Case study13 min

Case: the institution that "already had everything"

The situation

A 280-person payment institution, ISO/IEC 27001 certified for four years, aligned with EBA/GL/2019/04, with an annually tested continuity plan. The executive committee considers that DORA "does not change much".

The article-by-article gap analysis produces a more nuanced result.

What was already covered

ArticleStatusExisting source
9 ProtectionCoveredISO/IEC 27001 Annex A
10 DetectionCoveredExisting monitoring and SOC
12 BackupsPartiallyExisting policy, with no immutability requirement
13 LearningCoveredISMS improvement process
17 Incident managementCoveredExisting ITIL procedure
24–25 TestingPartiallyAnnual technical tests, no formalised programme

That is roughly 60% of requirements, already met by operational arrangements.

The four real gaps

Article 5 — board accountability. The framework existed but had never been formally approved by the board, and no director had received ICT risk training. Treatment: a resolution and a three-hour training session. Cost: low. Stakes: the first point examined in a review.

Article 8 — function / asset / third-party chain. The asset inventory existed, the process map too, but nothing linked them. Treatment: eight weeks of workshops. The costliest gap in time.

Article 19 — notification deadlines. The incident procedure existed, with no role empowered to classify alone out of hours and no report templates. Treatment: two weeks.

Article 28 — register of information. Non-existent. Procurement held a supplier list with no link to functions, no legal entity identifiers, no sub-outsourcing chain. Treatment: four months, two of them waiting for supplier responses.

What the case generalises

A mature security framework covers DORA's technical requirements well. It almost never covers the three requirements of a different nature: the board's personal governance, the chaining between business and technology, and the contractual inventory of third parties.

None of those can be derived from a prior standard. That is where effort must be concentrated from the outset.

Key takeaways

  • A mature ISO 27001 system covers roughly 60% of DORA
  • Gaps concentrate on the register, notification deadlines and board accountability
  • An article-by-article gap analysis saves six months of pointless work