What DORA (Regulation (EU) 2022/2554) sets on each scheduled job
Article 25 sets at least yearly testing of critical ICT systems; the Article 19 reporting timelines are referred to, not stated, in the held text. Tick DORA on the register and every job in these classes carries its row below. A lit cell is a figure the clause states; a row that reads no clock stays that way, because the register never fills a blank the standard left open.
The clock each rule sets
| Consumer class | Clock | Clause |
|---|---|---|
| Security monitoring and log review | ||
| Security event log review export | no clock | DORA Art. 10 Detectionpromptly |
| Security alert and monitoring report | no clock | DORA Art. 10 Detectionpromptly |
| Backup, restore and replication | ||
| Backup restore test | 8,760h | DORA Art. 25 Testing of ICT tools and systemscritical ICT systems tested at least yearly |
| no clock | DORA Art. 11 Response and recoveryregular testing | |
| Full backup | no clock | DORA Art. 12 Backup policies and procedures, restoration and recovery |
| Incremental or differential backup | no clock | DORA Art. 12 Backup policies and procedures, restoration and recovery |
| Database snapshot | no clock | DORA Art. 12 Backup policies and procedures, restoration and recovery |
| Replication and failover sync | no clock | DORA Art. 12 Backup policies and procedures, restoration and recovery |
| Incident and breach reporting | ||
| Breach notification report pack | no clock | DORA Art. 19 Reporting of major ICT-related incidentsthe prescribed timelines |
| Incident and service report | no clock | DORA Art. 17 ICT-related incident management process |
| Incident response exercise or drill | 8,760h | DORA Art. 25 Testing of ICT tools and systemsat least yearly |
| Regulator incident notification | no clock | DORA Art. 19 Reporting of major ICT-related incidentsthe prescribed timelines |
| Customer-facing feeds and statements | ||
| Customer statement and notification feed | no clock | DORA Art. 11 Response and recovery |
| Payment file and settlement batch | no clock | DORA Art. 11 Response and recovery |
| Pricing and rates feed | no clock | DORA Art. 11 Response and recovery |
The clauses in full
Financial entities shall have mechanisms to promptly detect anomalous activities, ICT network performance issues and ICT-related incidents, with multiple layers of control, defined alert thresholds and detection processes that enable timely incident response.
What an assessor asks to see: Anomaly/incident detection mechanisms with defined alert thresholds; Monitoring coverage records. Where it usually falls short: No anomaly detection or alerting
The testing programme shall include a range of assessments and tests (e.g. vulnerability assessments and scans, open-source analyses, network security assessments, gap analyses, physical security reviews, questionnaires, source-code reviews, scenario-based tests, compatibility/performance tests, end-to-end and penetration testing), with critical ICT systems tested at least yearly.
What an assessor asks to see: Test plans and results across the required assessment types; At least-yearly testing of critical ICT systems. Where it usually falls short: Critical systems not tested annually
Financial entities shall put in place an ICT business continuity policy and ICT response and recovery plans (including measures, procedures and arrangements) to ensure continuity of critical or important functions, quickly contain damage, resume activities and recover, subject to regular testing.
What an assessor asks to see: ICT business continuity policy + response/recovery plans; Records of plan testing. Where it usually falls short: No ICT continuity/response/recovery plans
Financial entities shall develop and document backup policies and procedures, and restoration and recovery procedures and methods, ensuring backups can be restored with minimal disruption, with backup systems physically and logically segregated from the source system.
What an assessor asks to see: Backup and restoration policies/procedures; Evidence of segregated backups and restoration tests. Where it usually falls short: No tested backups
Financial entities shall report major ICT-related incidents to the relevant competent authority within the prescribed timelines using initial, intermediate and final notifications, and may notify significant cyber threats on a voluntary basis.
What an assessor asks to see: Major-incident reports (initial/intermediate/final) submitted to the competent authority within the deadlines. Where it usually falls short: Late or missing major-incident reporting
Financial entities shall define, establish and implement an ICT-related incident management process to detect, manage and notify ICT-related incidents, including early warning indicators, procedures to identify/track/log/categorise incidents by priority and severity, roles and responsibilities, and communication plans.
What an assessor asks to see: Documented ICT incident management process with logging, categorisation and roles. Where it usually falls short: No structured incident management process
Requirement text quoted from the standards themselves, published at compliance.theartofservice.com, the same publisher as this register, read against the held text of each standard: our statement of each clause, not the instrument verbatim. Every regime: the index.