Classification of ICT-related incidents and cyber threats
Summary
Financial entities shall classify ICT-related incidents and significant cyber threats using criteria including clients affected, duration, geographical spread, data losses, criticality and economic impact.
Read the full official text: https://www.digital-operational-resilience-act.com/Article_18.html
← Article 17
ICT-related incident management process
Article 23 →
Operational or security payment-related incidents concerning credit institutions, payment institutions, account information service providers, and electronic money institutions
Track DORA article 18 as evidence
eurocompliant maps this obligation to a checklist task and the evidence that satisfies it, alongside every other framework you follow.
Start free trial