DORA
DORA Chapter V: ICT Third-Party Risk Management

DORA DORA-Art.28: ICT third-party risk: general principles

Financial entities shall manage ICT third-party risk as an integral component of ICT risk, maintain a Register of Information on all contractual arrangements for the use of ICT services, report it to competent authorities, assess risk before entering arrangements (including concentration and subcontracting), and adopt an ICT third-party risk strategy.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 76 controls across 23 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

FedRAMP High · 7 controls

  • SA-9 External System Services
  • SR-1 Policy and Procedures (SR-1)
  • SR-10 Inspection of Systems or Components (SR-10)
  • SR-11 Component Authenticity (SR-11)
  • SR-2 Supply Chain Risk Management Plan (SR-2)
  • SR-3 Supply Chain Controls and Processes (SR-3)
  • SR-6 Supplier Assessments and Reviews (SR-6)

FedRAMP Moderate · 7 controls

  • SA-9 External System Services
  • SR-1 Policy and Procedures (SR-1)
  • SR-10 Inspection of Systems or Components (SR-10)
  • SR-11 Component Authenticity (SR-11)
  • SR-2 Supply Chain Risk Management Plan (SR-2)
  • SR-3 Supply Chain Controls and Processes (SR-3)
  • SR-6 Supplier Assessments and Reviews (SR-6)

NIST SP 800-161 Rev 1 · 6 controls

  • CPS230-37 Service Provider Management Policy
  • CPS230-39 Register of Material Service Providers
  • CPS230-47 Monitoring and Senior Management Reporting on Material Arrangements
  • CPS230-P51 Annual Submission of the Material Service Provider Register to APRA
  • CPS230-P59 APRA Notification of Service Agreements and Offshoring

ISO 27001:2022 · 5 controls

  • 5.19 Information security in supplier relationships
  • 5.21 Managing information security in the information and communication technology (ICT) supply chain
  • 5.22 Monitoring, review and change management of supplier services
  • 5.23 Information security for use of cloud services
  • 8.30 Outsourced development

ISO 27002:2022 · 5 controls

  • 5.19 Information security in supplier relationships
  • 5.21 Managing information security in the ICT supply chain
  • 5.22 Monitoring, review and change management of supplier services
  • 5.23 Information security for use of cloud services
  • 8.30 Outsourced development

NIST SP 800-53 Rev 5 · 5 controls

CIS Controls v8 · 4 controls

  • CIS-15.1 Establish and Maintain an Inventory of Service Providers
  • CIS-15.2 Establish and Maintain a Service Provider Management Policy
  • CIS-15.5 Assess Service Providers
  • CIS-15.6 Monitor Service Providers
  • NIST-CSF-GV.SC-01 A cybersecurity supply chain risk management program, strategy, objectives, policies, and processes are established and agreed to by organizational stakeholders
  • NIST-CSF-GV.SC-03 Cybersecurity supply chain risk management is integrated into cybersecurity and enterprise risk management, risk assessment, and improvement processes
  • NIST-CSF-GV.SC-06 Planning and due diligence are performed to reduce risks before entering into formal supplier or other third-party relationships
  • NIST-CSF-ID.AM-04 Inventories of services provided by suppliers are maintained

C5 (Germany) · 3 controls

  • C5-SSO-01 Policies and instructions for controlling and monitoring third parties
  • C5-SSO-02 Risk assessment of service providers and suppliers
  • C5-SSO-03 Directory of service providers and suppliers

NIS2 Directive · 3 controls

  • Art.21.2.d Supply chain security, covering the relationship with each direct supplier and service provider
  • Art.21.3 Take account of supplier-specific vulnerabilities and of Union coordinated supply chain risk assessments
  • Art.3.4 Submit and maintain entity registration information with the competent authority

SOC 2 · 3 controls

  • SOC2-CC3.2 CC3.2 Identifying and analysing risks to objectives (COSO principle 7)
  • SOC2-CC9.2 CC9.2 Assessing and managing vendor and business partner risk
  • SOC2-P6.4 P6.4 Privacy commitments from vendors and third parties
  • CFTC-SS-26 Own Resources or Contractual Arrangements to Meet the Recovery Objective
  • CFTC-SS-30 Outsourcing with Retention of Complete Responsibility
  • CRA-Art.13_AnnexI Manufacturer obligations and essential requirements (Article 13 + Annex I)
  • CRA-Art.14_16 Reporting obligations and the single reporting platform (Articles 14 and 16)
  • EBA-GL-3.2.3 Use of third party providers

EU AI Act · 1 control

  • PSD2-Art.19_20 Use of agents and outsourcing rules (PSD2 Articles 19 and 20)

GDPR · 1 control

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in DORA Chapter V: ICT Third-Party Risk Management

You are reading one control. How much of DORA have you already done?

DORA DORA-Art.28 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of DORA your existing evidence covers. Hold NIS2 Directive and 17 of 26 DORA controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the NIS2 Directive pair alone.

Query this from an agent

The graph holds this control, the 76 it maps to, and the evidence behind each claim, over MCP and REST.