DORA
DORA Chapter IV: Digital Operational Resilience Testing

DORA DORA-Art.25: Testing of ICT tools and systems

The testing programme provides, proportionately under Article 4(2), for appropriate tests such as penetration and end-to-end tests, performance and compatibility testing, scenario-based tests, review of source code where feasible, scans and vulnerability assessments, analysis of open-source components, gap analyses, assessments of network security, reviews of physical security, and questionnaires with scanning software. Central securities depositories and central counterparties also run vulnerability assessments before deploying or redeploying applications or infrastructure components, and ICT services behind critical or important functions (Art. 25(2)). Microenterprises plan their tests by pairing a risk-based approach with strategic planning, weighing the resources and time spent against urgency, risk type, criticality and their capacity to take calculated risks (Art. 25(3)). The at least yearly testing of systems supporting critical or important functions is an Article 24(6) duty on entities other than microenterprises.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 54 controls across 15 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • CFTC-SS-12 Capacity and Performance Planning Category
  • CFTC-SS-13 Vulnerability Testing
  • CFTC-SS-14 External Penetration Testing
  • CFTC-SS-31 Testing Covers Outsourced Resources and Tester Independence from Providers
  • CFTC-SS-34 Internal Penetration Testing
  • CFTC-SS-5 Systems Development and Quality Assurance Category
  • CFTC-SS-6 Physical Security and Environmental Controls Category

FedRAMP High · 6 controls

  • CA-8 Penetration Testing
  • CA-8(1) Penetration Testing | Independent Penetration Testing Agent or Team (CA-8(1))
  • IR-3 Incident Response Testing
  • RA-5 Vulnerability Monitoring and Scanning
  • SA-11 Developer Testing and Evaluation
  • SI-2 Flaw Remediation

FedRAMP Moderate · 6 controls

  • CA-8 Penetration Testing
  • CA-8(1) Penetration Testing | Independent Penetration Testing Agent or Team (CA-8(1))
  • IR-3 Incident Response Testing
  • RA-5 Vulnerability Monitoring and Scanning
  • SA-11 Developer Testing and Evaluation
  • SI-2 Flaw Remediation

CIS Controls v8 · 4 controls

  • CIS-18.2 Perform Periodic External Penetration Tests
  • CIS-18.5 Perform Periodic Internal Penetration Tests
  • CIS-7.5 Perform Automated Vulnerability Scans of Internal Enterprise Assets
  • CIS-7.6 Perform Automated Vulnerability Scans of Externally-Exposed Enterprise Assets

NIST SP 800-53 Rev 5 · 4 controls

  • CPS230-33 Systematic BCP Testing Program
  • CPS230-34 Tailoring of the Testing Program
  • CPS230-P30 Monitoring, Review and Testing of Control Effectiveness

ISO 27001:2022 · 3 controls

  • 7.1 Physical security perimeters
  • 8.29 Security testing in development and acceptance
  • 8.8 Management of technical vulnerabilities

ISO 27002:2022 · 3 controls

  • 7.1 Physical security perimeters
  • 8.29 Security testing in development and acceptance
  • 8.8 Management of technical vulnerabilities
  • NIST-CSF-ID.IM-01 Improvements are identified from evaluations
  • NIST-CSF-ID.RA-01 Vulnerabilities in assets are identified, validated, and recorded
  • NIST-CSF-PR.PS-06 Secure software development practices are integrated, and their performance is monitored throughout the software development life cycle

C5 (Germany) · 2 controls

  • C5-OPS-19 Managing Vulnerabilities, Malfunctions and Errors - Penetration Tests
  • C5-OPS-22 Testing and Documentation of known Vulnerabilities

NIS2 Directive · 2 controls

  • Art.21.2.e Security in acquisition, development and maintenance, including vulnerability handling and disclosure
  • Art.21.2.f Policies and procedures to assess the effectiveness of the cybersecurity risk-management measures

NIST SP 800-161 Rev 1 · 2 controls

SOC 2 · 2 controls

  • SOC2-CC7.1 CC7.1 Detecting configuration changes and new vulnerabilities
  • SOC2-CC8.1 CC8.1 Managing changes to procedures, software, data and infrastructure

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in DORA Chapter IV: Digital Operational Resilience Testing

You are reading one control. How much of DORA have you already done?

DORA DORA-Art.25 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of DORA your existing evidence covers. Hold NIS2 Directive and 17 of 26 DORA controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the NIS2 Directive pair alone.

Query this from an agent

The graph holds this control, the 54 it maps to, and the evidence behind each claim, over MCP and REST.