EvidenceSheet

DORA: the evidence behind every control

26 controls. For each, the artefacts auditors ask for, which ones a system already holds, and the first move to stop evidencing it by periodic review.

DORA Chapter II: ICT Risk Management

Art.5Governance and organisation hardArt.6ICT risk management framework hardArt.7ICT systems, protocols and tools hardArt.8Identification hardArt.9Protection and prevention hardArt.10Detection easyArt.11Response and recovery hardArt.12Backup policies and procedures, restoration and recovery hardArt.13Learning and evolving hardArt.14Communication hardArt.16Simplified ICT risk management framework hard

DORA Chapter III: ICT-Related Incident Management

Art.17ICT-related incident management process easyArt.18Classification of ICT-related incidents and cyber threats hardArt.19Reporting of major ICT-related incidents hardArt.23Operational or security payment-related incidents hard

DORA Chapter IV: Digital Operational Resilience Testing

Art.24General requirements for the performance of digital operational resilience testing hardArt.25Testing of ICT tools and systems hardArt.26Advanced testing of ICT tools, systems and processes based on TLPT hardArt.27Requirements for testers for the carrying out of TLPT hard

DORA Chapter V: ICT Third-Party Risk Management

Art.28ICT third-party risk: general principles hardArt.29Preliminary assessment of ICT concentration risk at entity level hardArt.30Key contractual provisions hardArt.31Designation of critical ICT third-party service providers hard

DORA Chapters VI-VII: Information Sharing, Penalties and Data Protection

Art.45Information-sharing arrangements on cyber threat information and intelligence hardArt.50Administrative penalties and remedial measures hardArt.56Data protection hard