Financial entities may exchange amongst themselves cyber threat information and intelligence, including indicators of compromise, tactics, techniques and procedures, cyber security alerts and configuration tools, to the extent that such information and intelligence sharing takes place within trusted communities of financial entities, is aimed at enhancing the digital operational resilience of financial entities, takes place in compliance with applicable data protection rules, and is carried out in accordance with relevant competition law.
Policy document defining the institution's approach to sharing cyber threat information and intelligence with trusted communities, including scope, governance, data protection safeguards, and competition law compliance as required by DORA Article 45.
info-sharing-policyGenerated example artifact using the default institution profile (COMMON availability, synthetic data only).
INFORMATION SHARING POLICY
Cyber Threat Intelligence and Information Sharing Arrangements
Nordvik Bank AG
Policy Reference: POL-ISH-2025-001
Version 2.0 | Effective Date: 1 March 2025
Policy Owner: Chief Information Security Officer (CISO)
Classification: Internal
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
POLICY OBJECTIVES
This policy establishes Nordvik Bank AG's framework for sharing cyber threat
information and intelligence with trusted communities of financial entities, in
accordance with DORA Article 45. The policy aims to:
— Enhance the Bank's digital operational resilience through collective
intelligence on cyber threats, vulnerabilities, and attack techniques
— Enable timely exchange of indicators of compromise (IoCs), tactics,
techniques and procedures (TTPs), and cyber security alerts
— Ensure all information sharing activities comply with applicable data
protection regulations (GDPR, Swiss FADP) and competition law
— Define governance structures, roles, and responsibilities for information
sharing activities
— Establish safeguards to protect the Bank's proprietary information and
customer data during sharing activities
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
SCOPE OF INFORMATION SHARING
Types of Information Eligible for Sharing:
Category Examples
─────────────────────────────────────────────────────────────────────────────
Indicators of Compromise (IoCs) IP addresses, domain names, file hashes,
URLs, email addresses associated with
malicious activity
Tactics, Techniques and MITRE ATT&CK framework references,
Procedures (TTPs) attack chain descriptions, exploitation
methods observed
Cyber Security Alerts Vulnerability advisories, zero-day
notifications, threat actor activity
warnings
Configuration Tools YARA rules, Snort/Suricata signatures,
SIGMA detection rules, firewall rules
Incident Summaries Anonymised incident reports, lessons
learned, post-incident analysis findings
Types of Information Excluded from Sharing:
— Customer personally identifiable information (PII)
— Internal audit findings and regulatory examination results
— Proprietary trading strategies or algorithms
— Information subject to legal privilege
— Information classified as "Strictly Confidential" under the Bank's
information classification scheme
— Information that could reveal the Bank's specific security architecture
or defensive posture in exploitable detail
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
TRUSTED COMMUNITIES
The Bank participates in the following trusted communities for cyber threat
information sharing:
Community Type Joined Status
─────────────────────────────────────────────────────────────────────────────
FS-ISAC (Financial Services Sector ISAC 2019-06-01 Active
Information Sharing and
Analysis Center)
DACH Financial CERT Regional CERT 2022-03-15 Active
(Germany, Austria, Switzerland
financial sector CERT)
EBF Cyber Intelligence Industry body 2024-09-01 Active
Sharing Initiative (European
Banking Federation)
Criteria for Joining New Communities:
— Community must be composed primarily of financial entities or entities
supporting the financial sector
— Community must have a formal governance structure and membership agreement
— Community must enforce confidentiality obligations on all members
— Community must comply with applicable data protection regulations
— Community must have established procedures for anonymising shared
information
— Legal Counsel and DPO must approve membership before execution
— Board Risk Committee must be notified of new community memberships
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
GOVERNANCE AND OVERSIGHT
Roles and Responsibilities:
Role Responsibilities
─────────────────────────────────────────────────────────────────────────────
CISO (Policy Owner) Overall accountability for information
sharing activities; annual policy review;
approval of sharing decisions for HIGH
sensitivity information
Threat Intelligence Team Lead Day-to-day management of sharing
activities; review and approval of
outbound information; monitoring of
inbound intelligence
Threat Intelligence Analysts Preparation and anonymisation of
(2 FTE) outbound information; analysis and
dissemination of inbound intelligence;
