DORA and ISO 27001: Key Comparisons
DORA and ISO 27001: Key Comparisons
ISO 27001:2022
ISO 27001 ISO/IEC 27001:2022 Information security, cybersecurity and privacy protection
— Information security management systems — Requirements
[Link]
NOTE: The ISO 27000 family standards is mentioned by the regulation authorities (EBA, EIOPA,
ESMA), see, for example, “Draft Regulatory Technical Standards to further harmonise ICT risk
management tools, methods, processes and policies as mandated under Articles 15 and 16(3) of
Regulation (EU) 2022/2554”:
“Financial entities may use international standards, such as ISO 27002
as further guidance”
ISO
N DORA DORA requirements ISMS Topic
27001:2022
Article 4. Proportionality principle
1. Art.4 1. Financial entities shall implement the rules in accordance Context, Risk 4.1, 4.2,
with the principle of proportionality, taking into account their Management 6.1.3, A.5.31
size and overall risk profile, and the nature, scale and
complexity of their services, activities and operations. …
CHAPTER II. ICT risk management (Articles 5-16)
Article 5. Governance and organization
2. Art.5.1 1. Financial entities shall have in place an internal ISMS 4.4, 5.1, 5.2
governance and control framework that ensures an
effective and prudent management of ICT risk in order to
achieve a high level of digital operational resilience.
3. Art.5.2 2. The management body of the financial entity shall define, Leadership and 5.1, A.5.4
approve, oversee and be responsible for the implementation Commitment
of all arrangements related to the ICT risk management
framework
4. Art.5.2 a) For the purposes of the first subparagraph, the management Leadership and 5.1
body shall: Commitment
(a) bear the ultimate responsibility for managing the
financial entity’s ICT risk;
5. Art.5.2 b) (b) put in place policies that aim to ensure the maintenance IS Policy and 5.2, 7.5, A.5.1
of high standards of availability, authenticity, integrity and topic-specific
confidentiality, of data; policies
6. Art.5.2 c) (c) set clear roles and responsibilities for all ICT-related Roles and 5.3, A.5.2,
functions and establish appropriate governance arrangements Responsibilities A.5.4
to ensure effective and timely communication, cooperation and
coordination among those functions;
7. Art.5.2 d) (d) bear the overall responsibility for setting and approving the Risk 6.1.2, A.5.29,
digital operational resilience strategy including the Management, A.5.30, A.8.14
determination of the appropriate risk tolerance level of ICT Business
risk of the financial entity continuity and
Resilience
8. Art.5.2 e) (e) approve, oversee and periodically review the Business A.5.29,
implementation of the financial entity’s ICT business Continuity and A.5.30,
continuity policy and ICT response and recovery plans Resilience A.8.13, A.8.14
which may be adopted as a dedicated specific policy forming
an integral part of the financial entity’s overall business
continuity policy and response and recovery plan;
9. Art.5.2 f) (f) approve and periodically review the financial entity’s ICT Internal Audit 9.2, A.5.36
internal audit plans, ICT audits and material modifications to
them;
10. Art.5.2 g) (g) allocate and periodically review the appropriate budget to Support 7.1, 7.2, 7.3
fulfil the financial entity’s digital operational resilience needs in (Resources,
respect of all types of resources, including relevant ICT security Competence,
awareness programmes and digital operational resilience Awareness)
training, and ICT skills for all staff;
11. Art.5.2 h) (h) approve and periodically review the financial entity’s policy TPRM A.5.19 -
on arrangements regarding the use of ICT services provided by A.5.23
ICT third-party service providers;
12. Art.5.2 I) (i) put in place, at corporate level, reporting channels Communication, 7.4, 8.2,
enabling it to be duly informed of the following: TPRM A.5.22
(i) arrangements concluded with ICT third-party service
providers on the use of ICT services,
(ii) any relevant planned material changes regarding the ICT
third-party service providers,
20. Art.6.6 6. The ICT risk management framework of financial entities, Internal Audit 9.2, A.5.36
other than microenterprises, shall be subject to internal audit
by auditors on a regular basis in line with the financial entities’
audit plan. Those auditors shall possess sufficient knowledge,
skills and expertise in ICT risk, as well as appropriate
independence. The frequency and focus of ICT audits shall be
commensurate to the ICT risk of the financial entity.
21. Art.6.7 7. Based on the conclusions from the internal audit review, Nonconformity 10.2
financial entities shall establish a formal follow-up process, Management
including rules for the timely verification and remediation of
critical ICT audit findings.
