Business Wire

IL-ISACA

Share
ISACA Provides Guidance Around EU’s Proposed Digital Operational Resilience Act

Reforms following the 2008 financial crisis helped strengthen the resilience of the financial sector, but did not fully address digital operational resilience. The European Union’s recently released Digital Operational Resilience Act (DORA) draft is designed to provide digital operational resilience rules for EU financial institutions, and ISACA provides guidance on this proposal in its new white paper, Digital Operational Resilience in the EU Financial Sector: A Risk-Based Approach .

When finalized, DORA will enact rules for financial services system operators like investment firms, credit institutions, trading venues and electronic money institutions to ensure these systems’ stability and resilience to cyber incidents. Digital Operational Resilience in the EU Financial Sector outlines the objectives and legal basis for DORA, as well as its information and communication technology (ICT) requirements around risk management, information and cybersecurity, incident reporting, testing, and oversight of third-party service providers, some of which include:

  • Set up and maintain resilient ICT systems and tools that minimize the impact of ICT risk.
  • Have an ICT risk-management framework that includes strategies, policies, procedures, ICT protocols and tools necessary to effectively protect all relevant physical components and infrastructures from risk, such as damage and unauthorized access or usage.
  • Test the ICT business continuity policy and the ICT disaster recovery plan at least yearly, and after substantive changes to the ICT systems.
  • Include relevant provisions on accessibility, availability, integrity, security and protection of personal data, and guarantees for access, recover and return in the case of failures of the ICT third-party service providers in contracts that govern the relationship with third-party providers.

“The requirements laid out in DORA to identify all sources of ICT risk on a continuous basis and mandate an annual review of ICT risk management frameworks and review after a major incident, audit or testing are a step in the right direction,” says Chris Dimitriadis, ISACA chief global strategy officer. “However, to further strengthen the act, ISACA encourages provisions ensuring that ICT risk management plans go beyond being a compliance exercise by embedding governance responsibility within the management body, as well as requiring continuous training and ICT awareness of senior management and staff and independent testing performed by testers who are certified.”

During this period in which the DORA regulation is under consideration in the European Parliament and Council of the EU, ISACA’s EU Task Force is engaging with policy makers and sharing feedback. The final version of the regulation is expected in an estimated 18-24 months.

“ISACA is recognized among policy makers as an independent source of expertise on cybersecurity issues. The variety of backgrounds and experience of our members, reflected in the EU Task Force, have been welcomed by policy makers who have valued our contributions to the debate,” says Emily Bastedo, ISACA director for global government relations and public affairs.

To download a complimentary copy of Digital Operational Resilience in the EU Financial Sector , visit https://store.isaca.org/s/store#/store/browse/detail/a2S4w000004L1sxEAC . Additional publications that may be helpful for financial entities as they prepare for DORA include ISACA’s Risk IT Framework , 2nd Edition ; Risk IT Practitioner Guide, 2nd Edition ; and IT Risk Fundamentals Study Guide . Other IT risk-related resources can be found at www.isaca.org/resources/it-risk .

About ISACA

For more than 50 years, ISACA® (www.isaca.org ) has advanced the best talent, expertise and learning in technology. ISACA equips individuals with knowledge, credentials, education and community to progress their careers and transform their organizations, and enables enterprises to train and build quality teams. ISACA is a global professional association and learning organization that leverages the expertise of its more than 150,000 members who work in information security, governance, assurance, risk and privacy to drive innovation through technology. It has a presence in 188 countries, including more than 220 chapters worldwide. In 2020, ISACA launched One In Tech, a philanthropic foundation that supports IT education and career pathways for under-resourced, under-represented populations.

Twitter: www.twitter.com/ISACANews
LinkedIn: www.linkedin.com/company/isaca
Facebook: www.facebook.com/ISACAGlobal
Instagram: www.instagram.com/isacanews

Link:

ClickThru

About Business Wire

Business Wire
Business Wire
101 California Street, 20th Floor
CA 94111 San Francisco

http://businesswire.com

Subscribe to releases from Business Wire

Subscribe to all the latest releases from Business Wire by registering your e-mail address below. You can unsubscribe at any time.