maintenance of sharing platform
configurations
Data Protection Officer (DPO) Review of data protection compliance
for sharing arrangements; DPIA for new
communities; annual compliance audit
Legal Counsel Competition law review of sharing
arrangements; contract review for
participation agreements; legal risk
assessment
Governance Meetings:
— Quarterly review of sharing activities by CISO and Threat Intelligence
Team Lead
— Annual review of community memberships and participation agreements
— Ad-hoc review triggered by significant incidents or regulatory changes
Decision Authority for Outbound Sharing:
Information Sensitivity Approval Required
─────────────────────────────────────────────────────────────────────────────
LOW (IoCs, signatures) Threat Intelligence Analyst (self-approval)
MEDIUM (TTPs, alerts) Threat Intelligence Team Lead
HIGH (incident summaries) CISO
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
DATA PROTECTION SAFEGUARDS
All information sharing activities shall comply with the following data
protection requirements:
1. Anonymisation Before Sharing
All outbound information must be processed through the Bank's Threat
Intelligence Anonymisation Procedures (PROC-ISH-ANON-2025-001) before
sharing. This includes:
— Removal of all customer PII
— Removal of internal IP addresses and hostnames
— Removal of employee names and identifiers
— Replacement of institution-specific identifiers with generic labels
— Removal of information that could identify specific business units
or systems
2. Data Protection Impact Assessment (DPIA)
A DPIA shall be conducted before joining any new sharing community or
significantly changing the scope of information shared with an existing
community. The DPO is responsible for conducting and documenting the DPIA.
3. Data Minimisation
Only the minimum information necessary to achieve the sharing objective
shall be shared. Analysts must apply the principle of data minimisation
when preparing outbound intelligence.
4. Retention and Destruction
Inbound threat intelligence shall be retained for a maximum of 24 months
unless required for ongoing incident investigation. Outbound sharing
records shall be retained for 5 years for audit purposes.
5. Cross-Border Transfer Safeguards
For communities with members outside the EEA, appropriate transfer
mechanisms (Standard Contractual Clauses or adequacy decisions) must be
in place before sharing commences.
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
COMPETITION LAW COMPLIANCE
Information sharing arrangements must comply with EU and national competition
law. The following safeguards are in place:
— No sharing of commercially sensitive information (pricing, customer lists,
market strategies, business plans)
— No sharing of information that could facilitate market coordination or
collusion
— Legal Counsel has reviewed all participation agreements for competition
law compliance (last review: January 2025)
— Annual competition law training for all Threat Intelligence team members
— Sharing platforms configured to prevent inadvertent disclosure of
commercially sensitive information
— Legal Counsel available for ad-hoc consultation on borderline cases
Competition Law Review Schedule:
— Annual review of all active sharing arrangements by Legal Counsel
— Review triggered by any change in community membership or scope
— Last review completed: 15 January 2025
— Next scheduled review: January 2026
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
INFORMATION CLASSIFICATION FOR SHARING
The Bank applies the Traffic Light Protocol (TLP) for classifying shared
threat intelligence:
TLP Level Sharing Scope Bank Usage
─────────────────────────────────────────────────────────────────────────────
TLP:RED Named recipients only Restricted to CISO and
Threat Intelligence Team Lead
TLP:AMBER Community members only Shared within Threat
Intelligence team and
relevant SOC analysts
TLP:GREEN Community and partner May be shared with IT
organisations Security team and relevant
third-party providers
TLP:CLEAR Unrestricted May be shared publicly
All outbound information from the Bank defaults to TLP:AMBER unless the
sharing analyst explicitly assigns a different classification with
appropriate justification.
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
REVIEW SCHEDULE
Review Activity Frequency Responsible
─────────────────────────────────────────────────────────────────────────────
Policy review and update Annual CISO
Community membership review Annual Threat Intelligence Team Lead
Data protection compliance audit Annual DPO
Competition law review Annual Legal Counsel
Sharing activity metrics review Quarterly CISO
Anonymisation procedures review Annual Threat Intelligence Team Lead
Last policy review: 1 March 2025
Next scheduled review: 1 March 2026
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
APPROVAL
Prepared by: Threat Intelligence Team Lead
Reviewed by: DPO, Legal Counsel
Approved by: CISO
Endorsed by: Board Risk Committee
Date: 1 March 2025
Example structured facts that Detrixa would extract from this evidence (synthetic data, deterministic seed).
