Business Wire

IL-ISACA

14.10.2021 16:21:10 CEST | Business Wire | Press release

Share
ISACA Provides Guidance Around EU’s Proposed Digital Operational Resilience Act

Reforms following the 2008 financial crisis helped strengthen the resilience of the financial sector, but did not fully address digital operational resilience. The European Union’s recently released Digital Operational Resilience Act (DORA) draft is designed to provide digital operational resilience rules for EU financial institutions, and ISACA provides guidance on this proposal in its new white paper, Digital Operational Resilience in the EU Financial Sector: A Risk-Based Approach .

When finalized, DORA will enact rules for financial services system operators like investment firms, credit institutions, trading venues and electronic money institutions to ensure these systems’ stability and resilience to cyber incidents. Digital Operational Resilience in the EU Financial Sector outlines the objectives and legal basis for DORA, as well as its information and communication technology (ICT) requirements around risk management, information and cybersecurity, incident reporting, testing, and oversight of third-party service providers, some of which include:

  • Set up and maintain resilient ICT systems and tools that minimize the impact of ICT risk.
  • Have an ICT risk-management framework that includes strategies, policies, procedures, ICT protocols and tools necessary to effectively protect all relevant physical components and infrastructures from risk, such as damage and unauthorized access or usage.
  • Test the ICT business continuity policy and the ICT disaster recovery plan at least yearly, and after substantive changes to the ICT systems.
  • Include relevant provisions on accessibility, availability, integrity, security and protection of personal data, and guarantees for access, recover and return in the case of failures of the ICT third-party service providers in contracts that govern the relationship with third-party providers.

“The requirements laid out in DORA to identify all sources of ICT risk on a continuous basis and mandate an annual review of ICT risk management frameworks and review after a major incident, audit or testing are a step in the right direction,” says Chris Dimitriadis, ISACA chief global strategy officer. “However, to further strengthen the act, ISACA encourages provisions ensuring that ICT risk management plans go beyond being a compliance exercise by embedding governance responsibility within the management body, as well as requiring continuous training and ICT awareness of senior management and staff and independent testing performed by testers who are certified.”

During this period in which the DORA regulation is under consideration in the European Parliament and Council of the EU, ISACA’s EU Task Force is engaging with policy makers and sharing feedback. The final version of the regulation is expected in an estimated 18-24 months.

“ISACA is recognized among policy makers as an independent source of expertise on cybersecurity issues. The variety of backgrounds and experience of our members, reflected in the EU Task Force, have been welcomed by policy makers who have valued our contributions to the debate,” says Emily Bastedo, ISACA director for global government relations and public affairs.

To download a complimentary copy of Digital Operational Resilience in the EU Financial Sector , visit https://store.isaca.org/s/store#/store/browse/detail/a2S4w000004L1sxEAC . Additional publications that may be helpful for financial entities as they prepare for DORA include ISACA’s Risk IT Framework , 2nd Edition ; Risk IT Practitioner Guide, 2nd Edition ; and IT Risk Fundamentals Study Guide . Other IT risk-related resources can be found at www.isaca.org/resources/it-risk .

About ISACA

For more than 50 years, ISACA® (www.isaca.org ) has advanced the best talent, expertise and learning in technology. ISACA equips individuals with knowledge, credentials, education and community to progress their careers and transform their organizations, and enables enterprises to train and build quality teams. ISACA is a global professional association and learning organization that leverages the expertise of its more than 150,000 members who work in information security, governance, assurance, risk and privacy to drive innovation through technology. It has a presence in 188 countries, including more than 220 chapters worldwide. In 2020, ISACA launched One In Tech, a philanthropic foundation that supports IT education and career pathways for under-resourced, under-represented populations.

Twitter: www.twitter.com/ISACANews
LinkedIn: www.linkedin.com/company/isaca
Facebook: www.facebook.com/ISACAGlobal
Instagram: www.instagram.com/isacanews

Link:

ClickThru

About Business Wire

Business Wire
Business Wire
101 California Street, 20th Floor
CA 94111 San Francisco

http://businesswire.com

Subscribe to releases from Business Wire

Subscribe to all the latest releases from Business Wire by registering your e-mail address below. You can unsubscribe at any time.

