DORA-Art45-P1

Article
45 (1)
Pillar
Information Sharing
Regulation Ref
Regulation (EU) 2022/2554, Article 45(1)
Last Reviewed
2026-01-15

Financial entities may exchange amongst themselves cyber threat information and intelligence, including indicators of compromise, tactics, techniques and procedures, cyber security alerts and configuration tools, to the extent that such information and intelligence sharing takes place within trusted communities of financial entities, is aimed at enhancing the digital operational resilience of financial entities, takes place in compliance with applicable data protection rules, and is carried out in accordance with relevant competition law.

Evidence Profiles

Information Sharing Policy RARE

Policy document defining the institution's approach to sharing cyber threat information and intelligence with trusted communities, including scope, governance, data protection safeguards, and competition law compliance as required by DORA Article 45.

Formats
PDF
Evidence Class
info-sharing-policy
Availability
RARE
Update Frequency
annual
Typical Author
CISO
Approval Chain
CISO → DPO → Legal Counsel → Board Risk Committee

Content Sections

Expected Fields

Common Quality Issues

View Example

Generated example artifact using the default institution profile (COMMON availability, synthetic data only).

PLAIN_TEXT — Inline Preview
INFORMATION SHARING POLICY
Cyber Threat Intelligence and Information Sharing Arrangements
Nordvik Bank AG
Policy Reference: POL-ISH-2025-001
Version 2.0 | Effective Date: 1 March 2025
Policy Owner: Chief Information Security Officer (CISO)
Classification: Internal

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

POLICY OBJECTIVES

This policy establishes Nordvik Bank AG's framework for sharing cyber threat
information and intelligence with trusted communities of financial entities, in
accordance with DORA Article 45. The policy aims to:

  — Enhance the Bank's digital operational resilience through collective
    intelligence on cyber threats, vulnerabilities, and attack techniques
  — Enable timely exchange of indicators of compromise (IoCs), tactics,
    techniques and procedures (TTPs), and cyber security alerts
  — Ensure all information sharing activities comply with applicable data
    protection regulations (GDPR, Swiss FADP) and competition law
  — Define governance structures, roles, and responsibilities for information
    sharing activities
  — Establish safeguards to protect the Bank's proprietary information and
    customer data during sharing activities

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

SCOPE OF INFORMATION SHARING

Types of Information Eligible for Sharing:

  Category                          Examples
  ─────────────────────────────────────────────────────────────────────────────
  Indicators of Compromise (IoCs)   IP addresses, domain names, file hashes,
                                    URLs, email addresses associated with
                                    malicious activity
  Tactics, Techniques and           MITRE ATT&CK framework references,
  Procedures (TTPs)                 attack chain descriptions, exploitation
                                    methods observed
  Cyber Security Alerts             Vulnerability advisories, zero-day
                                    notifications, threat actor activity
                                    warnings
  Configuration Tools               YARA rules, Snort/Suricata signatures,
                                    SIGMA detection rules, firewall rules
  Incident Summaries                Anonymised incident reports, lessons
                                    learned, post-incident analysis findings

Types of Information Excluded from Sharing:

  — Customer personally identifiable information (PII)
  — Internal audit findings and regulatory examination results
  — Proprietary trading strategies or algorithms
  — Information subject to legal privilege
  — Information classified as "Strictly Confidential" under the Bank's
    information classification scheme
  — Information that could reveal the Bank's specific security architecture
    or defensive posture in exploitable detail

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

TRUSTED COMMUNITIES

The Bank participates in the following trusted communities for cyber threat
information sharing:

  Community                         Type              Joined       Status
  ─────────────────────────────────────────────────────────────────────────────
  FS-ISAC (Financial Services       Sector ISAC       2019-06-01   Active
  Information Sharing and
  Analysis Center)

  DACH Financial CERT               Regional CERT     2022-03-15   Active
  (Germany, Austria, Switzerland
  financial sector CERT)

  EBF Cyber Intelligence            Industry body     2024-09-01   Active
  Sharing Initiative (European
  Banking Federation)

Criteria for Joining New Communities:

  — Community must be composed primarily of financial entities or entities
    supporting the financial sector
  — Community must have a formal governance structure and membership agreement
  — Community must enforce confidentiality obligations on all members
  — Community must comply with applicable data protection regulations
  — Community must have established procedures for anonymising shared
    information
  — Legal Counsel and DPO must approve membership before execution
  — Board Risk Committee must be notified of new community memberships

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

GOVERNANCE AND OVERSIGHT

Roles and Responsibilities:

