100% found this document useful (1 vote)
187 views26 pages

DORA and ISO 27001: Key Comparisons

The document discusses the Digital Operational Resilience Act (EU DORA) and its alignment with ISO 27001:2022, focusing on the requirements for financial entities to establish a robust ICT risk management framework. It outlines key topics and controls related to information security management systems (ISMS) that are essential for achieving digital operational resilience. The document emphasizes the importance of governance, risk management, and continuous improvement in protecting information assets and ensuring compliance with regulatory standards.

Uploaded by

k3.kurkowski
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
100% found this document useful (1 vote)
187 views26 pages

DORA and ISO 27001: Key Comparisons

The document discusses the Digital Operational Resilience Act (EU DORA) and its alignment with ISO 27001:2022, focusing on the requirements for financial entities to establish a robust ICT risk management framework. It outlines key topics and controls related to information security management systems (ISMS) that are essential for achieving digital operational resilience. The document emphasizes the importance of governance, risk management, and continuous improvement in protecting information assets and ensuring compliance with regulatory standards.

Uploaded by

k3.kurkowski
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
  • Introduction
  • DORA Requirements
  • Information Sharing Arrangements

EU DORA and

ISO 27001:2022

Andrey Prozorov, CISM, CIPP/E, CDPSE, LA 27001


TLP:GREEN [Link]/AndreyProzorov || [Link]/in/AndreyProzorov
TLP:GREEN EU DORA and ISO 27001:2022
1.0, 10.04.2024

EU DORA Digital Operational Resilience Act (DORA)


Regulation (EU) 2022/2554 of the European Parliament and of the Council of 14
December 2022 on digital operational resilience for the financial sector and
amending Regulations (EC) No 1060/2009, (EU) No 648/2012, (EU) No
600/2014, (EU) No 909/2014 and (EU) 2016/1011
[Link]

ISO 27001 ISO/IEC 27001:2022 Information security, cybersecurity and privacy protection
— Information security management systems — Requirements
[Link]

Core ISMS Topics and IS controls mentioned in the EU DORA:


• Audit and Assessment • Access Control
• Communication • Awareness
• Competence and Awareness • Backup and Recovery
• Context • Business Continuity and Resilience
• Continual Improvement • Change Management
• Document Management • Contract (TPRM)
• Internal Audit • Cryptography
• ISMS • Incident Management
• IS Objectives • Information Classification
• IS Policy and topic-specific policies • Inventory of Assets
• Leadership and Commitment • Monitoring
• Management Review • Network Security
• Nonconformity Management • Patch Management
• Operational Planning and Control • Physical Security
• Performance Evaluation • Privacy
• Risk Management • Third-party risk management (TPRM)
• Roles and Responsibilities • Threat Intelligence
• SoA and RTP
• Support (Resources, Competence,
Awareness)

NOTE: The ISO 27000 family standards is mentioned by the regulation authorities (EBA, EIOPA,
ESMA), see, for example, “Draft Regulatory Technical Standards to further harmonise ICT risk
management tools, methods, processes and policies as mandated under Articles 15 and 16(3) of
Regulation (EU) 2022/2554”:
“Financial entities may use international standards, such as ISO 27002
as further guidance”

Andrey Prozorov, CISM, CIPP/E, CDPSE, LA 27001


TLP:GREEN [Link]/AndreyProzorov || [Link]/in/AndreyProzorov
TLP:GREEN EU DORA and ISO 27001:2022
1.0, 10.04.2024

EU DORA ISO 27001


• Internal governance and control Information security management system
framework (ISMS)
• ICT risk management framework The organization shall establish, implement,
maintain and continually improve an information
security management system, including the
processes needed and their interactions, in
accordance with the requirements of this document.
Article 5: ISO 27000
Financial entities shall have in place an internal Management system: set of interrelated or
governance and control framework that interacting elements of an organization to establish
ensures an effective and prudent management policies and objectives and processes to achieve
of ICT risk in order to achieve a high level of those objectives
digital operational resilience. Note: The system elements include the
The management body of the financial entity organization’s structure, roles and responsibilities,
shall define, approve, oversee and be planning and operation.
responsible for the implementation of all
arrangements related to the ICT risk
An ISMS consists of the policies, procedures,
management framework.
guidelines, and associated resources and
Article 6: activities, collectively managed by an organization,
[Link] entities shall have a sound, in the pursuit of protecting its information assets.
comprehensive and well-documented ICT risk
management framework as part of their
An ISMS is a systematic approach for establishing,
overall risk management system, which enables
implementing, operating, monitoring, reviewing,
them to address ICT risk quickly, efficiently and
maintaining and improving an organization’s
comprehensively and to ensure a high level of
information security to achieve business objectives.
digital operational resilience.
It is based on a risk assessment and the
2. The ICT risk management framework organization’s risk acceptance levels designed to
shall include at least strategies, policies, effectively treat and manage risks.
procedures, ICT protocols and tools that are
necessary to duly and adequately protect all
information assets and ICT assets, including Information security ensures the confidentiality,
computer software, hardware, servers, as well availability and integrity of information. Information
as to protect all relevant physical components security involves the application and management of
and infrastructures, such as premises, data appropriate controls that involves consideration of a
centres and sensitive designated areas, to wide range of threats, with the aim of ensuring
ensure that all information assets and ICT assets sustained business success and continuity, and
are adequately protected from risks including minimizing consequences of information security
damage and unauthorised access or usage. incidents.
3. In accordance with their ICT risk Information security is achieved through the
management framework, financial entities implementation of an applicable set of controls,
shall minimise the impact of ICT risk by selected through the chosen risk management
deploying appropriate strategies, policies, process and managed using an ISMS, including
procedures, ICT protocols and tools. They policies, processes, procedures, organizational
shall provide complete and updated information structures, software and hardware to protect the
on ICT risk and on their ICT risk management identified information assets. These controls need to
framework to the competent authorities upon be specified, implemented, monitored, reviewed and
their request. improved where necessary, to ensure that the
specific information security and business objectives
of the organization are met. Relevant information
security controls are expected to be seamlessly
integrated with an organization’s business processes.

Andrey Prozorov, CISM, CIPP/E, CDPSE, LA 27001


TLP:GREEN [Link]/AndreyProzorov || [Link]/in/AndreyProzorov
TLP:GREEN EU DORA and ISO 27001:2022
1.0, 10.04.2024

ISO
N DORA DORA requirements ISMS Topic
27001:2022
Article 4. Proportionality principle
1. Art.4 1. Financial entities shall implement the rules in accordance Context, Risk 4.1, 4.2,
with the principle of proportionality, taking into account their Management 6.1.3, A.5.31
size and overall risk profile, and the nature, scale and
complexity of their services, activities and operations. …
CHAPTER II. ICT risk management (Articles 5-16)
Article 5. Governance and organization
2. Art.5.1 1. Financial entities shall have in place an internal ISMS 4.4, 5.1, 5.2
governance and control framework that ensures an
effective and prudent management of ICT risk in order to
achieve a high level of digital operational resilience.
3. Art.5.2 2. The management body of the financial entity shall define, Leadership and 5.1, A.5.4
approve, oversee and be responsible for the implementation Commitment
of all arrangements related to the ICT risk management
framework
4. Art.5.2 a) For the purposes of the first subparagraph, the management Leadership and 5.1
body shall: Commitment
(a) bear the ultimate responsibility for managing the
financial entity’s ICT risk;
5. Art.5.2 b) (b) put in place policies that aim to ensure the maintenance IS Policy and 5.2, 7.5, A.5.1
of high standards of availability, authenticity, integrity and topic-specific
confidentiality, of data; policies
6. Art.5.2 c) (c) set clear roles and responsibilities for all ICT-related Roles and 5.3, A.5.2,
functions and establish appropriate governance arrangements Responsibilities A.5.4
to ensure effective and timely communication, cooperation and
coordination among those functions;
7. Art.5.2 d) (d) bear the overall responsibility for setting and approving the Risk 6.1.2, A.5.29,
digital operational resilience strategy including the Management, A.5.30, A.8.14
determination of the appropriate risk tolerance level of ICT Business
risk of the financial entity continuity and
Resilience
8. Art.5.2 e) (e) approve, oversee and periodically review the Business A.5.29,
implementation of the financial entity’s ICT business Continuity and A.5.30,
continuity policy and ICT response and recovery plans Resilience A.8.13, A.8.14
which may be adopted as a dedicated specific policy forming
an integral part of the financial entity’s overall business
continuity policy and response and recovery plan;
9. Art.5.2 f) (f) approve and periodically review the financial entity’s ICT Internal Audit 9.2, A.5.36
internal audit plans, ICT audits and material modifications to
them;
10. Art.5.2 g) (g) allocate and periodically review the appropriate budget to Support 7.1, 7.2, 7.3
fulfil the financial entity’s digital operational resilience needs in (Resources,
respect of all types of resources, including relevant ICT security Competence,
awareness programmes and digital operational resilience Awareness)
training, and ICT skills for all staff;
11. Art.5.2 h) (h) approve and periodically review the financial entity’s policy TPRM A.5.19 -
on arrangements regarding the use of ICT services provided by A.5.23
ICT third-party service providers;
12. Art.5.2 I) (i) put in place, at corporate level, reporting channels Communication, 7.4, 8.2,
enabling it to be duly informed of the following: TPRM A.5.22
(i) arrangements concluded with ICT third-party service
providers on the use of ICT services,
(ii) any relevant planned material changes regarding the ICT
third-party service providers,

