DORA (Regulation (EU) 2022/2554)
Requires an ICT risk management framework of policies and procedures approved by the management body (Article 5 and 6), an information security policy and protection and prevention policies (Article 9), response and recovery and backup policies (Articles 11 and 12), an incident management process (Article 17) and a policy on the use of ICT third-party services (Article 28).
Tick DORA on the register and these documents are expected and these clauses attach. Open the standard.
The documents it expects
11 documents expectedEach becomes a line on the gap list when the regime is ticked and no document on the paste resolves to it (or to the parent it may fold into).
Governance and the management system
- Information security policy (policy): DORA Art. 5, DORA Art. 9. Owner: Top management (the board or the CEO), with the information security lead drafting. Template: Information security policy.
- Information security roles and responsibilities (record; accepted folded into the information security policy): DORA Art. 5. Owner: The information security lead (CISO or ISMS manager). No template yet.
- Risk management policy (policy): DORA Art. 6. Owner: The information security lead (CISO or ISMS manager). Template: Risk management policy.
Access and identity
- Access control policy (policy): DORA Art. 9. Owner: The information security lead (CISO or ISMS manager). Template: Access control policy.
Operations and technology
- Backup policy (policy): DORA Art. 12. Owner: The head of IT operations. Template: Backup and recovery policy.
- Logging and monitoring standard (standard): DORA Art. 10. Owner: The head of IT operations. Template: Security monitoring and logging policy.
- Security testing and penetration testing policy (policy): DORA Art. 24, DORA Art. 25. Owner: The information security lead (CISO or ISMS manager). Template: Penetration testing policy.
Suppliers and third parties
- Supplier and third-party security policy (policy): DORA Art. 28. Owner: Procurement or the vendor manager, with the information security lead. Template: Third party risk management policy.
Resilience and incidents
- Business continuity plan (plan): DORA Art. 11. Owner: The business continuity manager or COO. Template: Business continuity plan.
- Disaster recovery plan (plan; accepted folded into the business continuity plan): DORA Art. 11, DORA Art. 12. Owner: The head of IT operations. Template: Disaster recovery plan.
- Incident response plan (plan): DORA Art. 17. Owner: The information security lead (CISO or ISMS manager). Template: Incident response plan.
Every document it reaches
24 types carry at least one of its clausesThe clauses, quoted
12 of 26 in the frameworkRequirement text quoted from the standards themselves, read clause by clause against the copy we hold: our statement of each clause, not the instrument verbatim.
DORA Art. 10 DetectionFinancial entities shall have mechanisms to promptly detect anomalous activities, ICT network performance issues and ICT-related incidents, with multiple layers of control, defined alert thresholds and detection processes that enable timely incident response.
Common gap: No anomaly detection or alerting
Source: DORA (Regulation (EU) 2022/2554)
DORA Art. 11 Response and recoveryFinancial entities shall put in place an ICT business continuity policy and ICT response and recovery plans (including measures, procedures and arrangements) to ensure continuity of critical or important functions, quickly contain damage, resume activities and recover, subject to regular testing.
Common gap: No ICT continuity/response/recovery plans
Source: DORA (Regulation (EU) 2022/2554)
DORA Art. 12 Backup policies and procedures, restoration and recoveryFinancial entities shall develop and document backup policies and procedures, and restoration and recovery procedures and methods, ensuring backups can be restored with minimal disruption, with backup systems physically and logically segregated from the source system.
Common gap: No tested backups
Source: DORA (Regulation (EU) 2022/2554)
DORA Art. 14 CommunicationFinancial entities shall have crisis communication plans enabling responsible disclosure of major ICT-related incidents or vulnerabilities to clients, counterparts and the public as appropriate, and designate communication policies for internal staff and external stakeholders.
Common gap: No crisis communication plan
Source: DORA (Regulation (EU) 2022/2554)
DORA Art. 17 ICT-related incident management processFinancial entities shall define, establish and implement an ICT-related incident management process to detect, manage and notify ICT-related incidents, including early warning indicators, procedures to identify/track/log/categorise incidents by priority and severity, roles and responsibilities, and communication plans.
Common gap: No structured incident management process
Source: DORA (Regulation (EU) 2022/2554)
DORA Art. 24 General requirements for the performance of digital operational resilience testingFinancial entities shall establish, maintain and review a sound and comprehensive digital operational resilience testing programme as an integral part of the ICT risk management framework, following a risk-based approach.
Common gap: No resilience testing programme
Source: DORA (Regulation (EU) 2022/2554)
DORA Art. 25 Testing of ICT tools and systemsThe testing programme shall include a range of assessments and tests (e.g. vulnerability assessments and scans, open-source analyses, network security assessments, gap analyses, physical security reviews, questionnaires, source-code reviews, scenario-based tests, compatibility/performance tests, end-to-end and penetration testing), with critical ICT systems tested at least yearly.
Common gap: Critical systems not tested annually
Source: DORA (Regulation (EU) 2022/2554)
DORA Art. 28 ICT third-party risk: general principlesFinancial entities shall manage ICT third-party risk as an integral component of ICT risk, maintain a Register of Information on all contractual arrangements for the use of ICT services, report it to competent authorities, assess risk before entering arrangements (including concentration and subcontracting), and adopt an ICT third-party risk strategy.
Common gap: No Register of Information
Source: DORA (Regulation (EU) 2022/2554)
DORA Art. 30 Key contractual provisionsContractual arrangements for the use of ICT services shall include the mandatory key contractual provisions (e.g. clear service descriptions, locations of data processing, data protection, accessibility/availability/integrity/security, assistance on incidents, audit and access rights, termination rights and exit strategies), with enhanced provisions for services supporting critical or important functions.
Common gap: Contracts missing audit/access, termination or exit provisions
Source: DORA (Regulation (EU) 2022/2554)
DORA Art. 5 Governance and organisationThe management body of the financial entity shall define, approve, oversee and be responsible for the implementation of the ICT risk management framework, bear ultimate responsibility for managing ICT risk, set roles and responsibilities, approve the digital operational resilience strategy, and allocate appropriate budget and training.
Common gap: No management-body ownership of ICT risk
Source: DORA (Regulation (EU) 2022/2554)
DORA Art. 6 ICT risk management frameworkFinancial entities shall have a sound, comprehensive and well-documented ICT risk management framework as part of their overall risk management system, enabling them to address ICT risk quickly, efficiently and comprehensively, reviewed at least annually and audited periodically by ICT-audit staff.
Common gap: No documented ICT risk framework
Source: DORA (Regulation (EU) 2022/2554)
DORA Art. 9 Protection and preventionFinancial entities shall continuously monitor and control the security and functioning of ICT systems and tools, and minimise ICT risk through appropriate ICT security policies, procedures, protocols and tools ensuring resilience, continuity and availability, and preserving confidentiality, integrity and authenticity of data (incl access management, encryption, secure configuration, network security).
Common gap: Weak or absent protective controls
Source: DORA (Regulation (EU) 2022/2554)
See what it expects of your list
Paste the policy list, tick the regime, and every document it reaches carries its clauses, with the ones it expects and the list does not carry named. Eight documents free, no account.
Build a register