Business Wire

IL-ISACA

Share
ISACA Provides Guidance Around EU’s Proposed Digital Operational Resilience Act

Reforms following the 2008 financial crisis helped strengthen the resilience of the financial sector, but did not fully address digital operational resilience. The European Union’s recently released Digital Operational Resilience Act (DORA) draft is designed to provide digital operational resilience rules for EU financial institutions, and ISACA provides guidance on this proposal in its new white paper, Digital Operational Resilience in the EU Financial Sector: A Risk-Based Approach .

When finalized, DORA will enact rules for financial services system operators like investment firms, credit institutions, trading venues and electronic money institutions to ensure these systems’ stability and resilience to cyber incidents. Digital Operational Resilience in the EU Financial Sector outlines the objectives and legal basis for DORA, as well as its information and communication technology (ICT) requirements around risk management, information and cybersecurity, incident reporting, testing, and oversight of third-party service providers, some of which include:

  • Set up and maintain resilient ICT systems and tools that minimize the impact of ICT risk.
  • Have an ICT risk-management framework that includes strategies, policies, procedures, ICT protocols and tools necessary to effectively protect all relevant physical components and infrastructures from risk, such as damage and unauthorized access or usage.
  • Test the ICT business continuity policy and the ICT disaster recovery plan at least yearly, and after substantive changes to the ICT systems.
  • Include relevant provisions on accessibility, availability, integrity, security and protection of personal data, and guarantees for access, recover and return in the case of failures of the ICT third-party service providers in contracts that govern the relationship with third-party providers.

“The requirements laid out in DORA to identify all sources of ICT risk on a continuous basis and mandate an annual review of ICT risk management frameworks and review after a major incident, audit or testing are a step in the right direction,” says Chris Dimitriadis, ISACA chief global strategy officer. “However, to further strengthen the act, ISACA encourages provisions ensuring that ICT risk management plans go beyond being a compliance exercise by embedding governance responsibility within the management body, as well as requiring continuous training and ICT awareness of senior management and staff and independent testing performed by testers who are certified.”

During this period in which the DORA regulation is under consideration in the European Parliament and Council of the EU, ISACA’s EU Task Force is engaging with policy makers and sharing feedback. The final version of the regulation is expected in an estimated 18-24 months.

“ISACA is recognized among policy makers as an independent source of expertise on cybersecurity issues. The variety of backgrounds and experience of our members, reflected in the EU Task Force, have been welcomed by policy makers who have valued our contributions to the debate,” says Emily Bastedo, ISACA director for global government relations and public affairs.

To download a complimentary copy of Digital Operational Resilience in the EU Financial Sector , visit https://store.isaca.org/s/store#/store/browse/detail/a2S4w000004L1sxEAC . Additional publications that may be helpful for financial entities as they prepare for DORA include ISACA’s Risk IT Framework , 2nd Edition ; Risk IT Practitioner Guide, 2nd Edition ; and IT Risk Fundamentals Study Guide . Other IT risk-related resources can be found at www.isaca.org/resources/it-risk .

About ISACA

For more than 50 years, ISACA® (www.isaca.org ) has advanced the best talent, expertise and learning in technology. ISACA equips individuals with knowledge, credentials, education and community to progress their careers and transform their organizations, and enables enterprises to train and build quality teams. ISACA is a global professional association and learning organization that leverages the expertise of its more than 150,000 members who work in information security, governance, assurance, risk and privacy to drive innovation through technology. It has a presence in 188 countries, including more than 220 chapters worldwide. In 2020, ISACA launched One In Tech, a philanthropic foundation that supports IT education and career pathways for under-resourced, under-represented populations.

Twitter: www.twitter.com/ISACANews
LinkedIn: www.linkedin.com/company/isaca
Facebook: www.facebook.com/ISACAGlobal
Instagram: www.instagram.com/isacanews

Link:

ClickThru

About Business Wire

Business Wire
Business Wire
101 California Street, 20th Floor
CA 94111 San Francisco

http://businesswire.com

Subscribe to releases from Business Wire

Subscribe to all the latest releases from Business Wire by registering your e-mail address below. You can unsubscribe at any time.

Latest releases from Business Wire

Andersen Global styrker platformen i Filippinerne med Du-Baladad and Associates3.5.2025 00:55:00 CEST | Pressemeddelelse

Andersen Global forstærker sit engagement i Asien og Stillehavsområdet gennem en samarbejdsaftale med Du-Baladad and Associates, et skatte- og virksomhedsservicefirma med base i Filippinerne. Firmaet blev grundlagt i 2009 af administrerende partner Benedicta Du-Baladad og tilbyder en bred vifte af ydelser, herunder skatterådgivning og -planlægning, transfer pricing, international skat, skattetvister og -retssager, compliance og bistand i forbindelse med incitamenter. Du-Baladad and Associates anerkendes konsekvent som et førende skattefirma i Filippinerne af Chambers and Partners, International Tax Review, The Legal 500 og Asialaw og servicerer multinationale virksomheder og store indenlandske selskaber på tværs af brancher, herunder inden for finansielle tjenesteydelser, energi, olie og gas, produktion, fast ejendom og teknologi. "Vores firma bygger på en helhedsorienteret tilgang til kunderne, som prioriterer praktiske og skræddersyede strategier til at styre risici og understøtte vo

