EU Digital Operational Resilience Act (2022/2554)
EU regulation establishing uniform requirements for ICT risk management, incident reporting, digital operational resilience testing, and ICT third-party risk management across financial entities. Covers banks, insurers, investment firms, crypto-asset service providers, and critical ICT third-party providers. Requires threat-led penetration testing (TLPT) and comprehensive ICT third-party oversight.
AC (19) AT (6) AU (12) CA (9) CM (11) CP (12) IA (9) IR (9) MA (7) MP (7) PE (3) PL (9) PM (4) PS (9) PT (2) RA (8) SA (14) SC (24) SI (15) SR (11)
AC Access Control
| Control | Name | EU DORA References |
|---|---|---|
| AC-01 | Policy and Procedures | Art.5(1)Art.6(1)Art.9(4)(c) |
| AC-02 | Account Management | Art.9(4)(c)Art.9(4)(d) |
| AC-03 | Access Enforcement | Art.9(4)(c) |
| AC-04 | Information Flow Enforcement | Art.9(4)(a) |
| AC-05 | Separation of Duties | Art.9(4)(c)Art.9(4)(d) |
| AC-06 | Least Privilege | Art.9(4)(c)Art.9(4)(d) |
| AC-07 | Unsuccessful Logon Attempts | Art.9(4)(c) |
| AC-08 | System Use Notification | Art.9(4)(c) |
| AC-09 | Previous Logon Notification | Art.10(1) |
| AC-10 | Concurrent Session Control | Art.9(4)(c) |
| AC-11 | Device Lock | Art.9(4)(c) |
| AC-12 | Session Termination | Art.9(4)(c) |
| AC-14 | Permitted Actions Without Identification or Authentication | Art.9(4)(c) |
| AC-15 | Automated Marking | Art.8(1) |
| AC-16 | Security and Privacy Attributes | Art.8(1)Art.8(4) |
| AC-17 | Remote Access | Art.9(4)(a)Art.9(4)(c) |
| AC-18 | Wireless Access | Art.9(4)(a) |
| AC-19 | Access Control for Mobile Devices | Art.9(4)(a)Art.9(4)(c) |
| AC-20 | Use of External Systems | Art.28(1)(a)Art.28(5) |
AT Awareness and Training
| Control | Name | EU DORA References |
|---|---|---|
| AT-01 | Policy and Procedures | Art.5(4)Art.13(6) |
| AT-02 | Literacy Training and Awareness | Art.5(4)Art.13(6) |
| AT-03 | Role-based Training | Art.5(4)Art.13(6) |
| AT-04 | Training Records | Art.13(6) |
| AT-05 | Contacts with Security Groups and Associations | Art.13(6)Art.45(1) |
| AT-06 | Training Feedback | Art.5(4)Art.13(6) |
AU Audit and Accountability
| Control | Name | EU DORA References |
|---|---|---|
| AU-01 | Policy and Procedures | Art.6(5)Art.6(8) |
| AU-02 | Event Logging | Art.10(1)Art.10(2) |
| AU-03 | Content of Audit Records | Art.10(1) |
| AU-04 | Audit Log Storage Capacity | Art.10(1) |
| AU-05 | Response to Audit Logging Process Failures | Art.10(1)Art.10(2) |
| AU-06 | Audit Record Review, Analysis, and Reporting | Art.10(1)Art.10(2) |
| AU-07 | Audit Record Reduction and Report Generation | Art.10(1) |
| AU-08 | Time Stamps | Art.10(1) |
| AU-09 | Protection of Audit Information | Art.10(1) |
| AU-10 | Non-repudiation | Art.10(1) |
| AU-11 | Audit Record Retention | Art.10(1)Art.19(4) |
| AU-12 | Audit Record Generation | Art.10(1) |
CA Security Assessment and Authorization
| Control | Name | EU DORA References |
|---|---|---|
| CA-01 | Policy and Procedures | Art.5(1)Art.6(1)Art.24(1) |
| CA-02 | Control Assessments | Art.6(4)Art.24(1)Art.24(2)Art.25(1) |
| CA-03 | Information Exchange | Art.9(4)(a) |
| CA-04 | Security Certification | Art.24(1)Art.25(1) |
| CA-05 | Plan of Action and Milestones | Art.6(4) |