22. Art.6.8 8. The ICT risk management framework shall include a digital Business A.5.29,
operational resilience strategy setting out how the Continuity and A.5.30, A.8.14
framework shall be implemented. Resilience
23. Art.6.8 a) To that end, the digital operational resilience strategy shall Context, 4.1, 5.1
include methods to address ICT risk and attain specific ICT Leadership and
objectives, by: Commitment
(a) explaining how the ICT risk management framework
supports the financial entity’s business strategy and
objectives;
24. Art.6.8 b) (b) establishing the risk tolerance level for ICT risk, in Risk 6.1.2
accordance with the risk appetite of the financial entity, and Management
analysing the impact tolerance for ICT disruptions;
25. Art.6.8 c) (c) setting out clear information security objectives, IS Objectives, 6.2, 8.2, 9.1
including key performance indicators and key risk Performance
metrics; Evaluation, Risk
Management
26. Art.6.8 d) (d) explaining the ICT reference architecture and any Context, Change 4.1, 5.1, 6.3
changes needed to reach specific business objectives; Management
27. Art.6.8 e) (e) outlining the different mechanisms put in place to detect Incident 6.1.3, A.5.24-
ICT-related incidents, prevent their impact and provide Management, A.5.27
protection from it; SoA and RTP
28. Art.6.8 f) (f) evidencing the current digital operational resilience situation Incident A.5.5, A.5.24-
on the basis of the number of major ICT-related incidents Management, A.5.28,
reported and the effectiveness of preventive measures; Business A.5.29, A.5.30
Continuity and
Resilience
29. Art.6.8 g) (g) implementing digital operational resilience testing; Business A.5.30
Continuity and
Resilience
30. Art.6.8 h) (h) outlining a communication strategy in the event of ICT- Communication, 7.4, A.5.5,
related incidents the disclosure of which is required. Incident A.5.6, A.5.26
Management
31. Art.6.9 9. Financial entities may, in the context of the digital TPRM, Business A.5.19,
operational resilience strategy referred to in paragraph 8, Continuity and A.5.30, A.8.14
define a holistic ICT multi-vendor strategy, at group or Resilience
entity level, showing key dependencies on ICT third-party
service providers and explaining the rationale behind the
procurement mix of ICT third-party service providers.
32. Art.6.10 10. Financial entities may, in accordance with Union and Audit and A.5.35
national sectoral law, outsource the tasks of verifying Assessment
compliance with ICT risk management requirements to intra-
group or external undertakings. In case of such outsourcing,
the financial entity remains fully responsible for the verification
of compliance with the ICT risk management requirements.
40. Art.8.7 7. Financial entities, other than microenterprises, shall on a Risk 6.1.2, 8.2,
regular basis, and at least yearly, conduct a specific ICT Management A.8.9, A.8.29
risk assessment on all legacy ICT systems and, in any
case before and after connecting technologies, applications or
systems.
Article 9. Protection and prevention
41. Art.9.1 1. For the purposes of adequately protecting ICT systems Performance 6.1.3, 8.1,
and with a view to organising response measures, financial evaluation, SoA 8.3, 9.1,
entities shall continuously monitor and control the security and RTP, A.8.16…
and functioning of ICT systems and tools and shall minimize Operational
the impact of ICT risk on ICT systems through the deployment planning and
of appropriate ICT security tools, policies and procedures. control
42. Art.9.2 2. Financial entities shall design, procure and implement ICT SoA and RPT, 6.1.3, 8.3
security policies, procedures, protocols and tools that Business …
aim to ensure the resilience, continuity and availability of ICT continuity and
systems, in particular for those supporting critical or important Resilience
functions, and to maintain high standards of availability,
authenticity, integrity and confidentiality of data,
whether at rest, in use or in transit.
43. Art.9.3 …The ICT solutions and processes shall: SoA and RPT 6.1.3, 8.3,
(a) ensure the security of the means of transfer of data; A.5.14, A.8.1-
(b) minimise the risk of corruption or loss of data, A.8.5,
unauthorised access and technical flaws that may hinder A.8.12…
business activity;
(c) prevent the lack of availability, the impairment of the
authenticity and integrity, the breaches of
confidentiality and the loss of data;
(d) ensure that data is protected from risks arising from
data management, including poor administration,
processing-
related risks and human error.
