Financial entities shall gather information on vulnerabilities, cyber threats and ICT-related incidents, conduct post-incident reviews, and continuously evolve the ICT risk management framework, ICT security awareness programmes and digital operational resilience training.
What else in your programme already covers this
This control maps to 96 controls across 19 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
NIST-CSF-ID.IM-03 Improvements are identified from execution of operational processes, procedures, and activities
NIST-CSF-ID.RA-01 Vulnerabilities in assets are identified, validated, and recorded
NIST-CSF-PR.AT-01 Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind
NIST-CSF-RS.AN-08 An incident's magnitude is estimated and validated
You are reading one control. How much of DORA have you already done?
DORA DORA-Art.13 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of DORA your existing evidence covers. Hold NIS2 Directive and 17 of 26 DORA controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the NIS2 Directive pair alone.