| CA-06 | Authorization | Art.5(2)Art.6(1) |
| CA-07 | Continuous Monitoring | Art.6(4)Art.10(1)Art.10(2)Art.24(1) |
| CA-08 | Penetration Testing | Art.24(1)Art.25(1)Art.26 |
| CA-09 | Internal System Connections | Art.6(4) |
CM Configuration Management
| Control | Name | EU DORA References |
|---|---|---|
| CM-01 | Policy and Procedures | Art.7(1)Art.9(1) |
| CM-02 | Baseline Configuration | Art.7(1)Art.9(1) |
| CM-03 | Configuration Change Control | Art.9(4)(e) |
| CM-04 | Impact Analyses | Art.9(4)(e)Art.25(1) |
| CM-05 | Access Restrictions for Change | Art.9(4)(c)Art.9(4)(e) |
| CM-06 | Configuration Settings | Art.7(1)Art.9(1) |
| CM-07 | Least Functionality | Art.7(1)Art.9(1) |
| CM-08 | System Component Inventory | Art.8(1)Art.8(4)Art.28(4) |
| CM-12 | Information Location | Art.8(1)Art.8(4)Art.28(4) |
| CM-13 | Data Action Mapping | Art.8(1) |
| CM-14 | Signed Components | Art.9(4)(e) |
CP Contingency Planning
| Control | Name | EU DORA References |
|---|---|---|
| CP-01 | Policy and Procedures | Art.11(1)Art.11(3)Art.12(1) |
| CP-02 | Contingency Plan | Art.11(1)Art.11(3)Art.11(4)Art.12(1) |
| CP-03 | Contingency Training | Art.11(6)Art.13(6) |
| CP-04 | Contingency Plan Testing | Art.11(6)Art.11(7) |
| CP-05 | Contingency Plan Update | Art.11(6) |
| CP-06 | Alternate Storage Site | Art.12(2)Art.12(5) |
| CP-07 | Alternate Processing Site | Art.11(3)Art.12(2)Art.12(5) |
| CP-08 | Telecommunications Services | Art.11(3)Art.12(2) |
| CP-09 | System Backup | Art.12(1)Art.12(2)Art.12(3)Art.12(5) |
| CP-10 | System Recovery and Reconstitution | Art.11(1)Art.11(2)Art.11(4) |
| CP-12 | Safe Mode | Art.11(1) |
| CP-13 | Alternative Security Mechanisms | Art.11(1) |
IA Identification and Authentication
| Control | Name | EU DORA References |
|---|---|---|
| IA-01 | Policy and Procedures | Art.9(4)(c)Art.9(4)(d) |
| IA-02 | Identification and Authentication (Organizational Users) | Art.9(4)(c)Art.9(4)(d) |
| IA-03 | Device Identification and Authentication | Art.9(4)(c) |
| IA-04 | Identifier Management | Art.9(4)(c)Art.9(4)(d) |
| IA-05 | Authenticator Management | Art.9(3)Art.9(4)(c)Art.9(4)(d) |
| IA-06 | Authentication Feedback | Art.9(4)(c) |
| IA-07 | Cryptographic Module Authentication | Art.9(3) |
| IA-08 | Identification and Authentication (Non-organizational Users) | Art.9(4)(d) |
| IA-12 | Identity Proofing | Art.9(4)(d) |
IR Incident Response
| Control | Name | EU DORA References |
|---|---|---|
| IR-01 | Policy and Procedures | Art.17(1)Art.17(2)Art.17(3) |
| IR-02 | Incident Response Training | Art.13(6)Art.17(3)(d) |
| IR-03 | Incident Response Testing | Art.17(2)Art.24(1) |
| IR-04 | Incident Handling | Art.17(1)Art.17(3)Art.18(1)Art.18(2) |
| IR-05 | Incident Monitoring | Art.17(3)(c)Art.18(1) |
| IR-06 | Incident Reporting | Art.11(7)Art.14Art.19(1)Art.19(4)Art.20(1) |
| IR-07 | Incident Response Assistance | Art.11(7)Art.14Art.17(3)(d)Art.22(1) |
| IR-08 | Incident Response Plan | Art.17(1) |
| IR-09 | Information Spillage Response | Art.17(1)Art.17(2)Art.17(3) |
MA Maintenance
| Control | Name | EU DORA References |
|---|---|---|
| MA-01 | Policy and Procedures | Art.7(1)Art.9(1) |
| MA-02 | Controlled Maintenance | Art.7(1) |
| MA-03 | Maintenance Tools | Art.7(1)Art.9(4)(e) |
| MA-04 | Nonlocal Maintenance | Art.9(4)(a)Art.9(4)(c) |