Andrey Prozorov, CISM, CIPP/E, CDPSE, LA 27001


TLP:GREEN [Link]/AndreyProzorov || [Link]/in/AndreyProzorov
TLP:GREEN EU DORA and ISO 27001:2022
1.0, 10.04.2024
(iii) the potential impact of such changes on the critical or
important functions subject to those arrangements, including a
risk analysis summary to assess the impact of those changes,
and at least major ICT-related incidents and their impact, as
well as response, recovery and corrective measures.
13. Art.5.3 3. Financial entities, other than microenterprises, shall establish TPRM A.5.22
a role in order to monitor the arrangements concluded with
ICT third-party service providers on the use of ICT
services, or shall designate a member of senior management
as responsible for overseeing the related risk exposure and
relevant documentation.
14. Art.5.4 4. Members of the management body of the financial entity Competence and 7.2, 7.3
shall actively keep up to date with sufficient knowledge and Awareness
skills to understand and assess ICT risk and its impact on the
operations of the financial entity, including by following specific
training on a regular basis, commensurate to the ICT risk being
managed.
Article 6. ICT risk management framework
15. Art.6.1 1. Financial entities shall have a sound, comprehensive and ISMS, Risk 6.1.3, 7.5,
well-documented ICT risk management framework as part Management, A.5.1
of their overall risk management system, which enables them Document
to address ICT risk quickly, efficiently and comprehensively and Management
to ensure a high level of digital operational resilience.
16. Art.6.2 2. The ICT risk management framework shall include at least ISMS, SoA and 4.4, 6.1.3,
strategies, policies, procedures, ICT protocols and tools RTP A.5.1, A.5.37
that are necessary to duly and adequately protect all
information assets and ICT assets, including computer
software, hardware, servers, as well as to protect all relevant
physical components and infrastructures, such as premises,
data centres and sensitive designated areas, to ensure that all
information assets and ICT assets are adequately protected
from risks including damage and unauthorised access or
usage.
17. Art.6.3 3. In accordance with their ICT risk management framework, ISMS, Risk 6.1.3, 7.4,
financial entities shall minimise the impact of ICT risk by Management, 8.1, A.5.5
deploying appropriate strategies, policies, procedures, ICT Operational
protocols and tools. They shall provide complete and Planning and
updated information on ICT risk and on their ICT risk Control,
management framework to the competent authorities upon Communication
their request.
18. Art.6.4 4. Financial entities, other than microenterprises, shall assign Leadership and 5.1, 5.3, 9.1,
the responsibility for managing and overseeing ICT risk to a Commitment, 9.2, 9.3,
control function and ensure an appropriate level of Management A.5.2, A.5.3,
independence of such control function in order to avoid Review A.5.4
conflicts of interest. Financial entities shall ensure appropriate
segregation and independence of ICT risk management
functions, control functions, and internal audit
functions, according to the three lines of defence model, or
an internal risk management and control model.
19. Art.6.5 5. The ICT risk management framework shall be ISMS, Document 7.4, 7.5, 10.1,
documented and reviewed at least once a year, or Management, A.5.1, A.5.5
periodically in the case of microenterprises, as well as upon the Continual
occurrence of major ICT-related incidents, and following Improvement,
supervisory instructions or conclusions derived from Communication
relevant digital operational resilience testing or audit processes.
It shall be continuously improved on the basis of lessons
derived from implementation and monitoring. A report on the
review of the ICT risk management framework shall be
submitted to the competent authority upon its request.

Andrey Prozorov, CISM, CIPP/E, CDPSE, LA 27001


TLP:GREEN [Link]/AndreyProzorov || [Link]/in/AndreyProzorov
TLP:GREEN EU DORA and ISO 27001:2022
1.0, 10.04.2024

20. Art.6.6 6. The ICT risk management framework of financial entities, Internal Audit 9.2, A.5.36
other than microenterprises, shall be subject to internal audit
by auditors on a regular basis in line with the financial entities’
audit plan. Those auditors shall possess sufficient knowledge,
skills and expertise in ICT risk, as well as appropriate
independence. The frequency and focus of ICT audits shall be
commensurate to the ICT risk of the financial entity.
21. Art.6.7 7. Based on the conclusions from the internal audit review, Nonconformity 10.2
financial entities shall establish a formal follow-up process, Management
including rules for the timely verification and remediation of
critical ICT audit findings.
22. Art.6.8 8. The ICT risk management framework shall include a digital Business A.5.29,
operational resilience strategy setting out how the Continuity and A.5.30, A.8.14
framework shall be implemented. Resilience
23. Art.6.8 a) To that end, the digital operational resilience strategy shall Context, 4.1, 5.1
include methods to address ICT risk and attain specific ICT Leadership and
objectives, by: Commitment
(a) explaining how the ICT risk management framework
supports the financial entity’s business strategy and
objectives;
24. Art.6.8 b) (b) establishing the risk tolerance level for ICT risk, in Risk 6.1.2
accordance with the risk appetite of the financial entity, and Management
analysing the impact tolerance for ICT disruptions;
25. Art.6.8 c) (c) setting out clear information security objectives, IS Objectives, 6.2, 8.2, 9.1
including key performance indicators and key risk Performance
metrics; Evaluation, Risk
Management
26. Art.6.8 d) (d) explaining the ICT reference architecture and any Context, Change 4.1, 5.1, 6.3
changes needed to reach specific business objectives; Management
27. Art.6.8 e) (e) outlining the different mechanisms put in place to detect Incident 6.1.3, A.5.24-
ICT-related incidents, prevent their impact and provide Management, A.5.27
protection from it; SoA and RTP
28. Art.6.8 f) (f) evidencing the current digital operational resilience situation Incident A.5.5, A.5.24-
on the basis of the number of major ICT-related incidents Management, A.5.28,
reported and the effectiveness of preventive measures; Business A.5.29, A.5.30
Continuity and
Resilience
29. Art.6.8 g) (g) implementing digital operational resilience testing; Business A.5.30
Continuity and
Resilience
30. Art.6.8 h) (h) outlining a communication strategy in the event of ICT- Communication, 7.4, A.5.5,
related incidents the disclosure of which is required. Incident A.5.6, A.5.26
Management
31. Art.6.9 9. Financial entities may, in the context of the digital TPRM, Business A.5.19,
operational resilience strategy referred to in paragraph 8, Continuity and A.5.30, A.8.14
define a holistic ICT multi-vendor strategy, at group or Resilience
entity level, showing key dependencies on ICT third-party
service providers and explaining the rationale behind the
procurement mix of ICT third-party service providers.
32. Art.6.10 10. Financial entities may, in accordance with Union and Audit and A.5.35
national sectoral law, outsource the tasks of verifying Assessment
compliance with ICT risk management requirements to intra-
group or external undertakings. In case of such outsourcing,
the financial entity remains fully responsible for the verification
of compliance with the ICT risk management requirements.

Andrey Prozorov, CISM, CIPP/E, CDPSE, LA 27001


TLP:GREEN [Link]/AndreyProzorov || [Link]/in/AndreyProzorov
TLP:GREEN EU DORA and ISO 27001:2022
1.0, 10.04.2024

Article 7. ICT systems, protocols and tools


33. Art.7 In order to address and manage ICT risk, financial entities shall SoA and RTP 6.1.1, 6.1.3
use and maintain updated ICT systems, protocols and
tools that are:
(a) appropriate to the magnitude of operations supporting the
conduct of their activities, in accordance with the
proportionality principle;
(b) reliable;
(c) equipped with sufficient capacity to accurately process the
data necessary for the performance of activities and the timely
provision of services, and to deal with peak orders, message or
transaction volumes, as needed, including where new
technology is introduced;
(d) technologically resilient in order to adequately deal with
additional information processing needs as required under
stressed market conditions or other adverse situations.
Article 8. Identification
34. Art.8.1 1. As part of the ICT risk management framework, financial Inventory of A.5.9, A.5.12
entities shall identify, classify and adequately document Assets,
all ICT supported business functions, roles and Information
responsibilities, the information assets and ICT assets Classification
supporting those functions, and their roles and
dependencies in relation to ICT risk. Financial entities shall
review as needed, and at least yearly, the adequacy of this
classification and of any relevant documentation.
35. Art.8.2 2. Financial entities shall, on a continuous basis, identify all Risk 6.1.2, 8.1.2
sources of ICT risk, in particular the risk exposure to and Management
from other financial entities, and assess cyber threats and
ICT vulnerabilities relevant to their ICT supported business
functions, information assets and ICT assets. Financial entities
shall review on a regular basis, and at least yearly, the risk
scenarios impacting them.
36. Art.8.3 3. Financial entities, other than microenterprises, shall perform Risk 8.1, 8.2
a risk assessment upon each major change in the network Management,
and information system infrastructure, in the processes or Change
procedures affecting their ICT supported business functions, management,
information assets or ICT assets. Operational
Planning and
Control
37. Art.8.4 4. Financial entities shall identify all information assets Inventory of A.5.9
and ICT assets, including those on remote sites, network Assets
resources and hardware equipment, and shall map those
considered critical. They shall map the configuration of the
information assets and ICT assets and the links and
interdependencies between the different information assets
and ICT assets
38. Art.8.5 5. Financial entities shall identify and document all Inventory of 8.1, A.5.9,
processes that are dependent on ICT third-party service Assets, TPRM, A.5.22
providers, and shall identify interconnections with ICT third- Operational
party service providers that provide services that support Planning and
critical or important functions. Control
39. Art.8.6 6. For the purposes of paragraphs 1, 4 and 5, financial entities Inventory of 8.1, A.5.9,
shall maintain relevant inventories and update them Assets, Change A.5.22
periodically and every time any major change Management,
Operational
Planning and
Control

