Business Wire

IL-ISACA

Share
ISACA Provides Guidance Around EU’s Proposed Digital Operational Resilience Act

Reforms following the 2008 financial crisis helped strengthen the resilience of the financial sector, but did not fully address digital operational resilience. The European Union’s recently released Digital Operational Resilience Act (DORA) draft is designed to provide digital operational resilience rules for EU financial institutions, and ISACA provides guidance on this proposal in its new white paper, Digital Operational Resilience in the EU Financial Sector: A Risk-Based Approach .

When finalized, DORA will enact rules for financial services system operators like investment firms, credit institutions, trading venues and electronic money institutions to ensure these systems’ stability and resilience to cyber incidents. Digital Operational Resilience in the EU Financial Sector outlines the objectives and legal basis for DORA, as well as its information and communication technology (ICT) requirements around risk management, information and cybersecurity, incident reporting, testing, and oversight of third-party service providers, some of which include:

  • Set up and maintain resilient ICT systems and tools that minimize the impact of ICT risk.
  • Have an ICT risk-management framework that includes strategies, policies, procedures, ICT protocols and tools necessary to effectively protect all relevant physical components and infrastructures from risk, such as damage and unauthorized access or usage.
  • Test the ICT business continuity policy and the ICT disaster recovery plan at least yearly, and after substantive changes to the ICT systems.
  • Include relevant provisions on accessibility, availability, integrity, security and protection of personal data, and guarantees for access, recover and return in the case of failures of the ICT third-party service providers in contracts that govern the relationship with third-party providers.

“The requirements laid out in DORA to identify all sources of ICT risk on a continuous basis and mandate an annual review of ICT risk management frameworks and review after a major incident, audit or testing are a step in the right direction,” says Chris Dimitriadis, ISACA chief global strategy officer. “However, to further strengthen the act, ISACA encourages provisions ensuring that ICT risk management plans go beyond being a compliance exercise by embedding governance responsibility within the management body, as well as requiring continuous training and ICT awareness of senior management and staff and independent testing performed by testers who are certified.”

During this period in which the DORA regulation is under consideration in the European Parliament and Council of the EU, ISACA’s EU Task Force is engaging with policy makers and sharing feedback. The final version of the regulation is expected in an estimated 18-24 months.

“ISACA is recognized among policy makers as an independent source of expertise on cybersecurity issues. The variety of backgrounds and experience of our members, reflected in the EU Task Force, have been welcomed by policy makers who have valued our contributions to the debate,” says Emily Bastedo, ISACA director for global government relations and public affairs.

To download a complimentary copy of Digital Operational Resilience in the EU Financial Sector , visit https://store.isaca.org/s/store#/store/browse/detail/a2S4w000004L1sxEAC . Additional publications that may be helpful for financial entities as they prepare for DORA include ISACA’s Risk IT Framework , 2nd Edition ; Risk IT Practitioner Guide, 2nd Edition ; and IT Risk Fundamentals Study Guide . Other IT risk-related resources can be found at www.isaca.org/resources/it-risk .

About ISACA

For more than 50 years, ISACA® (www.isaca.org ) has advanced the best talent, expertise and learning in technology. ISACA equips individuals with knowledge, credentials, education and community to progress their careers and transform their organizations, and enables enterprises to train and build quality teams. ISACA is a global professional association and learning organization that leverages the expertise of its more than 150,000 members who work in information security, governance, assurance, risk and privacy to drive innovation through technology. It has a presence in 188 countries, including more than 220 chapters worldwide. In 2020, ISACA launched One In Tech, a philanthropic foundation that supports IT education and career pathways for under-resourced, under-represented populations.

Twitter: www.twitter.com/ISACANews
LinkedIn: www.linkedin.com/company/isaca
Facebook: www.facebook.com/ISACAGlobal
Instagram: www.instagram.com/isacanews

Link:

ClickThru

About Business Wire

Business Wire
Business Wire
101 California Street, 20th Floor
CA 94111 San Francisco

http://businesswire.com

Subscribe to releases from Business Wire

Subscribe to all the latest releases from Business Wire by registering your e-mail address below. You can unsubscribe at any time.