info_sharing_arrangements_status — fs-info-sharing-arrangements
{
"factId": "a1b2c3d4-e5f6-7890-abcd-ef0123456789",
"evidenceId": "f0e1d2c3-b4a5-6789-0123-456789abcdef",
"evidenceClassId": "info-sharing-policy",
"factType": "info_sharing_arrangements_status",
"data": {
"assessment_date": "2025-03-01",
"has_sharing_policy": true,
"has_trusted_communities": true,
"trusted_communities_count": 3,
"data_protection_compliant": true,
"competition_law_reviewed": true,
"sharing_active": true,
"last_sharing_activity_date": "2025-02-18"
},
"provenance": "deterministic",
"extractorVersion": "dora-test-generator/0.1.0",
"extractedAt": "2025-03-02T09:30:00Z",
"supersededBy": null
}
info_sharing_participation_status — fs-info-sharing-participation
{
"factId": "b2c3d4e5-f6a7-8901-bcde-f01234567890",
"evidenceId": "a9b8c7d6-e5f4-3210-9876-543210fedcba",
"evidenceClassId": "info-sharing-agreement",
"factType": "info_sharing_participation_status",
"data": {
"community_name": "DACH Financial CERT",
"participation_date": "2022-03-15",
"agreement_signed": true,
"active_participant": true,
"indicators_shared_count": 142,
"indicators_received_count": 1837,
"last_contribution_date": "2025-02-18",
"confidentiality_obligations_met": true
},
"provenance": "deterministic",
"extractorVersion": "dora-test-generator/0.1.0",
"extractedAt": "2025-03-02T09:35:00Z",
"supersededBy": null
}
anonymisation_procedures_status — fs-anonymisation-procedures
{
"factId": "c3d4e5f6-a7b8-9012-cdef-012345678901",
"evidenceId": "d8e7f6a5-b4c3-2109-8765-43210fedcba9",
"evidenceClassId": "anonymisation-procedures",
"factType": "anonymisation_procedures_status",
"data": {
"procedure_version": "2.1",
"effective_date": "2025-02-01",
"has_pii_removal": true,
"has_attribution_removal": true,
"has_validation_checklist": true,
"automated_anonymisation": true,
"last_procedure_test_date": "2025-01-15",
"dpo_approved": true
},
"provenance": "deterministic",
"extractorVersion": "dora-test-generator/0.1.0",
"extractedAt": "2025-03-02T09:40:00Z",
"supersededBy": null
}
Formal agreement documenting participation in a trusted community for cyber threat information sharing, including terms of participation, confidentiality obligations, and data handling requirements.
info-sharing-agreementGenerated example artifact using the default institution profile (COMMON availability, synthetic data only).
INFORMATION SHARING PARTICIPATION AGREEMENT
DACH Financial CERT — Cyber Threat Intelligence Sharing Community
Nordvik Bank AG — Membership Agreement
Agreement Reference: ISA-DACHCERT-2022-047
Effective Date: 15 March 2022 | Last Renewed: 15 March 2025
Prepared by: Legal Counsel, Nordvik Bank AG
Classification: Confidential
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
AGREEMENT OVERVIEW
This Participation Agreement ("Agreement") governs Nordvik Bank AG's ("the
Member") membership in the DACH Financial CERT Cyber Threat Intelligence
Sharing Community ("the Community"), a trusted community of financial entities
operating in Germany, Austria, and Switzerland established for the purpose of
exchanging cyber threat information and intelligence in accordance with DORA
Article 45.
The Community is operated by the DACH Financial CERT Coordination Centre
("the Coordinator"), a not-for-profit entity established under German law
with registered office in Frankfurt am Main.
Agreement ID: ISA-DACHCERT-2022-047
Effective Date: 15 March 2022
Current Renewal Date: 15 March 2025
Renewal Period: 3 years (automatic renewal)
Community Name: DACH Financial CERT
Coordinator: DACH Financial CERT Coordination Centre e.V.
Member: Nordvik Bank AG
Member Representative: CISO, Nordvik Bank AG
Operational Contact: Threat Intelligence Team Lead, Nordvik Bank AG
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
PARTICIPATING PARTIES
The Community comprises financial entities and supporting organisations
operating in the DACH region (Germany, Austria, Switzerland). As of the
effective date of this renewal:
Total participating entities: 34
Banks: 18
Insurance companies: 8
Payment service providers: 4
Investment firms: 2
Supporting organisations: 2 (national CERTs)
Membership is open to:
— Financial entities as defined in DORA Article 2(1)
— National CERTs and CSIRTs with financial sector responsibilities
— Entities designated by ESAs as supporting the financial sector's
digital operational resilience
New members require unanimous approval of the Steering Committee and must
execute this standard Participation Agreement before accessing shared
intelligence.