| MA-05 | Maintenance Personnel | Art.28(5) |
| MA-06 | Timely Maintenance | Art.7(1) |
| MA-07 | Field Maintenance | Art.7(1) |
MP Media Protection
| Control | Name | EU DORA References |
|---|---|---|
| MP-01 | Policy and Procedures | Art.9(4)(a)Art.9(4)(b) |
| MP-02 | Media Access | Art.9(4)(b) |
| MP-03 | Media Marking | Art.8(1) |
| MP-04 | Media Storage | Art.9(4)(a)Art.9(4)(b) |
| MP-05 | Media Transport | Art.9(4)(a)Art.9(4)(b) |
| MP-06 | Media Sanitization | Art.9(4)(b) |
| MP-08 | Media Downgrading | Art.9(4)(b) |
PE Physical and Environmental Protection
PL Planning
| Control | Name | EU DORA References |
|---|---|---|
| PL-01 | Policy and Procedures | Art.5(1)Art.6(1) |
| PL-02 | System Security and Privacy Plans | Art.6(1)Art.6(2) |
| PL-03 | System Security Plan Update | Art.6(4) |
| PL-04 | Rules of Behavior | Art.5(4) |
| PL-05 | Privacy Impact Assessment | Art.6(2)Art.6(5) |
| PL-06 | Security-related Activity Planning | Art.6(1) |
| PL-09 | Central Management | Art.5(1)Art.5(2)Art.6(1) |
| PL-10 | Baseline Selection | Art.6(1)Art.24(2) |
| PL-11 | Baseline Tailoring | Art.6(1)Art.24(2) |
PM Program Management
PS Personnel Security
| Control | Name | EU DORA References |
|---|---|---|
| PS-01 | Policy and Procedures | Art.5(4) |
| PS-02 | Position Risk Designation | Art.5(4) |
| PS-03 | Personnel Screening | Art.5(4) |
| PS-04 | Personnel Termination | Art.9(4)(c) |
| PS-05 | Personnel Transfer | Art.9(4)(c) |
| PS-06 | Access Agreements | Art.5(4) |
| PS-07 | External Personnel Security | Art.28(5)Art.30(2)(a) |
| PS-08 | Personnel Sanctions | Art.5(4) |
| PS-09 | Position Descriptions | Art.5(4) |
PT Personally Identifiable Information Processing and Transparency
RA Risk Assessment
| Control | Name | EU DORA References |
|---|---|---|
| RA-01 | Policy and Procedures | Art.6(1)Art.6(2) |
| RA-02 | Security Categorization | Art.8(1)Art.8(4) |
| RA-03 | Risk Assessment | Art.6(2)Art.6(5) |
| RA-04 | Risk Assessment Update | Art.6(4)Art.6(5) |
| RA-05 | Vulnerability Monitoring and Scanning | Art.9(3)Art.13(1)Art.25(1) |
| RA-06 | Technical Surveillance Countermeasures Survey | Art.25(1)Art.26 |
| RA-07 | Risk Response | Art.6(1)Art.6(2)Art.6(5) |
| RA-09 | Criticality Analysis | Art.6(2)Art.8(4)Art.11(2)Art.11(3)Art.29(1)Art.30(3) |
SA System and Services Acquisition
| Control | Name | EU DORA References |
|---|---|---|
| SA-01 | Policy and Procedures | Art.7(1)Art.9(1) |
| SA-02 | Allocation of Resources | Art.6(1) |
| SA-03 | System Development Life Cycle | Art.7(1)Art.8(5) |
| SA-04 | Acquisition Process | Art.28(1)(a)Art.30(2)Art.30(3) |
| SA-05 | System Documentation | Art.8(1)Art.8(4) |
| SA-06 | Software Usage Restrictions | Art.9(4)(e) |
| SA-07 | User-installed Software | Art.9(4)(e) |
| SA-08 | Security and Privacy Engineering Principles | Art.7(1)Art.9(1) |
| SA-09 | External System Services | Art.28(1)(a)Art.28(2)Art.28(5)Art.30(2)Art.30(3) |
| SA-10 | Developer Configuration Management | Art.8(5)Art.9(4)(e) |
| SA-11 | Developer Testing and Evaluation | Art.9(4)(e)Art.25(1)Art.25(2) |
| SA-20 | Customized Development of Critical Components | Art.25(2) |
| SA-21 | Developer Screening | Art.28(5) |
| SA-22 | Unsupported System Components | Art.8(5) |
