DORA
DORA Chapter IV: Digital Operational Resilience Testing

DORA DORA-Art.27: Requirements for testers for the carrying out of TLPT

Entities required to perform TLPT use only testers that are highly suitable and reputable, have the technical and organisational capability and specific expertise in threat intelligence, penetration and red team testing, hold certification from a Member State accreditation body or subscribe to a formal code of conduct or ethics framework, give independent assurance or an audit report on how they manage TLPT risks (including protection of confidential information and redress), and hold full professional indemnity insurance that also covers misconduct and negligence. These conditions apply to every tester, internal or external. Internal testers may be used only where the competent authority or the designated TLPT authority has approved it, the authority has verified sufficient dedicated resources and no conflicts of interest, and the threat intelligence provider is external (Art. 27(2)). Contracts with external testers must require sound management of TLPT results and data so they create no risk to the entity (Art. 27(3)).

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 10 controls across 8 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

FedRAMP High · 2 controls

  • CA-2(1) Independent Assessors
  • CA-8(1) Penetration Testing | Independent Penetration Testing Agent or Team (CA-8(1))

FedRAMP Moderate · 2 controls

  • CA-2(1) Independent Assessors
  • CA-8(1) Penetration Testing | Independent Penetration Testing Agent or Team (CA-8(1))

C5 (Germany) · 1 control

  • C5-OPS-19 Managing Vulnerabilities, Malfunctions and Errors - Penetration Tests

CIS Controls v8 · 1 control

  • CIS-18.1 Establish and Maintain a Penetration Testing Program
  • TIBER-1.4 Procurement of threat intelligence and red team providers

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in DORA Chapter IV: Digital Operational Resilience Testing

You are reading one control. How much of DORA have you already done?

DORA DORA-Art.27 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of DORA your existing evidence covers. Hold NIS2 Directive and 17 of 26 DORA controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the NIS2 Directive pair alone.

Query this from an agent

The graph holds this control, the 10 it maps to, and the evidence behind each claim, over MCP and REST.