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
SCOPE OF SHARING
The Community facilitates the exchange of the following categories of cyber
threat information:
1. Indicators of Compromise (IoCs)
Malicious IP addresses, domains, URLs, file hashes (MD5, SHA-256),
email addresses, and certificate fingerprints associated with observed
threats targeting the financial sector.
2. Tactics, Techniques and Procedures (TTPs)
Descriptions of attack methodologies observed by members, mapped to the
MITRE ATT&CK framework where applicable. Includes initial access vectors,
lateral movement techniques, and data exfiltration methods.
3. Cyber Security Alerts
Early warnings of emerging threats, vulnerability advisories relevant to
financial sector technology stacks, and notifications of active campaigns
targeting DACH financial institutions.
4. Detection and Response Artefacts
YARA rules, Snort/Suricata signatures, SIGMA detection rules, and
other machine-readable detection content developed by members.
5. Anonymised Incident Summaries
Post-incident analysis findings shared in anonymised form to enable
collective learning. All incident summaries must be processed through
the Community's anonymisation standards before sharing.
Sharing is conducted via the Community's MISP (Malware Information Sharing
Platform) instance hosted by the Coordinator, with TLS 1.3 encryption for
all data in transit and AES-256 encryption at rest.
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
CONFIDENTIALITY OBLIGATIONS
1. Classification Standard
All information shared within the Community shall be classified using
the Traffic Light Protocol (TLP) version 2.0. Members shall respect
the TLP classification assigned by the originating member.
2. Non-Disclosure
Members shall not disclose information received through the Community
to any party outside the Community unless:
(a) The information is classified TLP:CLEAR; or
(b) The originating member has provided explicit written consent; or
(c) Disclosure is required by law or regulatory order, in which case
the disclosing member shall notify the Coordinator and the
originating member before disclosure where legally permitted.
3. Need-to-Know Principle
Within each member organisation, access to Community intelligence shall
be restricted to personnel with a demonstrated need-to-know, as
determined by the member's designated representative.
4. Confidentiality Level: RESTRICTED
This Agreement and the existence of the Community's membership list
are classified as RESTRICTED. Members may acknowledge their participation
in the Community to regulators and auditors but shall not publicly
disclose the membership list or specific intelligence received.
5. Survival
Confidentiality obligations survive termination of this Agreement for
a period of 5 years.
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
DATA HANDLING REQUIREMENTS
1. Data Protection Compliance
All information sharing activities under this Agreement shall comply
with Regulation (EU) 2016/679 (GDPR) and applicable national data
protection laws. The Coordinator has appointed a Data Protection
Officer and maintains a Record of Processing Activities for the
sharing platform.
2. Anonymisation Requirements
Before sharing any information that could directly or indirectly
identify a natural person, the originating member shall apply
anonymisation techniques in accordance with the Community's
Anonymisation Standard (DACH-CERT-STD-ANON-v2.1). This includes:
— Removal of all personal identifiers
— Generalisation of location data to country level
— Suppression of timestamps to date-level granularity where
individual identification is possible
3. Data Retention
Intelligence shared through the MISP platform shall be retained for
a maximum of 24 months from the date of submission. The Coordinator
shall implement automated deletion of expired intelligence.
Members shall apply equivalent retention limits to intelligence
downloaded to local systems.
4. Data Destruction
Upon termination of membership, the departing member shall destroy
all intelligence received through the Community within 90 days and
provide written confirmation of destruction to the Coordinator.
5. Cross-Border Transfers
The Community operates within the EEA and Switzerland (adequacy
decision). No transfers to third countries are permitted without
prior approval of the Steering Committee and implementation of
appropriate transfer mechanisms.
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
LIABILITY PROVISIONS
1. No Warranty
Information shared through the Community is provided "as is" without
warranty of any kind. The originating member makes no representation
as to the accuracy, completeness, or timeliness of shared intelligence.
2. Limitation of Liability
No member shall be liable to any other member for any loss, damage,
or expense arising from the use or reliance upon information shared
through the Community, except in cases of wilful misconduct or
gross negligence.