Spatial Releases 2025 1.0.1 with Enhancements for CAD Translation, Model Simplification, and Mesh Preparation for Manufacturing and Simulation2.5.2025 16:47:00 CEST | Press release

Spatial Corp., the leading software development toolkit provider for design, manufacturing and engineering solutions and a subsidiary of Dassault Systèmes, announces the 2025 1.0.1 release and updates across several product lines, reaffirming its commitment to providing innovative solutions for its customers in domains ranging from CAD to simulation, manufacturing, and beyond. The 2025 1.0.1 release delivers expanded functionality designed to streamline manufacturing and simulation workflows. Key highlights include a new custom feature detection API in ACIS for more efficient model simplification, expanded CAD format support—including STEP AP242 PMI writing—and continued enhancements to hidden-body removal. With this release, Spatial reduces manual tasks, increases fidelity in geometry translation, and strengthens its toolset for automated design-to-manufacture and design-to-simulation pipelines. 3D ACIS ModelerCustom Feature Detection (Beta): Model simplification often requires manual

Decent Cybersecurity Joins the Council of Slovak Exporters to Strengthen European Cybersecurity Exports2.5.2025 15:51:00 CEST | Press release

Decent Cybersecurity, a leading European provider of post-quantum security solutions, announces its membership in the Council of Slovak Exporters (CSE), reinforcing its commitment to expanding advanced cybersecurity exports across global markets. This strategic partnership combines Decent Cybersecurity's expertise in critical infrastructure protection with CSE's established export promotion platform. As a company holding national, EU, and NATO "Secret" level security clearances, Decent Cybersecurity brings specialized knowledge in post-quantum security, blockchain technology, and space traffic management solutions to the Council's network. "Joining the Council of Slovak Exporters represents a significant opportunity to strengthen Slovakia's position in the global cybersecurity market," said Matej Michalko, Founder and CEO of Decent Cybersecurity and a long-term expert on post-quantum cryptography and blockchain. "As cyber threats continue to evolve, our advanced solutions are increasin

Saudi Arabia Hosts EDGEx 2025, Pushing the Boundaries of Education2.5.2025 15:29:00 CEST | Press release

Saudi Arabia has taken another step forward in its educational reform journey with the successful conclusion of the International Education Exhibition (EDGEx), held from April 13–16, 2025. Organized by the Ministry of Education, the event convened education leaders, technology developers, and policymakers from around the world under the theme “Beyond Readiness.” This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20250502190798/en/ Saudi Arabia Hosts EDGEx 2025, Pushing the Boundaries of Education (Photo: AETOSWire) Over four days, EDGEx welcomed more than 20,000 local and international visitors, including government representatives, senior educators, academics, business leaders, and professionals in the field. The exhibition served as a platform for dialogue, knowledge exchange, and cross-sector collaboration—bringing together institutions, companies, and decision-makers to explore how education and training can evolve in a rapidl

IFF Announces Tender Offers for Certain Outstanding Series of Notes2.5.2025 15:10:00 CEST | Press release

IFF (NYSE: IFF) announced today the commencement of tender offers to purchase for cash certain of its outstanding series of notes listed in the tables below (collectively, the “Notes”) for an aggregate purchase price, excluding accrued and unpaid interest, of up to $1.8 billion. Pool 1 Tender Offers Pool 1 Maximum Amount: $1.0 billion(1(a)) Title of Security CUSIP/ISIN Principal Amount Outstanding(in millions) Acceptance Priority Level(2) Series Tender Cap(3) U.S. Treasury Reference Security Bloomberg Reference Page Fixed Spread(4) Early Tender Payment (4)(5) 1.230% Senior Notes due 2025 459506AN1 U45950AE9 $1,000 1 $500 million 5.000% UST due 9/30/25 FIT3 + 0 bps $30 1.832% Senior Notes due 2027 459506AP6 U45950AF6 $1,200 2 $300 million 3.750% UST due 4/30/27 FIT1 + 75 bps $30 2.300% Senior Notes due 2030 459506AQ4 U45950AG4 $1,500 3 N/A 3.875% UST due 4/30/30 FIT1 + 110 bps $30 4.450% Senior Notes due 2028 459506AK7 US459506AK78 $400 4 N/A 3.750% UST due 4/15/28 FIT1 + 95 bps $30 Poo

In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.

Visit our pressroom
World GlobeA line styled icon from Orion Icon Library.HiddenA line styled icon from Orion Icon Library.Eye