Digital Operational Resilience Act (DORA) — Training Courses

หมวดหมู่:

What Is Digital Operational Resilience?
Digital operational resilience refers to the ability of a financial entity to build, assure, and review its operational integrity and reliability by ensuring, either directly or indirectly through the use of services provided by ICT third-party service providers, the full range of ICT-related capabilities needed to address the security of the network and information systems which a financial entity uses, and which support the continued provision of financial services and their quality, including throughout disruptions.1

As the financial sector heavily relies on digital technologies, new cyber threats continue to emerge. In response, the European Union has developed the Digital Operational Resilience Act (DORA) to enhance digital operational resilience in the financial sector.

What Is DORA?
DORA is a regulation that requires entities in the financial sector to ensure they can withstand, respond to, and recover from all types of ICT-related incidents, risks, and threats. It was enacted by the European Parliament and the Council of the European Union on December 14, 2022, Regulation (EU) 2022/2554, and seeks to harmonize and streamline regulations related to ICT risk management, ensuring consistency and coherence across the EU. DORA requires financial entities to adhere to the principle of proportionality, which considers their operations’ size, risk profile, and complexity.

DORA sets out the key requirements for financial entities in five main areas: ICT risk management: Financial entities must establish and maintain an effective ICT risk management framework to effectively identify, classify, and reduce ICT risks.
Incident management: Financial entities must establish effective incident management and a harmonized framework for reporting major ICT-related incidents to regulatory bodies, facilitating a better understanding of emerging threats and enabling coordinated responses.
Digital operational resilience testing: Financial entities must conduct regular testing to assess their capacity to withstand ICT disruptions. This includes vulnerability assessments and penetration testing, with requirements tailored to the entity’s size and risk profile.
Third-party risk management: Recognizing the increasing reliance on third-party service providers, including cloud services, DORA sets out rules for managing ICT risks in the supply chain, ensuring that financial entities have oversight over the resilience of their critical third-party providers.
Information and intelligence sharing: DORA encourages financial entities to share cyber threat intelligence and other relevant information to enhance collective understanding and defense mechanisms against ICT threats.

Shopping Cart
Scroll to Top