+DORA Ch. II Sec. II Art. 13 2.

DORA Ch. II Sec. II Art. 13 2.

2.   Financial entities shall put in place post ICT-related incident reviews after a major ICT-related incident disrupts their core activities, analysing the causes of disruption and identifying required improvements to the ICT operations or within the ICT business continuity policy referred to in Article 11.

Financial entities, other than microenterprises, shall, upon request, communicate to the competent authorities, the changes that were implemented following post ICT-related incident reviews as referred to in the first subparagraph.

The post ICT-related incident reviews referred to in the first subparagraph shall determine whether the established procedures were followed and the actions taken were effective, including in relation to the following:

  • (a) the promptness in responding to security alerts and determining the impact of ICT-related incidents and their severity;
  • (b) the quality and speed of performing a forensic analysis, where deemed appropriate;
  • (c) the effectiveness of incident escalation within the financial entity;
  • (d) the effectiveness of internal and external communication.

1. Übersicht

Bezeichnung Regulierung

1.1 Referenzen

1.2 Identifizierte Anforderungen

1.3 Related Standards

2. Identifizierte Anforderungen

Anforderungen
Source Anforderung

3. Related Standards

Standards
Source Anforderung
NOREA Incident Management Process

Implement an incident management process to detect, manage, and report ICT incidents. This includes incident response procedures to mitigate impacts and ensure timely restoration of services. Assign specific roles and responsibilities for various incident scenarios. Also, establish a list of contacts with internal functions and external stakeholders that are directly involved in ICT operations security, including on detection and monitoring cyber threats, detection of anomalous activities and vulnerability management. Establish early warning indicators for potential incidents and incident triggers upon the occurance of malicious activity, data losses, adverse impact detected on financial entity's transactions and operations, systems and network unavailability, problems reported by users of the financial entity, and incident notifications from an third-party service provider detected in the systems and networks of the third-party service provider and which may affect the financial entity. Identify, document, and address incident root causes. Conduct post-ICT-related incident reviews after major disruptions. Analyze causes, evaluate response promptness and quality, and assess incident escalation and communication effectiveness.

NOREA Incident Tracking

Develop procedures to identify, track, log, categorize, and classify ICT-related incidents based on priority, severity, and criticality of impacted services. Maintain records of all ICT-related incidents and significant cyber threats. Implement a monitoring process to track incidents and cyber threats.

NOREA Incident Communication and Reporting

Create communication plans to inform both internal (staff, senior management) and external (clients/customers, financial counterparts) stakeholders on incidents. Designate at least one person in the to be tasked with implementing the communication strategy for ICT- related incidents and fulfil the public and media function for that purpose. Inform affected customers promptly upon awareness of an incident that impacts them. Provide details on the incident and outline mitigating measures taken and planned. Report major incidents to the regulator, involving three stages: 1) initial notification upon discovering the incident (within 4 hours from the moment of classification of the incident as major, but no later than 24 hours from the time of detection of the incident) , 2) intermediate report on incident developments (within 72 hours from the submission of the initial notification even where the status or the handling of the incident have not changed, or when regular activities have been recovered), and 3) the final report with the root cause analysis and follow-up actions (no later than one month from the submission of the latest updated intermediate report). 

The reporting obligations may be outsourced to a third-party service provider. In case of such outsourcing, the financial entity remains fully responsible for the fulfilment of the incident reporting requirements.

Also provide notifications to the regulator on significant cyber threats. The incident reports and notifications on cyber threats shall follow the content guidelines defined in the corresponding RTS/ITS. 

SCF Contingency Plan Root Cause Analysis (RCA) & Lessons Learned

Description

Mechanisms exist to conduct a Root Cause Analysis (RCA) and "lessons learned" activity every time the contingency plan is activated.

Possible Solutions & Considerations

Micro-Small Business (<10 staff) / BLS Firm Size Classes 1-2

∙ Root Cause Analysis (RCA) (After Action Review (AAR), lessons learned, etc.)

Small Business (10-49 staff) / BLS Firm Size Classes 3-4

∙ Root Cause Analysis (RCA) (After Action Review (AAR), lessons learned, etc.)

Medium Business (50-249 staff) / BLS Firm Size Classes 5-6

∙ Root Cause Analysis (RCA) (After Action Review (AAR), lessons learned, etc.)

Large Business (250-999 staff) / BLS Firm Size Classes 7-8

∙ Root Cause Analysis (RCA) (After Action Review (AAR), lessons learned, etc.)

Enterprise (> 1,000 staff) / BLS Firm Size Class 9

∙ Root Cause Analysis (RCA) (After Action Review (AAR), lessons learned, etc.)

SCR-CMM

Level 0 Not Performed

Practices are non-existent, based on the inability to demonstrate an implemented and operational capability. A reasonable person would conclude the control is not being performed.