3. Indemnification
Each member shall indemnify and hold harmless the Coordinator and
other members against any claims arising from the member's breach
of this Agreement, including unauthorised disclosure of confidential
information.
4. Coordinator Liability
The Coordinator's aggregate liability under this Agreement shall not
exceed the total annual membership fees paid by the affected member
in the 12 months preceding the claim.
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
TERMINATION CLAUSES
1. Voluntary Withdrawal
A member may withdraw from the Community by providing 90 days' written
notice to the Coordinator. The member's access to the MISP platform
shall be revoked upon the effective date of withdrawal.
2. Termination for Cause
The Steering Committee may terminate a member's participation with
immediate effect if the member:
(a) Materially breaches this Agreement and fails to remedy the
breach within 30 days of written notice;
(b) Discloses TLP:RED or TLP:AMBER information in violation of
the confidentiality obligations;
(c) Becomes subject to insolvency proceedings; or
(d) Is no longer a financial entity as defined in DORA Article 2(1).
3. Automatic Renewal
This Agreement renews automatically for successive 3-year periods
unless either party provides written notice of non-renewal at least
180 days before the end of the current period.
4. Post-Termination Obligations
Upon termination, the departing member shall:
— Destroy all received intelligence within 90 days
— Provide written confirmation of destruction
— Continue to comply with confidentiality obligations for 5 years
— Return or destroy any Community documentation or credentials
Termination Notice Period: 90 days (voluntary) / immediate (for cause)
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
SIGNATURES
For Nordvik Bank AG:
Name: [name]
Title: CISO
Date: 15 March 2025
Name: [name]
Title: Legal Counsel
Date: 15 March 2025
For DACH Financial CERT Coordination Centre e.V.:
Name: [name]
Title: Director
Date: 15 March 2025
Example structured facts that Detrixa would extract from this evidence (synthetic data, deterministic seed).
info_sharing_arrangements_status — fs-info-sharing-arrangements
{
"factId": "a1b2c3d4-e5f6-7890-abcd-ef0123456789",
"evidenceId": "f0e1d2c3-b4a5-6789-0123-456789abcdef",
"evidenceClassId": "info-sharing-policy",
"factType": "info_sharing_arrangements_status",
"data": {
"assessment_date": "2025-03-01",
"has_sharing_policy": true,
"has_trusted_communities": true,
"trusted_communities_count": 3,
"data_protection_compliant": true,
"competition_law_reviewed": true,
"sharing_active": true,
"last_sharing_activity_date": "2025-02-18"
},
"provenance": "deterministic",
"extractorVersion": "dora-test-generator/0.1.0",
"extractedAt": "2025-03-02T09:30:00Z",
"supersededBy": null
}
info_sharing_participation_status — fs-info-sharing-participation
{
"factId": "b2c3d4e5-f6a7-8901-bcde-f01234567890",
"evidenceId": "a9b8c7d6-e5f4-3210-9876-543210fedcba",
"evidenceClassId": "info-sharing-agreement",
"factType": "info_sharing_participation_status",
"data": {
"community_name": "DACH Financial CERT",
"participation_date": "2022-03-15",
"agreement_signed": true,
"active_participant": true,
"indicators_shared_count": 142,
"indicators_received_count": 1837,
"last_contribution_date": "2025-02-18",
"confidentiality_obligations_met": true
},
"provenance": "deterministic",
"extractorVersion": "dora-test-generator/0.1.0",
"extractedAt": "2025-03-02T09:35:00Z",
"supersededBy": null
}
anonymisation_procedures_status — fs-anonymisation-procedures
{
"factId": "c3d4e5f6-a7b8-9012-cdef-012345678901",
"evidenceId": "d8e7f6a5-b4c3-2109-8765-43210fedcba9",
"evidenceClassId": "anonymisation-procedures",
"factType": "anonymisation_procedures_status",
"data": {
"procedure_version": "2.1",
"effective_date": "2025-02-01",
"has_pii_removal": true,
"has_attribution_removal": true,
"has_validation_checklist": true,
"automated_anonymisation": true,
"last_procedure_test_date": "2025-01-15",
"dpo_approved": true
},
"provenance": "deterministic",
"extractorVersion": "dora-test-generator/0.1.0",
"extractedAt": "2025-03-02T09:40:00Z",
"supersededBy": null
}
JSON-structured procedures for anonymising and sanitising threat intelligence before sharing with external communities, ensuring compliance with data protection regulations.
anonymisation-proceduresGenerated example artifact using the default institution profile (COMMON availability, synthetic data only).