Andrey Prozorov, CISM, CIPP/E, CDPSE, LA 27001


TLP:GREEN [Link]/AndreyProzorov || [Link]/in/AndreyProzorov
TLP:GREEN EU DORA and ISO 27001:2022
1.0, 10.04.2024

40. Art.8.7 7. Financial entities, other than microenterprises, shall on a Risk 6.1.2, 8.2,
regular basis, and at least yearly, conduct a specific ICT Management A.8.9, A.8.29
risk assessment on all legacy ICT systems and, in any
case before and after connecting technologies, applications or
systems.
Article 9. Protection and prevention
41. Art.9.1 1. For the purposes of adequately protecting ICT systems Performance 6.1.3, 8.1,
and with a view to organising response measures, financial evaluation, SoA 8.3, 9.1,
entities shall continuously monitor and control the security and RTP, A.8.16…
and functioning of ICT systems and tools and shall minimize Operational
the impact of ICT risk on ICT systems through the deployment planning and
of appropriate ICT security tools, policies and procedures. control
42. Art.9.2 2. Financial entities shall design, procure and implement ICT SoA and RPT, 6.1.3, 8.3
security policies, procedures, protocols and tools that Business …
aim to ensure the resilience, continuity and availability of ICT continuity and
systems, in particular for those supporting critical or important Resilience
functions, and to maintain high standards of availability,
authenticity, integrity and confidentiality of data,
whether at rest, in use or in transit.
43. Art.9.3 …The ICT solutions and processes shall: SoA and RPT 6.1.3, 8.3,
(a) ensure the security of the means of transfer of data; A.5.14, A.8.1-
(b) minimise the risk of corruption or loss of data, A.8.5,
unauthorised access and technical flaws that may hinder A.8.12…
business activity;
(c) prevent the lack of availability, the impairment of the
authenticity and integrity, the breaches of
confidentiality and the loss of data;
(d) ensure that data is protected from risks arising from
data management, including poor administration,
processing-
related risks and human error.
44. Art.9.4 a) 4. As part of the ICT risk management framework, financial IS Policy 5.2, A.5.1
entities shall:
(a) develop and document an information security policy
defining rules to protect the availability, authenticity, integrity
and confidentiality of data, information assets and ICT assets,
including those of their customers, where applicable;
45. Art.9.4 b) (b) following a risk-based approach, establish a sound Incident 6.1.3, A.5.24,
network and infrastructure management structure using Management, A.5.26,
appropriate techniques, methods and protocols that may Network Security A.8.16,
include implementing automated mechanisms to isolate A.8.20,
affected information assets in the event of cyber-attacks; A.8.21, A.8.22
46. Art.9.4 c) (c) implement policies that limit the physical or logical Access Control, A.5.15,
access to information assets and ICT assets to what is Physical Security A.5.18, A.8.2,
required for legitimate and approved functions and activities A.8.3, A.8.4
only, and establish to that end a set of policies, procedures and A.7.2, A.7.3,
controls that address access rights and ensure a sound A.7.4
administration thereof;
47. Art.9.4 d) (d) implement policies and protocols for strong Access Control, A.5.12,
authentication mechanisms, based on relevant standards Cryptography, A.5.17, A.8.5,
and dedicated control systems, and protection measures of Information A.8.24,
cryptographic keys whereby data is encrypted based on classification
results of approved data classification and ICT risk
assessment processes;

Andrey Prozorov, CISM, CIPP/E, CDPSE, LA 27001


TLP:GREEN [Link]/AndreyProzorov || [Link]/in/AndreyProzorov
TLP:GREEN EU DORA and ISO 27001:2022
1.0, 10.04.2024

48. Art.9.4 e) (e) implement documented policies, procedures and Change 6.3, 8.1, 8.2,
controls for ICT change management, including changes to Management, A.8.32
software, hardware, firmware components, systems or security Operational
parameters, that are based on a risk assessment approach and planning and
are an integral part of the financial entity’s overall change control
management process, in order to ensure that all changes to
ICT systems are recorded, tested, assessed, approved,
implemented and verified in a controlled manner;
49. Art.9.4 f) (f) have appropriate and comprehensive documented policies Patch A.8.8, A.8.9
for patches and updates. management
50. Art.9.4 Financial entities shall design the network connection Network security A.8.22
infrastructure in a way that allows it to be instantaneously
severed or segmented in order to minimise and prevent
contagion, especially for interconnected financial processes.
51. Art.9.4 The ICT change management process shall be approved by Change A.8.32
appropriate lines of management and shall have specific management
protocols in place.
Article 10. Detection
52. Art.10.1 1. Financial entities shall have in place mechanisms to Monitoring A.8.16
promptly detect anomalous activities including ICT
network performance issues and ICT-related incidents, and to
identify potential material single points of failure.
All detection mechanisms shall be regularly tested.
53. Art.10.2 2. The detection mechanisms referred to in paragraph 1 shall Monitoring, A.5.25,
enable multiple layers of control, define alert thresholds and Incident A.5.26, A.8.16
criteria to trigger and initiate ICT-related incident Management
response processes, including automatic alert mechanisms for
relevant staff in charge of ICT-related incident response.
54. Art.10.3 3. Financial entities shall devote sufficient resources and Support 7.1, A.5.24,
capabilities to monitor user activity, the occurrence of ICT (Resources), A.8.16
anomalies and ICT-related incidents, in particular cyber- Monitoring,
attacks. Incident
Management
55. Art.10.4 4. Data reporting service providers shall, in addition, have Threat A.5.6, A.5.7
in place systems that can effectively check trade reports for intelligence
completeness, identify omissions and obvious errors, and
request re-transmission of those reports.
Article 11. Response and recovery
56. Art.11.1 1. As part of the ICT risk management framework and based Business A.5.30
on the identification requirements, financial entities shall put in continuity and
place a comprehensive ICT business continuity policy, Resilience
which may be adopted as a dedicated specific policy, forming
an integral part of the overall business continuity policy of the
financial entity.
57. Art.11.2 2. Financial entities shall implement the ICT business Business A.5.29, A.5.30
continuity policy through dedicated, appropriate and continuity and
documented arrangements, plans, procedures and Resilience
mechanisms aiming to:
(a) ensure the continuity of the financial entity’s critical or
important functions;
(b) quickly, appropriately and effectively respond to, and
resolve, all ICT-related incidents in a way that limits damage
and prioritises the resumption of activities and recovery
actions;
(c) activate, without delay, dedicated plans that enable
containment measures, processes and technologies suited to
each type of ICT-related incident and prevent further damage,
as well as tailored response and recovery procedures;

Andrey Prozorov, CISM, CIPP/E, CDPSE, LA 27001


TLP:GREEN [Link]/AndreyProzorov || [Link]/in/AndreyProzorov
TLP:GREEN EU DORA and ISO 27001:2022
1.0, 10.04.2024
(d) estimate preliminary impacts, damages and losses;
(e) set out communication and crisis management actions that
ensure that updated information is transmitted to all relevant
internal staff and external stakeholders, and report to the
competent authorities.
58. Art.11.3 3. As part of the ICT risk management framework, financial Business 9.2, A.5.29,
entities shall implement associated ICT response and continuity and A.5.30
recovery plans which, in the case of financial entities other Resilience,
than microenterprises, shall be subject to independent Internal Audit
internal audit reviews.
59. Art.11.4 4. Financial entities shall put in place, maintain and Business A.5.20,
periodically test appropriate ICT business continuity continuity and A.5.22,
plans, notably with regard to critical or important functions Resilience, A.5.29, A.5.30
outsourced or contracted through arrangements with ICT third- TPRM, Contract
party service providers.
60. Art.11.5 5. As part of the overall business continuity policy, financial Business A.5.9, A.5.30
entities shall conduct a business impact analysis (BIA) of continuity and
their exposures to severe business disruptions. Under the BIA, Resilience,
financial entities shall assess the potential impact of severe Inventory of
business disruptions by means of quantitative and qualitative assets
criteria, using internal and external data and scenario analysis,
as appropriate. The BIA shall consider the criticality of identified
and mapped business functions, support processes, third-party
dependencies and information assets, and their
interdependencies. Financial entities shall ensure that ICT
assets and ICT services are designed and used in full alignment
with the BIA, in particular with regard to adequately ensuring
the redundancy of all critical components.
61. Art.11.6 6. As part of their comprehensive ICT risk management, Business 7.4, A.5.29,
financial entities shall: continuity and A.5.30, A.8.13
(a) test the ICT business continuity plans and the ICT Resilience,
response and recovery plans in relation to ICT systems Communication
supporting all functions at least yearly, as well as in the event
of any substantive changes to ICT systems supporting critical
or important functions;
(b) test the crisis communication plans.
Financial entities, other than microenterprises, shall include in
the testing plans scenarios of cyber-attacks and switchovers
between the primary ICT infrastructure and the redundant
capacity, backups and redundant facilities necessary to meet
the obligations set out in Article 12.
62. Art.11.6 Financial entities shall regularly review their ICT business Business 10.1, A.5.29,
continuity policy and ICT response and recovery plans, continuity and A.5.30
taking into account the results of tests and recommendations Resilience,
stemming from audit checks or supervisory reviews. Continual
improvement
63. Art.11.7 7. Financial entities, other than microenterprises, shall have a Business 7.4, A.5.5,
crisis management function, which, in the event of continuity and A.5.6, A.5.26,
activation of their ICT business continuity plans or ICT response Resilience, A.5.30
and recovery plans, shall, inter alia, set out clear procedures to Communication
manage internal and external crisis communications
64. Art.11.8 8. Financial entities shall keep readily accessible records of Business A.5.28
activities before and during disruption events when their continuity and
ICT business continuity plans and ICT response and recovery Resilience,
plans are activated. Incident
Management

