Glossary term
Operational Resilience Testing
Also: Digital Operational Resilience Testing, DORA Art. 24-27
Mandatory testing programme under DORA Art. 24-27 for the operational resilience of financial entities' ICT systems. Covers vulnerability assessments, open-source analyses, network security reviews, gap analyses, physical security reviews, questionnaires, scans, penetration tests and TLPT.
DORA demands an annual testing programme proportional to the size, risk profile and complexity of the financial entity. The programme must define test methods, frequency, scope, acceptance criteria, escalation paths, reporting and remediation discipline. Results feed the annual ICT risk report to the supervisor.
Test spectrum: vulnerability assessments at least yearly, source-code reviews for critical applications, penetration tests for external and critical internal systems, network security assessments, performance and end-to-end tests. Significant entities additionally need TLPT at least every three years (Art. 26-27).
Audit logic: the testing programme must be steered by an independent function inside or outside the entity. Testers must not concurrently be developers or operators of the tested systems. Evidence duty: every test needs minutes, findings list, risk rating, remediation plan, retest.
Related terms
DORA
EU regulation on digital operational resilience in the financial sector. Directly applicable since 1…
TLPT (Threat-Led Penetration Testing)
Ein behördlich begleiteter, intelligenz-gesteuerter Penetrationstest, den DORA für signifikante Fina…
Compliance mapping
The explicit link between a decision (vendor, architecture, control) and the specific regulatory art…
AI Act Conformity Assessment
Procedure to demonstrate that a high-risk AI system complies with the EU AI Act before being placed …
AI Act Risk Categories
Four-tier classification under the EU AI Act: prohibited (Art. 5), high-risk (Annex I/III), limited …
Audit-ready decision
A decision whose record is structured, evidence-backed and stakeholder-signed to a level that a thir…
BAIT
BaFin circular that concretises IT requirements for credit institutions. Specifies MaRisk AT 7.2 for…
BCM
Discipline for maintaining critical business processes during disruptions. Standards: ISO 22301, BSI…
