Chapter II — ICT risk management
Section II — Protection and prevention
ICT systems, protocols and tools
Summary
Requires financial entities to use and maintain updated ICT systems, protocols, and tools that are appropriate to the scale of operations and adequate to support critical or important functions. Mandates capacity management, resilience engineering, and regular assessments of ICT system adequacy.
Key Requirements
- 1
Use reliable and resilient ICT systems proportionate to scale
- 2
Implement capacity management and performance monitoring
- 3
Ensure systems support critical or important functions adequately
- 4
Regularly assess whether ICT systems remain adequate
- 5
Minimize impact of ICT risks on systems through protection mechanisms
Detailed Analysis
Article 7 focuses on the technical foundations of ICT risk management, requiring financial entities to use and maintain ICT systems, protocols, and tools that are reliable, resilient, and proportionate to their operational needs. This article bridges governance (Article 5-6) and the specific protection measures (Articles 8-9).
Financial entities must ensure their ICT infrastructure can support the performance and availability requirements of their critical or important functions. This includes implementing robust capacity management processes that anticipate growth, seasonal peaks, and stress scenarios. Systems must be monitored for performance degradation, and thresholds must trigger timely alerts.
The article requires regular assessments of ICT system adequacy, particularly when there are significant changes in business volumes, organizational structure, or the threat landscape. These assessments must consider both current needs and foreseeable developments, ensuring that technological obsolescence does not create unmanaged risks.
A key aspect is the requirement for resilience engineering — designing systems that can withstand disruptions and continue operating, even in degraded mode. This means building redundancy, failover capabilities, and graceful degradation into the architecture of critical systems, rather than treating these as afterthoughts.
Ready to automate compliance with Article 7?
Valendir maps every DORA requirement to actionable controls, evidence, and workflows.