DORA: the evidence behind every control
26 controls. For each, the artefacts auditors ask for, which ones a system already holds, and the first move to stop evidencing it by periodic review.
DORA Chapter II: ICT Risk Management
Art.5Governance and organisation hardArt.6ICT risk management framework hardArt.7ICT systems, protocols and tools hardArt.8Identification hardArt.9Protection and prevention hardArt.10Detection easyArt.11Response and recovery hardArt.12Backup policies and procedures, restoration and recovery hardArt.13Learning and evolving hardArt.14Communication hardArt.16Simplified ICT risk management framework hardDORA Chapter III: ICT-Related Incident Management
Art.17ICT-related incident management process easyArt.18Classification of ICT-related incidents and cyber threats hardArt.19Reporting of major ICT-related incidents hardArt.23Operational or security payment-related incidents hardDORA Chapter IV: Digital Operational Resilience Testing
Art.24General requirements for the performance of digital operational resilience testing hardArt.25Testing of ICT tools and systems hardArt.26Advanced testing of ICT tools, systems and processes based on TLPT hardArt.27Requirements for testers for the carrying out of TLPT hardDORA Chapter V: ICT Third-Party Risk Management
Art.28ICT third-party risk: general principles hardArt.29Preliminary assessment of ICT concentration risk at entity level hardArt.30Key contractual provisions hardArt.31Designation of critical ICT third-party service providers hard