{
"procedureMetadata": {
"procedureId": "PROC-ISH-ANON-2025-001",
"title": "Threat Intelligence Anonymisation and Sanitisation Procedures",
"institution": "Nordvik Bank AG",
"version": "2.1",
"effectiveDate": "2025-02-01",
"lastReviewedDate": "2025-01-20",
"nextReviewDate": "2026-02-01",
"responsibleRole": "Threat Intelligence Analyst",
"approvedBy": [
{ "role": "Threat Intelligence Team Lead", "date": "2025-01-22" },
{ "role": "Data Protection Officer", "date": "2025-01-25" },
{ "role": "CISO", "date": "2025-01-28" }
],
"regulatoryBasis": "DORA Article 45, GDPR Article 5(1)(c), GDPR Article 89",
"applicableCommunities": [
"FS-ISAC",
"DACH Financial CERT",
"EBF Cyber Intelligence Sharing Initiative"
]
},
"anonymisationRules": [
{
"ruleId": "ANON-R01",
"category": "Personal Identifiers",
"description": "Remove all data that directly identifies a natural person.",
"dataElements": [
"Employee names and initials",
"Email addresses (personal and corporate)",
"Phone numbers",
"Employee IDs and badge numbers",
"Usernames and login identifiers",
"Biometric identifiers"
],
"technique": "suppression",
"implementation": "Replace with generic role labels (e.g., 'Analyst-1', 'Admin-2'). Do not use sequential numbering that could be correlated across reports.",
"automatedTooling": "MISP anonymisation module — PII filter v3.2",
"manualReviewRequired": true
},
{
"ruleId": "ANON-R02",
"category": "Organisational Identifiers",
"description": "Remove or generalise data that identifies the reporting institution or its specific business units.",
"dataElements": [
"Institution name and legal entity identifiers",
"Department and business unit names",
"Office locations and addresses",
"Internal project or programme names",
"Contract references and vendor identifiers"
],
"technique": "generalisation",
"implementation": "Replace institution name with sector-generic label (e.g., 'DACH mid-size bank'). Replace department names with functional descriptions (e.g., 'IT Operations team'). Remove all contract and vendor references.",
"automatedTooling": "Custom regex-based sanitiser — org-filter v1.4",
"manualReviewRequired": true
},
{
"ruleId": "ANON-R03",
"category": "Network Infrastructure",
"description": "Remove internal network identifiers that could reveal the institution's infrastructure topology.",
"dataElements": [
"Internal IP addresses (RFC 1918 ranges)",
"Internal hostnames and FQDNs",
"VLAN identifiers and network segment names",
"Internal DNS zone names",
"Active Directory domain names",
"Certificate common names for internal services"
],
"technique": "pseudonymisation",
"implementation": "Replace internal IPs with pseudonymised addresses from the 198.51.100.0/24 documentation range (RFC 5737). Replace hostnames with generic labels (e.g., 'server-A', 'workstation-12'). Preserve network topology relationships where relevant to the threat description.",
"automatedTooling": "MISP anonymisation module — network-sanitiser v2.0",
"manualReviewRequired": false
},
{
"ruleId": "ANON-R04",
"category": "Temporal Data",
"description": "Generalise timestamps to prevent correlation with publicly known incidents.",
"dataElements": [
"Exact incident timestamps",
"Log entry timestamps",
"Alert trigger times"
],
"technique": "generalisation",
"implementation": "Reduce timestamp precision to date level (remove hours, minutes, seconds). For multi-day incidents, express duration as approximate range (e.g., '3-5 days'). Preserve relative timing between events within the same incident.",
"automatedTooling": "Custom timestamp generaliser — time-filter v1.1",
"manualReviewRequired": false
},
{
"ruleId": "ANON-R05",
"category": "Financial Data",
"description": "Remove or generalise financial figures that could identify the institution or its customers.",
"dataElements": [
"Transaction amounts and account balances",
"Customer counts and revenue figures",
"Loss amounts from incidents",
"Budget and cost figures"
],
"technique": "generalisation",
"implementation": "Replace exact figures with order-of-magnitude ranges (e.g., 'EUR 1M-10M'). Remove all customer-specific financial data. Incident loss figures may be shared as percentage of annual revenue if relevant to threat assessment.",
"automatedTooling": null,
