Back to Frameworks

EBA Guidelines on ICT and Security Risk Management (EBA/GL/2024/07)

European Union (EBA)
v2024
7 domains
28 controls

The European Banking Authority Guidelines on ICT and security risk management (EBA/GL/2019/04, 28 November 2019, applied from 30 June 2020), addressed to financial institutions and payment service providers. (Reference corrected from a mislabelled 'EBA/GL/2024/07'.) Cover governance and strategy, the ICT and security risk management framework (identification, classification/risk assessment, mitigation, reporting, audit), information security (policy, logical and physical security, ICT operations security, monitoring, testing, training), ICT operations management and incident/problem management, ICT project and change management, business continuity management, and payment service user relationship management. Largely superseded for EU financial entities by DORA from January 2025.

Verified

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (7)

EBA GL 3.1/3.8: Proportionality and Payment Service User Relationship

2 controls
Controls in the EBA GL 3.1/3.8: Proportionality and Payment Service User Relationship domain of EBA Guidelines on ICT and Security Risk Management (EBA/GL/2024/07)2 controls
CodeTitle
EBA-GL-3.1Proportionality
EBA-GL-3.8Payment service user relationship management

EBA GL 3.2: Governance and Strategy

3 controls
Controls in the EBA GL 3.2: Governance and Strategy domain of EBA Guidelines on ICT and Security Risk Management (EBA/GL/2024/07)3 controls
CodeTitle
EBA-GL-3.2.1Governance
EBA-GL-3.2.2Strategy
EBA-GL-3.2.3Use of third party providers

EBA GL 3.3: ICT and Security Risk Management Framework

6 controls
Controls in the EBA GL 3.3: ICT and Security Risk Management Framework domain of EBA Guidelines on ICT and Security Risk Management (EBA/GL/2024/07)6 controls
CodeTitle
EBA-GL-3.3.1Organisation and objectives
EBA-GL-3.3.2Identification of functions, processes and assets
EBA-GL-3.3.3Classification and risk assessment
EBA-GL-3.3.4Risk mitigation
EBA-GL-3.3.5Reporting
EBA-GL-3.3.6Audit

EBA GL 3.4: Information Security

7 controls
Controls in the EBA GL 3.4: Information Security domain of EBA Guidelines on ICT and Security Risk Management (EBA/GL/2024/07)7 controls
CodeTitle
EBA-GL-3.4.1Information security policy
EBA-GL-3.4.2Logical security
EBA-GL-3.4.3Physical security
EBA-GL-3.4.4ICT operations security
EBA-GL-3.4.5Security monitoring
EBA-GL-3.4.6Information security reviews, assessment and testing
EBA-GL-3.4.7Information security training and awareness

EBA GL 3.5: ICT Operations Management

2 controls
Controls in the EBA GL 3.5: ICT Operations Management domain of EBA Guidelines on ICT and Security Risk Management (EBA/GL/2024/07)2 controls
CodeTitle
EBA-GL-3.5ICT operations management
EBA-GL-3.5.1ICT incident and problem management

EBA GL 3.6: ICT Project and Change Management

3 controls
Controls in the EBA GL 3.6: ICT Project and Change Management domain of EBA Guidelines on ICT and Security Risk Management (EBA/GL/2024/07)3 controls
CodeTitle
EBA-GL-3.6.1ICT project management
EBA-GL-3.6.2ICT systems acquisition and development
EBA-GL-3.6.3ICT change management

EBA GL 3.7: Business Continuity Management

5 controls
Controls in the EBA GL 3.7: Business Continuity Management domain of EBA Guidelines on ICT and Security Risk Management (EBA/GL/2024/07)5 controls
CodeTitle
EBA-GL-3.7.1Business impact analysis
EBA-GL-3.7.2Business continuity planning
EBA-GL-3.7.3Response and recovery plans
EBA-GL-3.7.4Testing of plans
EBA-GL-3.7.5Crisis communications

Your Compliance Coverage

If you comply with EBA Guidelines on ICT and Security Risk Management (EBA/GL/2024/07), you already cover:

Maps to 14 other frameworks

28 total controls
DORA
9 source controls mapped|8 target controls covered
32%
NIST Cybersecurity Framework 2.0
4 source controls mapped|3 target controls covered
14%
ISO 27002:2022
2 source controls mapped|3 target controls covered
7%
ISO 27018:2019
2 source controls mapped|2 target controls covered
7%
ISO 22301:2019
1 source controls mapped|2 target controls covered
4%
NIST SP 800-53 Rev 5
1 source controls mapped|1 target controls covered
4%
ISO 27701:2019
1 source controls mapped|1 target controls covered
4%
ISO 27017:2015
1 source controls mapped|1 target controls covered
4%
ISO 27001:2022
1 source controls mapped|2 target controls covered
4%
ISO 19011:2018
1 source controls mapped|1 target controls covered
4%
ISO/IEC 42001:2023
1 source controls mapped|1 target controls covered
4%
ISO/IEC 17025:2017 - General Requirements for Testing and Calibration
1 source controls mapped|3 target controls covered
4%
ISO 13485:2016
1 source controls mapped|1 target controls covered
4%
ISO/IEC 38500:2024
1 source controls mapped|11 target controls covered
4%

Frequently Asked Questions

What is EBA Guidelines on ICT and Security Risk Management (EBA/GL/2024/07)?

EBA Guidelines on ICT and Security Risk Management (EBA/GL/2024/07) is a compliance framework from European Union (EBA) with 7 domains and 28 controls. The European Banking Authority Guidelines on ICT and security risk management (EBA/GL/2019/04, 28 November 2019, applied from 30 June 2020), addressed to financial institutions and payment service providers. (Reference corrected from a mislabelled 'EBA/GL/2024/07'.) Cover governance and strategy, the ICT and security risk management framework (identification, classification/risk assessment, mitigation, reporting, audit), information security (policy, logical and physical security, ICT operations security, monitoring, testing, training), ICT operations management and incident/problem management, ICT project and change management, business continuity management, and payment service user relationship management. Largely superseded for EU financial entities by DORA from January 2025. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

How many controls does EBA Guidelines on ICT and Security Risk Management (EBA/GL/2024/07) have?

EBA Guidelines on ICT and Security Risk Management (EBA/GL/2024/07) has 28 controls organised across 7 domains. The largest domains are EBA GL 3.4: Information Security (7 controls), EBA GL 3.3: ICT and Security Risk Management Framework (6 controls), EBA GL 3.7: Business Continuity Management (5 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

What frameworks does EBA Guidelines on ICT and Security Risk Management (EBA/GL/2024/07) map to?

EBA Guidelines on ICT and Security Risk Management (EBA/GL/2024/07) maps to 14 other compliance frameworks. The top mapping partners are DORA (32% coverage), NIST Cybersecurity Framework 2.0 (14% coverage), ISO 27002:2022 (7% coverage). Use our comparison tool to explore control-level mappings between frameworks.

How do I get started with EBA Guidelines on ICT and Security Risk Management (EBA/GL/2024/07) compliance?

Start your EBA Guidelines on ICT and Security Risk Management (EBA/GL/2024/07) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about EBA Guidelines on ICT and Security Risk Management (EBA/GL/2024/07) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 28 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 723 frameworks.

Get Started Free →

Free forever — no credit card required