DORA
DORA Chapter II: ICT Risk Management

DORA DORA-Art.9: Protection and prevention

Financial entities keep the security and operation of ICT systems and tools under continuous monitoring and control and limit ICT risk with security policies, procedures, protocols and tooling designed to keep ICT systems (above all those supporting critical or important functions) resilient and available, and protect data at rest, in use and in transit. The chosen solutions must be appropriate under Article 4 and cover secure data transfer, data loss and corruption, unauthorised access and data management risk. Within the ICT risk management framework they keep an information security policy (covering customer data where applicable), a risk-based network and infrastructure management structure that can cut or segment connections at once, least-privilege access controls, strong authentication and cryptographic key protection, a risk-based ICT change management process approved by management, and documented patch and update policies. Entities listed in Article 16(1) are outside this Article and follow the simplified framework of Article 16 instead.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 114 controls across 18 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO 27001:2022 · 15 controls

  • 5.14 Information transfer
  • 5.15 Access control
  • 5.16 Identity management
  • 5.17 Authentication information
  • 5.18 Access rights
  • 5.37 Documented operating procedures
  • 7.4 Physical security monitoring
  • 8.2 Privileged access rights
  • 8.20 Networks security
  • 8.21 Security of network services
  • 8.24 Use of cryptography
  • 8.3 Information access restriction
  • 8.5 Secure authentication
  • 8.7 Protection against malware
  • 8.9 Configuration management

ISO 27002:2022 · 15 controls

  • 5.14 Information transfer
  • 5.15 Access control
  • 5.16 Identity management
  • 5.17 Authentication information
  • 5.18 Access rights
  • 5.37 Documented operating procedures
  • 7.4 Physical security monitoring
  • 8.2 Privileged access rights
  • 8.20 Networks security
  • 8.21 Security of network services
  • 8.24 Use of cryptography
  • 8.3 Information access restriction
  • 8.5 Secure authentication
  • 8.7 Protection against malware
  • 8.9 Configuration management

C5 (Germany) · 12 controls

  • C5-COS-08 Policies for data transmission
  • C5-CRY-01 Policy for the use of encryption procedures and key management
  • C5-CRY-02 Encryption of data for transmission (transport encryption)
  • C5-CRY-04 Secure key management
  • C5-IDM-01 Policy for user accounts and access rights
  • C5-IDM-03 Locking and withdrawal of user accounts in the event of inactivity or multiple failed logins
  • C5-IDM-05 Regular review of access rights
  • C5-OPS-04 Protection Against Malware - Concept
  • C5-OPS-16 Logging and Monitoring - Configuration
  • C5-OPS-23 Managing Vulnerabilities, Malfunctions and Errors - System Hardening
  • C5-PS-01 Physical Security and Environmental Control Requirements
  • C5-SP-01 Documentation, communication and provision of policies and instructions

SOC 2 · 10 controls

  • SOC2-CC5.1 CC5.1 Selecting control activities that mitigate risk (COSO principle 10)
  • SOC2-CC6.1 CC6.1 Logical access security over protected information assets
  • SOC2-CC6.2 CC6.2 Registering and authorising users before issuing credentials
  • SOC2-CC6.3 CC6.3 Role-based access, least privilege and segregation of duties
  • SOC2-CC6.4 CC6.4 Restricting physical access to facilities and assets
  • SOC2-CC6.6 CC6.6 Protection against threats from outside the system boundary
  • SOC2-CC6.7 CC6.7 Restricting and protecting information in transmission, movement and removal
  • SOC2-CC6.8 CC6.8 Preventing and detecting unauthorised or malicious software
  • SOC2-CC8.1 CC8.1 Managing changes to procedures, software, data and infrastructure
  • SOC2-PI1.2 PI1.2 Controls over system inputs

FedRAMP High · 9 controls

  • AC-2 Account Management
  • AC-3 Access Enforcement
  • CM-6 Configuration Settings
  • CP-9(8) System Backup | Cryptographic Protection (CP-9(8))
  • PE-1 Policy and Procedures
  • SC-13 Cryptographic Protection
  • SC-28 Protection of Information at Rest
  • SC-7 Boundary Protection
  • SC-8 Transmission Confidentiality and Integrity

FedRAMP Moderate · 9 controls

  • AC-2 Account Management
  • AC-3 Access Enforcement
  • CM-6 Configuration Settings
  • CP-9(8) System Backup | Cryptographic Protection (CP-9(8))
  • PE-1 Policy and Procedures
  • SC-13 Cryptographic Protection
  • SC-28 Protection of Information at Rest
  • SC-7 Boundary Protection
  • SC-8 Transmission Confidentiality and Integrity

CIS Controls v8 · 4 controls

  • CIS-12.2 Establish and Maintain a Secure Network Architecture
  • CIS-3.11 Encrypt Sensitive Data at Rest
  • CIS-4.1 Establish and Maintain a Secure Configuration Process
  • CIS-6.8 Define and Maintain Role-Based Access Control

GDPR · 4 controls

  • GDPR-Art.25 Data protection by design and by default
  • GDPR-Art.29 Processing under the authority of the controller or processor
  • GDPR-Art.32 Security of processing
  • GDPR-Art.5 Principles relating to processing of personal data

NIS2 Directive · 4 controls

  • Art.21.2.g Basic cyber hygiene practices and cybersecurity training
  • Art.21.2.h Policies and procedures on the use of cryptography and, where appropriate, encryption
  • Art.21.2.i Human resources security, access control policies and asset management
  • Art.21.2.j Multi-factor or continuous authentication, secured communications and secured emergency communications
  • NIST-CSF-PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties
  • NIST-CSF-PR.DS-01 The confidentiality, integrity, and availability of data-at-rest are protected
  • NIST-CSF-PR.IR-01 Networks and environments are protected from unauthorized logical access and usage
  • NIST-CSF-PR.PS-01 Configuration management practices are established and applied

NIST SP 800-161 Rev 1 · 4 controls

NIST SP 800-53 Rev 5 · 4 controls

  • CPS230-24 Design and Embedding of Internal Controls
  • CPS230-P30 Monitoring, Review and Testing of Control Effectiveness

EU AI Act · 1 control

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in DORA Chapter II: ICT Risk Management

You are reading one control. How much of DORA have you already done?

DORA DORA-Art.9 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of DORA your existing evidence covers. Hold NIS2 Directive and 17 of 26 DORA controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the NIS2 Directive pair alone.

Query this from an agent

The graph holds this control, the 114 it maps to, and the evidence behind each claim, over MCP and REST.