  Role                              Responsibilities
  ─────────────────────────────────────────────────────────────────────────────
  CISO (Policy Owner)               Overall accountability for information
                                    sharing activities; annual policy review;
                                    approval of sharing decisions for HIGH
                                    sensitivity information
  Threat Intelligence Team Lead     Day-to-day management of sharing
                                    activities; review and approval of
                                    outbound information; monitoring of
                                    inbound intelligence
  Threat Intelligence Analysts      Preparation and anonymisation of
  (2 FTE)                           outbound information; analysis and
                                    dissemination of inbound intelligence;
                                    maintenance of sharing platform
                                    configurations
  Data Protection Officer (DPO)     Review of data protection compliance
                                    for sharing arrangements; DPIA for new
                                    communities; annual compliance audit
  Legal Counsel                     Competition law review of sharing
                                    arrangements; contract review for
                                    participation agreements; legal risk
                                    assessment

Governance Meetings:

  — Quarterly review of sharing activities by CISO and Threat Intelligence
    Team Lead
  — Annual review of community memberships and participation agreements
  — Ad-hoc review triggered by significant incidents or regulatory changes

Decision Authority for Outbound Sharing:

  Information Sensitivity    Approval Required
  ─────────────────────────────────────────────────────────────────────────────
  LOW (IoCs, signatures)     Threat Intelligence Analyst (self-approval)
  MEDIUM (TTPs, alerts)      Threat Intelligence Team Lead
  HIGH (incident summaries)  CISO

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

DATA PROTECTION SAFEGUARDS

All information sharing activities shall comply with the following data
protection requirements:

  1. Anonymisation Before Sharing
     All outbound information must be processed through the Bank's Threat
     Intelligence Anonymisation Procedures (PROC-ISH-ANON-2025-001) before
     sharing. This includes:
       — Removal of all customer PII
       — Removal of internal IP addresses and hostnames
       — Removal of employee names and identifiers
       — Replacement of institution-specific identifiers with generic labels
       — Removal of information that could identify specific business units
         or systems

  2. Data Protection Impact Assessment (DPIA)
     A DPIA shall be conducted before joining any new sharing community or
     significantly changing the scope of information shared with an existing
     community. The DPO is responsible for conducting and documenting the DPIA.

  3. Data Minimisation
     Only the minimum information necessary to achieve the sharing objective
     shall be shared. Analysts must apply the principle of data minimisation
     when preparing outbound intelligence.

  4. Retention and Destruction
     Inbound threat intelligence shall be retained for a maximum of 24 months
     unless required for ongoing incident investigation. Outbound sharing
     records shall be retained for 5 years for audit purposes.

  5. Cross-Border Transfer Safeguards
     For communities with members outside the EEA, appropriate transfer
     mechanisms (Standard Contractual Clauses or adequacy decisions) must be
     in place before sharing commences.

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

COMPETITION LAW COMPLIANCE

Information sharing arrangements must comply with EU and national competition
law. The following safeguards are in place:

  — No sharing of commercially sensitive information (pricing, customer lists,
    market strategies, business plans)
  — No sharing of information that could facilitate market coordination or
    collusion
  — Legal Counsel has reviewed all participation agreements for competition
    law compliance (last review: January 2025)
  — Annual competition law training for all Threat Intelligence team members
  — Sharing platforms configured to prevent inadvertent disclosure of
    commercially sensitive information
  — Legal Counsel available for ad-hoc consultation on borderline cases

Competition Law Review Schedule:
  — Annual review of all active sharing arrangements by Legal Counsel
  — Review triggered by any change in community membership or scope
  — Last review completed: 15 January 2025
  — Next scheduled review: January 2026

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

INFORMATION CLASSIFICATION FOR SHARING

The Bank applies the Traffic Light Protocol (TLP) for classifying shared
threat intelligence:

  TLP Level     Sharing Scope                    Bank Usage
  ─────────────────────────────────────────────────────────────────────────────
  TLP:RED       Named recipients only            Restricted to CISO and
                                                 Threat Intelligence Team Lead
  TLP:AMBER     Community members only           Shared within Threat
                                                 Intelligence team and
                                                 relevant SOC analysts
  TLP:GREEN     Community and partner             May be shared with IT
                organisations                    Security team and relevant
                                                 third-party providers
  TLP:CLEAR     Unrestricted                     May be shared publicly

All outbound information from the Bank defaults to TLP:AMBER unless the
sharing analyst explicitly assigns a different classification with
appropriate justification.

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

REVIEW SCHEDULE

  Review Activity                   Frequency    Responsible
  ─────────────────────────────────────────────────────────────────────────────
  Policy review and update          Annual       CISO
  Community membership review       Annual       Threat Intelligence Team Lead
  Data protection compliance audit  Annual       DPO
  Competition law review            Annual       Legal Counsel
  Sharing activity metrics review   Quarterly    CISO
  Anonymisation procedures review   Annual       Threat Intelligence Team Lead

  Last policy review: 1 March 2025
  Next scheduled review: 1 March 2026

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

APPROVAL

  Prepared by:   Threat Intelligence Team Lead
  Reviewed by:   DPO, Legal Counsel
  Approved by:   CISO
  Endorsed by:   Board Risk Committee
  Date:          1 March 2025

