Capgemini-你准备好遵守规定了吗?确保不断变化的数字商业环境的稳定性(英)-2023-10页_1mb
报告摘要
1 Introduction and Regulatory Context
- Since 2008, the EU has strengthened financial resilience through regulatory measures.
- The Digital Operational Resilience Act (DORA) aims to enhance cyber and digital risk management for EU financial institutions and critical ICT providers.
- DORA requires robust operational resilience practices, set to fully enforce by January 17, 2025.
2 DORA Pillars and Requirements
- ICT Risk Management: Develop a comprehensive framework for risk identification, prevention, and response.
- Incident Reporting: Report significant cyber incidents promptly to authorities and encourage industry collaboration.
- Digital Operational Resilience Testing: Conduct threat-based penetration testing every three years with regulatory oversight.
- Third-Party Risk Management: Assess and manage ICT third-party providers' resilience annually.
- Information and Intelligence Sharing: Promote intelligence sharing between institutions to enhance collective security.
3 Compliance and Implications
- Timeline: Deadline for DORA compliance is January 17, 2025.
- Penalties: Non-compliance may lead to daily fines (up to 1% of average daily turnover for ICT providers) and potential criminal liability.
- Cross-Border Impact: DORA may apply to foreign firms operating in the EU, with similar regulatory movements in the UK and US.
4 Recommended Actions
- Strengthen business continuity planning and implement detailed dependency mapping.
- Perform regular vulnerability assessments and mitigation efforts.
- Ensure clear communication channels and standardize of risk management processes.
5 Next Steps
- Prioritize the development of an ICT risk management framework to align with DORA’s five pillars.
- Begin preparation for regular testing and internal assessments of third-party providers.
- Engage with industry consortia and intelligence sharing communities.
6 Related Developments
- United Kingdom: Plans to expand operational resilience regulation for critical third-party providers, timeline uncertain.
- United States: New York DFS is revising cybersecurity regulations with potentially stricter requirements.
展开完整摘要
试读结束,高清完整版pdf/doc/ppt,请点下载