DORA-Art8-P1

Article
8 (1)
Pillar
ICT Risk Management
Regulation Ref
Regulation (EU) 2022/2554, Article 8(1)
Last Reviewed
2026-01-15

Financial entities shall identify on a continuous basis all sources of ICT risk, in particular the risk exposure to and from other financial entities, and shall assess cyber threats and ICT vulnerabilities relevant to their ICT supported business functions, information assets and ICT assets.

Evidence Profiles

ICT Risk Assessment Report COMMON

Periodic risk assessment report identifying ICT risk sources, threat landscape, vulnerability analysis, and risk exposure levels as required by DORA Article 8.

Formats
PDF
Evidence Class
ict-risk-assessment
Availability
COMMON
Update Frequency
annual
Typical Author
Risk Manager
Approval Chain
Risk Manager → CISO → CRO

Content Sections

Expected Fields

Common Quality Issues

View Example

Generated example artifact using the default institution profile (COMMON availability, synthetic data only).

PLAIN_TEXT — Inline Preview
ICT RISK ASSESSMENT REPORT
Nordvik Bank AG
Assessment Reference: RA-ICT-2025-001
Assessment Date: 8 January 2025 | Next Assessment: 8 January 2026
Methodology: ISO 31000 / NIST CSF aligned
Classification: Confidential

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

EXECUTIVE SUMMARY

This report presents the results of the annual ICT risk assessment conducted for
Nordvik Bank AG ("the Bank") in January 2025. The assessment covers all ICT systems,
infrastructure, applications, and third-party ICT dependencies supporting the Bank's
business operations.

The assessment identified 42 ICT risks across the Bank's technology landscape. Of
these, 5 are rated High, 14 are rated Medium, and 23 are rated Low on the residual
risk scale after accounting for existing controls. No risks were rated Critical.

The overall ICT risk posture has improved compared to the 2024 assessment (which
identified 6 High risks), primarily due to the completion of the network
segmentation programme and the deployment of enhanced endpoint detection and
response (EDR) capabilities. However, new risks have emerged related to the
expansion of cloud-native services and the increasing sophistication of the cyber
threat landscape targeting the European financial sector.

Key areas requiring management attention:
  — Third-party concentration risk in cloud infrastructure (AWS)
  — Ransomware resilience for legacy on-premises systems
  — Insider threat detection capabilities
  — Supply chain attack vectors through software dependencies
  — DORA compliance readiness for digital operational resilience testing

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

SCOPE AND METHODOLOGY

2.1 Assessment Scope

The assessment covers:
  — 26 ICT asset categories comprising 1,247 individual assets
  — 8 critical business functions supported by ICT systems
  — 12 third-party ICT service providers (3 critical, 4 important, 5 standard)
  — On-premises infrastructure (Zurich DC-1, Geneva DC-2)
  — Cloud infrastructure (AWS eu-central-1, Microsoft Azure)
  — Network infrastructure (LAN, WAN, DMZ, branch connectivity)

2.2 Methodology

The assessment follows the Bank's ICT Risk Assessment Methodology (PROC-RA-2024-001),
which is aligned with ISO 31000:2018 and the NIST Cybersecurity Framework v2.0.

Risk scoring uses a 5×5 matrix:
  Likelihood:  1 (Rare) to 5 (Almost Certain)
  Impact:      1 (Negligible) to 5 (Catastrophic)
  Risk Score:  Likelihood × Impact (1–25)

Risk ratings:
  1–4:   Low       5–9:   Medium       10–16: High       17–25: Critical

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

THREAT LANDSCAPE

The following threat categories are assessed as most relevant to the Bank's
operating environment in 2025:

  Threat Category              Trend    Relevance
  ─────────────────────────────────────────────────────────────────────────────
  Ransomware                   ↑        High — Financial sector remains primary
                                        target; double-extortion tactics prevalent
  Advanced Persistent Threats  →        High — State-sponsored actors targeting
                                        European financial infrastructure
  Supply Chain Attacks         ↑        Medium — Increasing exploitation of
                                        software dependencies and update mechanisms
  Insider Threats              →        Medium — Hybrid working increases risk of
                                        data exfiltration and credential misuse
  DDoS Attacks                 →        Medium — Continued targeting of customer-
                                        facing banking services
  Cloud Misconfiguration       ↑        Medium — Expanding cloud footprint
                                        increases configuration risk surface
  Social Engineering           ↑        High — AI-enhanced phishing campaigns
                                        targeting financial sector employees

