DORA
DORA Chapter II: ICT Risk Management

DORA DORA-Art.7: ICT systems, protocols and tools

Financial entities shall use and maintain ICT systems, protocols and tools that are appropriate to the scale of operations, reliable, with sufficient capacity, and technologically resilient to handle additional information-processing needs under stressed conditions.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 37 controls across 13 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

FedRAMP High · 4 controls

  • AU-4 Audit Log Storage Capacity
  • CP-7 Alternate Processing Site
  • SA-22 Unsupported System Components (SA-22)
  • SC-5 Denial-of-Service Protection

FedRAMP Moderate · 4 controls

  • AU-4 Audit Log Storage Capacity
  • CP-7 Alternate Processing Site
  • SA-22 Unsupported System Components (SA-22)
  • SC-5 Denial-of-Service Protection
  • NIST-CSF-ID.AM-08 Systems, hardware, software, services, and data are managed throughout their life cycles
  • NIST-CSF-PR.IR-03 Mechanisms are implemented to achieve resilience requirements in normal and adverse situations
  • NIST-CSF-PR.IR-04 Adequate resource capacity to ensure availability is maintained
  • NIST-CSF-PR.PS-02 Software is maintained, replaced, and removed commensurate with risk

NIST SP 800-53 Rev 5 · 4 controls

  • CFTC-SS-1 Program of Risk Analysis and Oversight
  • CFTC-SS-12 Capacity and Performance Planning Category
  • CFTC-SS-23 Resources Sufficient to Fulfil Obligations

ISO 27001:2022 · 3 controls

  • 8.14 Redundancy of information processing facilities
  • 8.27 Secure system architecture and engineering principles
  • 8.6 Capacity management

ISO 27002:2022 · 3 controls

  • 8.14 Redundancy of information processing facilities
  • 8.27 Secure system architecture and engineering principles
  • 8.6 Capacity management

SOC 2 · 3 controls

  • SOC2-A1.1 A1.1 Managing processing capacity
  • SOC2-A1.2 A1.2 Environmental protection, backup and recovery infrastructure
  • SOC2-CC5.2 CC5.2 General controls over technology (COSO principle 11)

C5 (Germany) · 2 controls

CIS Controls v8 · 2 controls

  • CIS-12.1 Ensure Network Infrastructure is Up-to-Date
  • CIS-2.2 Ensure Authorized Software is Currently Supported
  • CPS230-P25 Information and Technology Capability and Asset Health

NIS2 Directive · 1 control

  • Art.21.2.g Basic cyber hygiene practices and cybersecurity training

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in DORA Chapter II: ICT Risk Management

You are reading one control. How much of DORA have you already done?

DORA DORA-Art.7 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of DORA your existing evidence covers. Hold NIS2 Directive and 17 of 26 DORA controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the NIS2 Directive pair alone.

Query this from an agent

The graph holds this control, the 37 it maps to, and the evidence behind each claim, over MCP and REST.