Law / European Union

DORA Technical Standards on ICT Risk Management Tools, Methods, Processes and Policies and the Simplified ICT Risk Management Framework

Commission Delegated Regulation (EU) 2024/1774

In force since .

A sector security regimes rule binding private bodies.

Private right of action
No
Obligation class
Security, Governance

As of .

What it requires

  • This Regulation details the ICT risk management duties of Regulation (EU) 2022/2554 (Articles 15 and 16(3)), so it reaches you if you are a financial entity under Article 2(1), points (a) to (t), of that Regulation. Title II applies to you unless you are an entity referred to in Article 16(1) of that Regulation, and Title III, the simplified framework, applies to you if you are. Take your size and overall risk profile, and the nature, scale and complexity of your services, activities and operations, into account when you develop and implement the policies, procedures, protocols and tools (Article 1).
  • Embed your ICT security policies, information security and related procedures, protocols and tools in your ICT risk management framework, align them with the information security objectives of your digital operational resilience strategy, and indicate the date of their formal approval by the management body (Article 2).
  • Develop, document and implement ICT risk management policies and procedures that contain the approved risk tolerance level for ICT risk, a procedure and a methodology to conduct the ICT risk assessment, ICT risk treatment measures, and provisions on the review of accepted residual ICT risks at least once a year (Article 3).
  • Develop, document and implement vulnerability management procedures that identify trustworthy information resources, perform automated vulnerability scanning and assessments (at least weekly for the ICT assets supporting critical or important functions), verify that ICT third-party service providers handle vulnerabilities and report at least the critical ones, track third-party and open-source libraries used by ICT services supporting critical or important functions, establish procedures for the responsible disclosure of vulnerabilities to clients, counterparties and the public, and prioritize the deployment of patches (Article 10(1) and (2)). Develop, document and implement patch management procedures that identify emergency procedures and set deadlines for installing patches and updates with escalation procedures in case those deadlines cannot be met (Article 10(3) and (4)).
  • Develop, document and implement logging procedures, protocols and tools that identify the events to be logged and the retention period, log events related to access control, identity management, capacity management, change management, ICT operations and network traffic, protect logs against tampering, deletion and unauthorized access, detect failures of logging systems, and synchronize the clocks of your ICT systems to a documented reliable reference time source (Article 12).
  • Develop, document and implement network security management policies that segregate and segment ICT systems and networks, document network connections and data flows, use a separate and dedicated network for the administration of ICT assets, apply network access controls, encrypt network connections, review the network architecture once a year (periodically if you are a microenterprise), and verify the adequacy of firewall rules and connection filters for ICT systems supporting critical or important functions at least every 6 months (Article 13).
  • Update access rights where changes are necessary and at least once a year for all ICT systems other than those supporting critical or important functions, and at least every 6 months for ICT systems supporting critical or important functions (Article 21).
  • Develop, document and implement an ICT-related incident policy that documents the incident management process, lists the relevant internal and external contacts, sets up mechanisms to support incident management, retains evidence relating to ICT-related incidents in a secure manner, and analyses significant or recurring incidents (Article 22). Set clear roles and responsibilities to detect and respond to ICT-related incidents and anomalous activities, collect, monitor and analyze logs, cyber threat information and incident notifications from ICT third-party service providers, implement tools that generate alerts at least for the ICT assets and information assets supporting critical or important functions, and log the date, time and type of each detected anomalous activity (Article 23).
  • Include in the ICT business continuity policy the objectives, scope, timeframe, activation and deactivation criteria, governance and recovery objectives set out in Article 24(1). If you are a central counterparty, set a maximum recovery time for your critical functions of not longer than 2 hours. If you are a central securities depository, ensure a recovery time objective of not longer than 2 hours for your critical or important functions. If you are a trading venue, ensure that trading can be resumed within or close to 2 hours of a disruptive incident and that the maximum amount of data lost is close to zero (Article 24(2) to (4)). Test the plans on scenarios that simulate potential disruptions, including severe but plausible scenarios, include the ICT services provided by ICT third-party service providers where applicable, document the results, and report identified deficiencies to the management body (Article 25).
  • Submit the report on the review of the ICT risk management framework in a searchable electronic format and include the information that Article 27(2) lists (Article 27).
  • If you are an entity referred to in Article 16(1) of Regulation (EU) 2022/2554, apply the simplified framework of Title III: have an internal governance and control framework with the management body responsibilities set out in Article 28, and meet Articles 29 to 41 on the information security policy, the classification of assets, ICT risk management, physical and environmental security, access control, ICT operations security, data, system and network security, ICT security testing, acquisition, development and maintenance, project and change management, the business continuity plan and the review report. Test your business continuity plans at least once every year for the back-up and restore procedures, or upon every major change of the plan (Article 40).

