web analytics

Cybersecurity – DORA Practical Guide

Rate this post

The Digital Operational Resilience Act (DORA) is set to come into effect on January 17, 2025, aiming to enhance the operational resilience of financial entities, including Asset Management Companies (AMCs). The guide outlines essential requirements and best practices for compliance with DORA, focusing on several key areas:

  1. Governance and Organisation: AMCs must establish a robust governance framework that prioritizes cyber resilience. This includes regular reporting to the board on cyber resilience strategies and ensuring board members are trained on risk management policies.
  2. Risk Management Framework: AMCs are required to formalize their risk management processes, particularly concerning third-party ICT service providers. This involves assessing potential conflicts of interest and ensuring that service providers comply with up-to-date information security standards.
  3. Incident Categorisation: The guide emphasizes the importance of classifying and managing incidents effectively. AMCs must have a communication and response plan in place, detailing how incidents are reported, including their impact, causes, corrective measures, and resolution timelines.
  4. Resilience Testing: Regular resilience testing is mandated to ensure that AMCs can withstand and recover from operational disruptions. This includes implementing incident management systems and alert management requirements to harmonize reporting with existing regulations.
  5. Third Party Management: AMCs must maintain a register of third-party service providers and develop policies governing their use. This includes creating strategic exit plans and ensuring that all new contracts reflect the requirements set forth by DORA.
  6. Information Sharing: Transparency and cooperation with relevant authorities are crucial during incidents. AMCs must report incidents to competent national authorities and provide detailed information about the incident’s status and impact.

The guide serves as a comprehensive resource for AMCs to prepare for DORA compliance, highlighting the need for a proactive approach to operational resilience and cybersecurity. It stresses the importance of educating the board and ensuring that cyber resilience is a priority in organizational strategy. As the regulatory landscape evolves, AMCs are encouraged to stay informed and adapt their practices accordingly.

Views: 4

LinkedIn
Twitter
Facebook
WhatsApp
Email

advisor pick´S post

More Latest Published Posts