Book

Regulamentul (UE) 2022/2554 privind reziliența operațională digitală a sectorului financiar

by Parlamentul European și Consiliul Uniunii Europene · 2022 · 1 reading card · public domain

1 card

  1. Regulamentul (UE) 2022/2554 privind reziliența operațională digitală a sectorului financiar · 2022

    DORA asks for proof that resilience works, not proof that it was planned.

    Regulation (EU) 2022/2554 applies directly to financial entities from 17 January 2025 and rests on five pillars: management of information and communication technology risk, incident handling and reporting, digital operational resilience testing, third-party technology provider risk, and information sharing on threats. Two requirements have no equivalent in a classic management system. The first is the register of information: every contractual arrangement for technology services, with the function it supports, in a form the supervisor can demand in full. The second is advanced threat-led testing, mandatory at least once every three years for entities identified by the competent authority — a simulation against live systems, not a vulnerability scan. Above them, providers designated as critical fall under the direct oversight of the European supervisory authorities. A certified system covers the first pillar well and much of the second; the rest asks for new things.

    Financial entities shall have in place an internal governance and control framework that ensures an effective and prudent management of ICT risk, in accordance with Article 6(4), in order to achieve a high level of digital operational resilience.

    Open the card