EIOPA Guidelines on ICT Security and Governance (EIOPA‑BoS‑23/146, 2023)
The European Insurance and Occupational Pensions Authority (EIOPA) Guidelines on Information and Communication Technology (ICT) Security and Governance (EIOPA‑BoS‑23/146, 2023) establish supervisory expectations for ICT governance, risk management, and security in insurance and reinsurance undertakings, covering governance structures, risk assessment, incident management, third‑party arrangements, and resilience measures.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (20)
Access
| Code | Title |
|---|---|
| EIOPA-ICT-7 | Logical Security |
Assurance
| Code | Title |
|---|---|
| EIOPA-ICT-20 | Audit and Assurance over ICT |
Business Continuity Management
| Code | Title |
|---|---|
| EIOPA-GL-20 | Business Impact Analysis |
| EIOPA-GL-21 | Business Continuity Planning |
| EIOPA-GL-22 | Response and Recovery Plans |
| EIOPA-GL-23 | Testing of Plans |
| EIOPA-GL-24 | Crisis Communications |
| EIOPA-GL-25 | Outsourcing of ICT Services |
Change
| Code | Title |
|---|---|
| EIOPA-ICT-15 | ICT Project and Change Management |
Detection
| Code | Title |
|---|---|
| EIOPA-ICT-10 | Security Monitoring |
General
| Code | Title |
|---|---|
| EIOPA-ICT-1 | Proportionality |
Governance
| Code | Title |
|---|---|
| EIOPA-ICT-2 | ICT Governance |
| EIOPA-ICT-3 | ICT Strategy |
| EIOPA-ICT-5 | Information Security Function |
ICT Operations and Change Management
| Code | Title |
|---|---|
| EIOPA-GL-14 | ICT Operations Management |
| EIOPA-GL-15 | ICT Project and Change Management |
| EIOPA-GL-16 | ICT Incident and Problem Management |
| EIOPA-GL-17 | Data and System Security |
| EIOPA-GL-18 | ICT System Acquisition and Development |
| EIOPA-GL-19 | ICT Third-Party Risk Management |
Incident
| Code | Title |
|---|---|
| EIOPA-ICT-14 | ICT Incident and Problem Management |
Information Security
VDA ISA information security requirements
| Code | Title |
|---|---|
| 37.1401(a) | General Security Requirements for SEFs |
| 38.1051(a) | General Security Requirements for DCMs |
| 39.18(a) | General Security Requirements for DCOs |
| 49.24(a) | General Security Requirements for SDRs |
| DSPF-INFO-1 | Information Classification |
| DSPF-INFO-2 | Information Handling |
| DSPF-INFO-3 | Information Access Controls |
| DSPF-INFO-4 | Security Markings |
| EIOPA-GL-10 | ICT Operations Security |
| EIOPA-GL-11 | Security Monitoring |
| EIOPA-GL-12 | Information Security Reviews, Assessment and Testing |
| EIOPA-GL-13 | Information Security Training and Awareness |
| EIOPA-GL-6 | Information Security Policy |
| EIOPA-GL-7 | Information Security Function |
| EIOPA-GL-8 | Logical Security |
| EIOPA-GL-9 | Physical Security |
| GLI33-4.1 | Information Security System Assessment |
| GLI33-4.2 | Penetration Testing |
| GLI33-4.3 | Data Protection and Encryption |
| GLI33-4.4 | Audit Trail and Logging |
| PSPF-INFO-1 | Sensitive and Classified Information |
| PSPF-INFO-2 | Security Classification System |
| PSPF-INFO-3 | Information Holdings |
| PSPF-INFO-4 | Information Disposal |
| PSPF-INFO-5 | Information Sharing |
| PSPF-INFO-6 | Security Caveated Information |
| PSPF-INFO-7 | Accountable Material |
| TISAX-IS-01 | Information Security Policy and Organisation |
| TISAX-IS-02 | Information Security Risk Management |
| TISAX-IS-03 | Third-Party Risk Management |
| TSSR-INFO-1 | Network Data Protection |
| TSSR-INFO-2 | Stored Communications Security |
| TSSR-INFO-3 | Lawful Interception Capability |
Operations
| Code | Title |
|---|---|
| EIOPA-ICT-13 | ICT Operations Management |
| EIOPA-ICT-9 | ICT Operations Security |
People
| Code | Title |
|---|---|