"manualReviewRequired": true
}
],
"sanitisationSteps": [
{
"stepNumber": 1,
"name": "Automated Pre-Processing",
"description": "Run the outbound intelligence through the automated anonymisation pipeline.",
"actions": [
"Execute MISP anonymisation modules (PII filter, network sanitiser)",
"Execute custom regex-based sanitisers (org-filter, time-filter)",
"Generate anonymisation report listing all modifications made"
],
"responsibleRole": "Threat Intelligence Analyst",
"estimatedDuration": "5 minutes (automated)"
},
{
"stepNumber": 2,
"name": "Manual Review",
"description": "Analyst reviews the anonymised output for residual identifying information.",
"actions": [
"Review anonymisation report for completeness",
"Check for indirect identifiers (combinations of data that could identify the institution)",
"Verify that threat intelligence value is preserved after anonymisation",
"Check for embedded metadata in attached files (EXIF, document properties)",
"Remove or redact any residual identifying information"
],
"responsibleRole": "Threat Intelligence Analyst",
"estimatedDuration": "15-30 minutes"
},
{
"stepNumber": 3,
"name": "TLP Classification",
"description": "Assign Traffic Light Protocol classification to the sanitised intelligence.",
"actions": [
"Determine appropriate TLP level based on content sensitivity",
"Apply TLP marking to all shared artefacts",
"Document classification rationale"
],
"responsibleRole": "Threat Intelligence Analyst",
"estimatedDuration": "5 minutes"
},
{
"stepNumber": 4,
"name": "Approval Gate",
"description": "Obtain required approval based on information sensitivity level.",
"actions": [
"LOW sensitivity (IoCs, signatures): self-approval by analyst",
"MEDIUM sensitivity (TTPs, alerts): approval by Team Lead",
"HIGH sensitivity (incident summaries): approval by CISO"
],
"responsibleRole": "Approver (per sensitivity level)",
"estimatedDuration": "Varies (immediate to 24 hours)"
},
{
"stepNumber": 5,
"name": "Submission to Sharing Platform",
"description": "Submit the approved, anonymised intelligence to the community sharing platform.",
"actions": [
"Upload to MISP instance with correct TLP marking and tags",
"Verify submission appears correctly in the platform",
"Log the sharing event in the internal sharing register"
],
"responsibleRole": "Threat Intelligence Analyst",
"estimatedDuration": "5 minutes"
}
],
"validationChecks": [
{
"checkId": "VAL-01",
"name": "PII Absence Verification",
"description": "Confirm no personal identifiers remain in the outbound intelligence.",
"method": "Automated regex scan plus manual spot-check",
"frequency": "Every outbound submission",
"passCondition": "Zero PII matches detected"
},
{
"checkId": "VAL-02",
"name": "Organisational Attribution Removal",
"description": "Confirm the institution cannot be identified from the shared intelligence.",
"method": "Manual review by analyst — would a reader be able to identify Nordvik Bank AG from this content?",
"frequency": "Every outbound submission",
"passCondition": "No reasonable identification possible"
},
{
"checkId": "VAL-03",
"name": "Metadata Sanitisation",
"description": "Confirm file metadata does not contain identifying information.",
"method": "Automated metadata extraction and review (exiftool, python-docx properties check)",
"frequency": "Every outbound submission containing file attachments",
"passCondition": "No author names, organisation names, or internal paths in metadata"
},
{
"checkId": "VAL-04",
"name": "Intelligence Value Preservation",
"description": "Confirm the anonymised intelligence retains sufficient value for community members.",
"method": "Analyst judgement — does the anonymised version still convey actionable threat information?",
"frequency": "Every outbound submission",
"passCondition": "Core threat indicators and TTPs preserved"
},
{
"checkId": "VAL-05",
"name": "TLP Compliance",
"description": "Confirm TLP marking is applied and appropriate for the content.",
"method": "Manual verification of TLP tag on MISP event",
"frequency": "Every outbound submission",
"passCondition": "TLP marking present and consistent with content sensitivity"
}
]
}
Example structured facts that Detrixa would extract from this evidence (synthetic data, deterministic seed).
