European Union
DORA
The Digital Operational Resilience Act sets uniform requirements for the security of network and information systems across EU financial entities and their critical ICT third-party providers, covering ICT risk management, incident reporting, resilience testing, and supplier oversight.
13 articles
Subject matter and scope
This Regulation lays down requirements for the digital operational resilience of financial entities and their critical ICT third-party service providers.
Definitions
Key definitions including ICT risk, ICT service, digital operational resilience, and incident.
ICT risk management framework
Financial entities shall have in place an effective and sound ICT risk management framework.
ICT systems, protocols and tools
Financial entities shall use and maintain updated ICT systems, protocols and tools that are reliable, have sufficient capacity, and are technologically resilient.
Detection
Financial entities shall have in place mechanisms to promptly detect anomalous activities, including ICT-related incidents.
Response and recovery
Financial entities shall put in place a comprehensive ICT business continuity policy and ICT response and recovery plans.
ICT-related incident management process
Financial entities shall put in place an ICT-related incident management process to detect, manage and notify ICT-related incidents.
General principles for ICT third-party risk management
Financial entities shall manage ICT third-party risk as an integral element of their ICT risk management framework.
Key ICT third-party service providers
Financial entities shall adopt a strategy on ICT third-party risk and exercise due diligence when assessing ICT third-party service providers.
Preliminary assessment of ICT concentration risk
Financial entities shall assess the potential impact of ICT concentration risk on the continuous delivery of critical or important functions.
Classification of major ICT-related incidents and significant cyber threats
Financial entities shall report major ICT-related incidents and significant cyber threats to the competent authorities.
General requirements for digital operational resilience testing
Financial entities shall establish, maintain and review a digital operational resilience testing programme.
Threat-led penetration testing
Financial entities identified by competent authorities shall carry out threat-led penetration testing on their critical or important functions at least every three years.
Turn DORA into tracked tasks
eurocompliant maps these obligations to checklists and evidence, so you can prove compliance instead of re-reading the text.
Start free trial