| EIOPA-ICT-12 | Information Security Training and Awareness |
Physical
| Code | Title |
|---|---|
| EIOPA-ICT-8 | Physical Security |
Policy
| Code | Title |
|---|---|
| EIOPA-ICT-6 | Information Security Policy |
Proportionality and Governance
| Code | Title |
|---|---|
| EIOPA-GL-1 | Proportionality |
| EIOPA-GL-2 | ICT Within the System of Governance |
| EIOPA-GL-3 | ICT Strategy |
| EIOPA-GL-4 | ICT and Security Risks Within the Risk Management System |
| EIOPA-GL-5 | Audit |
Resilience
| Code | Title |
|---|---|
| EIOPA-ICT-17 | Business Continuity and ICT Continuity |
Risk Management
| Code | Title |
|---|---|
| EIOPA-ICT-4 | ICT and Security Risk Management Framework |
SDLC
| Code | Title |
|---|---|
| EIOPA-ICT-16 | ICT Systems Acquisition and Development |
Testing
| Code | Title |
|---|---|
| EIOPA-ICT-11 | Information Security Reviews and Testing |
Third Party
| Code | Title |
|---|---|
| EIOPA-ICT-18 | Outsourcing of ICT Services |
| EIOPA-ICT-19 | Cloud Outsourcing |
Your Compliance Coverage
If you comply with EIOPA Guidelines on ICT Security and Governance (EIOPA‑BoS‑23/146, 2023), you already cover:
Defence Security Principles Framework (DSPF)
31%
22 controls mapped
Compare →Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1
30%
21 controls mapped
Compare →CFTC System Safeguards (17 CFR 37, 38, 39, 49)
30%
21 controls mapped
Compare →+ 658 more: Protective Security Policy Framework (PSPF) Release 2024 (30%), South Korea Cloud Security Assurance Program (CSAP) (30%)
See all 661 mapped frameworks ↓Maps to 661 other frameworks
Frequently Asked Questions
What is EIOPA Guidelines on ICT Security and Governance (EIOPA‑BoS‑23/146, 2023)?
EIOPA Guidelines on ICT Security and Governance (EIOPA‑BoS‑23/146, 2023) is a compliance framework from European Union (EIOPA) with 20 domains and 70 controls. The European Insurance and Occupational Pensions Authority (EIOPA) Guidelines on Information and Communication Technology (ICT) Security and Governance (EIOPA‑BoS‑23/146, 2023) establish supervisory expectations for ICT governance, risk management, and security in insurance and reinsurance undertakings, covering governance structures, risk assessment, incident management, third‑party arrangements, and resilience measures. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does EIOPA Guidelines on ICT Security and Governance (EIOPA‑BoS‑23/146, 2023) have?
EIOPA Guidelines on ICT Security and Governance (EIOPA‑BoS‑23/146, 2023) has 70 controls organised across 20 domains. The largest domains are Information Security (33 controls), Business Continuity Management (6 controls), ICT Operations and Change Management (6 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does EIOPA Guidelines on ICT Security and Governance (EIOPA‑BoS‑23/146, 2023) map to?
EIOPA Guidelines on ICT Security and Governance (EIOPA‑BoS‑23/146, 2023) maps to 661 other compliance frameworks. The top mapping partners are Defence Security Principles Framework (DSPF) (31% coverage), Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1 (30% coverage), CFTC System Safeguards (17 CFR 37, 38, 39, 49) (30% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with EIOPA Guidelines on ICT Security and Governance (EIOPA‑BoS‑23/146, 2023) compliance?
Start your EIOPA Guidelines on ICT Security and Governance (EIOPA‑BoS‑23/146, 2023) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about EIOPA Guidelines on ICT Security and Governance (EIOPA‑BoS‑23/146, 2023) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 70 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 768 frameworks.
Get Started Free →Free forever — no credit card required