Who enforces it

Enforcement body

The competent authority designated for each category of financial entity under Article 46 of Regulation (EU) 2022/2554, which ensures compliance with that Regulation in accordance with the powers granted by the respective legal acts.

What this law does

Drafted with AI

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page. How this site is made

Research summary

Legal information, not legal advice. This is LexLint's own research summary of a public legal source, and it creates no attorney-client relationship. For decisions that matter, consult qualified counsel in the relevant jurisdiction. About LexLint

Commission Delegated Regulation (EU) 2024/1774 supplements Regulation (EU) 2022/2554 with regulatory technical standards that specify ICT risk management tools, methods, processes and policies and the simplified ICT risk management framework.

Article 1 requires a financial entity to take into account its size and overall risk profile, and the nature, scale and elements of increased or reduced complexity of its services, activities and operations, when it develops and implements the policies, procedures, protocols and tools of Title II and the simplified framework of Title III.

Article 2(1) requires a financial entity to embed its ICT security policies, information security and related procedures, protocols and tools in its ICT risk management framework. Article 3 requires ICT risk management policies and procedures that contain a procedure and a methodology to conduct the ICT risk assessment, ICT risk treatment measures, and provisions on the review of the accepted residual ICT risks at least once a year.

Article 10(2) requires a financial entity to perform automated vulnerability scanning and assessments on the ICT assets supporting critical or important functions on at least a weekly basis. Article 10(2) also requires the vulnerability management procedures to include procedures for the responsible disclosure of vulnerabilities to clients, counterparties and the public.

Article 10(4) requires patch management procedures that identify emergency procedures for patching and updating ICT assets and that set deadlines for installing patches and updates, with escalation procedures for deadlines that cannot be met.

Article 12 requires logging procedures, protocols and tools that identify the events to be logged and their retention period, log events related to access control, capacity management, change management, ICT operations and network traffic, protect the logs against tampering, deletion and unauthorized access, and synchronize the clocks of the ICT systems.

Article 13 requires network security management policies that include segregation and segmentation of ICT systems and networks, a separate and dedicated network for the administration of ICT assets and encryption of network connections, and requires the adequacy of firewall rules and connection filters for ICT systems supporting critical or important functions to be verified at least every 6 months.

Article 21 requires access control policies that update access rights at least once a year for ICT systems other than those supporting critical or important functions and at least every 6 months for ICT systems supporting critical or important functions.

Article 22 requires an ICT-related incident policy that documents the incident management process, establishes a list of relevant contacts, sets up mechanisms to support incident management and retains all evidence relating to ICT-related incidents for a period no longer than necessary.

Article 23(2) requires mechanisms to identify anomalous activities and to implement tools generating alerts at least for the ICT assets and information assets supporting critical or important functions, with the alerts prioritized both during and outside working hours.

Article 24(3) and (4) set a recovery time objective of not longer than 2 hours for the critical or important functions of a central securities depository, and require a trading venue to be able to resume trading within or close to 2 hours of a disruptive incident.

Article 25(2) requires the testing of the ICT business continuity plans to use test scenarios that simulate potential disruptions, including severe but plausible scenarios, and to include the ICT services provided by ICT third-party service providers where applicable. Article 27(1) requires the report on the review of the ICT risk management framework to be submitted in a searchable electronic format.

Article 28(1) requires the financial entities referred to in Article 16(1) of Regulation (EU) 2022/2554 to have in place an internal governance and control framework that ensures an effective and prudent management of ICT risk. Article 40(1) requires the financial entities referred to in Article 16(1) of Regulation (EU) 2022/2554 to test their business continuity plans at least once every year for the back-up and restore procedures, or upon every major change of the business continuity plan.

Article 42 provides that the Regulation enters into force on the twentieth day following that of its publication in the Official Journal of the European Union. The penalties for a breach are those of the parent Regulation, whose Article 50(3) requires Member States to lay down effective, proportionate and dissuasive administrative penalties and remedial measures.

When LexLint raises it

When your app profile says your app provides financial services.

Back to the example  ·  Lint your app