Source: OJ L 333, 27.12.2022, p. 1–79
EN- Digital operational resilience in the financial sector
Basic legislative acts
- DORA regulation
Article 25 Testing of ICT tools and systems
The digital operational resilience testingas defined in Article 24 programme referred to in Article 24 shall provide, in accordance with the criteria set out in Article 4(2), for the execution of appropriate tests, such as vulnerability means a weakness, susceptibility or flaw of a product with digital elements that can be exploited by a cyber threat; assessments and scans, open source analyses, network security assessments, gap analyses, physical security reviews, questionnaires and scanning software means the part of an electronic information system which consists of computer code; solutions, source code reviews where feasible, scenario-based tests, compatibility testing, performance testing, end-to-end testing and penetration testing.
Central securities depositories means a central securities depository as defined in Article 2(1), point (1), of Regulation (EU) No 909/2014; and central counterparties means a central counterparty as defined in Article 2, point (1), of Regulation (EU) No 648/2012; shall perform vulnerability means a weakness, susceptibility or flaw of a product with digital elements that can be exploited by a cyber threat; assessments before any deployment or redeployment of new or existing applications and infrastructure components means software or hardware intended for integration into an electronic information system;, and ICT services means digital and data services provided through ICT systems to one or more internal or external users on an ongoing basis, including hardware as a service and hardware services which includes the provision of technical support via software or firmware updates by the hardware provider, excluding traditional analogue telephone services; supporting critical or important functions means a function, the disruption of which would materially impair the financial performance of a financial entity, or the soundness or continuity of its services and activities, or the discontinued, defective or failed performance of that function would materially impair the continuing compliance of a financial entity with the conditions and obligations of its authorisation, or with its other obligations under applicable financial services law; of the financial entity means a natural or legal person created and recognised as such under the national law of its place of establishment, which may, acting under its own name, exercise rights and be subject to obligations;.
Microenterprises, ‘small enterprises’ and ‘medium-sized enterprises’ mean, respectively, microenterprises, small enterprises and medium-sized enterprises as defined in the Annex to Recommendation 2003/361/EC; shall perform the tests referred to in paragraph 1 by combining a risk-based approach with a strategic planning of ICT testing, by duly considering the need to maintain a balanced approach between the scale of resources and the time to be allocated to the ICT testing provided for in this Article, on the one hand, and the urgency, type of risk means the potential for loss or disruption caused by an incident and is to be expressed as a combination of the magnitude of such loss or disruption and the likelihood of occurrence of the incident;, criticality of information assets means a collection of information, either tangible or intangible, that is worth protecting; and of services provided, as well as any other relevant factor, including the financial entity means a natural or legal person created and recognised as such under the national law of its place of establishment, which may, acting under its own name, exercise rights and be subject to obligations;’s ability to take calculated risks means the potential for loss or disruption caused by an incident and is to be expressed as a combination of the magnitude of such loss or disruption and the likelihood of occurrence of the incident;, on the other hand.
Springlex and this text is meant purely as a documentation tool and has no legal effect. No liability is assumed for its content. The authentic version of this act is the one published in the Official Journal of the European Union.