Expected Structured Facts

Example structured facts that Detrixa would extract from this evidence (synthetic data, deterministic seed).

info_sharing_arrangements_status — fs-info-sharing-arrangements
{
  "factId": "a1b2c3d4-e5f6-7890-abcd-ef0123456789",
  "evidenceId": "f0e1d2c3-b4a5-6789-0123-456789abcdef",
  "evidenceClassId": "info-sharing-policy",
  "factType": "info_sharing_arrangements_status",
  "data": {
    "assessment_date": "2025-03-01",
    "has_sharing_policy": true,
    "has_trusted_communities": true,
    "trusted_communities_count": 3,
    "data_protection_compliant": true,
    "competition_law_reviewed": true,
    "sharing_active": true,
    "last_sharing_activity_date": "2025-02-18"
  },
  "provenance": "deterministic",
  "extractorVersion": "dora-test-generator/0.1.0",
  "extractedAt": "2025-03-02T09:30:00Z",
  "supersededBy": null
}
info_sharing_participation_status — fs-info-sharing-participation
{
  "factId": "b2c3d4e5-f6a7-8901-bcde-f01234567890",
  "evidenceId": "a9b8c7d6-e5f4-3210-9876-543210fedcba",
  "evidenceClassId": "info-sharing-agreement",
  "factType": "info_sharing_participation_status",
  "data": {
    "community_name": "DACH Financial CERT",
    "participation_date": "2022-03-15",
    "agreement_signed": true,
    "active_participant": true,
    "indicators_shared_count": 142,
    "indicators_received_count": 1837,
    "last_contribution_date": "2025-02-18",
    "confidentiality_obligations_met": true
  },
  "provenance": "deterministic",
  "extractorVersion": "dora-test-generator/0.1.0",
  "extractedAt": "2025-03-02T09:35:00Z",
  "supersededBy": null
}
anonymisation_procedures_status — fs-anonymisation-procedures
{
  "factId": "c3d4e5f6-a7b8-9012-cdef-012345678901",
  "evidenceId": "d8e7f6a5-b4c3-2109-8765-43210fedcba9",
  "evidenceClassId": "anonymisation-procedures",
  "factType": "anonymisation_procedures_status",
  "data": {
    "procedure_version": "2.1",
    "effective_date": "2025-02-01",
    "has_pii_removal": true,
    "has_attribution_removal": true,
    "has_validation_checklist": true,
    "automated_anonymisation": true,
    "last_procedure_test_date": "2025-01-15",
    "dpo_approved": true
  },
  "provenance": "deterministic",
  "extractorVersion": "dora-test-generator/0.1.0",
  "extractedAt": "2025-03-02T09:40:00Z",
  "supersededBy": null
}

Information Sharing Participation Agreement RARE

Formal agreement documenting participation in a trusted community for cyber threat information sharing, including terms of participation, confidentiality obligations, and data handling requirements.

Formats
DOCX PDF
Evidence Class
info-sharing-agreement
Availability
RARE
Update Frequency
annual
Typical Author
Legal Counsel
Approval Chain
Legal Counsel → CISO → DPO

Content Sections

Expected Fields

Common Quality Issues

View Example

Generated example artifact using the default institution profile (COMMON availability, synthetic data only).

PLAIN_TEXT — Inline Preview
INFORMATION SHARING PARTICIPATION AGREEMENT
DACH Financial CERT — Cyber Threat Intelligence Sharing Community
Nordvik Bank AG — Membership Agreement
Agreement Reference: ISA-DACHCERT-2022-047
Effective Date: 15 March 2022 | Last Renewed: 15 March 2025
Prepared by: Legal Counsel, Nordvik Bank AG
Classification: Confidential

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

AGREEMENT OVERVIEW

This Participation Agreement ("Agreement") governs Nordvik Bank AG's ("the
Member") membership in the DACH Financial CERT Cyber Threat Intelligence
Sharing Community ("the Community"), a trusted community of financial entities
operating in Germany, Austria, and Switzerland established for the purpose of
exchanging cyber threat information and intelligence in accordance with DORA
Article 45.

The Community is operated by the DACH Financial CERT Coordination Centre
("the Coordinator"), a not-for-profit entity established under German law
with registered office in Frankfurt am Main.

  Agreement ID:                ISA-DACHCERT-2022-047
  Effective Date:              15 March 2022
  Current Renewal Date:        15 March 2025
  Renewal Period:              3 years (automatic renewal)
  Community Name:              DACH Financial CERT
  Coordinator:                 DACH Financial CERT Coordination Centre e.V.
  Member:                      Nordvik Bank AG
  Member Representative:       CISO, Nordvik Bank AG
  Operational Contact:         Threat Intelligence Team Lead, Nordvik Bank AG

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

PARTICIPATING PARTIES

The Community comprises financial entities and supporting organisations
operating in the DACH region (Germany, Austria, Switzerland). As of the
effective date of this renewal:

  Total participating entities:     34
  Banks:                            18
  Insurance companies:               8
  Payment service providers:         4
  Investment firms:                  2
  Supporting organisations:          2 (national CERTs)

Membership is open to:
  — Financial entities as defined in DORA Article 2(1)
  — National CERTs and CSIRTs with financial sector responsibilities
  — Entities designated by ESAs as supporting the financial sector's
    digital operational resilience

New members require unanimous approval of the Steering Committee and must
execute this standard Participation Agreement before accessing shared
intelligence.