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

VULNERABILITY ANALYSIS

4.1 Technical Vulnerability Summary (Q4 2024 scanning results)

  Severity     Count    Remediated    Open    SLA Compliance
  ─────────────────────────────────────────────────────────────────────────────
  Critical       3          3           0        100%
  High          18         16           2         89%
  Medium        47         38           9         81%
  Low           92         71          21         77%

4.2 Key Vulnerability Findings

  — Two high-severity vulnerabilities remain open in the legacy ATM management
    platform (NCR), pending vendor patch scheduled for February 2025
  — Nine medium-severity findings relate to TLS configuration inconsistencies
    across internal services (remediation in progress)
  — Legacy Oracle Database 19c instances require patching to January 2025 PSU

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

RISK EXPOSURE ASSESSMENT

5.1 Risk Summary by Severity

  Rating     Inherent    Residual    Change vs 2024
  ─────────────────────────────────────────────────────────────────────────────
  Critical      3           0           — (was 0)
  High         12           5           ↓ (was 6)
  Medium       18          14           ↑ (was 12)
  Low           9          23           ↑ (was 20)
  Total        42          42

5.2 Top 5 Residual Risks

  Rank  Risk ID       Description                          Residual Score
  ─────────────────────────────────────────────────────────────────────────────
  1     ICT-R-2025-03 Cloud concentration risk (AWS)            12 (High)
                      Single cloud provider hosts 4 of 8
                      critical business functions

  2     ICT-R-2025-07 Ransomware impact on legacy systems       12 (High)
                      On-premises systems lack immutable
                      backup capability

  3     ICT-R-2025-11 Insider threat — privileged access        10 (High)
                      Limited behavioural analytics for
                      privileged account activity

  4     ICT-R-2025-15 Third-party software supply chain         10 (High)
                      Dependency on unvetted open-source
                      components in digital banking platform

  5     ICT-R-2025-19 SWIFT network disruption                  10 (High)
                      Single SWIFT Alliance Gateway without
                      automated failover

5.3 Third-Party Risk Assessment

The assessment includes risks arising from 12 third-party ICT service providers:
  — 3 critical providers: AWS, Temenos AG, SWIFT
  — 4 important providers: Microsoft, Oracle, Palo Alto Networks, Splunk
  — 5 standard providers: NCR, Cisco, Lenovo, Swisscom, Wolters Kluwer

Concentration risk is identified for AWS, which hosts the Bank's internet banking,
mobile banking, and two additional critical applications. An exit strategy and
multi-cloud contingency plan are recommended.

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

RISK HEAT MAP

                    Impact
  Likelihood   1    2    3    4    5
  ─────────────────────────────────────
  5 (Almost)   -    -    1    -    -
  4 (Likely)   -    2    3    2    -
  3 (Possible) 1    5    4    1    -
  2 (Unlikely) 3    8    5    2    -
  1 (Rare)     2    2    1    -    -

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

RECOMMENDED MITIGATIONS

  Risk ID       Recommended Action                        Priority   Target Date
  ─────────────────────────────────────────────────────────────────────────────
  ICT-R-2025-03 Develop multi-cloud contingency plan      High       Q2 2025
                and AWS exit strategy
  ICT-R-2025-07 Deploy immutable backup solution for      High       Q1 2025
                on-premises critical systems
  ICT-R-2025-11 Implement privileged access behaviour     High       Q2 2025
                analytics (UEBA)
  ICT-R-2025-15 Implement software composition analysis   Medium     Q2 2025
                (SCA) in CI/CD pipeline
  ICT-R-2025-19 Deploy secondary SWIFT gateway with       High       Q3 2025
                automated failover

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

APPENDICES

Appendix A: Complete ICT Risk Register (42 entries) — see attached spreadsheet
Appendix B: Vulnerability Scanning Reports (Q4 2024) — see attached
Appendix C: Third-Party Provider Risk Scorecards — see attached
Appendix D: Threat Intelligence Sources and Methodology