44. Art.9.4 a) 4. As part of the ICT risk management framework, financial IS Policy 5.2, A.5.1
entities shall:
(a) develop and document an information security policy
defining rules to protect the availability, authenticity, integrity
and confidentiality of data, information assets and ICT assets,
including those of their customers, where applicable;
45. Art.9.4 b) (b) following a risk-based approach, establish a sound Incident 6.1.3, A.5.24,
network and infrastructure management structure using Management, A.5.26,
appropriate techniques, methods and protocols that may Network Security A.8.16,
include implementing automated mechanisms to isolate A.8.20,
affected information assets in the event of cyber-attacks; A.8.21, A.8.22
46. Art.9.4 c) (c) implement policies that limit the physical or logical Access Control, A.5.15,
access to information assets and ICT assets to what is Physical Security A.5.18, A.8.2,
required for legitimate and approved functions and activities A.8.3, A.8.4
only, and establish to that end a set of policies, procedures and A.7.2, A.7.3,
controls that address access rights and ensure a sound A.7.4
administration thereof;
47. Art.9.4 d) (d) implement policies and protocols for strong Access Control, A.5.12,
authentication mechanisms, based on relevant standards Cryptography, A.5.17, A.8.5,
and dedicated control systems, and protection measures of Information A.8.24,
cryptographic keys whereby data is encrypted based on classification
results of approved data classification and ICT risk
assessment processes;
48. Art.9.4 e) (e) implement documented policies, procedures and Change 6.3, 8.1, 8.2,
controls for ICT change management, including changes to Management, A.8.32
software, hardware, firmware components, systems or security Operational
parameters, that are based on a risk assessment approach and planning and
are an integral part of the financial entity’s overall change control
management process, in order to ensure that all changes to
ICT systems are recorded, tested, assessed, approved,
implemented and verified in a controlled manner;
49. Art.9.4 f) (f) have appropriate and comprehensive documented policies Patch A.8.8, A.8.9
for patches and updates. management
50. Art.9.4 Financial entities shall design the network connection Network security A.8.22
infrastructure in a way that allows it to be instantaneously
severed or segmented in order to minimise and prevent
contagion, especially for interconnected financial processes.
51. Art.9.4 The ICT change management process shall be approved by Change A.8.32
appropriate lines of management and shall have specific management
protocols in place.
Article 10. Detection
52. Art.10.1 1. Financial entities shall have in place mechanisms to Monitoring A.8.16
promptly detect anomalous activities including ICT
network performance issues and ICT-related incidents, and to
identify potential material single points of failure.
All detection mechanisms shall be regularly tested.
53. Art.10.2 2. The detection mechanisms referred to in paragraph 1 shall Monitoring, A.5.25,
enable multiple layers of control, define alert thresholds and Incident A.5.26, A.8.16
criteria to trigger and initiate ICT-related incident Management
response processes, including automatic alert mechanisms for
relevant staff in charge of ICT-related incident response.
54. Art.10.3 3. Financial entities shall devote sufficient resources and Support 7.1, A.5.24,
capabilities to monitor user activity, the occurrence of ICT (Resources), A.8.16
anomalies and ICT-related incidents, in particular cyber- Monitoring,
attacks. Incident
Management
55. Art.10.4 4. Data reporting service providers shall, in addition, have Threat A.5.6, A.5.7
in place systems that can effectively check trade reports for intelligence
completeness, identify omissions and obvious errors, and
request re-transmission of those reports.
Article 11. Response and recovery
56. Art.11.1 1. As part of the ICT risk management framework and based Business A.5.30
on the identification requirements, financial entities shall put in continuity and
place a comprehensive ICT business continuity policy, Resilience
which may be adopted as a dedicated specific policy, forming
an integral part of the overall business continuity policy of the
financial entity.
57. Art.11.2 2. Financial entities shall implement the ICT business Business A.5.29, A.5.30
continuity policy through dedicated, appropriate and continuity and
documented arrangements, plans, procedures and Resilience
mechanisms aiming to:
(a) ensure the continuity of the financial entity’s critical or
important functions;
(b) quickly, appropriately and effectively respond to, and
resolve, all ICT-related incidents in a way that limits damage
and prioritises the resumption of activities and recovery
actions;
(c) activate, without delay, dedicated plans that enable
containment measures, processes and technologies suited to
each type of ICT-related incident and prevent further damage,
as well as tailored response and recovery procedures;
65. Art.11.9 9. Central securities depositories shall provide the Communication, 7.4, A.5.5,
competent authorities with copies of the results of the Business A.5.30
ICT business continuity tests, or of similar exercises. continuity and
Resilience
66. Art.11.10 10. Financial entities, other than microenterprises, shall report Communication, 7.4, A.5.5
to the competent authorities, upon their request, an Business
estimation of aggregated annual costs and losses continuity and
caused by major ICT-related incidents. Resilience
Article 12. Backup policies and procedures, restoration and recovery procedures and methods
67. Art.12.1 1. For the purpose of ensuring the restoration of ICT systems Backup and A.8.13
and data with minimum downtime, limited disruption and loss, Recovery
as part of their ICT risk management framework, financial
entities shall develop and document:
(a) backup policies and procedures specifying the scope of
the data that is subject to the backup and the minimum
frequency of the backup, based on the criticality of information
or the confidentiality level of the data;
(b) restoration and recovery procedures and methods.