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

SCOPE OF SHARING

The Community facilitates the exchange of the following categories of cyber
threat information:

  1. Indicators of Compromise (IoCs)
     Malicious IP addresses, domains, URLs, file hashes (MD5, SHA-256),
     email addresses, and certificate fingerprints associated with observed
     threats targeting the financial sector.

  2. Tactics, Techniques and Procedures (TTPs)
     Descriptions of attack methodologies observed by members, mapped to the
     MITRE ATT&CK framework where applicable. Includes initial access vectors,
     lateral movement techniques, and data exfiltration methods.

  3. Cyber Security Alerts
     Early warnings of emerging threats, vulnerability advisories relevant to
     financial sector technology stacks, and notifications of active campaigns
     targeting DACH financial institutions.

  4. Detection and Response Artefacts
     YARA rules, Snort/Suricata signatures, SIGMA detection rules, and
     other machine-readable detection content developed by members.

  5. Anonymised Incident Summaries
     Post-incident analysis findings shared in anonymised form to enable
     collective learning. All incident summaries must be processed through
     the Community's anonymisation standards before sharing.

Sharing is conducted via the Community's MISP (Malware Information Sharing
Platform) instance hosted by the Coordinator, with TLS 1.3 encryption for
all data in transit and AES-256 encryption at rest.

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

CONFIDENTIALITY OBLIGATIONS

  1. Classification Standard
     All information shared within the Community shall be classified using
     the Traffic Light Protocol (TLP) version 2.0. Members shall respect
     the TLP classification assigned by the originating member.

  2. Non-Disclosure
     Members shall not disclose information received through the Community
     to any party outside the Community unless:
       (a) The information is classified TLP:CLEAR; or
       (b) The originating member has provided explicit written consent; or
       (c) Disclosure is required by law or regulatory order, in which case
           the disclosing member shall notify the Coordinator and the
           originating member before disclosure where legally permitted.

  3. Need-to-Know Principle
     Within each member organisation, access to Community intelligence shall
     be restricted to personnel with a demonstrated need-to-know, as
     determined by the member's designated representative.

  4. Confidentiality Level: RESTRICTED
     This Agreement and the existence of the Community's membership list
     are classified as RESTRICTED. Members may acknowledge their participation
     in the Community to regulators and auditors but shall not publicly
     disclose the membership list or specific intelligence received.

  5. Survival
     Confidentiality obligations survive termination of this Agreement for
     a period of 5 years.

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

DATA HANDLING REQUIREMENTS

  1. Data Protection Compliance
     All information sharing activities under this Agreement shall comply
     with Regulation (EU) 2016/679 (GDPR) and applicable national data
     protection laws. The Coordinator has appointed a Data Protection
     Officer and maintains a Record of Processing Activities for the
     sharing platform.

  2. Anonymisation Requirements
     Before sharing any information that could directly or indirectly
     identify a natural person, the originating member shall apply
     anonymisation techniques in accordance with the Community's
     Anonymisation Standard (DACH-CERT-STD-ANON-v2.1). This includes:
       — Removal of all personal identifiers
       — Generalisation of location data to country level
       — Suppression of timestamps to date-level granularity where
         individual identification is possible

  3. Data Retention
     Intelligence shared through the MISP platform shall be retained for
     a maximum of 24 months from the date of submission. The Coordinator
     shall implement automated deletion of expired intelligence.
     Members shall apply equivalent retention limits to intelligence
     downloaded to local systems.

  4. Data Destruction
     Upon termination of membership, the departing member shall destroy
     all intelligence received through the Community within 90 days and
     provide written confirmation of destruction to the Coordinator.

  5. Cross-Border Transfers
     The Community operates within the EEA and Switzerland (adequacy
     decision). No transfers to third countries are permitted without
     prior approval of the Steering Committee and implementation of
     appropriate transfer mechanisms.

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

LIABILITY PROVISIONS

  1. No Warranty
     Information shared through the Community is provided "as is" without
     warranty of any kind. The originating member makes no representation
     as to the accuracy, completeness, or timeliness of shared intelligence.

  2. Limitation of Liability
     No member shall be liable to any other member for any loss, damage,
     or expense arising from the use or reliance upon information shared
     through the Community, except in cases of wilful misconduct or
     gross negligence.

  3. Indemnification
     Each member shall indemnify and hold harmless the Coordinator and
     other members against any claims arising from the member's breach
     of this Agreement, including unauthorised disclosure of confidential
     information.

