+DORA Ch. II Sec. II Art. 12 1.

DORA Ch. II Sec. II Art. 12 1.

1.   For the purpose of ensuring the restoration of ICT systems and data with minimum downtime, limited disruption and loss, as part of their ICT risk management framework, financial entities shall develop and document:

  • (a) backup policies and procedures specifying the scope of the data that is subject to the backup and the minimum frequency of the backup, based on the criticality of information or the confidentiality level of the data;
  • (b) restoration and recovery procedures and methods.

1. Overview

Summary Regulation

1.1 References

1.2 Identified Requirements

1.3 Related Standards

2. Identified Requirements

Requirements
Source Requirement

3. Related Standards

Standards
Source Requirement
NOREA Critical and Important Functions
Identify, classify and adequately document all critical and important functions. This process involves determining which functions are essential for the entity's operational stability and continuity. Review as needed, and at least yearly, the adequacy of this classification.
NOREA Clear Segregation of Duties (SoD)
Establish Segregation of Duties (SoD) with regard to risk management functions, following the three lines of defence model or internal risk management and control model.
NOREA ICT Risk management framework

A sound, comprehensive and well-documented ICT risk management framework is in place. Which as goal to address all ICT risks properly and ensure a high level of digital resilience. The reponsibility for risk management is properly assigned to a control function. 

The ICT risk management framework shall be documented and reviewed at least annually, or periodically for microenterprises, with immediate reviews triggered by major ICT-related incidents or supervisory feedback. Continuous improvement will be ensured by incorporating lessons learned from implementation, monitoring, and audits. The report of the review will be prepared according to the requirements as stated in chapter 5 (Article 27) of the RTS RM and will be made available for submission to the competent authority upon request. 

Assess new standards and relevant technology developments in the field of information security, cybersecurity and resilience on a continuous basis and make proposals on how they can strengthen the information security and cybersecurity control measures of the institution.

NOREA Annual Framework Review and Audit Process

The effectiveness of the risk management framework is monitored based on the risk exposure over time to critical or important business functions. Implement a reviewing and auditing process, with a minimum yearly review of the framework, triggered by major ICT incidents, regulator instructions, or major audit findings. 

The tasks of verifying compliance with ICT risk management requirements may be outsourced to intra-group or external undertakings. In case of such outsourcing, the financial entity remains fully responsible for the verification of compliance with the ICT risk management requirements.

NOREA Third-Party (Multi-vendor) Risk Management Program

Maintain a comprehensive third-party risk management program which includes:

  • A register of information related to the use of thirdparty service providers, especially those supporting critical or important functions (see also control 17.3).
  • Put in place a policy on the management of ICT third-parties, including the criteria for determining the criticality of service providers and the internal responsibilities for managing third-parties.
  • Ensuring that senior management reviews the policy and designate a member to monitor relations with the third-parties and the contractual arrangements.
  • A (holistic) multi-vendor strategy, if deemed relevant,  showing key dependencies on ICT third-party service providers and explaining the rationale behind the procurement mix of ICT third-party service providers.  
NOREA Backup Policy
Define backup policies aimed at ensuring minimum downtime, limited disruption, and loss, and put in place restoration and recovery procedures. Specify the scope of the data subject to backups and the minimum frequency of backups, based on the criticality or confidentiality of data. Determine a Recovery Time Objective (RTO) and a Recovery Point Objective (RPO) based on data criticality and overall impact on market efficiency to ensure that service levels are met in extreme scenarios.
NOREA Restore Procedures

Ensure that the activation of backup systems will not jeopardize the security of ICT systems or the availability, authenticity, integrity or confidentiality of data. For example through the execution of periodic restore tests based on the backup, restoration, and recovery procedures. 

Ensure that when restoring backup data using self-managed systems, that systems are used that are both physically and logically segregated from the source system to ensure protection. Furthermore, the backup systems shall be securely protected from any unauthorized access or IT corruption and allow for timely restoration. Institutions must validate that the highest level of data integrity is maintained when restoring backups.

Additionally for central counterparties: the recovery plans shall enable the recovery of all transactions at the time of disruption to allow the central counterparty to continue to operate with certainty and to complete settlement on the scheduled date.