68. Art.12.2 2. Financial entities shall set up backup systems that can be Backup and A.8.13
activated in accordance with the backup policies and Recovery
procedures, as well as restoration and recovery procedures and
methods. The activation of backup systems shall not jeopardise
the security of the network and information systems or the
availability, authenticity, integrity or confidentiality of data.
Testing of the backup procedures and restoration and
recovery procedures and methods shall be undertaken
periodically.
69. Art.12.3 3. When restoring backup data using own systems, financial Backup and A.5.29,
entities shall use ICT systems that are physically and logically Recovery, A.5.30, A.8.13
segregated from the source ICT system. The ICT systems Business
shall be securely protected from any unauthorised access continuity and
or ICT corruption and allow for the timely restoration of Resilience
services making use of data and system backups as necessary.
For central counterparties, the recovery plans shall enable the
recovery of all transactions at the time of disruption to allow
the central counterparty to continue to operate with certainty
and to complete settlement on the scheduled date.
Data reporting service providers shall additionally maintain
adequate resources and have back-up and restoration facilities
in place in order to offer and maintain their services at all times.
70. Art.12.4 4. Financial entities, other than microenterprises, shall maintain Business A.8.14
redundant ICT capacities equipped with resources, continuity and
capabilities and functions that are adequate to ensure business Resilience
needs. Microenterprises shall assess the need to maintain such
redundant ICT capacities based on their risk profile.
71. Art.12.5 5. Central securities depositories shall maintain at least one Business A.8.14
secondary processing site endowed with adequate continuity and
resources, capabilities, functions and staffing arrangements to Resilience
ensure business needs.
The secondary processing site shall be:
(a) located at a geographical distance from the primary
processing site to ensure that it bears a distinct risk profile and
to prevent it from being affected by the event which has
affected the primary site;
(b) capable of ensuring the continuity of critical or important
functions identically to the primary site, or providing the level
of services necessary to ensure that the financial entity
performs its critical operations within the recovery objectives;
77. Art.13.4 4. Financial entities shall monitor the effectiveness of the Risk 8.2, 10.1
implementation of their digital operational resilience Management,
strategy set out in Article 6(8). They shall map the evolution Continual
of ICT risk over time, analyse the frequency, types, magnitude improvement
and evolution of ICT-related incidents, in particular cyber-
attacks and their patterns, with a view to understanding the
level of ICT risk exposure, in particular in relation to critical or
important functions, and enhance the cyber maturity and
preparedness of the financial entity.
78. Art.13.5 5. Senior ICT staff shall report at least yearly to the Management 9.3, 10.2
management body on the findings referred to in paragraph review,
3 and put forward recommendations. Nonconformity
Managment
79. Art.13.6 6. Financial entities shall develop ICT security awareness Awareness 7.3, A.6.3
programmes and digital operational resilience training
as compulsory modules in their staff training schemes. Those
programmes and training shall be applicable to all employees
and to senior management staff, and shall have a level of
complexity commensurate to the remit of their functions.
Where appropriate, financial entities shall also include ICT
third-party service providers in their relevant training schemes
80. Art.13.7 7. Financial entities, other than microenterprises, shall Context, Risk 4.1, 6.1.2, 8.2
monitor relevant technological developments on a Management
continuous basis, also with a view to understanding the
possible impact of the deployment of such new technologies on
ICT security requirements and digital operational resilience.
They shall keep up-to-date with the latest ICT risk management
processes, in order to effectively combat current or new forms
of cyber-attacks.
Article 14. Communication
81. Art.14.1 1. As part of the ICT risk management framework, financial Communication, 7.4, A.5.26
entities shall have in place crisis communication plans Incident
enabling a responsible disclosure of, at least, major ICT-related Management
incidents or vulnerabilities to clients and counterparts as well
as to the public, as appropriate.
82. Art.14.2 2. As part of the ICT risk management framework, financial Communication, 7.4, A.5.26
entities shall implement communication policies for Incident
internal staff and for external stakeholders. Management
Communication policies for staff shall take into account the
need to differentiate between staff involved in ICT risk
management, in particular the staff responsible for response
and recovery, and staff that needs to be informed.
83. Art.14.3 3. At least one person in the financial entity shall be tasked with Communication, 7.4, A.5.26
implementing the communication strategy for ICT- Incident
related incidents and fulfil the public and media function Management
for that purpose.
