Glossary

DORA Regulatory Glossary

Every key term from the Digital Operational Resilience Act, defined and cross-referenced.

A

Access control

governance
Art. 9

B

Backup policy

risk
Art. 12

Business impact analysis (BIA)

risk
Art. 11

C

Competent authority

governance
Art. 19

Contractual arrangements

third party
Art. 30

Critical ICT third-party service provider

third party
Art. 31

Critical or important function

core
Art. 3(22)

Cyber threat

risk
Art. 3(12)

D

Data integrity

core
Art. 3(3)

Digital operational resilience

core
Art. 3(1)

Digital operational resilience testing

testing
Art. 24

E

Exit strategy

third party
Art. 30

I

ICT assets

core
Art. 3(6)

ICT business continuity policy

governance
Art. 11

ICT change management

governance
Art. 9

ICT concentration risk

third party
Art. 3(29)

ICT disaster recovery plan

risk
Art. 11

ICT risk

risk
Art. 3(5)

ICT risk management framework

governance
Art. 6

ICT security policy

governance
Art. 9

ICT services

core
Art. 3(21)

ICT third-party service provider

third party
Art. 3(19)

Incident reporting

incident
Art. 19

Information asset

core
Art. 3(7)

Information-sharing arrangements

governance
Art. 45

L

Lead Overseer

third party
Art. 31-32

M

Major ICT-related incident

incident
Art. 3(10)

Management body

governance
Art. 5

P

Post-incident review

incident
Art. 13

Proportionality principle

governance
Art. 4

R

Recovery point objective (RPO)

risk
Art. 11

Recovery time objective (RTO)

risk
Art. 11

Red team testing

testing
Art. 26

Register of information

third party
Art. 28(3)

Root cause analysis

incident
Art. 17

S

Simplified ICT risk management framework

governance
Art. 16

Subcontracting

third party
Art. 30

Substitutability

third party
Art. 29

T

Threat intelligence

risk
Art. 13, Art. 45

Threat-led penetration testing (TLPT)

testing
Art. 3(17)

V

Vulnerability assessment

testing
Art. 25