Latest releases from Business Wire

UAE announces Google Gemini Is Now the Most Culturally Accurate AI for Arabs28.11.2025 22:31:00 CET | Press release

The world’s first assessment to assess AI models’ alignment with Emirati identity and values The UAE’s Artificial Intelligence, Digital Economy, and Remote Work Applications Office announced that Google Gemini has ranked first in the “AI in the Ring” Index, the world’s first benchmark designed to evaluate how effectively AI language models reflect Emirati culture, dialects, traditions, and national values through a challenge centered on cultural intelligence within the UAE context. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20251128785463/en/ UAE announces Google Gemini Is Now the Most Culturally Accurate AI for Arabs (Photo: AETOSWire) Gemini earned the top ranking following a review of over 400 questions across 7 cultural dimensions and 5,200 generated responses from 11 major language models. A Committee of Emirati experts evaluated the outputs to identify which models demonstrated the strongest cultural understanding. F

GE HealthCare announces CE Mark for the Omni 128cm total body PET/CT system28.11.2025 12:00:00 CET | Press release

FOR USE IN CE-MARK EUROPEAN COUNTRIES ONLY GE HealthCare announces CE Mark for its Omni 128cm total body PET/CT,i a next-generation imaging system designed to advance precision care as well as cancer diagnosis, staging and treatment planning The new system is designed to accommodate head-to-thigh imaging in a single bed to improve workflow and efficiency, and enable a significant reduction in dose/scan time – all important factors, especially for populations like pediatric patients Built for both clinical and research excellence, the system may support the development and evaluation of new clinical pathways, novel PET tracers and emerging theranostic agents GE HealthCare today announced CE Mark for its next-generation Omni 128cm total body positron emission tomography / computed tomography (PET/CT) system,i a major milestone in its mission to advance precision care. Designed to advance cancer diagnosis, staging, therapeutic planning and treatment response monitoring, this innovative sy

King Abdulaziz Foundation Organizes the First Edition of the Forum on the “History of Hajj and the Two Holy Mosques” in Jeddah28.11.2025 10:53:00 CET | Press release

King Abdulaziz Foundation (Darah) held the first edition of the Forum on the “History of Hajj and the Two Holy Mosques”, convened as part of the program of the “Hajj Conference and Exhibition 2025” at the Super Dome Hall in Jeddah, in cooperation with the Ministry of Hajj and Umrah and the Guests of God Service Program, during the period from 9–12 November 2025. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20251128600368/en/ King Abdulaziz Foundation Organizes the First Edition of the Forum on the “History of Hajj and the Two Holy Mosques” in Jeddah (Photo: AETOSWire) The forum’s activities were inaugurated following the announcement by His Royal Highness Prince Faisal bin Salman bin Abdulaziz Al Saud, Special Advisor to the Custodian of the Two Holy Mosques and Chairman of the Board of Directors of the King Abdulaziz Foundation, who declared the launch of the forum during the opening ceremony of the “Hajj Conference and Exh

VSO Unveils VCP v1.0, a First-of-Its-Kind Cryptographic Audit Protocol to Restore Trust in AI-Driven Markets28.11.2025 06:30:00 CET | Press release

New open standard replaces opaque server logs with mathematically verifiable evidence, helping market participants meet EU AI Act and MiFID II transparency requirements The VeritasChain Standards Organization (VSO), an independent international standards body, today announced the global release of VeritasChain Protocol (VCP) v1.0, an open cryptographic audit protocol designed to provide mathematically provable transparency for AI‑driven and algorithmic trading systems. VCP replaces mutable server logs with a tamper‑evident chain of cryptographic evidence, enabling regulators, brokers, exchanges and trading firms to move from trust‑based oversight to verification‑based supervision. Why This Matters Now The launch of VCP v1.0 comes at a pivotal moment for global market infrastructure: More than 80 proprietary trading firms collapsed between 2024 and 2025 amid regulatory scrutiny, opaque execution models and frozen payout disputes, leaving a trust gap between traders and platforms. Regula

Andersen Consulting styrker sine kompetencer med BMA27.11.2025 22:48:00 CET | Pressemeddelelse

Andersen Consulting udvider sine kompetencer inden for bæredygtighed og virksomhedsforandring gennem en samarbejdsaftale med BMA, der er et sydafrikansk firma, som arbejder for at styrke konkurrenceevnen i fremstillingsindustrien og fremme inkluderende industriel vækst. BMA, der blev etableret for mere end to årtier siden, arbejder på tværs af produktionsværdikæder – fra producenter til deres kunder – sammen med myndigheder og udviklingsagenturer for at fremme bæredygtig industriel konkurrenceevne. Gennem sine sektorfokuserede industrielle klynger leverer firmaet integrerede tjenester inden for industriel politik og strategisk udvikling, værdikædestrategi, produktionskonkurrenceevne og lean-rådgivning, reduktion af CO2-udledning samt udvikling af små og mellemstore virksomheder og samler interessenter omkring fælles prioriteter og skalerbare, langsigtede løsninger. "Bæredygtig produktion handler om mere end effektivitet. Det drejer sig om at skabe økosystemer, der er regenerative, resi

In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.

Visit our pressroom
World GlobeA line styled icon from Orion Icon Library.HiddenA line styled icon from Orion Icon Library.Eye