procedure

Guide professionnel – Cybersécurité – Guide pratique DORA

ID 26203

The present guide provides a comprehensive overview of DORA and its implications for financial entities, particularly asset management companies. It outlines the key provisions of DORA, emphasizing the need for operational resilience in the digital domain and the obligations it imposes on financial entities and their digital service providers.
DORA aims to enhance the overall resilience of the financial sector by requiring entities to develop, maintain, and reassess their operational integrity and reliability, especially in the face of disruptions. The act applies to financial entities, including asset management companies, and their digital service providers. It emphasizes the importance of proportionality in applying measures based on the size, risk profile, nature, and complexity of services, activities, and operations of the entities.
The guide highlights the role of the board in overseeing the implementation of DORA’s obligations and emphasizes the need for the board to define, validate, and supervise the deployment of the digital risk management framework. It recommends annual training and emphasizes the challenges associated with board engagement and reporting on cyber resilience and IT risk.
Furthermore, the guide delves into the framework for managing digital risks, emphasizing the need for detailed documentation and strategies to ensure the security of information systems. It emphasizes the importance of separating IT management, control functions, and internal audit functions within asset management companies and the need for a digital resilience strategy.
The document also addresses the categorization of incidents and the need for entities to develop incident management processes, including incident registers, roles and responsibilities, response procedures, and communication plans. It emphasizes the importance of board involvement in incident management and the validation of critical processes and subcontractors.
Additionally, the guide discusses the management of third-party service providers supporting critical or important functions, highlighting the need for exit strategies and increased risk analysis. It emphasizes the responsibility of asset management companies in ensuring compliance with the services provided by third-party providers and the impact of DORA on the maturity level of these providers.

Other Features
auditing
best practice
capital management companies
companies
compliance
cooperation
credit
crypto-assets
cyber security
digital assets
governance
operational
outsourcing
payment services
penalties
pension funds
process
regulatory
reporting
resilience
risk
risk management
securities
standard
Date Published: 2023-12-12
Regulatory Framework: Digital Operational Resilience Act (DORA)
Regulatory Type: procedure

L’ESMA publie son rapport final portant sur les modifications de la méthodologie ...

ID 26552
The AFG published it’s response to ESMA’s publication on 19 December 2023 of i ...

Publication des rapports du FSB et de l’OICV sur la gestion de la liquidité des ...

ID 26533
Back in Septembr 2023, the AFG responded to corresponding consultations by the FSB and IOS ...

Réponse AFG à la consultation de la Commission Européenne sur la révision du niveau ...

ID 26441
The AFG responded to the EC’s Targeted Consultation on SFDR Implementation. As a rem ...

Réponse AFG au Call for Evidence de l’ESMA sur un raccourcissement du cycle de ...

ID 26387
In response to ESMA‘ Call for Evidence regarding the potential reduction of the secu ...
  • Topic Filter

    Top Tag Search
    Top Tag Search
    Top Tag Search
    Top Tag Search
You are on the training version of RISP core with limited functions and data. Please subscribe to RISP core for professional or academic use. We supply free real time datasets for approved academic research; professional subscriptions start at 950€ plus VAT per annum.

Compare Listings