Operational information security

Operational information security Transitioning to DORA: impact on BAIT/VAIT ISMS requirements (Page 24) BaFin confirms: Key areas of uplift compared with BAIT/VAIT: 1. Stronger link to risk analysis 2. Mandatory, technology-agnostic control implementation 3. Universal applicability to all ICT systems Use of cyberspace and network security controls (Art. 9(3)(e)(vi) DORA) (Page 25) DORA requires institutions to implement network security measures appropriate to the institution’s size and risk profile. Key measures explicitly listed: The PDF confirms that BAIT/VAIT already include similar expectations, but DORA renders them formally binding and auditable on the basis of EU law. Information security measures (RTS RMF Art. 8) (Page 25) This … Continue reading Operational information securityRead More →