SEE Also Article 16. Simplified ICT risk management framework (the exceptions for small companies)
ISO
N DORA DORA requirements ISMS Topic
27001:2022
CHAPTER III. ICT-related incident management, classification and reporting (Articles 17-23)
Article 17. ICT-related incident management process
84. Art.17.1 1. Financial entities shall define, establish and implement an Incident A.5.24
ICT-related incident management process to detect, Management
manage and notify ICT-related incidents.
85. Art.17.2 2. Financial entities shall record all ICT-related incidents Incident A.5.24-A.5.28
and significant cyber threats. Financial entities shall Management
establish appropriate procedures and processes to ensure a
consistent and integrated monitoring, handling and follow-up
of ICT-related incidents, to ensure that root causes are
identified, documented and addressed in order to prevent the
occurrence of such incidents.
86. Art.17.3 3. The ICT-related incident management process shall: Incident 7.4, A.5.24-
(a) put in place early warning indicators; Management, A.5.26
(b) establish procedures to identify, track, log, categorise and Communication
classify ICT-related incidents according to their priority and
severity and according to the criticality of the services
impacted;
(c) assign roles and responsibilities that need to be activated
for different ICT-related incident types and scenarios;
(d) set out plans for communication to staff, external
stakeholders and media and for notification to clients, for
internal escalation procedures, including ICT-related customer
complaints, as well as for the provision of information to
financial entities that act as counterparts, as appropriate;
(e) ensure that at least major ICT-related incidents are
reported to relevant senior management and inform the
management body of at least major ICT-related incidents,
explaining the impact, response and additional controls to be
established as a result of such ICT-related incidents;
(f) establish ICT-related incident response procedures to
mitigate impacts and ensure that services become operational
and secure in a timely manner.
Article 18. Classification of ICT-related incidents and cyber threats
87. Art.18.1 1. Financial entities shall classify ICT-related incidents and Incident A.5.24, A.5.25
shall determine their impact based on the following criteria: Management
(a) the number and/or relevance of clients or financial
counterparts affected and, where applicable, the amount or
number of transactions affected by the ICT-related incident,
and whether the ICT-related incident has caused reputational
impact;
(b) the duration of the ICT-related incident, including the
service downtime;
(c) the geographical spread with regard to the areas affected
by the ICT-related incident, particularly if it affects more than
two Member States;
(d) the data losses that the ICT-related incident entails, in
relation to availability, authenticity, integrity or confidentiality
of data;
(e) the criticality of the services affected, including the financial
entity’s transactions and operations;
(f) the economic impact, in particular direct and indirect costs
and losses, of the ICT-related incident in both absolute and
relative terms.
88. Art.18.2 2. Financial entities shall classify cyber threats as significant Risk 6.1.2
based on the criticality of the services at risk, including the Management
financial entity’s transactions and operations, number and/or
relevance of clients or financial counterparts targeted and the
geographical spread of the areas at risk.
Article 19. Reporting of major ICT-related incidents and voluntary notification of significant cyber
threats
89. Art.19.1 1. Financial entities shall report major ICT-related Incident 7.4, A.5.5,
incidents to the relevant competent authority. … Management, A.5.24-A.5.28
Financial entities shall produce, after collecting and analysing Communication
all relevant information, the initial notification and reports using
the templates and submit them to the competent authority. In
the event that a technical impossibility prevents the submission
of the initial notification using the template, financial entities
shall notify the competent authority about it via alternative
means.
The initial notification and reports shall include all information
necessary for the competent authority to determine the
significance of the major ICT-related incident and assess
possible cross-border impacts.
Member States may additionally determine that some or all
financial entities shall also provide the initial notification and
each report using the templates to the competent authorities
or the computer security incident response teams (CSIRTs)
designated or established in accordance with Directive (EU)
2022/2555 [NIS 2 Directive]…
90. Art.19.2 2. Financial entities may, on a voluntary basis, notify Threat A.5.5, A.5.7
significant cyber threats to the relevant competent intelligence
authority when they deem the threat to be of relevance to the
financial system, service users or clients. The relevant
competent authority may provide such information to other
relevant authorities.
ISO
N DORA DORA requirements ISMS Topic
27001:2022
CHAPTER IV Digital operational resilience testing (Articles 24-27)
Article 24 General requirements for the performance of digital operational resilience testing
96. Art.24.1 1. For the purpose of assessing preparedness for handling ICT- Audit and 9.2, A.5.30,
related incidents, of identifying weaknesses, deficiencies and Assessment A.5.35,
gaps in digital operational resilience, and of promptly A.8.29,
implementing corrective measures, financial entities, other A.8.31, A.8.33
than microenterprises, shall establish, maintain and review a
sound and comprehensive digital operational resilience
testing programme as an integral part of the ICT risk-
management framework.