Andrey Prozorov, CISM, CIPP/E, CDPSE, LA 27001


TLP:GREEN [Link]/AndreyProzorov || [Link]/in/AndreyProzorov
TLP:GREEN EU DORA and ISO 27001:2022
1.0, 10.04.2024

65. Art.11.9 9. Central securities depositories shall provide the Communication, 7.4, A.5.5,
competent authorities with copies of the results of the Business A.5.30
ICT business continuity tests, or of similar exercises. continuity and
Resilience
66. Art.11.10 10. Financial entities, other than microenterprises, shall report Communication, 7.4, A.5.5
to the competent authorities, upon their request, an Business
estimation of aggregated annual costs and losses continuity and
caused by major ICT-related incidents. Resilience
Article 12. Backup policies and procedures, restoration and recovery procedures and methods
67. Art.12.1 1. For the purpose of ensuring the restoration of ICT systems Backup and A.8.13
and data with minimum downtime, limited disruption and loss, Recovery
as part of their ICT risk management framework, financial
entities shall develop and document:
(a) backup policies and procedures specifying the scope of
the data that is subject to the backup and the minimum
frequency of the backup, based on the criticality of information
or the confidentiality level of the data;
(b) restoration and recovery procedures and methods.
68. Art.12.2 2. Financial entities shall set up backup systems that can be Backup and A.8.13
activated in accordance with the backup policies and Recovery
procedures, as well as restoration and recovery procedures and
methods. The activation of backup systems shall not jeopardise
the security of the network and information systems or the
availability, authenticity, integrity or confidentiality of data.
Testing of the backup procedures and restoration and
recovery procedures and methods shall be undertaken
periodically.
69. Art.12.3 3. When restoring backup data using own systems, financial Backup and A.5.29,
entities shall use ICT systems that are physically and logically Recovery, A.5.30, A.8.13
segregated from the source ICT system. The ICT systems Business
shall be securely protected from any unauthorised access continuity and
or ICT corruption and allow for the timely restoration of Resilience
services making use of data and system backups as necessary.
For central counterparties, the recovery plans shall enable the
recovery of all transactions at the time of disruption to allow
the central counterparty to continue to operate with certainty
and to complete settlement on the scheduled date.
Data reporting service providers shall additionally maintain
adequate resources and have back-up and restoration facilities
in place in order to offer and maintain their services at all times.
70. Art.12.4 4. Financial entities, other than microenterprises, shall maintain Business A.8.14
redundant ICT capacities equipped with resources, continuity and
capabilities and functions that are adequate to ensure business Resilience
needs. Microenterprises shall assess the need to maintain such
redundant ICT capacities based on their risk profile.
71. Art.12.5 5. Central securities depositories shall maintain at least one Business A.8.14
secondary processing site endowed with adequate continuity and
resources, capabilities, functions and staffing arrangements to Resilience
ensure business needs.
The secondary processing site shall be:
(a) located at a geographical distance from the primary
processing site to ensure that it bears a distinct risk profile and
to prevent it from being affected by the event which has
affected the primary site;
(b) capable of ensuring the continuity of critical or important
functions identically to the primary site, or providing the level
of services necessary to ensure that the financial entity
performs its critical operations within the recovery objectives;

Andrey Prozorov, CISM, CIPP/E, CDPSE, LA 27001


TLP:GREEN [Link]/AndreyProzorov || [Link]/in/AndreyProzorov
TLP:GREEN EU DORA and ISO 27001:2022
1.0, 10.04.2024
(c) immediately accessible to the financial entity’s staff to
ensure continuity of critical or important functions in the event
that the primary processing site has become unavailable.
72. Art.12.6 6. In determining the recovery time and recovery point Business 8.1, A.5.9,
objectives for each function, financial entities shall take into continuity and A.5.30
account whether it is a critical or important function and the Resilience,
potential overall impact on market efficiency. Such time Inventory of
objectives shall ensure that, in extreme scenarios, the agreed assets,
service levels are met. Operational
planning and
control
73. Art.12.7 7. When recovering from an ICT-related incident, Business A.5.26, A.8.13
financial entities shall perform necessary checks, including any continuity and
multiple checks and reconciliations, in order to ensure that the Resilience,
highest level of data integrity is maintained. These checks Incident
shall also be performed when reconstructing data from external Management
stakeholders, in order to ensure that all data is consistent
between systems.
Article 13. Learning and evolving
74. Art.13.1 1. Financial entities shall have in place capabilities and staff Support 7.1, A.5.24
to gather information on vulnerabilities and cyber threats, ICT- (Resources),
related incidents, in particular cyber-attacks, and analyse the Incident
impact they are likely to have on their digital operational Management
resilience.
75. Art.13.2 2. Financial entities shall put in place post ICT-related Incident 7.4, A.5.5,
incident reviews after a major ICT-related incident disrupts Management, A.5.27
their core activities, analysing the causes of disruption and Communication
identifying required improvements to the ICT operations or
within the ICT business continuity policy.

Financial entities, other than microenterprises, shall, upon


request, communicate to the competent authorities, the
changes that were implemented following post ICT-related
incident reviews.

The post ICT-related incident reviews referred to in the first


subparagraph shall determine whether the established
procedures were followed and the actions taken were effective,
including in relation to the following:
(a) the promptness in responding to security alerts and
determining the impact of ICT-related incidents and their
severity;
(b) the quality and speed of performing a forensic analysis,
where deemed appropriate;
(c) the effectiveness of incident escalation within the financial
entity;
(d) the effectiveness of internal and external communication.
76. Art.13.3 3. Lessons derived from the digital operational resilience testing Risk 8.2, 10.1, 10.2
carried out in accordance with Articles 26 and 27 and from real Management,
life ICT-related incidents, in particular cyber-attacks, along with Continual
challenges faced upon the activation of ICT business continuity improvement,
plans and ICT response and recovery plans, together with Nonconformity
relevant information exchanged with counterparts and Management
assessed during supervisory reviews, shall be duly
incorporated on a continuous basis into the ICT risk
assessment process. Those findings shall form the basis for
appropriate reviews of relevant components of the ICT risk
management framework.

Andrey Prozorov, CISM, CIPP/E, CDPSE, LA 27001


TLP:GREEN [Link]/AndreyProzorov || [Link]/in/AndreyProzorov
TLP:GREEN EU DORA and ISO 27001:2022
1.0, 10.04.2024

77. Art.13.4 4. Financial entities shall monitor the effectiveness of the Risk 8.2, 10.1
implementation of their digital operational resilience Management,
strategy set out in Article 6(8). They shall map the evolution Continual
of ICT risk over time, analyse the frequency, types, magnitude improvement
and evolution of ICT-related incidents, in particular cyber-
attacks and their patterns, with a view to understanding the
level of ICT risk exposure, in particular in relation to critical or
important functions, and enhance the cyber maturity and
preparedness of the financial entity.
78. Art.13.5 5. Senior ICT staff shall report at least yearly to the Management 9.3, 10.2
management body on the findings referred to in paragraph review,
3 and put forward recommendations. Nonconformity
Managment
79. Art.13.6 6. Financial entities shall develop ICT security awareness Awareness 7.3, A.6.3
programmes and digital operational resilience training
as compulsory modules in their staff training schemes. Those
programmes and training shall be applicable to all employees
and to senior management staff, and shall have a level of
complexity commensurate to the remit of their functions.
Where appropriate, financial entities shall also include ICT
third-party service providers in their relevant training schemes
80. Art.13.7 7. Financial entities, other than microenterprises, shall Context, Risk 4.1, 6.1.2, 8.2
monitor relevant technological developments on a Management
continuous basis, also with a view to understanding the
possible impact of the deployment of such new technologies on
ICT security requirements and digital operational resilience.
They shall keep up-to-date with the latest ICT risk management
processes, in order to effectively combat current or new forms
of cyber-attacks.
Article 14. Communication
81. Art.14.1 1. As part of the ICT risk management framework, financial Communication, 7.4, A.5.26
entities shall have in place crisis communication plans Incident
enabling a responsible disclosure of, at least, major ICT-related Management
incidents or vulnerabilities to clients and counterparts as well
as to the public, as appropriate.
82. Art.14.2 2. As part of the ICT risk management framework, financial Communication, 7.4, A.5.26
entities shall implement communication policies for Incident
internal staff and for external stakeholders. Management
Communication policies for staff shall take into account the
need to differentiate between staff involved in ICT risk
management, in particular the staff responsible for response
and recovery, and staff that needs to be informed.
83. Art.14.3 3. At least one person in the financial entity shall be tasked with Communication, 7.4, A.5.26
implementing the communication strategy for ICT- Incident
related incidents and fulfil the public and media function Management
for that purpose.

