+DORA Ch. II Sec. I Art. 5 3.

DORA Ch. II Sec. I Art. 5 3.

3. Financial entities, other than microenterprises, shall establish a role in order to monitor the arrangements concluded with ICT third-party service providers on the use of ICT services, or shall designate a member of senior management as responsible for overseeing the related risk exposure and relevant documentation.

1. Übersicht

Bezeichnung Regulierung

1.1 Referenzen

1.2 Identifizierte Anforderungen

1.3 Related Standards

2. Identifizierte Anforderungen

Anforderungen
Source Anforderung

3. Related Standards

Standards
Source Anforderung
NOREA Governance of ICT risk

The Management body shall take ultimate responsibility for effectively managing all ICT risks of the financial entity. As such, the management body periodically (e.g. annually) ensures:

  • Establish policies related to the availability, authenticity, integrity, and confidentiality of data, including the policy on arrangements with ICT third-party service providers (see control 2.1).
  • Define the roles, responsibilities and goverance arrangements for ICT related functions risk management (including those related to ICT third-party arrangements), including the continuous monitoring thereof.
  • Review the policy on arrangements with ICT third-party service providers and stay informed about third-party  arrangements, services provided, planned material changes regarding third- party service providers, and understand the impact of these changes on critical and important functions of the entity (including risk assessment results). 
NOREA Knowledge of the Management Body
The Management body shall ensure that it is kept up to date with sufficient knowledge and skills to understand and assess ICT risks and operations (e.g. through periodic trainings).
NOREA Digital Operational Resilience Strategy

The Management body shall set and approve the digital operational resilience strategy and periodically update when needed.

The digital operational resilience strategy  must:

  • Set out how the risk management framework will be implemented.
  • Elaborate on the alignment between the risk management framework and the business strategy and objectives.
  • Establish the ICT risk tolerance level (based on risk appetite) and the impact tolerance level for ICT disruptions.
  • Include clear security objectives, including Key Performance Indicators (KPIs) and risk metrics.
  • Elaborate on the ICT reference architecture and any changes needed to reach specific business objectives.
  • Outline the mechanisms in place to detect ICT-related incidents
  • Contain evidence to prove the current digital operational resilience situation (e.g. based on the number of major ICT-related incidents and the effectiveness of preventive measures.
  • Contain how the digital operational resilience testing is implemented (see controls under 19 and 20).
  • Outline the communication strategy in case of incidents (see 11.3)

The Management body shall allocate and review the budget required for resources to fulfill the digital operational resilience needs of the entity.

Ensure monitoring is arranged on the the effectiveness of the implementation of the digital operational resilience.

NOREA Business Continuity Oversight
The Management body reviews and approves periodically (e.g. annually) the ICT business continuity policy and the ICT response and recovery plans.
NOREA Audit Plan Approval and Review
The Management body reviews and approves periodically (e.g. annually) internal ICT audit plans, ICT audits, and material modifications to the audits.
SCF Assigned Security, Compliance & Resilience Responsibilities

Description

Mechanisms exist to assign one or more qualified individuals with the mission and resources to centrally-manage, coordinate, develop, implement and maintain an enterprise-wide Security, Compliance & Resilience Program (SCRP).

Possible Solutions & Considerations

Micro-Small Business (<10 staff) / BLS Firm Size Classes 1-2

∙ Third-party advisors (e.g., virtual CISO (vCISO), Managed Security Services Provider (MSSP))
∙ Designated internal security point of contact
∙ vCISO services (e.g., Truvantis, private vCISO firms)

Small Business (10-49 staff) / BLS Firm Size Classes 3-4

∙ Third-party advisors (e.g., virtual CISO (vCISO), Managed Security Services Provider (MSSP))
∙ Part-time or shared security manager
∙ vCISO services with defined scope and deliverables

Medium Business (50-249 staff) / BLS Firm Size Classes 5-6

∙ Dedicated Information Security Manager (ISM) or fractional CISO
∙ Chief Information Security Officer (CISO) or equivalent role
∙ Defined Information Security Management System (ISMS) ownership

Large Business (250-999 staff) / BLS Firm Size Classes 7-8

∙ Chief Information Security Officer (CISO) with defined authority and budget
∙ Security leadership team (CISO, DPO, IAM lead, etc.)
∙ Security organizational structure with clear reporting lines

Enterprise (> 1,000 staff) / BLS Firm Size Class 9

∙ Chief Information Security Officer (CISO) with C-suite authority and board access
∙ Security leadership organization (CISO, Deputy CISO, DPO, domain leads)
∙ Security Center of Excellence (CoE)
∙ Defined succession planning for key security roles

SCR-CMM

Level 0 Not Performed

Practices are non-existent, based on the inability to demonstrate an implemented and operational capability. A reasonable person would conclude the control is not being performed.

