DORA
DORA Chapter II: ICT Risk Management

DORA DORA-Art.14: Communication

Within their ICT risk management framework, entities keep crisis communication plans to disclose responsibly, at a minimum, major ICT-related incidents and any vulnerabilities to clients, counterparts and, where appropriate, the public; they set communication policies for internal staff and external stakeholders that separate staff involved in response and recovery from staff who only need to be informed, and name at least one person to carry out the incident communication strategy and handle public and media contact. Entities listed in Article 16(1) are outside this Article and follow the simplified framework of Article 16 instead.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 43 controls across 17 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

NIS2 Directive · 5 controls

  • Art.21.2.c Business continuity, backup management, disaster recovery and crisis management
  • Art.21.2.e Security in acquisition, development and maintenance, including vulnerability handling and disclosure
  • Art.21.2.j Multi-factor or continuous authentication, secured communications and secured emergency communications
  • Art.23.1 Notify significant incidents to the CSIRT or competent authority, and warn affected service recipients
  • Art.23.2 Tell affected service recipients about significant cyber threats and the remedies open to them
  • NIST-CSF-RC.CO-03 Recovery activities and progress in restoring operational capabilities are communicated to designated internal and external stakeholders
  • NIST-CSF-RC.CO-04 Public updates on incident recovery are shared using approved methods and messaging
  • NIST-CSF-RS.CO-02 Internal and external stakeholders are notified of incidents
  • NIST-CSF-RS.CO-03 Information is shared with designated internal and external stakeholders

C5 (Germany) · 3 controls

  • C5-IDM-07 Access to cloud customer data
  • C5-OPS-21 Involvement of Cloud Customers in the Event of Incidents
  • C5-SIM-03 Documentation and reporting of security incidents

CIS Controls v8 · 3 controls

  • CIS-17.2 Establish and Maintain Contact Information for Reporting Security Incidents
  • CIS-17.3 Establish and Maintain an Enterprise Process for Reporting Incidents
  • CIS-17.6 Define Mechanisms for Communicating During Incident Response

FedRAMP High · 3 controls

  • IR-6 Incident Reporting
  • IR-8 Incident Response Plan
  • SI-5 Security Alerts, Advisories, and Directives

FedRAMP Moderate · 3 controls

  • IR-6 Incident Reporting
  • IR-8 Incident Response Plan
  • SI-5 Security Alerts, Advisories, and Directives

ISO/IEC 23894:2023 · 3 controls

  • 23894-5.5 Communication and Consultation
  • ISO23894-6.1 Communication and Consultation
  • 6.2 Communication and consultation

NIST SP 800-53 Rev 5 · 3 controls

SOC 2 · 3 controls

  • SOC2-CC2.2 CC2.2 Internal communication of objectives and control responsibilities (COSO principle 14)
  • SOC2-CC2.3 CC2.3 Communication with external parties about internal control (COSO principle 15)
  • SOC2-P6.6 P6.6 Notifying breaches and incidents

ISO 27001:2022 · 2 controls

  • 5.24 Information security incident management planning and preparation 
  • 5.5 Contact with authorities

ISO 27002:2022 · 2 controls

  • 5.24 Information security incident management planning and preparation
  • 5.5 Contact with authorities

GDPR · 1 control

  • GDPR-Art.34 Communication of a personal data breach to the data subject

ISO 10006:2003 · 1 control

  • 7.6 Communication-related processes

ISO 27005:2022 · 1 control

  • 10.3 Communication and consultation

ISO 31000:2018 · 1 control

  • 6.2 Communication and consultation

ISO/IEC 42001:2023 · 1 control

  • A.8.4 Communication of incidents

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in DORA Chapter II: ICT Risk Management

You are reading one control. How much of DORA have you already done?

DORA DORA-Art.14 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of DORA your existing evidence covers. Hold NIS2 Directive and 17 of 26 DORA controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the NIS2 Directive pair alone.

Query this from an agent

The graph holds this control, the 43 it maps to, and the evidence behind each claim, over MCP and REST.