Back to Frameworks

EIOPA Guidelines on ICT Security and Governance (EIOPA-BoS-20/600)

European Union (EIOPA)
v2023
5 domains
25 controls

EIOPA Guidelines (EIOPA-BoS-20/600, issued 12 October 2020, applied from 1 July 2021) on how insurance and reinsurance undertakings should apply the Solvency II governance requirements (Directive 2009/138/EC and Delegated Regulation (EU) 2015/35) to information and communication technology (ICT) security and governance. 25 guidelines covering ICT governance and strategy, ICT and security risk management, information security, ICT operations and change management, business continuity, and outsourcing of ICT services. WITHDRAWN from 17 January 2025, superseded by the Digital Operational Resilience Act (DORA, Regulation (EU) 2022/2554) for EU financial entities.

Verified

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (5)

EIOPA ICT - Business Continuity Management

6 controls
Controls in the EIOPA ICT - Business Continuity Management domain of EIOPA Guidelines on ICT Security and Governance (EIOPA-BoS-20/600)6 controls
CodeTitle
EIOPA-ICTSG-GL.19Business continuity management
EIOPA-ICTSG-GL.20Business impact analysis
EIOPA-ICTSG-GL.21Business continuity planning
EIOPA-ICTSG-GL.22Response and recovery plans
EIOPA-ICTSG-GL.23Testing of plans
EIOPA-ICTSG-GL.24Crisis communications

EIOPA ICT - Governance and Risk Management

5 controls
Controls in the EIOPA ICT - Governance and Risk Management domain of EIOPA Guidelines on ICT Security and Governance (EIOPA-BoS-20/600)5 controls
CodeTitle
EIOPA-ICTSG-GL.1Proportionality
EIOPA-ICTSG-GL.2ICT within the system of governance
EIOPA-ICTSG-GL.3ICT strategy
EIOPA-ICTSG-GL.4ICT and security risks within the risk management system
EIOPA-ICTSG-GL.5Audit

EIOPA ICT - ICT Operations and Change Management

5 controls
Controls in the EIOPA ICT - ICT Operations and Change Management domain of EIOPA Guidelines on ICT Security and Governance (EIOPA-BoS-20/600)5 controls
CodeTitle
EIOPA-ICTSG-GL.14ICT operations management
EIOPA-ICTSG-GL.15ICT incident and problem management
EIOPA-ICTSG-GL.16ICT project management
EIOPA-ICTSG-GL.17ICT systems acquisition and development
EIOPA-ICTSG-GL.18ICT change management

EIOPA ICT - Information Security

8 controls
Controls in the EIOPA ICT - Information Security domain of EIOPA Guidelines on ICT Security and Governance (EIOPA-BoS-20/600)8 controls
CodeTitle
EIOPA-ICTSG-GL.10ICT operations security
EIOPA-ICTSG-GL.11Security monitoring
EIOPA-ICTSG-GL.12Information security reviews, assessment and testing
EIOPA-ICTSG-GL.13Information security training and awareness
EIOPA-ICTSG-GL.6Information security policy and measures
EIOPA-ICTSG-GL.7Information security function
EIOPA-ICTSG-GL.8Logical security
EIOPA-ICTSG-GL.9Physical security

EIOPA ICT - Outsourcing of ICT Services

1 controls
Controls in the EIOPA ICT - Outsourcing of ICT Services domain of EIOPA Guidelines on ICT Security and Governance (EIOPA-BoS-20/600)1 controls
CodeTitle
EIOPA-ICTSG-GL.25Outsourcing of ICT services and ICT systems

Maps to 2 other frameworks

25 total controls
DORA
15 source controls mapped|12 target controls covered
60%
NIST Cybersecurity Framework 2.0
4 source controls mapped|4 target controls covered
16%

Frequently Asked Questions

What is EIOPA Guidelines on ICT Security and Governance (EIOPA-BoS-20/600)?

EIOPA Guidelines on ICT Security and Governance (EIOPA-BoS-20/600) is a compliance framework from European Union (EIOPA) with 5 domains and 25 controls. EIOPA Guidelines (EIOPA-BoS-20/600, issued 12 October 2020, applied from 1 July 2021) on how insurance and reinsurance undertakings should apply the Solvency II governance requirements (Directive 2009/138/EC and Delegated Regulation (EU) 2015/35) to information and communication technology (ICT) security and governance. 25 guidelines covering ICT governance and strategy, ICT and security risk management, information security, ICT operations and change management, business continuity, and outsourcing of ICT services. WITHDRAWN from 17 January 2025, superseded by the Digital Operational Resilience Act (DORA, Regulation (EU) 2022/2554) for EU financial entities. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

How many controls does EIOPA Guidelines on ICT Security and Governance (EIOPA-BoS-20/600) have?

EIOPA Guidelines on ICT Security and Governance (EIOPA-BoS-20/600) has 25 controls organised across 5 domains. The largest domains are EIOPA ICT - Information Security (8 controls), EIOPA ICT - Business Continuity Management (6 controls), EIOPA ICT - Governance and Risk Management (5 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

What frameworks does EIOPA Guidelines on ICT Security and Governance (EIOPA-BoS-20/600) map to?

EIOPA Guidelines on ICT Security and Governance (EIOPA-BoS-20/600) maps to 2 other compliance frameworks. The top mapping partners are DORA (60% coverage), NIST Cybersecurity Framework 2.0 (16% coverage). Use our comparison tool to explore control-level mappings between frameworks.

How do I get started with EIOPA Guidelines on ICT Security and Governance (EIOPA-BoS-20/600) compliance?

Start your EIOPA Guidelines on ICT Security and Governance (EIOPA-BoS-20/600) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about EIOPA Guidelines on ICT Security and Governance (EIOPA-BoS-20/600) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 25 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 700 frameworks.

Get Started Free →

Free forever — no credit card required