97. Art.24.2 2. The digital operational resilience testing programme Audit and 9.2, A.5.30,
shall include a range of assessments, tests, Assessment A.5.35,
methodologies, practices and tools to be applied in A.8.29,
accordance with Articles 25 and 26. A.8.31, A.8.33
98. Art.24.3 3. When conducting the digital operational resilience Audit and 4.1, 9.2,
testing programme, financial entities, other than Assessment, A.5.30, A.5.35
microenterprises, shall follow a risk-based approach taking into Context, Risk
account the criteria set out in Article 4(2) [the Proportionality Management
principle] duly considering the evolving landscape of ICT risk,
any specific risks to which the financial entity concerned is or
might be exposed, the criticality of information assets and of
services provided, as well as any other factor the financial entity
deems appropriate.
99. Art.24.4 4. Financial entities, other than microenterprises, shall ensure Audit and 9.2, A.5.30,
that tests are undertaken by independent parties, Assessment A.5.35
whether internal or external. Where tests are undertaken by an
internal tester, financial entities shall dedicate sufficient
resources and ensure that conflicts of interest are avoided
throughout the design and execution phases of the test.
100. Art.24.5 5. Financial entities, other than microenterprises, shall establish Nonconformity 10.1, 10.2
procedures and policies to prioritise, classify and Management,
remedy all issues revealed throughout the performance of Continual
the tests and shall establish internal validation methodologies improvement
to ascertain that all identified weaknesses, deficiencies or gaps
are fully addressed.
101. Art.24.6 6. Financial entities, other than microenterprises, shall ensure, Audit and 9.2, A.5.30,
at least yearly, that appropriate tests are conducted on Assessment A.5.35
all ICT systems and applications supporting critical or
important functions.
Article 25. Testing of ICT tools and systems
102. Art.25.1 1. The digital operational resilience testing programme Audit and 9.2, A.5.30,
shall provide for the execution of appropriate tests, such as Assessment A.5.35, A.8.8
vulnerability assessments and scans, open source analyses,
network security assessments, gap analyses, physical security
reviews, questionnaires and scanning software solutions,
source code reviews where feasible, scenario-based tests,
compatibility testing, performance testing, end-to-end testing
and penetration testing.
103. Art.25.2 2. Central securities depositories and central counterparties Audit and A.8.4, A.8.8,
shall perform vulnerability assessments before any Assessment A.8.9, A.8.19,
deployment or redeployment of new or existing applications A.8.25-A.8.30
and infrastructure components, and ICT services supporting
critical or important functions of the financial entity.
104. Art.25.3 3. Microenterprises shall perform the tests referred to in Audit and 6.1.2, 9.2,
paragraph 1 by combining a risk-based approach with a Assessment, Risk A.5.30, A.5.35
strategic planning of ICT testing, by duly considering the need Management
to maintain a balanced approach between the scale of
resources and the time to be allocated to the ICT testing
provided for in this Article, on the one hand, and the urgency,
type of risk, criticality of information assets and of services
provided, as well as any other relevant factor, including the
financial entity’s ability to take calculated risks, on the other
hand.
Article 26. Advanced testing of ICT tools, systems and processes based on TLPT [Threat-led penetration test]
105. Art.26.1 1. Financial entities [see the exceptions] shall carry out at least Audit and 7.4, A.5.35
every 3 years advanced testing by means of TLPT. Based Assessment,
on the risk profile of the financial entity and taking into account Communication
operational circumstances, the competent authority may,
where necessary, request the financial entity to reduce or
increase this frequency.
106. Art.26.2 2. Each threat-led penetration test shall cover several or Audit and 7.4, A.5.5,
all critical or important functions of a financial entity, and Assessment, A.5.9, A.5.20,
shall be performed on live production systems Inventory of A.5.35
supporting such functions. Assets,
Financial entities shall identify all relevant underlying ICT Communication,
systems, processes and technologies supporting critical or Contract
important functions and ICT services, including those
supporting the critical or important functions which have been
outsourced or contracted to ICT third-party service providers.
Financial entities shall assess which critical or important
functions need to be covered by the TLPT. The result of this
assessment shall determine the precise scope of TLPT and
shall be validated by the competent authorities.
107. Art.26.3 3. Where ICT third-party service providers are included in TPRM, Audit and A.5.19-A.5.23
the scope of TLPT, the financial entity shall take the necessary Assessment
measures and safeguards to ensure the participation of
such ICT third-party service providers in the TLPT and shall
retain at all times full responsibility for ensuring compliance
with this Regulation. [DORA]
108. Art.26.4 4. Without prejudice to paragraph 2, first and second TPRM, Audit and A.5.19, A.5.20
subparagraphs, where the participation of an ICT third-party Assessment,
service provider in the TLPT, referred to in paragraph 3, is Contract
reasonably expected to have an adverse impact on the quality
or security of services delivered by the ICT third-party service
provider to customers that are entities falling outside the scope
of this Regulation, or on the confidentiality of the data related
to such services, the financial entity and the ICT third-party
service provider may agree in writing that the ICT third-party
service provider directly enters into contractual
arrangements with an external tester, for the purpose of
conducting, under the direction of one designated financial
entity, a pooled TLPT involving several financial entities (pooled
testing) to which the ICT third-party service provider provides
ICT services.