info_sharing_arrangements_status — fs-info-sharing-arrangements
{
"factId": "a1b2c3d4-e5f6-7890-abcd-ef0123456789",
"evidenceId": "f0e1d2c3-b4a5-6789-0123-456789abcdef",
"evidenceClassId": "info-sharing-policy",
"factType": "info_sharing_arrangements_status",
"data": {
"assessment_date": "2025-03-01",
"has_sharing_policy": true,
"has_trusted_communities": true,
"trusted_communities_count": 3,
"data_protection_compliant": true,
"competition_law_reviewed": true,
"sharing_active": true,
"last_sharing_activity_date": "2025-02-18"
},
"provenance": "deterministic",
"extractorVersion": "dora-test-generator/0.1.0",
"extractedAt": "2025-03-02T09:30:00Z",
"supersededBy": null
}
info_sharing_participation_status — fs-info-sharing-participation
{
"factId": "b2c3d4e5-f6a7-8901-bcde-f01234567890",
"evidenceId": "a9b8c7d6-e5f4-3210-9876-543210fedcba",
"evidenceClassId": "info-sharing-agreement",
"factType": "info_sharing_participation_status",
"data": {
"community_name": "DACH Financial CERT",
"participation_date": "2022-03-15",
"agreement_signed": true,
"active_participant": true,
"indicators_shared_count": 142,
"indicators_received_count": 1837,
"last_contribution_date": "2025-02-18",
"confidentiality_obligations_met": true
},
"provenance": "deterministic",
"extractorVersion": "dora-test-generator/0.1.0",
"extractedAt": "2025-03-02T09:35:00Z",
"supersededBy": null
}
anonymisation_procedures_status — fs-anonymisation-procedures
{
"factId": "c3d4e5f6-a7b8-9012-cdef-012345678901",
"evidenceId": "d8e7f6a5-b4c3-2109-8765-43210fedcba9",
"evidenceClassId": "anonymisation-procedures",
"factType": "anonymisation_procedures_status",
"data": {
"procedure_version": "2.1",
"effective_date": "2025-02-01",
"has_pii_removal": true,
"has_attribution_removal": true,
"has_validation_checklist": true,
"automated_anonymisation": true,
"last_procedure_test_date": "2025-01-15",
"dpo_approved": true
},
"provenance": "deterministic",
"extractorVersion": "dora-test-generator/0.1.0",
"extractedAt": "2025-03-02T09:40:00Z",
"supersededBy": null
}
fs-info-sharing-arrangementsDORA-Art45-P1assessment_datetrusted_communities_count{
"properties": {
"assessment_date": {
"format": "date",
"type": "string"
},
"competition_law_reviewed": {
"type": "boolean"
},
"data_protection_compliant": {
"type": "boolean"
},
"has_sharing_policy": {
"type": "boolean"
},
"has_trusted_communities": {
"type": "boolean"
},
"last_sharing_activity_date": {
"format": "date",
"type": "string"
},
"sharing_active": {
"type": "boolean"
},
"trusted_communities_count": {
"minimum": 0,
"type": "integer"
}
},
"required": [
"assessment_date",
"has_sharing_policy",
"has_trusted_communities",
"data_protection_compliant"
],
"type": "object"
}
fs-info-sharing-participationDORA-Art45-P1participation_datelast_contribution_date{
"properties": {
"active_participant": {
"type": "boolean"
},
"agreement_signed": {
"type": "boolean"
},
"community_name": {
"minLength": 1,
"type": "string"
},
"confidentiality_obligations_met": {
"type": "boolean"
},
"indicators_received_count": {
"minimum": 0,
"type": "integer"
},
"indicators_shared_count": {
"minimum": 0,
"type": "integer"
},
"last_contribution_date": {
"format": "date",
"type": "string"
},
"participation_date": {
"format": "date",
"type": "string"
}
},
"required": [
"community_name",
"participation_date",
"agreement_signed",
"active_participant"
],
"type": "object"
}
fs-anonymisation-proceduresDORA-Art45-P1effective_datelast_procedure_test_date{
"properties": {
"automated_anonymisation": {
"type": "boolean"
},
"dpo_approved": {
"type": "boolean"
},
"effective_date": {
"format": "date",
"type": "string"
},
"has_attribution_removal": {
"type": "boolean"
},
"has_pii_removal": {
"type": "boolean"
},
"has_validation_checklist": {
"type": "boolean"
},
"last_procedure_test_date": {
"format": "date",
"type": "string"
},
"procedure_version": {
"minLength": 1,
"type": "string"
}
},
"required": [
"procedure_version",
"effective_date",
"has_pii_removal",
"has_attribution_removal",
"has_validation_checklist"
],
"type": "object"
}