SEE Also Article 16. Simplified ICT risk management framework (the exceptions for small companies)

Andrey Prozorov, CISM, CIPP/E, CDPSE, LA 27001


TLP:GREEN [Link]/AndreyProzorov || [Link]/in/AndreyProzorov
TLP:GREEN EU DORA and ISO 27001:2022
1.0, 10.04.2024

ISO
N DORA DORA requirements ISMS Topic
27001:2022
CHAPTER III. ICT-related incident management, classification and reporting (Articles 17-23)
Article 17. ICT-related incident management process
84. Art.17.1 1. Financial entities shall define, establish and implement an Incident A.5.24
ICT-related incident management process to detect, Management
manage and notify ICT-related incidents.
85. Art.17.2 2. Financial entities shall record all ICT-related incidents Incident A.5.24-A.5.28
and significant cyber threats. Financial entities shall Management
establish appropriate procedures and processes to ensure a
consistent and integrated monitoring, handling and follow-up
of ICT-related incidents, to ensure that root causes are
identified, documented and addressed in order to prevent the
occurrence of such incidents.
86. Art.17.3 3. The ICT-related incident management process shall: Incident 7.4, A.5.24-
(a) put in place early warning indicators; Management, A.5.26
(b) establish procedures to identify, track, log, categorise and Communication
classify ICT-related incidents according to their priority and
severity and according to the criticality of the services
impacted;
(c) assign roles and responsibilities that need to be activated
for different ICT-related incident types and scenarios;
(d) set out plans for communication to staff, external
stakeholders and media and for notification to clients, for
internal escalation procedures, including ICT-related customer
complaints, as well as for the provision of information to
financial entities that act as counterparts, as appropriate;
(e) ensure that at least major ICT-related incidents are
reported to relevant senior management and inform the
management body of at least major ICT-related incidents,
explaining the impact, response and additional controls to be
established as a result of such ICT-related incidents;
(f) establish ICT-related incident response procedures to
mitigate impacts and ensure that services become operational
and secure in a timely manner.
Article 18. Classification of ICT-related incidents and cyber threats
87. Art.18.1 1. Financial entities shall classify ICT-related incidents and Incident A.5.24, A.5.25
shall determine their impact based on the following criteria: Management
(a) the number and/or relevance of clients or financial
counterparts affected and, where applicable, the amount or
number of transactions affected by the ICT-related incident,
and whether the ICT-related incident has caused reputational
impact;
(b) the duration of the ICT-related incident, including the
service downtime;
(c) the geographical spread with regard to the areas affected
by the ICT-related incident, particularly if it affects more than
two Member States;
(d) the data losses that the ICT-related incident entails, in
relation to availability, authenticity, integrity or confidentiality
of data;
(e) the criticality of the services affected, including the financial
entity’s transactions and operations;
(f) the economic impact, in particular direct and indirect costs
and losses, of the ICT-related incident in both absolute and
relative terms.

Andrey Prozorov, CISM, CIPP/E, CDPSE, LA 27001


TLP:GREEN [Link]/AndreyProzorov || [Link]/in/AndreyProzorov
TLP:GREEN EU DORA and ISO 27001:2022
1.0, 10.04.2024

88. Art.18.2 2. Financial entities shall classify cyber threats as significant Risk 6.1.2
based on the criticality of the services at risk, including the Management
financial entity’s transactions and operations, number and/or
relevance of clients or financial counterparts targeted and the
geographical spread of the areas at risk.
Article 19. Reporting of major ICT-related incidents and voluntary notification of significant cyber
threats
89. Art.19.1 1. Financial entities shall report major ICT-related Incident 7.4, A.5.5,
incidents to the relevant competent authority. … Management, A.5.24-A.5.28
Financial entities shall produce, after collecting and analysing Communication
all relevant information, the initial notification and reports using
the templates and submit them to the competent authority. In
the event that a technical impossibility prevents the submission
of the initial notification using the template, financial entities
shall notify the competent authority about it via alternative
means.
The initial notification and reports shall include all information
necessary for the competent authority to determine the
significance of the major ICT-related incident and assess
possible cross-border impacts.
Member States may additionally determine that some or all
financial entities shall also provide the initial notification and
each report using the templates to the competent authorities
or the computer security incident response teams (CSIRTs)
designated or established in accordance with Directive (EU)
2022/2555 [NIS 2 Directive]…
90. Art.19.2 2. Financial entities may, on a voluntary basis, notify Threat A.5.5, A.5.7
significant cyber threats to the relevant competent intelligence
authority when they deem the threat to be of relevance to the
financial system, service users or clients. The relevant
competent authority may provide such information to other
relevant authorities.

Member States may determine that those financial entities that


on a voluntary basis may also transmit that notification to the
CSIRTs designated or established in accordance with Directive
(EU) 2022/2555 [NIS 2 Directive]…
91. Art.19.3 3. Where a major ICT-related incident occurs and has an impact Incident 7.4, A.5.25,
on the financial interests of clients, financial entities shall, Management, A.5.26
without undue delay as soon as they become aware of it, Communication
inform their clients about the major ICT-related
incident and about the measures that have been taken to
mitigate the adverse effects of such incident.

In the case of a significant cyber threat, financial entities shall,


where applicable, inform their clients that are potentially
affected of any appropriate protection measures which the
latter may consider taking.
92. Art.19.4 4. Financial entities shall, within the time limits to be laid Incident 7.4, A.5.5,
down submit the following to the relevant competent Management, A.5.24-A.5.28
authority: Communication
(a) an initial notification;
(b) an intermediate report after the initial notification
referred to in point (a), as soon as the status of the original
incident has changed significantly or the handling of the major
ICT-related incident has changed based on new information
available, followed, as appropriate, by updated notifications
every time a relevant status update is available, as well as upon
a specific request of the competent authority;

Andrey Prozorov, CISM, CIPP/E, CDPSE, LA 27001


TLP:GREEN [Link]/AndreyProzorov || [Link]/in/AndreyProzorov
TLP:GREEN EU DORA and ISO 27001:2022
1.0, 10.04.2024
(c) a final report, when the root cause analysis has been
completed, regardless of whether mitigation measures have
already been implemented, and when the actual impact figures
are available to replace estimates.
93. Art.19.5 5. Financial entities may outsource, in accordance with Union Incident A.5.24
and national sectoral law, the reporting obligations to a Management
third-party service provider. In case of such outsourcing, the
financial entity remains fully responsible for the fulfilment of
the incident reporting requirements.
Article 22. Supervisory feedback
94. Art.22.1 1. Without prejudice to the technical input, advice or remedies Incident 7.4, A.5.5
and subsequent follow-up which may be provided, where Management,
applicable, in accordance with national law, by the CSIRTs Communication
under Directive (EU) 2022/2555, the competent authority
shall, upon receipt of the initial notification and of each report,
acknowledge receipt and may, where feasible, provide in a
timely manner relevant and proportionate feedback or
high-level guidance to the financial entity, in particular by
making available any relevant anonymised information and
intelligence on similar threats, and may discuss remedies
applied at the level of the financial entity and ways to minimise
and mitigate adverse impact across the financial sector.
Without prejudice to the supervisory feedback received,
financial entities shall remain fully responsible for the handling
and for consequences of the ICT-related incidents reported. …
Article 23. Operational or security payment-related incidents concerning credit institutions, payment
institutions, account information service providers, and electronic money institutions
95. Art.23 The requirements laid down in III Chapter [articles 17-23] shall Incident A.5.24
also apply to operational or security payment-related Management
incidents and to major operational or security payment-
related incidents, where they concern credit institutions,
payment institutions, account information service providers,
and electronic money institutions.

Andrey Prozorov, CISM, CIPP/E, CDPSE, LA 27001


TLP:GREEN [Link]/AndreyProzorov || [Link]/in/AndreyProzorov
TLP:GREEN EU DORA and ISO 27001:2022
1.0, 10.04.2024

ISO
N DORA DORA requirements ISMS Topic
27001:2022
CHAPTER IV Digital operational resilience testing (Articles 24-27)
Article 24 General requirements for the performance of digital operational resilience testing
96. Art.24.1 1. For the purpose of assessing preparedness for handling ICT- Audit and 9.2, A.5.30,
related incidents, of identifying weaknesses, deficiencies and Assessment A.5.35,
gaps in digital operational resilience, and of promptly A.8.29,
implementing corrective measures, financial entities, other A.8.31, A.8.33
than microenterprises, shall establish, maintain and review a
sound and comprehensive digital operational resilience
testing programme as an integral part of the ICT risk-
management framework.
97. Art.24.2 2. The digital operational resilience testing programme Audit and 9.2, A.5.30,
shall include a range of assessments, tests, Assessment A.5.35,
methodologies, practices and tools to be applied in A.8.29,
accordance with Articles 25 and 26. A.8.31, A.8.33
98. Art.24.3 3. When conducting the digital operational resilience Audit and 4.1, 9.2,
testing programme, financial entities, other than Assessment, A.5.30, A.5.35
microenterprises, shall follow a risk-based approach taking into Context, Risk
account the criteria set out in Article 4(2) [the Proportionality Management
principle] duly considering the evolving landscape of ICT risk,
any specific risks to which the financial entity concerned is or
might be exposed, the criticality of information assets and of
services provided, as well as any other factor the financial entity
deems appropriate.
99. Art.24.4 4. Financial entities, other than microenterprises, shall ensure Audit and 9.2, A.5.30,
that tests are undertaken by independent parties, Assessment A.5.35
whether internal or external. Where tests are undertaken by an
internal tester, financial entities shall dedicate sufficient
resources and ensure that conflicts of interest are avoided
throughout the design and execution phases of the test.
100. Art.24.5 5. Financial entities, other than microenterprises, shall establish Nonconformity 10.1, 10.2
procedures and policies to prioritise, classify and Management,
remedy all issues revealed throughout the performance of Continual
the tests and shall establish internal validation methodologies improvement
to ascertain that all identified weaknesses, deficiencies or gaps
are fully addressed.
101. Art.24.6 6. Financial entities, other than microenterprises, shall ensure, Audit and 9.2, A.5.30,
at least yearly, that appropriate tests are conducted on Assessment A.5.35
all ICT systems and applications supporting critical or
important functions.
Article 25. Testing of ICT tools and systems
102. Art.25.1 1. The digital operational resilience testing programme Audit and 9.2, A.5.30,
shall provide for the execution of appropriate tests, such as Assessment A.5.35, A.8.8
vulnerability assessments and scans, open source analyses,
network security assessments, gap analyses, physical security
reviews, questionnaires and scanning software solutions,
source code reviews where feasible, scenario-based tests,
compatibility testing, performance testing, end-to-end testing
and penetration testing.
103. Art.25.2 2. Central securities depositories and central counterparties Audit and A.8.4, A.8.8,
shall perform vulnerability assessments before any Assessment A.8.9, A.8.19,
deployment or redeployment of new or existing applications A.8.25-A.8.30
and infrastructure components, and ICT services supporting
critical or important functions of the financial entity.