Prepared by: Risk Management Function
Lead Assessor: Erik Lindqvist, Chief Risk Officer
Reviewed by: Katrin Halvorsen, CISO
Approved by: Board Risk Committee
Date: 14 January 2025

Expected Structured Facts

Example structured facts that Detrixa would extract from this evidence (synthetic data, deterministic seed).

ict_risk_assessment_status — fs-ict-risk-assessment
{
  "factId": "c1d2e3f4-a5b6-7890-cdef-100000000006",
  "evidenceId": "a0b1c2d3-e4f5-6789-abcd-100000000006",
  "evidenceClassId": "ict-risk-assessment",
  "factType": "ict_risk_assessment_status",
  "data": {
    "assessment_date": "2025-01-08",
    "scope_complete": true,
    "methodology": "ISO 31000:2018 / NIST Cybersecurity Framework v2.0 aligned",
    "total_risks_identified": 42,
    "high_risks_count": 5,
    "medium_risks_count": 14,
    "low_risks_count": 23,
    "includes_third_party_risks": true,
    "next_assessment_date": "2026-01-08"
  },
  "provenance": "deterministic",
  "extractorVersion": "dora-test-generator/0.1.0",
  "extractedAt": "2025-01-15T09:00:00Z",
  "supersededBy": null
}
ict_dependency_mapping_status — fs-ict-dependency-mapping
{
  "factId": "c1d2e3f4-a5b6-7890-cdef-100000000007",
  "evidenceId": "a0b1c2d3-e4f5-6789-abcd-100000000007",
  "evidenceClassId": "ict-dependency-mapping",
  "factType": "ict_dependency_mapping_status",
  "data": {
    "mapping_date": "2025-01-08",
    "systems_mapped": 14,
    "dependencies_documented": 28,
    "has_critical_path_analysis": true,
    "single_points_of_failure_identified": 3,
    "third_party_dependencies_mapped": true
  },
  "provenance": "deterministic",
  "extractorVersion": "dora-test-generator/0.1.0",
  "extractedAt": "2025-01-15T09:00:00Z",
  "supersededBy": null
}

ICT Dependency Mapping Document PARTIAL

XML-structured mapping of dependencies between ICT systems, business functions, and third-party services, identifying critical paths and single points of failure.

Formats
XML JSON
Evidence Class
ict-dependency-mapping
Availability
PARTIAL
Update Frequency
quarterly
Typical Author
Enterprise Architect
Approval Chain
Enterprise Architect → CIO

Content Sections

Expected Fields

Common Quality Issues

View Example

Generated example artifact using the default institution profile (COMMON availability, synthetic data only).

XML — Inline Preview
<?xml version="1.0" encoding="UTF-8"?>
<ICTDependencyMapping
    mappingVersion="1.4"
    lastUpdated="2025-01-08"
    institution="Nordvik Bank AG"
    preparedBy="Marta Novak, Enterprise Architect"
    approvedBy="Johan Lindberg, CIO">

  <!-- ═══════════════════════════════════════════════════════════════════════
       SYSTEM DEPENDENCIES
       Maps dependencies between internal ICT systems.
       ═══════════════════════════════════════════════════════════════════════ -->
  <SystemDependencies totalSystems="14" totalDependencies="28">

    <System id="SYS-001" name="Temenos T24 Core Banking" criticality="Critical"
            owner="Johan Lindberg" location="Zurich DC-1">
      <DependsOn>
        <Dependency targetId="SYS-002" type="data_store" criticality="Critical"
                    description="Primary transaction and customer data storage" />
        <Dependency targetId="SYS-010" type="infrastructure" criticality="Critical"
                    description="Primary data centre network connectivity" />
        <Dependency targetId="SYS-013" type="authentication" criticality="Critical"
                    description="Active Directory for service account authentication" />
      </DependsOn>
    </System>

