Glossary
DORA Regulatory Glossary
Every key term from the Digital Operational Resilience Act, defined and cross-referenced.
A
Access control
governanceArt. 9
B
Backup policy
riskArt. 12
Business impact analysis (BIA)
riskArt. 11
C
Competent authority
governanceArt. 19
Contractual arrangements
third partyArt. 30
Critical ICT third-party service provider
third partyArt. 31
Critical or important function
coreArt. 3(22)
Cyber threat
riskArt. 3(12)
D
Data integrity
coreArt. 3(3)
Digital operational resilience
coreArt. 3(1)
Digital operational resilience testing
testingArt. 24
E
Exit strategy
third partyArt. 30
I
ICT assets
coreArt. 3(6)
ICT business continuity policy
governanceArt. 11
ICT change management
governanceArt. 9
ICT concentration risk
third partyArt. 3(29)
ICT disaster recovery plan
riskArt. 11
ICT risk
riskArt. 3(5)
ICT risk management framework
governanceArt. 6
ICT security policy
governanceArt. 9
ICT services
coreArt. 3(21)
ICT third-party service provider
third partyArt. 3(19)
ICT-related incident
incidentArt. 3(8)
Incident reporting
incidentArt. 19
Information asset
coreArt. 3(7)
Information-sharing arrangements
governanceArt. 45
L
Lead Overseer
third partyArt. 31-32
M
Major ICT-related incident
incidentArt. 3(10)
Management body
governanceArt. 5
P
Post-incident review
incidentArt. 13
Proportionality principle
governanceArt. 4
R
Recovery point objective (RPO)
riskArt. 11
Recovery time objective (RTO)
riskArt. 11
Red team testing
testingArt. 26
Register of information
third partyArt. 28(3)
Root cause analysis
incidentArt. 17
S
Simplified ICT risk management framework
governanceArt. 16
Subcontracting
third partyArt. 30
Substitutability
third partyArt. 29
T
Threat intelligence
riskArt. 13, Art. 45
Threat-led penetration testing (TLPT)
testingArt. 3(17)
V
Vulnerability assessment
testingArt. 25