DORA (Regulation (EU) 2022/2554)
6 of the 26 clauses of DORA (Regulation (EU) 2022/2554) are cited by this register, on Backup restore test, Breach notification report pack, Customer statement and notification feed, Database snapshot, Full backup, Incident and service report, Incident response exercise or drill, Incremental or differential backup and more. Every one below is quoted from the copy we hold, with the hours it states where it states any.
Financial entities shall have mechanisms to promptly detect anomalous activities, ICT network performance issues and ICT-related incidents, with multiple layers of control, defined alert thresholds and detection processes that enable timely incident response.
What an assessor asks to see: Anomaly/incident detection mechanisms with defined alert thresholds; Monitoring coverage records. Where it usually falls short: No anomaly detection or alerting
Financial entities shall put in place an ICT business continuity policy and ICT response and recovery plans (including measures, procedures and arrangements) to ensure continuity of critical or important functions, quickly contain damage, resume activities and recover, subject to regular testing.
What an assessor asks to see: ICT business continuity policy + response/recovery plans; Records of plan testing. Where it usually falls short: No ICT continuity/response/recovery plans
Financial entities shall develop and document backup policies and procedures, and restoration and recovery procedures and methods, ensuring backups can be restored with minimal disruption, with backup systems physically and logically segregated from the source system.
What an assessor asks to see: Backup and restoration policies/procedures; Evidence of segregated backups and restoration tests. Where it usually falls short: No tested backups
Financial entities shall define, establish and implement an ICT-related incident management process to detect, manage and notify ICT-related incidents, including early warning indicators, procedures to identify/track/log/categorise incidents by priority and severity, roles and responsibilities, and communication plans.
What an assessor asks to see: Documented ICT incident management process with logging, categorisation and roles. Where it usually falls short: No structured incident management process
Financial entities shall report major ICT-related incidents to the relevant competent authority within the prescribed timelines using initial, intermediate and final notifications, and may notify significant cyber threats on a voluntary basis.
What an assessor asks to see: Major-incident reports (initial/intermediate/final) submitted to the competent authority within the deadlines. Where it usually falls short: Late or missing major-incident reporting
The testing programme shall include a range of assessments and tests (e.g. vulnerability assessments and scans, open-source analyses, network security assessments, gap analyses, physical security reviews, questionnaires, source-code reviews, scenario-based tests, compatibility/performance tests, end-to-end and penetration testing), with critical ICT systems tested at least yearly.
What an assessor asks to see: Test plans and results across the required assessment types; At least-yearly testing of critical ICT systems. Where it usually falls short: Critical systems not tested annually
Requirement text quoted from the standards themselves, published at compliance.theartofservice.com, the same publisher as this register, read against the held text of each standard: our statement of each clause, not the instrument verbatim. The whole standard on compliance.theartofservice.com.