  4. Coordinator Liability
     The Coordinator's aggregate liability under this Agreement shall not
     exceed the total annual membership fees paid by the affected member
     in the 12 months preceding the claim.

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

TERMINATION CLAUSES

  1. Voluntary Withdrawal
     A member may withdraw from the Community by providing 90 days' written
     notice to the Coordinator. The member's access to the MISP platform
     shall be revoked upon the effective date of withdrawal.

  2. Termination for Cause
     The Steering Committee may terminate a member's participation with
     immediate effect if the member:
       (a) Materially breaches this Agreement and fails to remedy the
           breach within 30 days of written notice;
       (b) Discloses TLP:RED or TLP:AMBER information in violation of
           the confidentiality obligations;
       (c) Becomes subject to insolvency proceedings; or
       (d) Is no longer a financial entity as defined in DORA Article 2(1).

  3. Automatic Renewal
     This Agreement renews automatically for successive 3-year periods
     unless either party provides written notice of non-renewal at least
     180 days before the end of the current period.

  4. Post-Termination Obligations
     Upon termination, the departing member shall:
       — Destroy all received intelligence within 90 days
       — Provide written confirmation of destruction
       — Continue to comply with confidentiality obligations for 5 years
       — Return or destroy any Community documentation or credentials

  Termination Notice Period:  90 days (voluntary) / immediate (for cause)

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

SIGNATURES

For Nordvik Bank AG:

  Name:      [name]
  Title:     CISO
  Date:      15 March 2025

  Name:      [name]
  Title:     Legal Counsel
  Date:      15 March 2025

For DACH Financial CERT Coordination Centre e.V.:

  Name:      [name]
  Title:     Director
  Date:      15 March 2025

Expected Structured Facts

Example structured facts that Detrixa would extract from this evidence (synthetic data, deterministic seed).

info_sharing_arrangements_status — fs-info-sharing-arrangements
{
  "factId": "a1b2c3d4-e5f6-7890-abcd-ef0123456789",
  "evidenceId": "f0e1d2c3-b4a5-6789-0123-456789abcdef",
  "evidenceClassId": "info-sharing-policy",
  "factType": "info_sharing_arrangements_status",
  "data": {
    "assessment_date": "2025-03-01",
    "has_sharing_policy": true,
    "has_trusted_communities": true,
    "trusted_communities_count": 3,
    "data_protection_compliant": true,
    "competition_law_reviewed": true,
    "sharing_active": true,
    "last_sharing_activity_date": "2025-02-18"
  },
  "provenance": "deterministic",
  "extractorVersion": "dora-test-generator/0.1.0",
  "extractedAt": "2025-03-02T09:30:00Z",
  "supersededBy": null
}
info_sharing_participation_status — fs-info-sharing-participation
{
  "factId": "b2c3d4e5-f6a7-8901-bcde-f01234567890",
  "evidenceId": "a9b8c7d6-e5f4-3210-9876-543210fedcba",
  "evidenceClassId": "info-sharing-agreement",
  "factType": "info_sharing_participation_status",
  "data": {
    "community_name": "DACH Financial CERT",
    "participation_date": "2022-03-15",
    "agreement_signed": true,
    "active_participant": true,
    "indicators_shared_count": 142,
    "indicators_received_count": 1837,
    "last_contribution_date": "2025-02-18",
    "confidentiality_obligations_met": true
  },
  "provenance": "deterministic",
  "extractorVersion": "dora-test-generator/0.1.0",
  "extractedAt": "2025-03-02T09:35:00Z",
  "supersededBy": null
}
anonymisation_procedures_status — fs-anonymisation-procedures
{
  "factId": "c3d4e5f6-a7b8-9012-cdef-012345678901",
  "evidenceId": "d8e7f6a5-b4c3-2109-8765-43210fedcba9",
  "evidenceClassId": "anonymisation-procedures",
  "factType": "anonymisation_procedures_status",
  "data": {
    "procedure_version": "2.1",
    "effective_date": "2025-02-01",
    "has_pii_removal": true,
    "has_attribution_removal": true,
    "has_validation_checklist": true,
    "automated_anonymisation": true,
    "last_procedure_test_date": "2025-01-15",
    "dpo_approved": true
  },
  "provenance": "deterministic",
  "extractorVersion": "dora-test-generator/0.1.0",
  "extractedAt": "2025-03-02T09:40:00Z",
  "supersededBy": null
}

Threat Intelligence Anonymisation Procedures RARE

JSON-structured procedures for anonymising and sanitising threat intelligence before sharing with external communities, ensuring compliance with data protection regulations.

Formats
JSON
Evidence Class
anonymisation-procedures
Availability
RARE
Update Frequency
annual
Typical Author
Threat Intelligence Analyst
Approval Chain
Threat Intelligence Analyst → DPO → CISO

Content Sections

Expected Fields

Common Quality Issues

View Example

Generated example artifact using the default institution profile (COMMON availability, synthetic data only).

