Solvency II Directive (2009/138/EC) — ICT and Security Risk
EU prudential regulation for insurance and reinsurance undertakings. Pillar 2 governance and risk management requirements include ICT risk, operational resilience, outsourcing controls, and key function holder accountability. Supplemented by EIOPA Guidelines on ICT Security and Governance (EIOPA-BoS-20/600) covering information security policy, logical security, cryptography, operations security, security monitoring, business continuity, and third-party ICT risk management.
Clauses: 37
Avg Coverage: 64.5%
Publisher: European Parliament and Council / EIOPA Version: 2009/138/EC (EIOPA GL 2020) | Clause | Title | SP 800-53 Controls |
|---|---|---|
| Art.41(1) | System of governance — general governance requirements | |
| Art.41(3) | System of governance — written policies | |
| Art.42 | Fit and proper requirements for persons running the undertaking | |
| Art.44(1) | Risk management — effective risk management system | |
| Art.44(2) | Risk management — coverage of risks including operational risk | |
| Art.45 | Own Risk and Solvency Assessment (ORSA) | |
| Art.46 | Internal control — compliance function | |
| Art.47 | Internal audit function | |
| Art.48 | Actuarial function | |
| Art.49(1) | Outsourcing — general requirements and oversight | |
| Art.49(2) | Outsourcing — critical or important operational activities or functions | |
| Art.49(3) | Outsourcing — data protection and confidentiality | |
| DR.258 | Delegated Regulation Art. 258 — general governance requirements | |
| DR.259 | Delegated Regulation Art. 259 — remuneration policy | |
| DR.260 | Delegated Regulation Art. 260 — risk management function | |
| DR.266 | Delegated Regulation Art. 266 — operational risk management including IT risk | |
| DR.266-BCP | Delegated Regulation Art. 266 — business continuity and disaster recovery | |
| DR.266-DataSec | Delegated Regulation Art. 266 — data security and information classification | |
| DR.267 | Delegated Regulation Art. 267 — investment risk management | |
| DR.272 | Delegated Regulation Art. 272 — outsourcing policy | |
| DR.274 | Delegated Regulation Art. 274 — contingency plans for outsourcing | |
| EIOPA-Cloud-GL3 | EIOPA Cloud Outsourcing Guidelines — due diligence and risk assessment | |
| EIOPA-Cloud-GL7 | EIOPA Cloud Outsourcing Guidelines — access and audit rights | |
| EIOPA-Cloud-GL9 | EIOPA Cloud Outsourcing Guidelines — data protection and data location | |
| EIOPA-Cloud-GL11 | EIOPA Cloud Outsourcing Guidelines — exit strategies and portability | |
| EIOPA-ICT-4.1 | EIOPA ICT Guidelines — ICT governance and strategy | |
| EIOPA-ICT-4.2 | EIOPA ICT Guidelines — ICT risk management framework | |
| EIOPA-ICT-4.3 | EIOPA ICT Guidelines — ICT asset management and classification | |
| EIOPA-ICT-4.4 | EIOPA ICT Guidelines — logical security and access control | |
| EIOPA-ICT-4.5 | EIOPA ICT Guidelines — physical security | |
| EIOPA-ICT-4.6 | EIOPA ICT Guidelines — network security | |
| EIOPA-ICT-4.7 | EIOPA ICT Guidelines — cryptography and key management | |
| EIOPA-ICT-4.8 | EIOPA ICT Guidelines — ICT operations management | |
| EIOPA-ICT-4.9 | EIOPA ICT Guidelines — ICT incident and problem management | |
| EIOPA-ICT-4.10 | EIOPA ICT Guidelines — business continuity management | |
| EIOPA-ICT-4.11 | EIOPA ICT Guidelines — ICT project management and change | |
| Pillar3-Reporting | Pillar 3 — supervisory reporting and public disclosure (data integrity) |