Andrey Prozorov, CISM, CIPP/E, CDPSE, LA 27001


TLP:GREEN [Link]/AndreyProzorov || [Link]/in/AndreyProzorov
TLP:GREEN EU DORA and ISO 27001:2022
1.0, 10.04.2024

104. Art.25.3 3. Microenterprises shall perform the tests referred to in Audit and 6.1.2, 9.2,
paragraph 1 by combining a risk-based approach with a Assessment, Risk A.5.30, A.5.35
strategic planning of ICT testing, by duly considering the need Management
to maintain a balanced approach between the scale of
resources and the time to be allocated to the ICT testing
provided for in this Article, on the one hand, and the urgency,
type of risk, criticality of information assets and of services
provided, as well as any other relevant factor, including the
financial entity’s ability to take calculated risks, on the other
hand.
Article 26. Advanced testing of ICT tools, systems and processes based on TLPT [Threat-led penetration test]
105. Art.26.1 1. Financial entities [see the exceptions] shall carry out at least Audit and 7.4, A.5.35
every 3 years advanced testing by means of TLPT. Based Assessment,
on the risk profile of the financial entity and taking into account Communication
operational circumstances, the competent authority may,
where necessary, request the financial entity to reduce or
increase this frequency.
106. Art.26.2 2. Each threat-led penetration test shall cover several or Audit and 7.4, A.5.5,
all critical or important functions of a financial entity, and Assessment, A.5.9, A.5.20,
shall be performed on live production systems Inventory of A.5.35
supporting such functions. Assets,
Financial entities shall identify all relevant underlying ICT Communication,
systems, processes and technologies supporting critical or Contract
important functions and ICT services, including those
supporting the critical or important functions which have been
outsourced or contracted to ICT third-party service providers.
Financial entities shall assess which critical or important
functions need to be covered by the TLPT. The result of this
assessment shall determine the precise scope of TLPT and
shall be validated by the competent authorities.
107. Art.26.3 3. Where ICT third-party service providers are included in TPRM, Audit and A.5.19-A.5.23
the scope of TLPT, the financial entity shall take the necessary Assessment
measures and safeguards to ensure the participation of
such ICT third-party service providers in the TLPT and shall
retain at all times full responsibility for ensuring compliance
with this Regulation. [DORA]
108. Art.26.4 4. Without prejudice to paragraph 2, first and second TPRM, Audit and A.5.19, A.5.20
subparagraphs, where the participation of an ICT third-party Assessment,
service provider in the TLPT, referred to in paragraph 3, is Contract
reasonably expected to have an adverse impact on the quality
or security of services delivered by the ICT third-party service
provider to customers that are entities falling outside the scope
of this Regulation, or on the confidentiality of the data related
to such services, the financial entity and the ICT third-party
service provider may agree in writing that the ICT third-party
service provider directly enters into contractual
arrangements with an external tester, for the purpose of
conducting, under the direction of one designated financial
entity, a pooled TLPT involving several financial entities (pooled
testing) to which the ICT third-party service provider provides
ICT services.
That pooled testing shall cover the relevant range of ICT
services supporting critical or important functions contracted to
the respective ICT third-party service provider by the financial
entities. The pooled testing shall be considered TLPT carried
out by the financial entities participating in the pooled testing.
The number of financial entities participating in the pooled
testing shall be duly calibrated taking into account the
complexity and types of services involved.

Andrey Prozorov, CISM, CIPP/E, CDPSE, LA 27001


TLP:GREEN [Link]/AndreyProzorov || [Link]/in/AndreyProzorov
TLP:GREEN EU DORA and ISO 27001:2022
1.0, 10.04.2024

109. Art.26.5 5. Financial entities shall, with the cooperation of ICT Risk 6.1.3, 8.3,
third-party service providers and other parties involved, Management, A.5.21-A.5.23
including the testers but excluding the competent authorities, TPRM
apply effective risk management controls to mitigate
the risks of any potential impact on data, damage to assets,
and disruption to critical or important functions, services or
operations at the financial entity itself, its counterparts or to
the financial sector.
110. Art.26.6 6. At the end of the testing, after reports and remediation plans Audit and 7.4, 10.1,
have been agreed, the financial entity and, where applicable, Assessment, 10.2, A.5.5
the external testers shall provide to the authority a Communication
summary of the relevant findings, the remediation
plans and the documentation demonstrating that the
TLPT has been conducted in accordance with the
requirements.
111. Art.26.7 7. Authorities shall provide financial entities with an Audit and 7.4, 10.1,
attestation confirming that the test was performed in Assessment, 10.2, A.5.5,
accordance with the requirements as evidenced in the Communication A.5.35
documentation in order to allow for mutual recognition of threat
led penetration tests between competent authorities. The
financial entity shall notify the relevant competent
authority of the attestation, the summary of the
relevant findings and the remediation plans.

Without prejudice to such attestation, financial entities shall


remain at all times fully responsible for the impact of the tests.
112. Art.26.8 8. Financial entities shall contract testers for the purposes of Audit and A.5.35
undertaking TLPT. When financial entities use internal testers Assessment
for the purposes of undertaking TLPT, they shall contract
external testers every three tests. …
Article 27. Requirements for testers for the carrying out of TLPT
113. Art.27.1 1. Financial entities shall only use testers for the carrying Audit and A.5.35
out of TLPT, that: Assessment
(a) are of the highest suitability and reputability;
(b) possess technical and organisational capabilities and
demonstrate specific expertise in threat intelligence,
penetration testing and red team testing;
(c) are certified by an accreditation body in a Member
State or adhere to formal codes of conduct or ethical
frameworks;
(d) provide an independent assurance, or an audit report, in
relation to the sound management of risks associated with the
carrying out of TLPT, including the due protection of the
financial entity’s confidential information and redress for the
business risks of the financial entity;
(e) are duly and fully covered by relevant professional
indemnity insurances, including against risks of misconduct and
negligence.
114. Art.27.2 2. When using internal testers, financial entities shall ensure Audit and A.5.35
that, in addition to the requirements in paragraph 1, the Assessment
following conditions are met:
(a) such use has been approved by the relevant
competent authority or by the single public authority;
(b) the relevant competent authority has verified that the
financial entity has sufficient dedicated resources and ensured
that conflicts of interest are avoided throughout the design and
execution phases of the test; and
(c) the threat intelligence provider is external to the financial
entity.

Andrey Prozorov, CISM, CIPP/E, CDPSE, LA 27001


TLP:GREEN [Link]/AndreyProzorov || [Link]/in/AndreyProzorov
TLP:GREEN EU DORA and ISO 27001:2022
1.0, 10.04.2024

115. Art.27.3 3. Financial entities shall ensure that contracts concluded Audit and A.5.20, A.5.35
with external testers require a sound management of Assessment,
the TLPT results and that any data processing thereof, TPRM, Contract
including any generation, store, aggregation, draft, report,
communication or destruction, do not create risks to the
financial entity.

ISO
N DORA DORA requirements ISMS Topic
27001:2022
CHAPTER V Managing of ICT third-party risk (Articles 28-44)
Article 28. General principles
116. Art.28.1 1. Financial entities shall manage ICT third-party risk as an TPRM, Risk 6.1, 8.1, 8.2,
integral component of ICT risk within their ICT risk Management, 8.3, A.5.19,
management framework, and in accordance with the following Contract A.5.20, A.5.21
principles:
(a) financial entities that have in place contractual
arrangements for the use of ICT services to run their
business operations shall, at all times, remain fully responsible
for compliance with, and the discharge of, all obligations under
this Regulation and applicable financial services law;
(b) financial entities’ management of ICT third-party risk shall
be implemented in light of the principle of proportionality,
taking into account:
(i) the nature, scale, complexity and importance of ICT-
related dependencies,
(ii) the risks arising from contractual arrangements on the
use of ICT services concluded with ICT third-party service
providers, taking into account the criticality or importance
of the respective service, process or function, and the
potential impact on the continuity and availability of
financial services and activities, at individual and at group
level.
117. Art.28.2 2. As part of their ICT risk management framework, financial TPRM, Risk 6.1.2, 8.1,
entities [see the exceptions] shall adopt, and regularly review, Management, 8.2, A.5.19,
a strategy on ICT third-party risk, taking into account the Contract 5.20, A.5.21
multi-vendor strategy, where applicable. The strategy on
ICT third-party risk shall include a policy on the use of ICT
services supporting critical or important functions provided by
ICT third-party service providers and shall apply on an
individual basis and, where relevant, on a sub-consolidated and
consolidated basis.
The management body shall, on the basis of an
assessment of the overall risk profile of the financial entity
and the scale and complexity of the business services, regularly
review the risks identified in respect to contractual
arrangements on the use of ICT services supporting critical or
important functions.
118. Art.28.3 3. As part of their ICT risk management framework, financial TPRM, Contract A.5.9, A.5.20
entities shall maintain and update at entity level, and at sub-
consolidated and consolidated levels, a register of
information in relation to all contractual arrangements
on the use of ICT services provided by ICT third-party service
providers.
119. Art.28.3 The contractual arrangements shall be appropriately TPRM, Contract A.5.20
documented, distinguishing between those that cover ICT
services supporting critical or important functions and those
that do not.

