# Solvency II Directive (2009/138/EC) — ICT and Security Risk

Framework id: `solvency_ii`. Prudential Regulation. Publisher: European Parliament and Council / EIOPA. Version: 2009/138/EC (EIOPA GL 2020). Region: EU. Mapping licence: CC BY-SA 4.0.
Source text: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32009L0138

Each line is a clause, the NIST SP 800-53 controls OSA maps to it, and OSA's estimate of how far those controls cover it.
Clause titles and coverage figures are OSA's own summaries and estimates. No line-by-line check against the source text is recorded for this framework, so quote the source, not this card.

## Clauses (37, average coverage 65%)
- Art.41(1) System of governance — general governance requirements: AC-01, CA-01, PL-01, PL-09, PM-01, PM-02, PM-29 (60%)
- Art.41(3) System of governance — written policies: AC-01, AT-01, AU-01, CA-01, CM-01, CP-01, IA-01, IR-01, MA-01, MP-01, PE-01, PL-01, PS-01, RA-01, SA-01, SC-01, SI-01, SR-01 (80%)
- Art.42 Fit and proper requirements for persons running the undertaking: PS-01, PS-02, PS-03, PS-06, PS-09 (35%)
- Art.44(1) Risk management — effective risk management system: PL-09, PL-10, PL-11, PM-01, PM-28, PM-29, RA-01, RA-03, RA-07, RA-09 (72%)
- Art.44(2) Risk management — coverage of risks including operational risk: PM-08, PM-09, PM-11, PM-28, RA-01, RA-02, RA-03, RA-07 (65%)
- Art.45 Own Risk and Solvency Assessment (ORSA): CA-02, CA-05, CA-07, PM-09, PM-28, RA-03, RA-07, RA-09 (40%)
- Art.46 Internal control — compliance function: AU-01, AU-06, CA-02, CA-05, CA-07, PM-04, PM-06, PM-14 (55%)
- Art.47 Internal audit function: CA-02, CA-05, CA-07, PM-06, PM-14 (50%)
- Art.48 Actuarial function: no control mapped (0%)
- Art.49(1) Outsourcing — general requirements and oversight: AC-20, PS-07, SA-04, SA-09, SA-21, SR-01, SR-02, SR-03, SR-05, SR-06 (70%)
- Art.49(2) Outsourcing — critical or important operational activities or functions: RA-09, SA-04, SA-09, SR-01, SR-02, SR-03, SR-06, SR-10 (65%)
- Art.49(3) Outsourcing — data protection and confidentiality: AC-04, PT-01, PT-02, PT-03, PT-04, SA-09, SC-08, SC-28, SI-12 (75%)
- DR.258 Delegated Regulation Art. 258 — general governance requirements: AC-01, AT-01, CA-01, PL-01, PL-09, PM-01, PM-02, PM-29, PS-01, PS-09 (68%)
- DR.259 Delegated Regulation Art. 259 — remuneration policy: no control mapped (0%)
- DR.260 Delegated Regulation Art. 260 — risk management function: PM-01, PM-02, PM-09, PM-28, PM-29, RA-01, RA-03, RA-07 (60%)
- DR.266 Delegated Regulation Art. 266 — operational risk management including IT risk: AC-01, AT-01, AT-02, AT-03, CA-01, CA-02, CM-01, CM-02, CM-06, CP-01, CP-02, IA-01, IR-01, IR-04, PM-01, PM-08, PM-09, PM-11, RA-01, RA-03, RA-05, SA-01, SC-01, SI-01, SI-02 (82%)
- DR.266-BCP Delegated Regulation Art. 266 — business continuity and disaster recovery: CP-01, CP-02, CP-03, CP-04, CP-06, CP-07, CP-08, CP-09, CP-10, CP-12, CP-13 (85%)
- DR.266-DataSec Delegated Regulation Art. 266 — data security and information classification: AC-03, AC-04, AC-16, CM-08, CM-12, MP-01, MP-02, MP-03, MP-04, MP-06, RA-02, SC-08, SC-12, SC-13, SC-28, SI-12 (88%)