JSON — Inline Preview
{
  "procedureMetadata": {
    "procedureId": "PROC-ISH-ANON-2025-001",
    "title": "Threat Intelligence Anonymisation and Sanitisation Procedures",
    "institution": "Nordvik Bank AG",
    "version": "2.1",
    "effectiveDate": "2025-02-01",
    "lastReviewedDate": "2025-01-20",
    "nextReviewDate": "2026-02-01",
    "responsibleRole": "Threat Intelligence Analyst",
    "approvedBy": [
      { "role": "Threat Intelligence Team Lead", "date": "2025-01-22" },
      { "role": "Data Protection Officer", "date": "2025-01-25" },
      { "role": "CISO", "date": "2025-01-28" }
    ],
    "regulatoryBasis": "DORA Article 45, GDPR Article 5(1)(c), GDPR Article 89",
    "applicableCommunities": [
      "FS-ISAC",
      "DACH Financial CERT",
      "EBF Cyber Intelligence Sharing Initiative"
    ]
  },
  "anonymisationRules": [
    {
      "ruleId": "ANON-R01",
      "category": "Personal Identifiers",
      "description": "Remove all data that directly identifies a natural person.",
      "dataElements": [
        "Employee names and initials",
        "Email addresses (personal and corporate)",
        "Phone numbers",
        "Employee IDs and badge numbers",
        "Usernames and login identifiers",
        "Biometric identifiers"
      ],
      "technique": "suppression",
      "implementation": "Replace with generic role labels (e.g., 'Analyst-1', 'Admin-2'). Do not use sequential numbering that could be correlated across reports.",
      "automatedTooling": "MISP anonymisation module — PII filter v3.2",
      "manualReviewRequired": true
    },
    {
      "ruleId": "ANON-R02",
      "category": "Organisational Identifiers",
      "description": "Remove or generalise data that identifies the reporting institution or its specific business units.",
      "dataElements": [
        "Institution name and legal entity identifiers",
        "Department and business unit names",
        "Office locations and addresses",
        "Internal project or programme names",
        "Contract references and vendor identifiers"
      ],
      "technique": "generalisation",
      "implementation": "Replace institution name with sector-generic label (e.g., 'DACH mid-size bank'). Replace department names with functional descriptions (e.g., 'IT Operations team'). Remove all contract and vendor references.",
      "automatedTooling": "Custom regex-based sanitiser — org-filter v1.4",
      "manualReviewRequired": true
    },
    {
      "ruleId": "ANON-R03",
      "category": "Network Infrastructure",
      "description": "Remove internal network identifiers that could reveal the institution's infrastructure topology.",
      "dataElements": [
        "Internal IP addresses (RFC 1918 ranges)",
        "Internal hostnames and FQDNs",
        "VLAN identifiers and network segment names",
        "Internal DNS zone names",
        "Active Directory domain names",
        "Certificate common names for internal services"
      ],
      "technique": "pseudonymisation",
      "implementation": "Replace internal IPs with pseudonymised addresses from the 198.51.100.0/24 documentation range (RFC 5737). Replace hostnames with generic labels (e.g., 'server-A', 'workstation-12'). Preserve network topology relationships where relevant to the threat description.",
      "automatedTooling": "MISP anonymisation module — network-sanitiser v2.0",
      "manualReviewRequired": false
    },
    {
      "ruleId": "ANON-R04",
      "category": "Temporal Data",
      "description": "Generalise timestamps to prevent correlation with publicly known incidents.",
      "dataElements": [
        "Exact incident timestamps",
        "Log entry timestamps",
        "Alert trigger times"
      ],
      "technique": "generalisation",
      "implementation": "Reduce timestamp precision to date level (remove hours, minutes, seconds). For multi-day incidents, express duration as approximate range (e.g., '3-5 days'). Preserve relative timing between events within the same incident.",
      "automatedTooling": "Custom timestamp generaliser — time-filter v1.1",
      "manualReviewRequired": false
    },
    {
      "ruleId": "ANON-R05",
      "category": "Financial Data",
      "description": "Remove or generalise financial figures that could identify the institution or its customers.",
      "dataElements": [
        "Transaction amounts and account balances",
        "Customer counts and revenue figures",
        "Loss amounts from incidents",
        "Budget and cost figures"
      ],
      "technique": "generalisation",
      "implementation": "Replace exact figures with order-of-magnitude ranges (e.g., 'EUR 1M-10M'). Remove all customer-specific financial data. Incident loss figures may be shared as percentage of annual revenue if relevant to threat assessment.",