SC System and Communications Protection
| Control | Name | EU DORA References |
|---|---|---|
| SC-01 | Policy and Procedures | Art.9(1)Art.9(4)(a) |
| SC-02 | Separation of System and User Functionality | Art.9(4)(a) |
| SC-03 | Security Function Isolation | Art.9(4)(a) |
| SC-04 | Information in Shared System Resources | Art.9(4)(b) |
| SC-05 | Denial-of-service Protection | Art.9(2) |
| SC-06 | Resource Availability | Art.9(2) |
| SC-07 | Boundary Protection | Art.9(4)(a) |
| SC-08 | Transmission Confidentiality and Integrity | Art.9(3)Art.9(4)(a) |
| SC-10 | Network Disconnect | Art.9(4)(c) |
| SC-12 | Cryptographic Key Establishment and Management | Art.9(3) |
| SC-13 | Cryptographic Protection | Art.9(3) |
| SC-14 | Public Access Protections | Art.9(2) |
| SC-15 | Collaborative Computing Devices and Applications | Art.9(4)(a) |
| SC-16 | Transmission of Security and Privacy Attributes | Art.9(3) |
| SC-17 | Public Key Infrastructure Certificates | Art.9(3) |
| SC-18 | Mobile Code | Art.9(4)(e) |
| SC-20 | Secure Name/Address Resolution Service (Authoritative Source) | Art.9(4)(a) |
| SC-21 | Secure Name/Address Resolution Service (Recursive or Caching Resolver) | Art.9(4)(a) |
| SC-22 | Architecture and Provisioning for Name/Address Resolution Service | Art.9(4)(a) |
| SC-23 | Session Authenticity | Art.9(3) |
| SC-24 | Fail in Known State | Art.9(2)Art.11(4)Art.12(2) |
| SC-28 | Protection of Information at Rest | Art.9(3) |
| SC-46 | Cross Domain Policy Enforcement | Art.9(4)(a) |
| SC-47 | Alternate Communications Paths | Art.9(4)(a) |
SI System and Information Integrity
| Control | Name | EU DORA References |
|---|---|---|
| SI-01 | Policy and Procedures | Art.7(1)Art.9(1) |
| SI-02 | Flaw Remediation | Art.7(2)Art.9(4)(e) |
| SI-03 | Malicious Code Protection | Art.9(4)(b) |
| SI-04 | System Monitoring | Art.10(1)Art.10(2) |
| SI-05 | Security Alerts, Advisories, and Directives | Art.10(1)Art.13(1) |
| SI-06 | Security and Privacy Function Verification | Art.10(1)Art.10(2) |
| SI-07 | Software, Firmware, and Information Integrity | Art.9(4)(b)Art.9(4)(e) |
| SI-08 | Spam Protection | Art.9(4)(b) |
| SI-10 | Information Input Validation | Art.9(4)(e) |
| SI-11 | Error Handling | Art.9(4)(e) |
| SI-12 | Information Management and Retention | Art.8(1)Art.12(3) |
| SI-13 | Predictable Failure Prevention | Art.7(1)Art.9(2) |
| SI-16 | Memory Protection | Art.10(1) |
| SI-20 | Tainting | Art.10(1) |
| SI-21 | Information Refresh | Art.13(1) |
SR Supply Chain Risk Management
| Control | Name | EU DORA References |
|---|---|---|
| SR-01 | Policy and Procedures | Art.28(1)(a)Art.28(2)Art.28(4) |
| SR-02 | Supply Chain Risk Management Plan | Art.28(4)Art.28(5) |
| SR-03 | Supply Chain Controls and Processes | Art.28(2)Art.29(1)Art.30(2) |
| SR-04 | Provenance | Art.28(5)Art.30(2)(a) |
| SR-05 | Acquisition Strategies, Tools, and Methods | Art.28(5)Art.30(2)(a) |
| SR-06 | Supplier Assessments and Reviews | Art.28(6)Art.30(3) |
| SR-07 | Supply Chain Operations Security | Art.28(5)Art.30(2)(a) |
| SR-08 | Notification Agreements | Art.19(1)Art.28(7) |
| SR-10 | Inspection of Systems or Components | Art.28(6) |
| SR-11 | Component Authenticity | Art.28(5)Art.30(2)(a) |
| SR-12 | Component Disposal | Art.28(8)Art.30(2)(g) |