Framework overlap

Does EIOPA Guidelines on ICT Security and Governance (EIOPA-BoS-20/600) cover EBA Guidelines on ICT and Security Risk Management (EBA/GL/2024/07)?

You hold EIOPA Guidelines on ICT Security and Governance (EIOPA-BoS-20/600) and have been told to do EBA Guidelines on ICT and Security Risk Management (EBA/GL/2024/07). Here is how much overlaps, control by control.

46% of EBA Guidelines on ICT and Security Risk Management (EBA/GL/2024/07) you already have

EIOPA Guidelines on ICT Security and Governance (EIOPA-BoS-20/600) already covers about 46% of EBA Guidelines on ICT and Security Risk Management (EBA/GL/2024/07), leaving 15 of 28 controls as genuinely new work.

Already covered 0 Likely covered 13 New work 15

No control in EIOPA Guidelines on ICT Security and Governance (EIOPA-BoS-20/600) maps directly to one in EBA Guidelines on ICT and Security Risk Management (EBA/GL/2024/07). Everything counted as covered is covered because both map to the same third standard, which is what a crosswalk is, but it is an inference rather than a lookup.

What is genuinely new work

Nothing in EIOPA Guidelines on ICT Security and Governance (EIOPA-BoS-20/600) reaches these. This is the list to scope.

EBA-GL-3.1
Proportionality
EBA-GL-3.2.2
Strategy
EBA-GL-3.3.3
Classification and risk assessment
EBA-GL-3.3.4
Risk mitigation
EBA-GL-3.3.5
Reporting
EBA-GL-3.4.1
Information security policy
EBA-GL-3.4.4
ICT operations security
EBA-GL-3.5
ICT operations management
EBA-GL-3.6.1
ICT project management
EBA-GL-3.6.2
ICT systems acquisition and development
EBA-GL-3.6.3
ICT change management
EBA-GL-3.7.2
Business continuity planning
EBA-GL-3.7.4
Testing of plans
EBA-GL-3.7.5
Crisis communications
EBA-GL-3.8
Payment service user relationship management
Show the 13 you already have
EBA-GL-3.2.1
Governance
EBA-GL-3.2.3
Use of third party providers
EBA-GL-3.3.1
Organisation and objectives
EBA-GL-3.3.2
Identification of functions, processes and assets
EBA-GL-3.3.6
Audit
EBA-GL-3.4.2
Logical security
EBA-GL-3.4.3
Physical security
EBA-GL-3.4.5
Security monitoring
EBA-GL-3.4.6
Information security reviews, assessment and testing
EBA-GL-3.4.7
Information security training and awareness
EBA-GL-3.5.1
ICT incident and problem management
EBA-GL-3.7.1
Business impact analysis
EBA-GL-3.7.3
Response and recovery plans

How this is calculated

Already covered means a mapping runs from a control in EIOPA Guidelines on ICT Security and Governance (EIOPA-BoS-20/600) to that control. Likely covered means no direct mapping exists but both frameworks map to the same control in a third standard. New work means neither. We keep those separate rather than adding them into one friendlier number, because blending them would present a two-hop inference as a verified fact.

Coverage is not symmetric. Run it the other way and you will get a different number; both are correct.

From 332,959 cross-framework control mappings across 723 frameworks, 531 of them verified against their source documents. It does not tell you that you are compliant: a mapped control means the two standards ask for the same thing, not that you have done it.

Try another pair ยท Today's edition