Andrey Prozorov, CISM, CIPP/E, CDPSE, LA 27001


TLP:GREEN [Link]/AndreyProzorov || [Link]/in/AndreyProzorov
TLP:GREEN EU DORA and ISO 27001:2022
1.0, 10.04.2024

120. Art.28.3 Financial entities shall report at least yearly to the Communication, 7.4, A.5.5
competent authorities on the number of new TPRM
arrangements on the use of ICT services, the categories
of ICT third-party service providers, the type of contractual
arrangements and the ICT services and functions which are
being provided.
121. Art.28.3 Financial entities shall make available to the competent Communication 7.4, A.5.5
authority, upon its request, the full register of information
or, as requested, specified sections thereof, along with any
information deemed necessary to enable the effective
supervision of the financial entity.
122. Art.28.3 Financial entities shall inform the competent authority in a Communication, 7.4, A.5.5,
timely manner about any planned contractual TPRM, Contract A.5.20
arrangement on the use of ICT services supporting critical
or important functions as well as when a function has become
critical or important.
123. Art.28.4 4. Before entering into a contractual arrangement on the TPRM, Contract 6.1.2, 8.2,
use of ICT services, financial entities shall: A.5.20
(a) assess whether the contractual arrangement covers the use
of ICT services supporting a critical or important function;
(b) assess if supervisory conditions for contracting are met;
(c) identify and assess all relevant risks in relation to the
contractual arrangement, including the possibility that such
contractual arrangement may contribute to reinforcing ICT
concentration risk;
(d) undertake all due diligence on prospective ICT third-party
service providers and ensure throughout the selection and
assessment processes that the ICT third-party service provider
is suitable;
(e) identify and assess conflicts of interest that the contractual
arrangement may cause.
124. Art.28.5 5. Financial entities may only enter into contractual TPRM, Contract A.5.19, A.5.20
arrangements with ICT third-party service providers that
comply with appropriate information security standards.
When those contractual arrangements concern critical or
important functions, financial entities shall, prior to concluding
the arrangements, take due consideration of the use, by ICT
third-party service providers, of the most up-to-date and
highest quality information security standards.
125. Art.28.6 6. In exercising access, inspection and audit rights over the ICT Audit and A.5.19,
third-party service provider, financial entities shall, on the basis Assessment, A.5.20,
of a risk-based approach, pre-determine the frequency of TPRM, Contract A.5.21, A.5.22
audits and inspections as well as the areas to be audited
through adhering to commonly accepted audit standards in line
with any supervisory instruction on the use and incorporation
of such audit standards.
Where contractual arrangements concluded with ICT third-
party service providers on the use of ICT services entail high
technical complexity, the financial entity shall verify that
auditors, whether internal or external, or a pool of auditors,
possess appropriate skills and knowledge to effectively perform
the relevant audits and assessments.
126. Art.28.7 7. Financial entities shall ensure that contractual TPRM, Contract A.5.20
arrangements on the use of ICT services may be terminated
in any of the following circumstances:
(a) significant breach by the ICT third-party service provider of
applicable laws, regulations or contractual terms;

Andrey Prozorov, CISM, CIPP/E, CDPSE, LA 27001


TLP:GREEN [Link]/AndreyProzorov || [Link]/in/AndreyProzorov
TLP:GREEN EU DORA and ISO 27001:2022
1.0, 10.04.2024
(b) circumstances identified throughout the monitoring of ICT
third-party risk that are deemed capable of altering the
performance of the functions provided through the contractual
arrangement, including material changes that affect the
arrangement or the situation of the ICT third-party service
provider;
(c) ICT third-party service provider’s evidenced weaknesses
pertaining to its overall ICT risk management and in particular
in the way it ensures the availability, authenticity, integrity and,
confidentiality, of data, whether personal or otherwise sensitive
data, or non-personal data;
(d) where the competent authority can no longer effectively
supervise the financial entity as a result of the conditions of, or
circumstances related to, the respective contractual
arrangement.
127. Art.28.8 8. For ICT services supporting critical or important functions, TPRM, Contract A.5.19,
financial entities shall put in place exit strategies. The exit A.5.20,
strategies shall take into account risks that may emerge at the A.5.22, A.5.23
level of ICT third-party service providers, in particular a
possible failure on their part, a deterioration of the quality of
the ICT services provided, any business disruption due to
inappropriate or failed provision of ICT services or any material
risk arising in relation to the appropriate and continuous
deployment of the respective ICT service, or the termination of
contractual arrangements with ICT third-party service
providers under any of the circumstances listed in paragraph 7.
Financial entities shall ensure that they are able to exit
contractual arrangements without:
(a) disruption to their business activities,
(b) limiting compliance with regulatory requirements,
(c) detriment to the continuity and quality of services provided
to clients.
Exit plans shall be comprehensive, documented and, in
accordance with the criteria set out in Article 4(2), shall be
sufficiently tested and reviewed periodically.
Financial entities shall identify alternative solutions and develop
transition plans enabling them to remove the contracted ICT
services and the relevant data from the ICT third-party service
provider and to securely and integrally transfer them to
alternative providers or reincorporate them in-house.
Financial entities shall have appropriate contingency measures
in place to maintain business continuity in the event of the
circumstances referred to in the first subparagraph.
Article 29. Preliminary assessment of ICT concentration risk at entity level
128. Art.29.1 1. When performing the identification and assessment of TPRM, Risk A.5.19,
risks referred to in Article 28(4), point (c), financial entities Management, A.5.20, A.5.21
shall also take into account whether the envisaged conclusion Contract
of a contractual arrangement in relation to ICT services
supporting critical or important functions would lead to any of
the following:
(a) contracting an ICT third-party service provider that is not
easily substitutable; or
(b) having in place multiple contractual arrangements in
relation to the provision of ICT services supporting critical or
important functions with the same ICT third-party service
provider or with closely connected ICT third-party service
providers.

Andrey Prozorov, CISM, CIPP/E, CDPSE, LA 27001


TLP:GREEN [Link]/AndreyProzorov || [Link]/in/AndreyProzorov
TLP:GREEN EU DORA and ISO 27001:2022
1.0, 10.04.2024
Financial entities shall weigh the benefits and costs of
alternative solutions, such as the use of different ICT third-
party service providers, taking into account if and how
envisaged solutions match the business needs and objectives
set out in their digital resilience strategy.
129. Art.29.2 2. Where the contractual arrangements on the use of ICT TPRM, Contract A.5.19,
services supporting critical or important functions include the A.5.20, A.5.21
possibility that an ICT third-party service provider further
subcontracts ICT services supporting a critical or important
function to other ICT third-party service providers, financial
entities shall weigh benefits and risks that may arise in
connection with such subcontracting, in particular in the case
of an ICT subcontractor established in a third-country.
130. Art.29.2 Where contractual arrangements concern ICT services TPRM, Contract A.5.19,
supporting critical or important functions, financial entities shall A.5.20, A.5.21
duly consider the insolvency law provisions that would apply
in the event of the ICT third-party service provider’s
bankruptcy as well as any constraint that may arise in respect
to the urgent recovery of the financial entity’s data.
131. Art.29.2 Where contractual arrangements on the use of ICT services TPRM, Privacy, A.5.19,
supporting critical or important functions are concluded with an Contract A.5.20,
ICT third-party service provider established in a third country, A.5.21, A.5.34
financial entities shall, in addition to the considerations referred
to in the second subparagraph, also consider the compliance
with Union data protection rules and the effective
enforcement of the law in that third country.
132. Art.29.2 Where the contractual arrangements on the use of ICT TPRM, Contract A.5.19,
services supporting critical or important functions provide for A.5.20, A.5.21
subcontracting, financial entities shall assess whether and
how potentially long or complex chains of subcontracting may
impact their ability to fully monitor the contracted functions and
the ability of the competent authority to effectively supervise
the financial entity in that respect.
Article 30. Key contractual provisions
133. Art.30.1 1. The rights and obligations of the financial entity and of TPRM, Contract A.5.20
the ICT third-party service provider shall be clearly allocated
and set out in writing. The full contract shall include the
service level agreements and be documented in one written
document which shall be available to the parties on paper, or
in a document with another downloadable, durable and
accessible format.
134. Art.30.2 2. The contractual arrangements on the use of ICT services TPRM, Contract A.5.20
shall include at least the following elements:
(a) a clear and complete description of all functions and ICT
services to be provided by the ICT third-party service provider,
indicating whether subcontracting of an ICT service supporting
a critical or important function, or material parts thereof, is
permitted and, when that is the case, the conditions applying
to such subcontracting;
(b) the locations, namely the regions or countries, where the
contracted or subcontracted functions and ICT services are to
be provided and where data is to be processed, including the
storage location, and the requirement for the ICT third-party
service provider to notify the financial entity in advance if it
envisages changing such locations;
(c) provisions on availability, authenticity, integrity and
confidentiality in relation to the protection of data, including
personal data;