That pooled testing shall cover the relevant range of ICT
services supporting critical or important functions contracted to
the respective ICT third-party service provider by the financial
entities. The pooled testing shall be considered TLPT carried
out by the financial entities participating in the pooled testing.
The number of financial entities participating in the pooled
testing shall be duly calibrated taking into account the
complexity and types of services involved.
109. Art.26.5 5. Financial entities shall, with the cooperation of ICT Risk 6.1.3, 8.3,
third-party service providers and other parties involved, Management, A.5.21-A.5.23
including the testers but excluding the competent authorities, TPRM
apply effective risk management controls to mitigate
the risks of any potential impact on data, damage to assets,
and disruption to critical or important functions, services or
operations at the financial entity itself, its counterparts or to
the financial sector.
110. Art.26.6 6. At the end of the testing, after reports and remediation plans Audit and 7.4, 10.1,
have been agreed, the financial entity and, where applicable, Assessment, 10.2, A.5.5
the external testers shall provide to the authority a Communication
summary of the relevant findings, the remediation
plans and the documentation demonstrating that the
TLPT has been conducted in accordance with the
requirements.
111. Art.26.7 7. Authorities shall provide financial entities with an Audit and 7.4, 10.1,
attestation confirming that the test was performed in Assessment, 10.2, A.5.5,
accordance with the requirements as evidenced in the Communication A.5.35
documentation in order to allow for mutual recognition of threat
led penetration tests between competent authorities. The
financial entity shall notify the relevant competent
authority of the attestation, the summary of the
relevant findings and the remediation plans.
115. Art.27.3 3. Financial entities shall ensure that contracts concluded Audit and A.5.20, A.5.35
with external testers require a sound management of Assessment,
the TLPT results and that any data processing thereof, TPRM, Contract
including any generation, store, aggregation, draft, report,
communication or destruction, do not create risks to the
financial entity.
ISO
N DORA DORA requirements ISMS Topic
27001:2022
CHAPTER V Managing of ICT third-party risk (Articles 28-44)
Article 28. General principles
116. Art.28.1 1. Financial entities shall manage ICT third-party risk as an TPRM, Risk 6.1, 8.1, 8.2,
integral component of ICT risk within their ICT risk Management, 8.3, A.5.19,
management framework, and in accordance with the following Contract A.5.20, A.5.21
principles:
(a) financial entities that have in place contractual
arrangements for the use of ICT services to run their
business operations shall, at all times, remain fully responsible
for compliance with, and the discharge of, all obligations under
this Regulation and applicable financial services law;
(b) financial entities’ management of ICT third-party risk shall
be implemented in light of the principle of proportionality,
taking into account:
(i) the nature, scale, complexity and importance of ICT-
related dependencies,
(ii) the risks arising from contractual arrangements on the
use of ICT services concluded with ICT third-party service
providers, taking into account the criticality or importance
of the respective service, process or function, and the
potential impact on the continuity and availability of
financial services and activities, at individual and at group
level.
117. Art.28.2 2. As part of their ICT risk management framework, financial TPRM, Risk 6.1.2, 8.1,
entities [see the exceptions] shall adopt, and regularly review, Management, 8.2, A.5.19,
a strategy on ICT third-party risk, taking into account the Contract 5.20, A.5.21
multi-vendor strategy, where applicable. The strategy on
ICT third-party risk shall include a policy on the use of ICT
services supporting critical or important functions provided by
ICT third-party service providers and shall apply on an
individual basis and, where relevant, on a sub-consolidated and
consolidated basis.
The management body shall, on the basis of an
assessment of the overall risk profile of the financial entity
and the scale and complexity of the business services, regularly
review the risks identified in respect to contractual
arrangements on the use of ICT services supporting critical or
important functions.
118. Art.28.3 3. As part of their ICT risk management framework, financial TPRM, Contract A.5.9, A.5.20
entities shall maintain and update at entity level, and at sub-
consolidated and consolidated levels, a register of
information in relation to all contractual arrangements
on the use of ICT services provided by ICT third-party service
providers.
