EBA Guidelines on ICT and Security Risk Management (EBA/GL/2024/07)
The European Banking Authority Guidelines on ICT and security risk management (EBA/GL/2019/04, 28 November 2019, applied from 30 June 2020), addressed to financial institutions and payment service providers. (Reference corrected from a mislabelled 'EBA/GL/2024/07'.) Cover governance and strategy, the ICT and security risk management framework (identification, classification/risk assessment, mitigation, reporting, audit), information security (policy, logical and physical security, ICT operations security, monitoring, testing, training), ICT operations management and incident/problem management, ICT project and change management, business continuity management, and payment service user relationship management. Largely superseded for EU financial entities by DORA from January 2025.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (7)
EBA GL 3.1/3.8: Proportionality and Payment Service User Relationship
| Code | Title |
|---|---|
| EBA-GL-3.1 | Proportionality |
| EBA-GL-3.8 | Payment service user relationship management |
EBA GL 3.2: Governance and Strategy
| Code | Title |
|---|---|
| EBA-GL-3.2.1 | Governance |
| EBA-GL-3.2.2 | Strategy |
| EBA-GL-3.2.3 | Use of third party providers |
EBA GL 3.3: ICT and Security Risk Management Framework
| Code | Title |
|---|---|
| EBA-GL-3.3.1 | Organisation and objectives |
| EBA-GL-3.3.2 | Identification of functions, processes and assets |
| EBA-GL-3.3.3 | Classification and risk assessment |
| EBA-GL-3.3.4 | Risk mitigation |
| EBA-GL-3.3.5 | Reporting |
| EBA-GL-3.3.6 | Audit |
EBA GL 3.4: Information Security
| Code | Title |
|---|---|
| EBA-GL-3.4.1 | Information security policy |
| EBA-GL-3.4.2 | Logical security |
| EBA-GL-3.4.3 | Physical security |
| EBA-GL-3.4.4 | ICT operations security |
| EBA-GL-3.4.5 | Security monitoring |
| EBA-GL-3.4.6 | Information security reviews, assessment and testing |
| EBA-GL-3.4.7 | Information security training and awareness |
EBA GL 3.5: ICT Operations Management
| Code | Title |
|---|---|
| EBA-GL-3.5 | ICT operations management |
| EBA-GL-3.5.1 | ICT incident and problem management |
EBA GL 3.6: ICT Project and Change Management
| Code | Title |
|---|---|
| EBA-GL-3.6.1 | ICT project management |
| EBA-GL-3.6.2 | ICT systems acquisition and development |
| EBA-GL-3.6.3 | ICT change management |
EBA GL 3.7: Business Continuity Management
| Code | Title |
|---|---|
| EBA-GL-3.7.1 | Business impact analysis |
| EBA-GL-3.7.2 | Business continuity planning |
| EBA-GL-3.7.3 | Response and recovery plans |
| EBA-GL-3.7.4 | Testing of plans |
| EBA-GL-3.7.5 | Crisis communications |
Your Compliance Coverage
If you comply with EBA Guidelines on ICT and Security Risk Management (EBA/GL/2024/07), you already cover:
DORA
32%
9 controls mapped
Compare →NIST Cybersecurity Framework 2.0
14%
4 controls mapped
Compare →ISO 27002:2022
7%
2 controls mapped
Compare →+ 11 more: ISO 27018:2019 (7%), ISO 22301:2019 (4%)
See all 14 mapped frameworks ↓Maps to 14 other frameworks
Frequently Asked Questions
What is EBA Guidelines on ICT and Security Risk Management (EBA/GL/2024/07)?
EBA Guidelines on ICT and Security Risk Management (EBA/GL/2024/07) is a compliance framework from European Union (EBA) with 7 domains and 28 controls. The European Banking Authority Guidelines on ICT and security risk management (EBA/GL/2019/04, 28 November 2019, applied from 30 June 2020), addressed to financial institutions and payment service providers. (Reference corrected from a mislabelled 'EBA/GL/2024/07'.) Cover governance and strategy, the ICT and security risk management framework (identification, classification/risk assessment, mitigation, reporting, audit), information security (policy, logical and physical security, ICT operations security, monitoring, testing, training), ICT operations management and incident/problem management, ICT project and change management, business continuity management, and payment service user relationship management. Largely superseded for EU financial entities by DORA from January 2025. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does EBA Guidelines on ICT and Security Risk Management (EBA/GL/2024/07) have?
EBA Guidelines on ICT and Security Risk Management (EBA/GL/2024/07) has 28 controls organised across 7 domains. The largest domains are EBA GL 3.4: Information Security (7 controls), EBA GL 3.3: ICT and Security Risk Management Framework (6 controls), EBA GL 3.7: Business Continuity Management (5 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does EBA Guidelines on ICT and Security Risk Management (EBA/GL/2024/07) map to?
EBA Guidelines on ICT and Security Risk Management (EBA/GL/2024/07) maps to 14 other compliance frameworks. The top mapping partners are DORA (32% coverage), NIST Cybersecurity Framework 2.0 (14% coverage), ISO 27002:2022 (7% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with EBA Guidelines on ICT and Security Risk Management (EBA/GL/2024/07) compliance?
Start your EBA Guidelines on ICT and Security Risk Management (EBA/GL/2024/07) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about EBA Guidelines on ICT and Security Risk Management (EBA/GL/2024/07) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 28 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 723 frameworks.
Get Started Free →Free forever — no credit card required