Level 1 Performed Informally

SCR-CMM Level 1 criteria definitions are not available for this control:
▪ A reasonable person would conclude this control requires a structured process.
▪ At this level of maturity, the "ad hoc" nature of performing a capability informally would indicate the intent of the control is not met due to a lack of consistency and formality.

Level 2 Planned Tracked

Cybersecurity & Data Protection Governance (GOV) capabilities are requirements-driven, but are not standardized across the entity (e.g., local/regional level consistency). Capability criteria associated with this control reasonably expect the following criteria to exist:
▪ Policies and standards associated with GOV domain capabilities are formally documented and centrally-managed by the entity.
▪ Standardized Operating Procedures (SOP) associated with GOV domain capabilities are documented and maintained by process owners.
▪ IT and/or cybersecurity personnel work with business stakeholders and process owners to appropriately scope and reasonably implement cybersecurity and data protection controls associated with GOV domain capabilities to address applicable statutory, regulatory and/or contractual requirements for Technology Assets, Applications, Services and/or Data (TAASD).
▪ Governance-related controls are primarily administrative and preventative in nature (e.g., policies, standards, procedures & guidelines).
▪ No formal Governance, Risk & Compliance (GRC) team exists. GRC roles are assigned to existing IT and/or cybersecurity personnel.
▪ A qualified individual is assigned the role and responsibilities to centrally manage, coordinate, develop, implement and maintain a cybersecurity and data protection program (e.g., cybersecurity director or Chief Information Security Officer (CISO)).
▪ The individual assigned the role and responsibilities to centrally manage, coordinate, develop, implement and maintain a cybersecurity and data protection program develops plans to implement the organization's security, compliance and resiliency-related objectives.

Level 3 Well Defined

Cybersecurity & Data Protection Governance (GOV) capabilities are standardized across the entity for applicability to People, Processes, Technologies, Data and/or Facilities (PPTDF) to ensure consistency for Technology Assets, Applications, Services and/or Data (TAASD). Capability criteria associated with this control reasonably expect the following criteria to exist:
▪ Policies and standards associated with GOV domain capabilities are formally documented and centrally-managed by the entity's Governance, Risk & Compliance (GRC) team, or similar function.
▪ Standardized Operating Procedures (SOP) associated with GOV domain capabilities are well-documented and kept current by process owners.
▪ The entity's GRC team, or similar function, is appropriately staffed and supported to implement and maintain GOV domain capabilities to address Minimum Compliance Requirements (MCR) (e.g., applicable statutory, regulatory and/or contractual requirements) and Discretionary Security Requirements (DSR) (e.g., entity-required controls).
▪ Technology is leveraged to enhance the efficiency and accuracy of governance, risk management and compliance operations (e.g., GRC platform).
▪ A qualified individual is assigned the role and responsibilities to centrally-manage, coordinate, develop, implement and maintain an enterprise-wide Security, Compliance & Resilience Program (SCRP) (e.g., cybersecurity director or Chief Information Security Officer (CISO)).

Level 4 Quantitatively Controlled

Utilize SCR-CMM Level 3 criteria definitions:
▪ There are no defined Level 4 criteria, since it is reasonable to assume a quantitatively-controlled process is not necessary to operationalize this control.
▪ While it may be possible to develop “metrics-driven” capabilities for this control, the criteria would be organization-specific to define.

Level 5 Continuously Improving

Utilize SCR-CMM Level 3 or Level 4 (if available) criteria definitions:
▪ There are no defined Level 5 criteria, since it is reasonable to assume a continuously-improving process is not necessary to operationalize this control.
▪ Level 5 capabilities should be considered “world-class” where the control builds on Level 4 capabilities, but are continuously improving through Artificial Intelligence (AI) and/or Machine Learning (ML) technologies.
▪ While it may be possible to develop responsive capabilities for this control through the use of AI and/or ML technologies, the criteria would be organization-specific to define.
Impressum Deutsch Englisch