DORA Glossary
Clear, accessible definitions of the technical terms related to DORA and financial sector cybersecurity.
- Business continuity plan (BCP/DRP)
- The arrangements that allow a financial entity to maintain or resume its critical activities after an ICT incident.
- DORA
- Digital Operational Resilience Act — EU Regulation (EU) 2022/2554 on digital operational resilience for the financial sector.
- Financial entity
- Any organisation listed in Article 2 of DORA: bank, insurer, investment firm, crypto-asset provider...
- European Supervisory Authorities (ESAs)
- EBA, ESMA and EIOPA — the three authorities that draft DORA's technical standards and oversee critical ICT providers.
- ICT risk management
- DORA's first pillar: the governance, protection and continuity framework every financial entity must put in place.
- Major ICT-related incident
- An ICT incident whose severity exceeds defined thresholds, triggering an obligation to notify the authorities.
- Lead Overseer
- The European authority designated to directly oversee a critical third-party ICT provider.
- Lex specialis
- The legal principle by which DORA takes precedence over the NIS2 directive for the financial entities it covers.
- NIS2
- The European cybersecurity directive, for which DORA is the specialised track for the financial sector.
- Third-party ICT provider
- Any external provider (cloud, hosting, SaaS...) that a financial entity relies on for its ICT functions.
- Principle of proportionality
- The way DORA's requirements are adapted to the size, risk profile and systemic importance of each entity.
- Register of information
- The document listing all of a financial entity's contracts with its ICT service providers.
- Digital operational resilience
- A financial entity's ability to prevent, withstand, respond to and recover from an ICT-related disruption.
- RTS / ITS
- Regulatory and implementing technical standards that specify how DORA's requirements are applied in practice.
- ICT
- Information and Communication Technologies — the systems, software and networks whose resilience DORA regulates.
- TLPT
- Threat-Led Penetration Testing — penetration tests based on real threats, mandatory for the most significant financial entities.