Additionally for data reporting service providers*: the providers shall additionally maintain adequate resources and have back-up and restoration facilities in place in order to offer and maintain their services at all times.

*For definition of DRSP see: https://www.esma.europa.eu/esmas-activities/markets-and-infrastructure/data-reporting-services-providers 

NOREA Protection Measures

Implement policies and procedures to protect all information, ICT assets, and relevant physical ICT components and infrastructures. At least the following policies shall be established and maintained.

  • Security policy
  • Human resources policy
  • Encryption and cryptographic control policy
  • Identity and access management (IAM) policy
  • Change management policy
  • Network security policy
  • ICT operating policies and procedures
  • (Crisis) Communication policy
  • Vulnerability and patch management policy
  • Back up policy
  • Project management policy
  • Physical and environmental security policy
  • Business continuity policy with response and recovery plans (including testing plans), see control1.4 *
  • ICT third-party service providers management policy, see control 1.1. *
  • Operations of ICT assets (ensuring network security, protect against intrusions and data misuse and defining how the entity operates, monitors, controls, and restores ICT assets, including the documentation of ICT operations).

* must be approved by the Management body

SCF Business Continuity Management System (BCMS)

Description

Mechanisms exist to facilitate the implementation of contingency planning controls to help ensure resilient Technology Assets, Applications and/or Services (TAAS) (e.g., Continuity of Operations Plan (COOP) or Business Continuity & Disaster Recovery (BC/DR) playbooks).

Possible Solutions & Considerations

Micro-Small Business (<10 staff) / BLS Firm Size Classes 1-2

∙ Continuity of Operations Plan (COOP)
∙ Business Continuity Plan (BCP)
∙ Disaster Recovery Plan (DRP)
∙ Business Impact Analysis (BIA)
∙ Criticality assessments

Small Business (10-49 staff) / BLS Firm Size Classes 3-4

∙ Continuity of Operations Plan (COOP)
∙ Business Continuity Plan (BCP)
∙ Disaster Recovery Plan (DRP)
∙ Business Impact Analysis (BIA)
∙ Criticality assessments

Medium Business (50-249 staff) / BLS Firm Size Classes 5-6

∙ Continuity of Operations Plan (COOP)
∙ Business Continuity Plan (BCP)
∙ Disaster Recovery Plan (DRP)
∙ Business Impact Analysis (BIA)
∙ Criticality assessments

Large Business (250-999 staff) / BLS Firm Size Classes 7-8

∙ Continuity of Operations Plan (COOP)
∙ Business Continuity Plan (BCP)
∙ Disaster Recovery Plan (DRP)
∙ Business Impact Analysis (BIA)
∙ Criticality assessments

Enterprise (> 1,000 staff) / BLS Firm Size Class 9

∙ Continuity of Operations Plan (COOP)
∙ Business Continuity Plan (BCP)
∙ Disaster Recovery Plan (DRP)
∙ Business Impact Analysis (BIA)
∙ Criticality assessments

SCR-CMM

Level 0 Not Performed

Practices are non-existent, based on the inability to demonstrate an implemented and operational capability. A reasonable person would conclude the control is not being performed.

Level 1 Performed Informally

Business Continuity & Disaster Recovery (BCD) domain capabilities are ad hoc and inconsistent. Capability criteria associated with this control may include:
▪ Policies, standards & procedures associated with BCD domain capabilities provide limited coverage due to the depth and breadth of the existing documentation.
▪ Contingency management-related activities are decentralized (e.g., a localized/regionalized function) and uses non-standardized methods to implement secure, resilient and compliant practices.
▪ Limited technologies exist to support near real-time network infrastructure failover (e.g., redundant ISPs, redundant power, etc.).
▪ IT and/or cybersecurity personnel develop limited Disaster Recovery Plans (DRP) to recover business-critical Technology Assets, Applications and/or Services (TAAS) and services.