Level 1 Performed Informally

Business Continuity & Disaster Recovery (BCD) domain capabilities are ad hoc and inconsistent. Capability criteria associated with this control may include:
▪ Policies, standards & procedures associated with BCD domain capabilities provide limited coverage due to the depth and breadth of the existing documentation.
▪ Contingency management-related activities are decentralized (e.g., a localized/regionalized function) and uses non-standardized methods to implement secure, resilient and compliant practices.
▪ Limited technologies exist to support near real-time network infrastructure failover (e.g., redundant ISPs, redundant power, etc.).

Level 2 Planned Tracked

Business Continuity & Disaster Recovery (BCD) capabilities are requirements-driven, but are not standardized across the entity (e.g., local/regional level consistency). Capability criteria associated with this control reasonably expect the following criteria to exist:
▪ Policies and standards associated with BCD domain capabilities are formally documented and centrally-managed by the entity.
▪ Standardized Operating Procedures (SOP) associated with BCD domain capabilities are documented and maintained by process owners.
▪ IT and/or cybersecurity personnel work with business stakeholders and process owners to appropriately scope and reasonably implement cybersecurity and data protection controls associated with BCD domain capabilities to address applicable statutory, regulatory and/or contractual requirements for Technology Assets, Applications, Services and/or Data (TAASD).
▪ Business Continuity / Disaster Recovery (BC/DR)-related controls are primarily administrative and preventative in nature (e.g., policies, standards, procedures & guidelines).
▪ BC/DR may be a defined function (e.g., team or department) or assigned as an additional duty to existing IT and/or cybersecurity personnel.

Level 3 Well Defined

Business Continuity & Disaster Recovery (BCD) capabilities are standardized across the entity for applicability to People, Processes, Technologies, Data and/or Facilities (PPTDF) to ensure consistency for Technology Assets, Applications, Services and/or Data (TAASD). Capability criteria associated with this control reasonably expect the following criteria to exist:
▪ Policies and standards associated with BCD domain capabilities are formally documented and centrally-managed by the entity's Governance, Risk & Compliance (GRC) team, or similar function.
▪ Standardized Operating Procedures (SOP) associated with BCD domain capabilities are well-documented and kept current by process owners.
▪ A Business Continuity & Disaster Recovery (BC/DR) team, or similar function, is appropriately staffed and supported to implement and maintain BCD domain capabilities.
▪ Technology is leveraged to enhance the efficiency and accuracy of BC/DR operations (e.g., BC/DR planning software, Disaster Recovery as a Service (DRaaS), Orchestration and Automation Tools, etc.).
▪ The entity's Governance, Risk & Compliance (GRC) team, or similar function, works with business stakeholders and process owners to appropriately scope and reasonably implement cybersecurity and data protection controls associated with BCD domain capabilities to address Minimum Compliance Requirements (MCR) (e.g., applicable statutory, regulatory and/or contractual requirements) and Discretionary Security Requirements (DSR) (e.g., entity-required controls).
▪ An implemented and operational capability exists to conduct a Root Cause Analysis (RCA) and "lessons learned" activity every time the contingency plan is activated.

Level 4 Quantitatively Controlled

Utilize SCR-CMM Level 3 criteria definitions:
▪ There are no defined Level 4 criteria, since it is reasonable to assume a quantitatively-controlled process is not necessary to operationalize this control.
▪ While it may be possible to develop “metrics-driven” capabilities for this control, the criteria would be organization-specific to define.

Level 5 Continuously Improving

Utilize SCR-CMM Level 3 or Level 4 (if available) criteria definitions:
▪ There are no defined Level 5 criteria, since it is reasonable to assume a continuously-improving process is not necessary to operationalize this control.
▪ Level 5 capabilities should be considered “world-class” where the control builds on Level 4 capabilities, but are continuously improving through Artificial Intelligence (AI) and/or Machine Learning (ML) technologies.
▪ While it may be possible to develop responsive capabilities for this control through the use of AI and/or ML technologies, the criteria would be organization-specific to define.
SCF Root Cause Analysis (RCA) & Lessons Learned

Description

Mechanisms exist to incorporate lessons learned from analyzing and resolving cybersecurity and data protection incidents to reduce the likelihood or impact of future incidents.

Possible Solutions & Considerations

Micro-Small Business (<10 staff) / BLS Firm Size Classes 1-2

∙ Root Cause Analysis (RCA)

Small Business (10-49 staff) / BLS Firm Size Classes 3-4

∙ Root Cause Analysis (RCA)

Medium Business (50-249 staff) / BLS Firm Size Classes 5-6

∙ Root Cause Analysis (RCA)

Large Business (250-999 staff) / BLS Firm Size Classes 7-8

∙ Root Cause Analysis (RCA)

Enterprise (> 1,000 staff) / BLS Firm Size Class 9

∙ Root Cause Analysis (RCA)

SCR-CMM

Level 0 Not Performed

Practices are non-existent, based on the inability to demonstrate an implemented and operational capability. A reasonable person would conclude the control is not being performed.