Andrey Prozorov, CISM, CIPP/E, CDPSE, LA 27001


TLP:GREEN [Link]/AndreyProzorov || [Link]/in/AndreyProzorov
TLP:GREEN EU DORA and ISO 27001:2022
1.0, 10.04.2024
(d) provisions on ensuring access, recovery and return in an
easily accessible format of personal and non-personal data
processed by the financial entity in the event of the insolvency,
resolution or discontinuation of the business operations of the
ICT third-party service provider, or in the event of the
termination of the contractual arrangements;
(e) service level descriptions, including updates and revisions
thereof;
(f) the obligation of the ICT third-party service provider to
provide assistance to the financial entity at no additional cost,
or at a cost that is determined ex-ante, when an ICT incident
that is related to the ICT service provided to the financial entity
occurs;
(g) the obligation of the ICT third-party service provider to fully
cooperate with the competent authorities and the resolution
authorities of the financial entity, including persons appointed
by them;
(h) termination rights and related minimum notice periods for
the termination of the contractual arrangements, in accordance
with the expectations of competent authorities and resolution
authorities;
(i) the conditions for the participation of ICT third-party service
providers in the financial entities’ ICT security awareness
programmes and digital operational resilience training.
135. Art.30.3 3. The contractual arrangements on the use of ICT services TPRM, Contract A.5.20
supporting critical or important functions shall include, in
addition, at least the following:
(a) full service level descriptions, including updates and
revisions thereof with precise quantitative and qualitative
performance targets within the agreed service levels to allow
effective monitoring by the financial entity of ICT services and
enable appropriate corrective actions to be taken, without
undue delay, when agreed service levels are not met;
(b) notice periods and reporting obligations of the ICT third-
party service provider to the financial entity, including
notification of any development that might have a material
impact on the ICT third-party service provider’s ability to
effectively provide the ICT services supporting critical or
important functions in line with agreed service levels;
(c) requirements for the ICT third-party service provider to
implement and test business contingency plans and to have in
place ICT security measures, tools and policies that provide an
appropriate level of security for the provision of services by the
financial entity in line with its regulatory framework;
(d) the obligation of the ICT third-party service provider to
participate and fully cooperate in the financial entity’s TLPT;
(e) the right to monitor, on an ongoing basis, the ICT third-
party service provider’s performance, which entails the
following:
(i) unrestricted rights of access, inspection and audit by the
financial entity, or an appointed third party, and by the
competent authority, and the right to take copies of relevant
documentation on-site if they are critical to the operations of
the ICT third-party service provider, the effective exercise of
which is not impeded or limited by other contractual
arrangements or implementation policies;
(ii) the right to agree on alternative assurance levels if other
clients’ rights are affected;
(iii) the obligation of the ICT third-party service provider to fully
cooperate during the onsite inspections and audits

Andrey Prozorov, CISM, CIPP/E, CDPSE, LA 27001


TLP:GREEN [Link]/AndreyProzorov || [Link]/in/AndreyProzorov
TLP:GREEN EU DORA and ISO 27001:2022
1.0, 10.04.2024
performed by the competent authorities, the Lead Overseer,
financial entity or an appointed third party; and
(iv) the obligation to provide details on the scope, procedures
to be followed and frequency of such inspections and audits;
(f) exit strategies, in particular the establishment of a
mandatory adequate transition period:
(i) during which the ICT third-party service provider will
continue providing the respective functions, or ICT services,
with a view to reducing the risk of disruption at the financial
entity or to ensure its effective resolution and restructuring;
(ii) allowing the financial entity to migrate to another ICT third-
party service provider or change to in-house solutions
consistent with the complexity of the service provided.

By way of derogation from point (e), the ICT third-party service


provider and the financial entity that is a microenterprise may
agree that the financial entity’s rights of access, inspection and
audit can be delegated to an independent third party,
appointed by the ICT third-party service provider, and that the
financial entity is able to request information and assurance on
the ICT third-party service provider’s performance from the
third party at any time.
136. Art.30.4 4. When negotiating contractual arrangements, financial TPRM, Contract A.5.20
entities and ICT third-party service providers shall consider the
use of standard contractual clauses developed by public
authorities for specific services. …
Other
137. Art.31.12 12. Financial entities shall only make use of the services of an TPRM A.5.19
ICT third-party service provider established in a third
country and which has been designated as critical in
accordance with paragraph 1, point (a), if the latter has
established a subsidiary in the Union within the 12
months following the designation.

Andrey Prozorov, CISM, CIPP/E, CDPSE, LA 27001


TLP:GREEN [Link]/AndreyProzorov || [Link]/in/AndreyProzorov
TLP:GREEN EU DORA and ISO 27001:2022
1.0, 10.04.2024

ISO
N DORA DORA requirements ISMS Topic
27001:2022
CHAPTER VI Information-sharing arrangements (Article 45)
Article 45. Information-sharing arrangements on cyber threat information and intelligence
138. Art.45.1 1. Financial entities may exchange amongst themselves Threat 7.4, A.5.6,
cyber threat information and intelligence, including intelligence, A.5.7
indicators of compromise, tactics, techniques, and procedures, Communication
cyber security alerts and configuration tools, to the extent that
such information and intelligence sharing:
(a) aims to enhance the digital operational resilience of financial
entities, in particular through raising awareness in relation to
cyber threats, limiting or impeding the cyber threats’ ability to
spread, supporting defence capabilities, threat detection
techniques, mitigation strategies or response and recovery
stages;
(b) takes places within trusted communities of financial entities;
(c) is implemented through information-sharing arrangements
that protect the potentially sensitive nature of the information
shared, and that are governed by rules of conduct in full respect
of business confidentiality, protection of personal data in
accordance with Regulation (EU) 2016/679 [GDPR] and
guidelines on competition policy.
139. Art.45.2 2. … The information-sharing arrangements shall define Threat 7.4, A.5.5,
the conditions for participation and, where appropriate, shall intelligence, A.5.6, A.5.7,
set out the details on the involvement of public authorities and Communication A.5.20
the capacity in which they may be associated to the
information-sharing arrangements, on the involvement of ICT
third-party service providers, and on operational elements,
including the use of dedicated IT platforms.
140. Art.45.3 3. Financial entities shall notify competent authorities of Threat 7.4, A.5.5
their participation in the information-sharing intelligence,
arrangements, upon validation of their membership, or, as Communication
applicable, of the cessation of their membership, once it takes
effect.

All EU DORA-related documents – [Link]


All NIS 2 Directive - related documents – [Link]

See also: ISMS Implementation Toolkit (ISO 27001)-


[Link]/posts/47806655

Andrey Prozorov, CISM, CIPP/E, CDPSE, LA 27001


TLP:GREEN [Link]/AndreyProzorov || [Link]/in/AndreyProzorov

TLP:GREEN 
Andrey Prozorov, CISM, CIPP/E, CDPSE, LA 27001 
www.patreon.com/AndreyProzorov || www.linkedin.com/in/AndreyProzor
TLP:GREEN 
EU DORA and ISO 27001:2022  
1.0, 10.04.2024 
 
TLP:GREEN 
Andrey Prozorov, CISM, CIPP/E, CDPSE, LA 27001 
www.pat
TLP:GREEN 
EU DORA and ISO 27001:2022  
1.0, 10.04.2024 
 
TLP:GREEN 
Andrey Prozorov, CISM, CIPP/E, CDPSE, LA 27001 
www.pat
TLP:GREEN 
EU DORA and ISO 27001:2022  
1.0, 10.04.2024 
 
TLP:GREEN 
Andrey Prozorov, CISM, CIPP/E, CDPSE, LA 27001 
www.pat
TLP:GREEN 
EU DORA and ISO 27001:2022  
1.0, 10.04.2024 
 
TLP:GREEN 
Andrey Prozorov, CISM, CIPP/E, CDPSE, LA 27001 
www.pat
TLP:GREEN 
EU DORA and ISO 27001:2022  
1.0, 10.04.2024 
 
TLP:GREEN 
Andrey Prozorov, CISM, CIPP/E, CDPSE, LA 27001 
www.pat
TLP:GREEN 
EU DORA and ISO 27001:2022  
1.0, 10.04.2024 
 
TLP:GREEN 
Andrey Prozorov, CISM, CIPP/E, CDPSE, LA 27001 
www.pat
TLP:GREEN 
EU DORA and ISO 27001:2022  
1.0, 10.04.2024 
 
TLP:GREEN 
Andrey Prozorov, CISM, CIPP/E, CDPSE, LA 27001 
www.pat
TLP:GREEN 
EU DORA and ISO 27001:2022  
1.0, 10.04.2024 
 
TLP:GREEN 
Andrey Prozorov, CISM, CIPP/E, CDPSE, LA 27001 
www.pat
TLP:GREEN 
EU DORA and ISO 27001:2022  
1.0, 10.04.2024 
 
TLP:GREEN 
Andrey Prozorov, CISM, CIPP/E, CDPSE, LA 27001 
www.pat

You might also like