DORA
DORA Chapter II: ICT Risk Management

DORA DORA-Art.13: Learning and evolving

Financial entities shall gather information on vulnerabilities, cyber threats and ICT-related incidents, conduct post-incident reviews, and continuously evolve the ICT risk management framework, ICT security awareness programmes and digital operational resilience training.

What else in your programme already covers this

This control maps to 96 controls across 19 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

FedRAMP Moderate · 9 controls

  • AT-1 Policy and Procedures
  • AT-2 Literacy Training and Awareness
  • AT-3 Role-Based Training
  • AT-4 Training Records
  • CA-5 Plan of Action and Milestones
  • CP-3 Contingency Training
  • IR-2 Incident Response Training
  • RA-5 Vulnerability Monitoring and Scanning
  • RA-7 Risk Response

FedRAMP High · 8 controls

  • AT-1 Policy and Procedures
  • AT-2 Literacy Training and Awareness
  • AT-3 Role-Based Training
  • AT-4 Training Records
  • CA-5 Plan of Action and Milestones
  • CP-3 Contingency Training
  • IR-2 Incident Response Training
  • RA-5 Vulnerability Monitoring and Scanning
  • AT-1 Policy and Procedures
  • AT-2 Literacy Training and Awareness
  • AT-3 Role-Based Training
  • AT-4 Training Records
  • CA-5 Plan of Action and Milestones
  • CP-3 Contingency Training
  • IR-2 Incident Response Training
  • RA-5 Vulnerability Monitoring and Scanning
  • AT-1 Policy and Procedures
  • AT-2 Literacy Training and Awareness
  • AT-3 Role-Based Training
  • AT-4 Training Records
  • CA-5 Plan of Action and Milestones
  • CP-3 Contingency Training
  • IR-2 Incident Response Training
  • RA-5 Vulnerability Monitoring and Scanning
  • AT-1 Policy and Procedures
  • AT-2 Literacy Training and Awareness
  • AT-3 Role-Based Training
  • AT-4 Training Records
  • CA-5 Plan of Action and Milestones
  • CP-3 Contingency Training
  • IR-2 Incident Response Training
  • RA-5 Vulnerability Monitoring and Scanning

NIS2 Directive · 5 controls

  • Art.20.2 Train the management body, and offer equivalent training to staff on a regular basis
  • Art.21.2.b Incident handling
  • Art.21.2.e Security in acquisition, development and maintenance, including vulnerability handling and disclosure
  • Art.21.2.g Basic cyber hygiene practices and cybersecurity training
  • Art.23.4.d Submit a final report within one month, and a progress report where the incident is still running
  • NIST-CSF-ID.IM-01 Improvements are identified from evaluations
  • NIST-CSF-ID.IM-03 Improvements are identified from execution of operational processes, procedures, and activities
  • NIST-CSF-ID.RA-01 Vulnerabilities in assets are identified, validated, and recorded
  • NIST-CSF-PR.AT-01 Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind
  • NIST-CSF-RS.AN-08 An incident's magnitude is estimated and validated

NIST SP 800-161 Rev 1 · 5 controls

SOC 2 · 5 controls

  • SOC2-CC1.4 COSO principle 4: Demonstrates commitment to attract and retain competent individuals
  • SOC2-CC2.1 COSO principle 13: Obtains and generates relevant, quality information
  • SOC2-CC4.2 COSO principle 17: Evaluates and communicates deficiencies in a timely manner
  • SOC2-CC7.1 Detection and monitoring procedures for security events are in place
  • SOC2-CC7.5 Identifies the root cause of security incidents

C5 (Germany) · 4 controls

  • C5-DEV-04 Safety training and awareness programme regarding continuous software delivery and associated systems, components or tools
  • C5-HR-03 Security training and awareness programme
  • C5-OPS-18 Managing Vulnerabilities, Malfunctions and Errors - Concept
  • C5-SIM-05 Evaluation and learning process

CIS Controls v8 · 4 controls

  • CIS-14.1 Establish and Maintain a Security Awareness Program
  • CIS-14.9 Conduct Role-Specific Security Awareness and Skills Training
  • CIS-17.8 Conduct Post-Incident Reviews
  • CIS-7.1 Establish and Maintain a Vulnerability Management Process

ISO 27001:2022 · 4 controls

  • 5.27 Learning from information security incidents
  • 5.7 Threat intelligence
  • 6.3 Information security awareness, education and training
  • 8.8 Management of technical vulnerabilities

ISO 27002:2022 · 4 controls

  • 5.27 Learning from information security incidents
  • 5.7 Threat intelligence
  • 6.3 Information security awareness, education and training
  • 8.8 Management of technical vulnerabilities

NIST SP 800-53 Rev 5 · 4 controls

  • CPS230-27 Identification and Escalation of Incidents and Near Misses
  • CPS230-P31 Remediation of Material Operational Risk Weaknesses
  • CPS230-P45 Annual Update of the Business Continuity Plan

EU AI Act · 3 controls

  • EUAI-Art.20 Corrective actions and duty of information
  • EUAI-Art.4 AI literacy
  • EUAI-Art.72 Post-market monitoring by providers and post-market monitoring plan for high-risk AI systems
  • CFTC-SS-21 Remediation of Vulnerabilities and Deficiencies
  • CFTC-SS-3 Information Security Category
  • PSD2-Art.98 Article 98 RTS - SCA + common and secure communication (Commission Delegated Regulation (EU) 2018/389)

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in DORA Chapter II: ICT Risk Management

You are reading one control. How much of DORA have you already done?

DORA DORA-Art.13 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of DORA your existing evidence covers. Hold NIS2 Directive and 17 of 26 DORA controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the NIS2 Directive pair alone.

Query this from an agent

The graph holds this control, the 96 it maps to, and the evidence behind each claim, over MCP and REST.