- DR.267 Delegated Regulation Art. 267 — investment risk management: PM-09, RA-03 (15%)
- DR.272 Delegated Regulation Art. 272 — outsourcing policy: AC-20, PS-07, SA-04, SA-09, SR-01, SR-02, SR-03, SR-04, SR-05, SR-06, SR-07, SR-08, SR-10, SR-11 (72%)
- DR.274 Delegated Regulation Art. 274 — contingency plans for outsourcing: CP-02, CP-04, SA-09, SR-01, SR-12 (55%)
- EIOPA-Cloud-GL3 EIOPA Cloud Outsourcing Guidelines — due diligence and risk assessment: AC-20, RA-03, RA-09, SA-04, SA-09, SR-02, SR-03, SR-04, SR-05, SR-06 (68%)
- EIOPA-Cloud-GL7 EIOPA Cloud Outsourcing Guidelines — access and audit rights: CA-02, SR-06, SR-10 (55%)
- EIOPA-Cloud-GL9 EIOPA Cloud Outsourcing Guidelines — data protection and data location: AC-04, CM-12, PT-01, PT-02, PT-04, SC-08, SC-28, SI-12 (62%)
- EIOPA-Cloud-GL11 EIOPA Cloud Outsourcing Guidelines — exit strategies and portability: CP-02, SA-09, SR-01, SR-12 (40%)
- EIOPA-ICT-4.1 EIOPA ICT Guidelines — ICT governance and strategy: PL-01, PL-02, PL-09, PM-01, PM-02, PM-03, PM-29, SA-02 (65%)
- EIOPA-ICT-4.2 EIOPA ICT Guidelines — ICT risk management framework: CA-02, CA-07, PL-09, PL-10, PL-11, PM-01, PM-09, PM-28, RA-01, RA-03, RA-07, RA-09 (75%)
- EIOPA-ICT-4.3 EIOPA ICT Guidelines — ICT asset management and classification: AC-16, CM-08, CM-12, CM-13, RA-02, RA-09, SA-05 (82%)
- EIOPA-ICT-4.4 EIOPA ICT Guidelines — logical security and access control: AC-01, AC-02, AC-03, AC-05, AC-06, AC-07, AC-11, AC-12, AC-17, IA-01, IA-02, IA-04, IA-05, IA-08, IA-12 (92%)
- EIOPA-ICT-4.5 EIOPA ICT Guidelines — physical security: PE-01, PE-02, PE-03, PE-04, PE-05, PE-06, PE-08, PE-09, PE-10, PE-11, PE-12, PE-13, PE-14, PE-15, PE-17, PE-18 (90%)
- EIOPA-ICT-4.6 EIOPA ICT Guidelines — network security: AC-04, AC-17, AC-18, AC-19, CA-03, SC-02, SC-03, SC-05, SC-07, SC-08, SC-20, SC-21, SC-22, SC-46, SC-47 (90%)
- EIOPA-ICT-4.7 EIOPA ICT Guidelines — cryptography and key management: IA-07, SC-08, SC-12, SC-13, SC-17, SC-28 (90%)
- EIOPA-ICT-4.8 EIOPA ICT Guidelines — ICT operations management: CM-02, CM-03, CM-04, CM-05, CM-06, CM-07, CM-14, MA-01, MA-02, MA-03, MA-06, SI-02, SI-07, SI-13 (87%)
- EIOPA-ICT-4.9 EIOPA ICT Guidelines — ICT incident and problem management: AU-06, IR-01, IR-02, IR-03, IR-04, IR-05, IR-06, IR-07, IR-08, IR-09, SI-04, SI-05 (80%)
- EIOPA-ICT-4.10 EIOPA ICT Guidelines — business continuity management: CP-01, CP-02, CP-03, CP-04, CP-06, CP-07, CP-08, CP-09, CP-10, CP-12, CP-13, SC-24 (82%)
- EIOPA-ICT-4.11 EIOPA ICT Guidelines — ICT project management and change: CM-03, CM-04, CM-05, CM-14, SA-03, SA-08, SA-10, SA-11, SA-15, SA-17 (78%)
- Pillar3-Reporting Pillar 3 — supervisory reporting and public disclosure (data integrity): AU-02, AU-03, AU-09, AU-10, AU-11, SI-07, SI-10, SI-12 (60%)

## More
- A pattern's controls with their clauses in this framework: /api/v1/patterns/{id}/crosswalk?framework=solvency_ii
- Control-to-clause mappings as JSON: /api/v1/frameworks/solvency_ii?fields=mappings&per_page=100
- Rationale and gaps for each clause, as JSON: https://raw.githubusercontent.com/opensecurityarchitecture/osa-data/main/data/framework-coverage/solvency-ii.json
- Page for people: /frameworks/solvency-ii/
