Framework 2.0 (14% coverage), ISO 27002:2022 (7% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I implement EBA Guidelines on ICT and Security Risk Management (EBA/GL/2024/07)?
Start your EBA Guidelines on ICT and Security Risk Management (EBA/GL/2024/07) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about EBA Guidelines on ICT and Security Risk Management (EBA/GL/2024/07) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 28 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 683 frameworks.
Get Started Free →Free forever — no credit card required