Latest releases from Business Wire

IDWS 2025 Concludes with Focus on Global Knowledge Exchange, Financial Opportunities, and Scalable Water Solutions16.12.2025 20:03:00 CET | Press release

The 4th Innovation Driven Water Sustainability Conference (IDWS) 2025 concluded on Wednesday in Jeddah, confirming its status as one of the world’s most influential platforms for shaping the future of water innovation, sustainability, and security. Gathering senior global policymakers and international industry leaders, this year’s edition has advanced critical dialogue on safeguarding the planet’s most vital resource, with Saudi Arabia at the forefront. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20251216483490/en/ Investors, innovators, and global institutions gather in Saudi to outline how capital, collaboration, and governance can accelerate long term water sustainability (Photo: AETOSWire) Among the most consequential engagements were a series of meetings that brought together discussions powered by SWA, centred on shared challenges, knowledge exchange, and exploring opportunities within the global water ecosystem. Att

OAG Appoints ex-Skyscanner Executive Filip Filipov as New Chief Executive Officer16.12.2025 17:00:00 CET | Press release

OAG announces today the appointment of Filip Filipov, ex-Skyscanner executive, as new Chief Executive Officer. Filip Filipov currently serves as the company’s Chief Operating Officer and takes over from Phil Callow who has chosen to step down having completed thirteen transformational years at the helm of OAG to pursue his many other interests. Since joining in 2024, Filipovhas played a leading role in the company’s ambitious next phase of growth and ongoing acceleration. He will now lead OAG into a new era defined by advanced data products and AI-driven intelligence. Before joining OAG, Filipov held senior roles in travel technology and big-data consulting, including on Skyscanner’s executive team. Filip Filipov said: “It’s a privilege to step into this role and lead a company with such a strong heritage and reputation. I’m excited for what’s ahead and committed to serving our customers with the reliability, service, and innovation they depend on.” Chairman of OAG, Gehan Talwatte, com

Xsolla Integrates SPENN in Rwanda and Zambia Giving Developers Access to a Strong Consumer-Merchant Ecosystem16.12.2025 16:49:00 CET | Press release

Developers Can Now Maximize Revenue and Boost Player Engagement with a New Integration Delivering a Smoother Checkout, Fewer Declines, and Access to a Growing Digital Wallet User Base Xsolla, a global video game commerce company that helps developers launch, grow, and monetize their games, today announced that it has added SPENN to its payments solution portfolio in Rwanda and Zambia. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20251216303338/en/ Xsolla Integrates SPENN In Rwanda And Zambia Giving Developers Access To A Strong Consumer-Merchant Ecosystem Both Rwanda and Zambia are mobile-first, wallet-led economies where mobile money drives financial inclusion and rapid growth in digital transactions. Reports found that approximately 86% of Rwandan adults own or have used mobile money. As of mid-2024, mobile money transaction volumes in Zambia increased by 44% to 1.4 billion transactions from mid-2023. By adding SPENN as a

New Survey of Nearly 4,300 C-suite Leaders Reveals Intensifying Demand for Faster Innovation, Higher ROI and Stronger Business Resilience16.12.2025 15:00:00 CET | Press release

Executives face growing pressure to deliver AI-driven transformation while navigating rising costs, increasing risk and shortages in skilled IT talent Rimini Street, Inc. (Nasdaq: RMNI), a global provider of end-to-end enterprise software support, managed services and Agentic AI ERP innovation solutions, and the leading third-party support provider for Oracle, SAP and VMware software, today announced the findings of its new global survey, “C-suite Imperatives: Accelerating Innovation in a Shifting Landscape.” The research was conducted in partnership with Censuswide surveying nearly 4,300 CFOs, CIOs, CEOs and CISOs across the globe, examining the pressures influencing executive-level technology decisions and the priorities shaping their investment strategies. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20251216456670/en/ New Survey of Nearly 4,300 C-suite Leaders Reveals Intensifying Demand for Faster Innovation, Higher ROI

Enersense Selects Sitetracker as the Platform of Choice for 5G and Fiber Expansion Initiatives16.12.2025 15:00:00 CET | Press release

Sitetracker, the global leader in complete Asset Lifecycle Management, announced that Enersense, a leading lifecycle partner for customers operating in energy transmission and production, industrial energy transition and telecommunications services across Finland and the Baltics, has selected Sitetracker to digitize and scale its operations. The implementation enabled Enersense to replace legacy systems, standardize workflows, and support their ability to deliver services with short lead times and high process precision. The first phase of implementation is already supporting Finland’s 5G and rapidly expanding fiber-to-the-home (FTTH) initiatives. Before Sitetracker, Enersense relied on spreadsheets and email to manage project execution, resulting in limited visibility into project milestones, asset tracking, and field performance. As 5G and FTTH deployment accelerated, these manual processes created operational bottlenecks, slowed invoicing, and hindered communication with customers a

In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.

Visit our pressroom
World GlobeA line styled icon from Orion Icon Library.HiddenA line styled icon from Orion Icon Library.Eye