      "automatedTooling": null,
      "manualReviewRequired": true
    }
  ],
  "sanitisationSteps": [
    {
      "stepNumber": 1,
      "name": "Automated Pre-Processing",
      "description": "Run the outbound intelligence through the automated anonymisation pipeline.",
      "actions": [
        "Execute MISP anonymisation modules (PII filter, network sanitiser)",
        "Execute custom regex-based sanitisers (org-filter, time-filter)",
        "Generate anonymisation report listing all modifications made"
      ],
      "responsibleRole": "Threat Intelligence Analyst",
      "estimatedDuration": "5 minutes (automated)"
    },
    {
      "stepNumber": 2,
      "name": "Manual Review",
      "description": "Analyst reviews the anonymised output for residual identifying information.",
      "actions": [
        "Review anonymisation report for completeness",
        "Check for indirect identifiers (combinations of data that could identify the institution)",
        "Verify that threat intelligence value is preserved after anonymisation",
        "Check for embedded metadata in attached files (EXIF, document properties)",
        "Remove or redact any residual identifying information"
      ],
      "responsibleRole": "Threat Intelligence Analyst",
      "estimatedDuration": "15-30 minutes"
    },
    {
      "stepNumber": 3,
      "name": "TLP Classification",
      "description": "Assign Traffic Light Protocol classification to the sanitised intelligence.",
      "actions": [
        "Determine appropriate TLP level based on content sensitivity",
        "Apply TLP marking to all shared artefacts",
        "Document classification rationale"
      ],
      "responsibleRole": "Threat Intelligence Analyst",
      "estimatedDuration": "5 minutes"
    },
    {
      "stepNumber": 4,
      "name": "Approval Gate",
      "description": "Obtain required approval based on information sensitivity level.",
      "actions": [
        "LOW sensitivity (IoCs, signatures): self-approval by analyst",
        "MEDIUM sensitivity (TTPs, alerts): approval by Team Lead",
        "HIGH sensitivity (incident summaries): approval by CISO"
      ],
      "responsibleRole": "Approver (per sensitivity level)",
      "estimatedDuration": "Varies (immediate to 24 hours)"
    },
    {
      "stepNumber": 5,
      "name": "Submission to Sharing Platform",
      "description": "Submit the approved, anonymised intelligence to the community sharing platform.",
      "actions": [
        "Upload to MISP instance with correct TLP marking and tags",
        "Verify submission appears correctly in the platform",
        "Log the sharing event in the internal sharing register"
      ],
      "responsibleRole": "Threat Intelligence Analyst",
      "estimatedDuration": "5 minutes"
    }
  ],
  "validationChecks": [
    {
      "checkId": "VAL-01",
      "name": "PII Absence Verification",
      "description": "Confirm no personal identifiers remain in the outbound intelligence.",
      "method": "Automated regex scan plus manual spot-check",
      "frequency": "Every outbound submission",
      "passCondition": "Zero PII matches detected"
    },
    {
      "checkId": "VAL-02",
      "name": "Organisational Attribution Removal",
      "description": "Confirm the institution cannot be identified from the shared intelligence.",
      "method": "Manual review by analyst — would a reader be able to identify Nordvik Bank AG from this content?",
      "frequency": "Every outbound submission",
      "passCondition": "No reasonable identification possible"
    },
    {
      "checkId": "VAL-03",
      "name": "Metadata Sanitisation",
      "description": "Confirm file metadata does not contain identifying information.",
      "method": "Automated metadata extraction and review (exiftool, python-docx properties check)",
      "frequency": "Every outbound submission containing file attachments",
      "passCondition": "No author names, organisation names, or internal paths in metadata"
    },
    {
      "checkId": "VAL-04",
      "name": "Intelligence Value Preservation",
      "description": "Confirm the anonymised intelligence retains sufficient value for community members.",
      "method": "Analyst judgement — does the anonymised version still convey actionable threat information?",
      "frequency": "Every outbound submission",
      "passCondition": "Core threat indicators and TTPs preserved"
    },
    {
      "checkId": "VAL-05",
      "name": "TLP Compliance",
      "description": "Confirm TLP marking is applied and appropriate for the content.",
      "method": "Manual verification of TLP tag on MISP event",
      "frequency": "Every outbound submission",
      "passCondition": "TLP marking present and consistent with content sensitivity"
    }
  ]
}

