<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Digital Operational Resilience Act for Financial Sector (DORA) in Industry News</title>
    <link>https://community.isc2.org/t5/Industry-News/Digital-Operational-Resilience-Act-for-Financial-Sector-DORA/m-p/66483#M6672</link>
    <description>&lt;P&gt;Thanks for sharing&amp;nbsp;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/809125741"&gt;@Caute_cautim&lt;/a&gt;.&lt;/P&gt;</description>
    <pubDate>Wed, 24 Jan 2024 01:33:03 GMT</pubDate>
    <dc:creator>Kyaw_Myo_Oo</dc:creator>
    <dc:date>2024-01-24T01:33:03Z</dc:date>
    <item>
      <title>Digital Operational Resilience Act for Financial Sector (DORA)</title>
      <link>https://community.isc2.org/t5/Industry-News/Digital-Operational-Resilience-Act-for-Financial-Sector-DORA/m-p/66480#M6670</link>
      <description>&lt;P&gt;Hi All&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;Cryptography management and cryptoagility closer to become regulation after the three European Supervisory Authorities (&lt;A href="https://www.linkedin.com/company/european-banking-authority/" target="_blank" rel="noopener"&gt;European Banking Authority (EBA)&lt;/A&gt;, &lt;A href="https://www.linkedin.com/company/eiopa-eu/" target="_blank" rel="noopener"&gt;European Insurance and Occupational Pensions Authority (EIOPA)&lt;/A&gt; and &lt;A href="https://www.linkedin.com/company/european-securities-and-markets-authority-esma/" target="_blank" rel="noopener"&gt;European Securities and Markets Authority (ESMA)&lt;/A&gt; – the ESAs) published today the&amp;nbsp;first set of final draft Regulatory Technical Standards&amp;nbsp;(RTS) under the DORA. (Find the relevant links at the end)&lt;BR /&gt;&lt;BR /&gt;DORA is the Digital Operational Resilience Act for the financial sector with&amp;nbsp;rules for the protection, detection, containment, recovery and repair capabilities against IT incidents.&lt;BR /&gt;&lt;BR /&gt;The draft RTS on ICT risk management framework covers encryption and cryptography in section IV (page 49). Review highlight Article 6, point 4:&lt;BR /&gt;"Financial entities shall include in the policy on encryption and cryptographic controls provisions to, where necessary, on the basis of developments in cryptanalysis, update or change the cryptographic technology to ensure they remain resilient against cyber threats [...]. Where the financial entity cannot update or change the cryptographic technology, it shall adopt mitigation and monitoring measures to ensure they remain resilient against cyber threats."&lt;BR /&gt;&lt;BR /&gt;These final draft technical standards have been submitted to the European Commission, who will now start working on their review with the objective to adopt these first standards in the coming months. So, proper cryptography management and cryptoagility will soon be part of the regulatory compliance obligations of financial entities in Europe.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;&lt;A href="https://lnkd.in/dnzDP9PG" target="_self"&gt;https://lnkd.in/dnzDP9PG&lt;/A&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;&lt;A href="https://lnkd.in/dp2aUj75" target="_self"&gt;https://lnkd.in/dp2aUj75&lt;/A&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;&lt;A href="https://lnkd.in/dtJguGHf" target="_self"&gt;https://lnkd.in/dtJguGHf&lt;/A&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;Regards&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;Caute_Cautim&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jan 2024 22:38:30 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Digital-Operational-Resilience-Act-for-Financial-Sector-DORA/m-p/66480#M6670</guid>
      <dc:creator>Caute_cautim</dc:creator>
      <dc:date>2024-01-23T22:38:30Z</dc:date>
    </item>
    <item>
      <title>Re: Digital Operational Resilience Act for Financial Sector (DORA)</title>
      <link>https://community.isc2.org/t5/Industry-News/Digital-Operational-Resilience-Act-for-Financial-Sector-DORA/m-p/66483#M6672</link>
      <description>&lt;P&gt;Thanks for sharing&amp;nbsp;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/809125741"&gt;@Caute_cautim&lt;/a&gt;.&lt;/P&gt;</description>
      <pubDate>Wed, 24 Jan 2024 01:33:03 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Digital-Operational-Resilience-Act-for-Financial-Sector-DORA/m-p/66483#M6672</guid>
      <dc:creator>Kyaw_Myo_Oo</dc:creator>
      <dc:date>2024-01-24T01:33:03Z</dc:date>
    </item>
    <item>
      <title>Re: Digital Operational Resilience Act for Financial Sector (DORA)</title>
      <link>https://community.isc2.org/t5/Industry-News/Digital-Operational-Resilience-Act-for-Financial-Sector-DORA/m-p/75647#M7318</link>
      <description>&lt;P&gt;Thanks for sharing&amp;nbsp;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/809125741"&gt;@Caute_cautim&lt;/a&gt;&amp;nbsp;. I came across this subject when I was searching for DORA related articles, webinars... but couldn't find any in the ISC2 community.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How can we have the RTS and ITS that are validated for use? Are they available for public?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;SecuFreak&lt;/P&gt;</description>
      <pubDate>Fri, 13 Dec 2024 10:46:54 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Digital-Operational-Resilience-Act-for-Financial-Sector-DORA/m-p/75647#M7318</guid>
      <dc:creator>SecuFreak</dc:creator>
      <dc:date>2024-12-13T10:46:54Z</dc:date>
    </item>
  </channel>
</rss>