Level 2 Planned Tracked

Business Continuity & Disaster Recovery (BCD) capabilities are requirements-driven, but are not standardized across the entity (e.g., local/regional level consistency). Capability criteria associated with this control reasonably expect the following criteria to exist:
▪ Policies and standards associated with BCD domain capabilities are formally documented and centrally-managed by the entity.
▪ Standardized Operating Procedures (SOP) associated with BCD domain capabilities are documented and maintained by process owners.
▪ IT and/or cybersecurity personnel work with business stakeholders and process owners to appropriately scope and reasonably implement cybersecurity and data protection controls associated with BCD domain capabilities to address applicable statutory, regulatory and/or contractual requirements for Technology Assets, Applications, Services and/or Data (TAASD).
▪ Business Continuity / Disaster Recovery (BC/DR)-related controls are primarily administrative and preventative in nature (e.g., policies, standards, procedures & guidelines).
▪ BC/DR may be a defined function (e.g., team or department) or assigned as an additional duty to existing IT and/or cybersecurity personnel.
▪ Business stakeholders and process owners identify business-critical TAASD and External Service Providers (ESPs).
▪ IT and/or cybersecurity personnel work with business stakeholders and process owners to identify single points of failure from a TAASD perspective.
▪ IT and/or cybersecurity personnel work with business stakeholders and process owners to develop BC/DR plans to recover business-critical TAASD.
▪ Data/process owners conduct a Business Impact Analysis (BIA) at least annually, or after any major technology or process change, to identify TAASD that are critical to the business, as well as single points of failure.
▪ Business stakeholders and process owners designate alternative decision-makers if primary decision-makers are unavailable.

Level 3 Well Defined

Business Continuity & Disaster Recovery (BCD) capabilities are standardized across the entity for applicability to People, Processes, Technologies, Data and/or Facilities (PPTDF) to ensure consistency for Technology Assets, Applications, Services and/or Data (TAASD). Capability criteria associated with this control reasonably expect the following criteria to exist:
▪ Policies and standards associated with BCD domain capabilities are formally documented and centrally-managed by the entity's Governance, Risk & Compliance (GRC) team, or similar function.
▪ Standardized Operating Procedures (SOP) associated with BCD domain capabilities are well-documented and kept current by process owners.
▪ A Business Continuity & Disaster Recovery (BC/DR) team, or similar function, is appropriately staffed and supported to implement and maintain BCD domain capabilities.
▪ Technology is leveraged to enhance the efficiency and accuracy of BC/DR operations (e.g., BC/DR planning software, Disaster Recovery as a Service (DRaaS), Orchestration and Automation Tools, etc.).
▪ The entity's Governance, Risk & Compliance (GRC) team, or similar function, works with business stakeholders and process owners to appropriately scope and reasonably implement cybersecurity and data protection controls associated with BCD domain capabilities to address Minimum Compliance Requirements (MCR) (e.g., applicable statutory, regulatory and/or contractual requirements) and Discretionary Security Requirements (DSR) (e.g., entity-required controls).
▪ An implemented and operational capability exists to facilitate the implementation of contingency planning controls to help ensure resilient Technology Assets, Applications and/or Services (TAAS) (e.g., Continuity of Operations Plan (COOP) or BC/DR playbooks).

Level 4 Quantitatively Controlled

Business Continuity & Disaster Recovery (BCD) capabilities, in addition to being standardized across the entity and centrally managed to ensure consistency across Technology Assets, Applications, Services and/or Data (TAASD), efforts are metrics driven to provide sufficient insight for decision makers to predict optimal performance, ensure continued operations and/or identify areas for improvement. Capability criteria associated with this control reasonably expect the following criteria to exist:
▪ Applicable SCR-CMM Level 3 (Well Defined) capabilities are implemented and operational.
▪ Metrics reporting includes quantitative analysis of Key Performance Indicators (KPIs).
▪ Metrics reporting includes quantitative analysis of Key Risk Indicators (KRIs).
▪ Scope of metrics, KPIs and KRIs covers organization-wide cybersecurity and data protection controls, including functions performed by third-parties.
▪ Organizational leadership maintains a formal process to objectively review and respond to metrics, KPIs and KRIs (e.g., monthly or quarterly review).
▪ Based on metrics analysis, process improvement recommendations are submitted for review and are handled in accordance with change control processes.
▪ Business and technical stakeholders are involved in reviewing and approving proposed changes to evolve capabilities.