Expected Structured Facts

Example structured facts that Detrixa would extract from this evidence (synthetic data, deterministic seed).

info_sharing_arrangements_status — fs-info-sharing-arrangements
{
  "factId": "a1b2c3d4-e5f6-7890-abcd-ef0123456789",
  "evidenceId": "f0e1d2c3-b4a5-6789-0123-456789abcdef",
  "evidenceClassId": "info-sharing-policy",
  "factType": "info_sharing_arrangements_status",
  "data": {
    "assessment_date": "2025-03-01",
    "has_sharing_policy": true,
    "has_trusted_communities": true,
    "trusted_communities_count": 3,
    "data_protection_compliant": true,
    "competition_law_reviewed": true,
    "sharing_active": true,
    "last_sharing_activity_date": "2025-02-18"
  },
  "provenance": "deterministic",
  "extractorVersion": "dora-test-generator/0.1.0",
  "extractedAt": "2025-03-02T09:30:00Z",
  "supersededBy": null
}
info_sharing_participation_status — fs-info-sharing-participation
{
  "factId": "b2c3d4e5-f6a7-8901-bcde-f01234567890",
  "evidenceId": "a9b8c7d6-e5f4-3210-9876-543210fedcba",
  "evidenceClassId": "info-sharing-agreement",
  "factType": "info_sharing_participation_status",
  "data": {
    "community_name": "DACH Financial CERT",
    "participation_date": "2022-03-15",
    "agreement_signed": true,
    "active_participant": true,
    "indicators_shared_count": 142,
    "indicators_received_count": 1837,
    "last_contribution_date": "2025-02-18",
    "confidentiality_obligations_met": true
  },
  "provenance": "deterministic",
  "extractorVersion": "dora-test-generator/0.1.0",
  "extractedAt": "2025-03-02T09:35:00Z",
  "supersededBy": null
}
anonymisation_procedures_status — fs-anonymisation-procedures
{
  "factId": "c3d4e5f6-a7b8-9012-cdef-012345678901",
  "evidenceId": "d8e7f6a5-b4c3-2109-8765-43210fedcba9",
  "evidenceClassId": "anonymisation-procedures",
  "factType": "anonymisation_procedures_status",
  "data": {
    "procedure_version": "2.1",
    "effective_date": "2025-02-01",
    "has_pii_removal": true,
    "has_attribution_removal": true,
    "has_validation_checklist": true,
    "automated_anonymisation": true,
    "last_procedure_test_date": "2025-01-15",
    "dpo_approved": true
  },
  "provenance": "deterministic",
  "extractorVersion": "dora-test-generator/0.1.0",
  "extractedAt": "2025-03-02T09:40:00Z",
  "supersededBy": null
}

Fact Schemas

info_sharing_arrangements_status

Schema ID
fs-info-sharing-arrangements
Control
DORA-Art45-P1

Valid Ranges

assessment_date
within last 12 months
trusted_communities_count
at least 1 for active participation

Related Schemas

JSON Schema

{
  "properties": {
    "assessment_date": {
      "format": "date",
      "type": "string"
    },
    "competition_law_reviewed": {
      "type": "boolean"
    },
    "data_protection_compliant": {
      "type": "boolean"
    },
    "has_sharing_policy": {
      "type": "boolean"
    },
    "has_trusted_communities": {
      "type": "boolean"
    },
    "last_sharing_activity_date": {
      "format": "date",
      "type": "string"
    },
    "sharing_active": {
      "type": "boolean"
    },
    "trusted_communities_count": {
      "minimum": 0,
      "type": "integer"
    }
  },
  "required": [
    "assessment_date",
    "has_sharing_policy",
    "has_trusted_communities",
    "data_protection_compliant"
  ],
  "type": "object"
}

info_sharing_participation_status

Schema ID
fs-info-sharing-participation
Control
DORA-Art45-P1

Valid Ranges

participation_date
current or within agreement validity period
last_contribution_date
within last 6 months for active participation

Related Schemas

JSON Schema

{
  "properties": {
    "active_participant": {
      "type": "boolean"
    },
    "agreement_signed": {
      "type": "boolean"
    },
    "community_name": {
      "minLength": 1,
      "type": "string"
    },
    "confidentiality_obligations_met": {
      "type": "boolean"
    },
    "indicators_received_count": {
      "minimum": 0,
      "type": "integer"
    },
    "indicators_shared_count": {
      "minimum": 0,
      "type": "integer"
    },
    "last_contribution_date": {
      "format": "date",
      "type": "string"
    },
    "participation_date": {
      "format": "date",
      "type": "string"
    }
  },
  "required": [
    "community_name",
    "participation_date",
    "agreement_signed",
    "active_participant"
  ],
  "type": "object"
}

anonymisation_procedures_status

Schema ID
fs-anonymisation-procedures
Control
DORA-Art45-P1

Valid Ranges

effective_date
within last 18 months
last_procedure_test_date
within last 12 months

Related Schemas

JSON Schema

{
  "properties": {
    "automated_anonymisation": {
      "type": "boolean"
    },
    "dpo_approved": {
      "type": "boolean"
    },
    "effective_date": {
      "format": "date",
      "type": "string"
    },
    "has_attribution_removal": {
      "type": "boolean"
    },
    "has_pii_removal": {
      "type": "boolean"
    },
    "has_validation_checklist": {
      "type": "boolean"
    },
    "last_procedure_test_date": {
      "format": "date",
      "type": "string"
    },
    "procedure_version": {
      "minLength": 1,
      "type": "string"
    }
  },
  "required": [
    "procedure_version",
    "effective_date",
    "has_pii_removal",
    "has_attribution_removal",
    "has_validation_checklist"
  ],
  "type": "object"
}