Level 1 Performed Informally

SCR-CMM Level 1 criteria definitions are not available for this control:
▪ A reasonable person would conclude this control requires a structured process.
▪ At this level of maturity, the "ad hoc" nature of performing a capability informally would indicate the intent of the control is not met due to a lack of consistency and formality.

Level 2 Planned Tracked

Incident Response (IRO) capabilities are requirements-driven, but are not standardized across the entity (e.g., local/regional level consistency). Capability criteria associated with this control reasonably expect the following criteria to exist:
▪ Policies and standards associated with IRO domain capabilities are formally documented and centrally-managed by the entity.
▪ Standardized Operating Procedures (SOP) associated with DCH domain capabilities are documented and maintained by process owners.
▪ IT and/or cybersecurity personnel work with business stakeholders and process owners to appropriately scope and reasonably implement cybersecurity and data protection controls associated with IRO domain capabilities to address applicable statutory, regulatory and/or contractual requirements for Technology Assets, Applications, Services and/or Data (TAASD).
▪ Incident response-related controls are primarily administrative and preventative in nature (e.g., policies, standards, procedures & guidelines).
▪ Incident response management may be a defined function (e.g., team or department) or assigned as an additional duty to existing IT and/or cybersecurity personnel.
▪ IT and/or cybersecurity personnel operate an incident response capability using a documented and tested Incident Response Plan (IRP) to facilitate incident management operations that cover preparation, detection and analysis, containment, eradication and recovery.
▪ Incident responders provide After Action Review (AAR) feedback on what worked, what did not work and ways to improve future responses to similar incidents.
▪ A formal Root Cause Analysis (RCA) is performed that documents the findings in a report for both technical and business leadership management.

Level 3 Well Defined

Incident Response (IRO) capabilities are standardized across the entity for applicability to People, Processes, Technologies, Data and/or Facilities (PPTDF) to ensure consistency for Technology Assets, Applications, Services and/or Data (TAASD). Capability criteria associated with this control reasonably expect the following criteria to exist:
▪ Policies and standards associated with IRO domain capabilities are formally documented and centrally-managed by the entity's Governance, Risk & Compliance (GRC) team, or similar function.
▪ Cybersecurity personnel operate an incident response capability using a documented and tested Incident Response Plan (IRP) to facilitate incident management operations that cover preparation, detection and analysis, containment, eradication and recovery.
▪ An incident response team, or similar function, is appropriately staffed and supported to implement and maintain IRO domain capabilities.
▪ Technology is leveraged to enhance the efficiency and accuracy of incident response operations (e.g., incident management software, etc.).
▪ The entity's Governance, Risk & Compliance (GRC) team, or similar function, works with business stakeholders and process owners to appropriately scope and reasonably implement cybersecurity and data protection controls associated with IRO domain capabilities to address Minimum Compliance Requirements (MCR) (e.g., applicable statutory, regulatory and/or contractual requirements) and Discretionary Security Requirements (DSR) (e.g., entity-required controls).
▪ An implemented and operational capability exists to incorporate lessons learned from analyzing and resolving cybersecurity and data protection incidents to reduce the likelihood or impact of future incidents.

Level 4 Quantitatively Controlled

Incident Response (IRO) capabilities, in addition to being standardized across the entity and centrally managed to ensure consistency across Technology Assets, Applications, Services and/or Data (TAASD), efforts are metrics driven to provide sufficient insight for decision makers to predict optimal performance, ensure continued operations and/or identify areas for improvement. Capability criteria associated with this control reasonably expect the following criteria to exist:
▪ Applicable SCR-CMM Level 3 (Well Defined) capabilities are implemented and operational.
▪ Metrics reporting includes quantitative analysis of Key Performance Indicators (KPIs).
▪ Metrics reporting includes quantitative analysis of Key Risk Indicators (KRIs).
▪ Scope of metrics, KPIs and KRIs covers organization-wide cybersecurity and data protection controls, including functions performed by third-parties.
▪ Organizational leadership maintains a formal process to objectively review and respond to metrics, KPIs and KRIs (e.g., monthly or quarterly review).
▪ Based on metrics analysis, process improvement recommendations are submitted for review and are handled in accordance with change control processes.
▪ Business and technical stakeholders are involved in reviewing and approving proposed changes to evolve capabilities.

Level 5 Continuously Improving

Utilize SCR-CMM Level 3 or Level 4 (if available) criteria definitions:
▪ There are no defined Level 5 criteria, since it is reasonable to assume a continuously-improving process is not necessary to operationalize this control.
▪ Level 5 capabilities should be considered “world-class” where the control builds on Level 4 capabilities, but are continuously improving through Artificial Intelligence (AI) and/or Machine Learning (ML) technologies.
▪ While it may be possible to develop responsive capabilities for this control through the use of AI and/or ML technologies, the criteria would be organization-specific to define.
Impressum Deutsch Englisch