Latest releases from Business Wire

Andersen Consulting udvider sine kompetencer med tilføjelsen af SHMA5.2.2026 19:20:00 CET | Pressemeddelelse

Andersen Consulting indgår en samarbejdsaftale med SHMA, en førende virksomhed inden for aktuarfaglig og finansiel rådgivning med hovedsæde i De Forenede Arabiske Emirater. SHMA er et aktuarfagligt rådgivningsfirma med næsten fire årtiers erfaring i at hjælpe organisationer med at navigere i kompleksitet, håndtere risiko og skabe muligheder gennem aktuarfaglig og forsikringsmæssig rådgivning, risikostyring samt værdiansættelse af slutvederlag (End-of-Service Benefits, EOSB). Ved at samarbejde med forsikringsselskaber, pensionsordninger samt private og offentlige organisationer hjælper SHMA sine kunder med at opbygge robuste og resiliente organisationer. "Hos SHMA er kvalitet, skræddersyede løsninger og ægte menneskelig forbindelse i centrum for vores mission," udtaler Shariq Sikander, direktør for SHMA. "Samarbejdet med Andersen Consulting giver os mulighed for at udvide vores indflydelse globalt og styrke vores aktuarfaglige ydelser ud over MENA-regionen, samtidig med at vi leverer in

Verimatrix: Sale of Extended Threat Defense Assets (Mobile Application Protection) to Guardsquare5.2.2026 17:45:00 CET | Press release

Completion of the sale of XTD assets (code and mobile application protection), including a portfolio of patents and a team of experts.The Group is refocusing on anti-piracy (video protection), its core business, which represents approximately 90% of its total revenue. Regulatory News: Verimatrix, (Euronext Paris: VMX), a leading provider of security solutions for a safer connected world, today announced that it has completed the sale of 100% of its Extended Threat Defense (XTD) assets to Guardsquare, a Belgian company and leader in mobile application security. This transaction follows the signing of an agreement announced in a press release on December 8, 2025, as well as regulatory approval. It is part of Verimatrix's overall strategy to refocus on its core business, reflecting the group's strategic decision to concentrate on the key growth segments of the video protection market. Commenting on the announcement, Laurent Dechaux, CEO of Verimatrix, said: “Verimatrix has a strong techno

Duna, Built by Stripe Veterans, Raises €30 Million CapitalG-led Series A to Solve Business Identity For The Internet5.2.2026 15:00:00 CET | Press release

Duna, the identity fintech founded by two Stripe alumni, today announced a €30 million Series A funding round led by CapitalG, Alphabet’s independent growth fund. Existing investors Index Ventures, Puzzle Ventures and Snowflake Chairman Frank Slootman also participated in the round. The company, based in Germany and the Netherlands, was launched in 2023 by Duco van Lanschot, who was head of Benelux and DACH at Stripe for three years, and David Schreiber, who spent six years at Stripe where he ran the company’s largest global business unit, including the core card payment platform. In May 2025, the company announced a €10.7 million seed round led by Index Ventures. The latest fundraise brings Duna’s total funding to more than €40 million. Duna’s mission is to build global trust infrastructure by providing a digital passport for every business. Over time, this will evolve into a network for shareable identity and one-click onboarding. Today Duna’s AI-native business identity platform ser

AI-Powered Experian Assistant for Model Risk Management Wins 2026 BIG Innovation Award5.2.2026 15:00:00 CET | Press release

Highlights how Experian’s AI capabilities help global financial institutions keep regulatory documentation aligned with rapid model innovations Experian today announced that its recently launched, AI‑powered Experian Assistant for Model Risk Management has been awarded the 2026 BIG Innovation Award in the Innovative Products category. Recognizing trailblazers across industries since 2014, this global award celebrates exceptional innovation and the value it brings to a recipient’s clients, stakeholders and community. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260205042051/en/ Experian's recently launched, AI-powered Experian Assistant for Model Risk Management has been awarded the 2026 BIG Innovation Award in the Innovative Products category. Fully integrated into the Experian Ascend Platform™ and powered by ValidMind technology, Experian Assistant for Model Risk Management helps accelerate model validation, improve audit

LTIMindtree Recognized as a Leader in Everest Group Payments IT Services PEAK Matrix® Assessment 20255.2.2026 14:30:00 CET | Press release

LTIMindtree [NSE: LTIM, BSE: 540005], a leading global technology consulting and digital solutions provider, has been positioned as a Leader in the Everest Group Payments IT Services PEAK Matrix® Assessment 2025. This recognition is for being a strategic transformation partner that combines modernization scale, platform alliances, and innovation across real-time, digital assets, and ensure secure, regulator-ready payment environments. Everest Group highlighted LTIMindtree’s strong market impact and vision and capability in delivering largescale payments across issuers, acquirers, payment processors, card networks, and FinTechs. The assessment comes at a time when enterprises are rapidly modernizing legacy payments platforms to support real-time, cross-border, and ISO 20022 compliant payment environments, while enhancing resiliency, interoperability, and regulatory compliance. LTIMindtree stands out for its product engineering expertise across major payment platforms like Finastra GPP/P

In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.

Visit our pressroom
World GlobeA line styled icon from Orion Icon Library.HiddenA line styled icon from Orion Icon Library.Eye