Level 5 Continuously Improving

Utilize SCR-CMM Level 3 or Level 4 (if available) criteria definitions:
▪ There are no defined Level 5 criteria, since it is reasonable to assume a continuously-improving process is not necessary to operationalize this control.
▪ Level 5 capabilities should be considered “world-class” where the control builds on Level 4 capabilities, but are continuously improving through Artificial Intelligence (AI) and/or Machine Learning (ML) technologies.
▪ While it may be possible to develop responsive capabilities for this control through the use of AI and/or ML technologies, the criteria would be organization-specific to define.
SCF Data Backups

Description

Mechanisms exist to create recurring backups of data, software and/or system images, as well as verify the integrity of these backups, to ensure the availability of the data to satisfy Recovery Time Objectives (RTOs) and Recovery Point Objectives (RPOs).

Possible Solutions & Considerations

Micro-Small Business (<10 staff) / BLS Firm Size Classes 1-2

∙ Disaster Recovery Plan (DRP)
∙ 3-2-1 backup rule (3 copies, 2 media types, 1 offsite)
∙ Cloud backup service (e.g., Backblaze B2, iDrive, Veeam Agent Free)

Small Business (10-49 staff) / BLS Firm Size Classes 3-4

∙ Disaster Recovery Plan (DRP)
∙ 3-2-1 backup strategy (on-site + off-site/cloud)
∙ Cloud backup service (e.g., Acronis, Veeam, Azure Backup)

Medium Business (50-249 staff) / BLS Firm Size Classes 5-6

∙ Disaster Recovery Plan (DRP)
∙ 3-2-1-1 backup strategy (including immutable/offsite copy)
∙ Enterprise backup solution (e.g., Veeam Backup & Replication, Acronis Cyber Backup)

Large Business (250-999 staff) / BLS Firm Size Classes 7-8

∙ Disaster Recovery Plan (DRP)
∙ Immutable backup copies (air-gapped or object-locked S3/Azure Blob)
∙ Enterprise backup platform (e.g., Veeam, Commvault, Cohesity)
∙ Automated backup testing and alerting

Enterprise (> 1,000 staff) / BLS Firm Size Class 9

∙ Disaster Recovery Plan (DRP)
∙ Enterprise backup platform with immutable storage (e.g., Commvault, Veeam, Rubrik)
∙ Ransomware-resilient backup architecture (air-gap or immutable)
∙ Automated backup validation and recovery testing
∙ Backup data encrypted at rest and in transit

SCR-CMM

Level 0 Not Performed

Practices are non-existent, based on the inability to demonstrate an implemented and operational capability. A reasonable person would conclude the control is not being performed.

Level 1 Performed Informally

Business Continuity & Disaster Recovery (BCD) domain capabilities are ad hoc and inconsistent. Capability criteria associated with this control may include:
▪ Policies, standards & procedures associated with BCD domain capabilities provide limited coverage due to the depth and breadth of the existing documentation.
▪ Contingency management-related activities are decentralized (e.g., a localized/regionalized function) and uses non-standardized methods to implement secure, resilient and compliant practices.
▪ Limited technologies exist to support near real-time network infrastructure failover (e.g., redundant ISPs, redundant power, etc.).
▪ Backups are performed ad-hoc and focus on business-critical Technology Assets, Applications, Services and/or Data (TAASD).
▪ IT and/or cybersecurity personnel use a backup methodology (e.g., grandfather, father & son rotation) to create backups to support business needs (e.g., Recovery Time Objectives).
▪ Limited technologies exist to conduct full, incremental or differential backups (e.g., tape/disk, hybrid cloud or direct-to-cloud).
▪ Backups of sensitive/regulated data are cryptographically protected to prevent the unauthorized disclosure and modification of backup information.