119. Art.28.3 The contractual arrangements shall be appropriately TPRM, Contract A.5.20
documented, distinguishing between those that cover ICT
services supporting critical or important functions and those
that do not.
120. Art.28.3 Financial entities shall report at least yearly to the Communication, 7.4, A.5.5
competent authorities on the number of new TPRM
arrangements on the use of ICT services, the categories
of ICT third-party service providers, the type of contractual
arrangements and the ICT services and functions which are
being provided.
121. Art.28.3 Financial entities shall make available to the competent Communication 7.4, A.5.5
authority, upon its request, the full register of information
or, as requested, specified sections thereof, along with any
information deemed necessary to enable the effective
supervision of the financial entity.
122. Art.28.3 Financial entities shall inform the competent authority in a Communication, 7.4, A.5.5,
timely manner about any planned contractual TPRM, Contract A.5.20
arrangement on the use of ICT services supporting critical
or important functions as well as when a function has become
critical or important.
123. Art.28.4 4. Before entering into a contractual arrangement on the TPRM, Contract 6.1.2, 8.2,
use of ICT services, financial entities shall: A.5.20
(a) assess whether the contractual arrangement covers the use
of ICT services supporting a critical or important function;
(b) assess if supervisory conditions for contracting are met;
(c) identify and assess all relevant risks in relation to the
contractual arrangement, including the possibility that such
contractual arrangement may contribute to reinforcing ICT
concentration risk;
(d) undertake all due diligence on prospective ICT third-party
service providers and ensure throughout the selection and
assessment processes that the ICT third-party service provider
is suitable;
(e) identify and assess conflicts of interest that the contractual
arrangement may cause.
124. Art.28.5 5. Financial entities may only enter into contractual TPRM, Contract A.5.19, A.5.20
arrangements with ICT third-party service providers that
comply with appropriate information security standards.
When those contractual arrangements concern critical or
important functions, financial entities shall, prior to concluding
the arrangements, take due consideration of the use, by ICT
third-party service providers, of the most up-to-date and
highest quality information security standards.
125. Art.28.6 6. In exercising access, inspection and audit rights over the ICT Audit and A.5.19,
third-party service provider, financial entities shall, on the basis Assessment, A.5.20,
of a risk-based approach, pre-determine the frequency of TPRM, Contract A.5.21, A.5.22
audits and inspections as well as the areas to be audited
through adhering to commonly accepted audit standards in line
with any supervisory instruction on the use and incorporation
of such audit standards.
Where contractual arrangements concluded with ICT third-
party service providers on the use of ICT services entail high
technical complexity, the financial entity shall verify that
auditors, whether internal or external, or a pool of auditors,
possess appropriate skills and knowledge to effectively perform
the relevant audits and assessments.
126. Art.28.7 7. Financial entities shall ensure that contractual TPRM, Contract A.5.20
arrangements on the use of ICT services may be terminated
in any of the following circumstances:
(a) significant breach by the ICT third-party service provider of
applicable laws, regulations or contractual terms;
ISO
N DORA DORA requirements ISMS Topic
27001:2022
CHAPTER VI Information-sharing arrangements (Article 45)
Article 45. Information-sharing arrangements on cyber threat information and intelligence
138. Art.45.1 1. Financial entities may exchange amongst themselves Threat 7.4, A.5.6,
cyber threat information and intelligence, including intelligence, A.5.7
indicators of compromise, tactics, techniques, and procedures, Communication
cyber security alerts and configuration tools, to the extent that
such information and intelligence sharing:
(a) aims to enhance the digital operational resilience of financial
entities, in particular through raising awareness in relation to
cyber threats, limiting or impeding the cyber threats’ ability to
spread, supporting defence capabilities, threat detection
techniques, mitigation strategies or response and recovery
stages;
(b) takes places within trusted communities of financial entities;
(c) is implemented through information-sharing arrangements
that protect the potentially sensitive nature of the information
shared, and that are governed by rules of conduct in full respect
of business confidentiality, protection of personal data in
accordance with Regulation (EU) 2016/679 [GDPR] and
guidelines on competition policy.
139. Art.45.2 2. … The information-sharing arrangements shall define Threat 7.4, A.5.5,
the conditions for participation and, where appropriate, shall intelligence, A.5.6, A.5.7,
set out the details on the involvement of public authorities and Communication A.5.20
the capacity in which they may be associated to the
information-sharing arrangements, on the involvement of ICT
third-party service providers, and on operational elements,
including the use of dedicated IT platforms.
140. Art.45.3 3. Financial entities shall notify competent authorities of Threat 7.4, A.5.5
their participation in the information-sharing intelligence,
arrangements, upon validation of their membership, or, as Communication
applicable, of the cessation of their membership, once it takes
effect.