Level 2 Planned Tracked

Business Continuity & Disaster Recovery (BCD) capabilities are requirements-driven, but are not standardized across the entity (e.g., local/regional level consistency). Capability criteria associated with this control reasonably expect the following criteria to exist:
▪ Policies and standards associated with BCD domain capabilities are formally documented and centrally-managed by the entity.
▪ Standardized Operating Procedures (SOP) associated with BCD domain capabilities are documented and maintained by process owners.
▪ IT and/or cybersecurity personnel work with business stakeholders and process owners to appropriately scope and reasonably implement cybersecurity and data protection controls associated with BCD domain capabilities to address applicable statutory, regulatory and/or contractual requirements for Technology Assets, Applications, Services and/or Data (TAASD).
▪ Business Continuity / Disaster Recovery (BC/DR)-related controls are primarily administrative and preventative in nature (e.g., policies, standards, procedures & guidelines).
▪ BC/DR may be a defined function (e.g., team or department) or assigned as an additional duty to existing IT and/or cybersecurity personnel.
▪ Appropriate TAASD exist to conduct full, incremental and/or differential backups (e.g., tape/disk, hybrid cloud or direct-to-cloud).
▪ IT personnel configure business-critical Technology Assets, Applications and/or Services to transfer backup data to the alternate site(s) at a rate that is capable of meeting RTOs and RPOs.
▪ The backup methodology is sufficient to support RTOs and RPOs for critical business functions.
▪ IT personnel store backups in a secondary location, separate from the primary storage site (e.g., cloud-based storage).

Level 3 Well Defined

Business Continuity & Disaster Recovery (BCD) capabilities are standardized across the entity for applicability to People, Processes, Technologies, Data and/or Facilities (PPTDF) to ensure consistency for Technology Assets, Applications, Services and/or Data (TAASD). Capability criteria associated with this control reasonably expect the following criteria to exist:
▪ Policies and standards associated with BCD domain capabilities are formally documented and centrally-managed by the entity's Governance, Risk & Compliance (GRC) team, or similar function.
▪ Standardized Operating Procedures (SOP) associated with BCD domain capabilities are well-documented and kept current by process owners.
▪ A Business Continuity & Disaster Recovery (BC/DR) team, or similar function, is appropriately staffed and supported to implement and maintain BCD domain capabilities.
▪ Technology is leveraged to enhance the efficiency and accuracy of BC/DR operations (e.g., BC/DR planning software, Disaster Recovery as a Service (DRaaS), Orchestration and Automation Tools, etc.).
▪ The entity's Governance, Risk & Compliance (GRC) team, or similar function, works with business stakeholders and process owners to appropriately scope and reasonably implement cybersecurity and data protection controls associated with BCD domain capabilities to address Minimum Compliance Requirements (MCR) (e.g., applicable statutory, regulatory and/or contractual requirements) and Discretionary Security Requirements (DSR) (e.g., entity-required controls).
▪ An implemented and operational capability exists to create recurring backups of data, software and/or system images, as well as verify the integrity of these backups, to ensure the availability of the data to satisfy Recovery Time Objectives (RTOs) and Recovery Point Objectives (RPOs).

Level 4 Quantitatively Controlled

Business Continuity & Disaster Recovery (BCD) capabilities, in addition to being standardized across the entity and centrally managed to ensure consistency across Technology Assets, Applications, Services and/or Data (TAASD), efforts are metrics driven to provide sufficient insight for decision makers to predict optimal performance, ensure continued operations and/or identify areas for improvement. Capability criteria associated with this control reasonably expect the following criteria to exist:
▪ Applicable SCR-CMM Level 3 (Well Defined) capabilities are implemented and operational.
▪ Metrics reporting includes quantitative analysis of Key Performance Indicators (KPIs).
▪ Metrics reporting includes quantitative analysis of Key Risk Indicators (KRIs).
▪ Scope of metrics, KPIs and KRIs covers organization-wide cybersecurity and data protection controls, including functions performed by third-parties.
▪ Organizational leadership maintains a formal process to objectively review and respond to metrics, KPIs and KRIs (e.g., monthly or quarterly review).
▪ Based on metrics analysis, process improvement recommendations are submitted for review and are handled in accordance with change control processes.
▪ Business and technical stakeholders are involved in reviewing and approving proposed changes to evolve capabilities.

Level 5 Continuously Improving

Utilize SCR-CMM Level 3 or Level 4 (if available) criteria definitions:
▪ There are no defined Level 5 criteria, since it is reasonable to assume a continuously-improving process is not necessary to operationalize this control.
▪ Level 5 capabilities should be considered “world-class” where the control builds on Level 4 capabilities, but are continuously improving through Artificial Intelligence (AI) and/or Machine Learning (ML) technologies.
▪ While it may be possible to develop responsive capabilities for this control through the use of AI and/or ML technologies, the criteria would be organization-specific to define.
Impressum German English