    <System id="SYS-002" name="Oracle Database 19c Cluster" criticality="Critical"
            owner="Lars Eriksson" location="Zurich DC-1">
      <DependsOn>
        <Dependency targetId="SYS-010" type="infrastructure" criticality="Critical"
                    description="Network connectivity for replication and client access" />
        <Dependency targetId="SYS-011" type="storage" criticality="Critical"
                    description="SAN storage for database files and backups" />
      </DependsOn>
    </System>

    <System id="SYS-003" name="SWIFT Alliance Gateway" criticality="Critical"
            owner="Petra Hoffman" location="Zurich DC-1">
      <DependsOn>
        <Dependency targetId="SYS-001" type="data_source" criticality="Critical"
                    description="Payment instructions from core banking" />
        <Dependency targetId="SYS-010" type="infrastructure" criticality="Critical"
                    description="Dedicated SWIFT network segment" />
        <Dependency targetId="EXT-001" type="external_service" criticality="Critical"
                    description="SWIFT network connectivity (SWIFTNet)" />
      </DependsOn>
    </System>

    <System id="SYS-004" name="Internet Banking Portal" criticality="Critical"
            owner="Thomas Andersen" location="AWS eu-central-1">
      <DependsOn>
        <Dependency targetId="SYS-001" type="api" criticality="Critical"
                    description="Core banking API for account and transaction data" />
        <Dependency targetId="EXT-002" type="cloud_infrastructure" criticality="Critical"
                    description="AWS compute, networking, and load balancing" />
        <Dependency targetId="SYS-014" type="security" criticality="Important"
                    description="WAF and DDoS protection" />
      </DependsOn>
    </System>

    <System id="SYS-005" name="Mobile Banking Application" criticality="Critical"
            owner="Thomas Andersen" location="AWS eu-central-1">
      <DependsOn>
        <Dependency targetId="SYS-004" type="api" criticality="Critical"
                    description="Shared API gateway with internet banking" />
        <Dependency targetId="EXT-002" type="cloud_infrastructure" criticality="Critical"
                    description="AWS backend services" />
      </DependsOn>
    </System>

    <System id="SYS-006" name="AML System (NICE Actimize)" criticality="Critical"
            owner="Ingrid Solberg" location="Zurich DC-1">
      <DependsOn>
        <Dependency targetId="SYS-002" type="data_store" criticality="Critical"
                    description="Transaction data for screening" />
        <Dependency targetId="SYS-001" type="data_source" criticality="Critical"
                    description="Real-time transaction feed" />
      </DependsOn>
    </System>

    <System id="SYS-007" name="SIEM Platform (Splunk)" criticality="Critical"
            owner="Katrin Halvorsen" location="Zurich DC-1">
      <DependsOn>
        <Dependency targetId="SYS-010" type="infrastructure" criticality="Critical"
                    description="Network access to all monitored systems" />
        <Dependency targetId="SYS-011" type="storage" criticality="Important"
                    description="High-performance storage for log ingestion" />
      </DependsOn>
    </System>

    <System id="SYS-008" name="Regulatory Reporting Platform" criticality="Important"
            owner="Ingrid Solberg" location="Zurich DC-1">
      <DependsOn>
        <Dependency targetId="SYS-002" type="data_store" criticality="Important"
                    description="Financial data for regulatory reports" />
      </DependsOn>
    </System>

    <System id="SYS-009" name="ATM Management Platform" criticality="Important"
            owner="Annika Berglund" location="Zurich DC-1">
      <DependsOn>
        <Dependency targetId="SYS-001" type="api" criticality="Important"
                    description="Account balance and transaction processing" />
        <Dependency targetId="SYS-012" type="network" criticality="Important"
                    description="Branch WAN for ATM connectivity" />
      </DependsOn>
    </System>

    <System id="SYS-010" name="Primary DC Network (Zurich)" criticality="Critical"
            owner="Marta Novak" location="Zurich DC-1">
      <DependsOn>
        <Dependency targetId="SYS-014" type="security" criticality="Critical"
                    description="Firewall pair for network segmentation" />
      </DependsOn>
    </System>

    <System id="SYS-011" name="SAN Storage Infrastructure" criticality="Critical"
            owner="Lars Eriksson" location="Zurich DC-1">
      <DependsOn>
        <Dependency targetId="SYS-010" type="infrastructure" criticality="Critical"
                    description="Storage network (FC/iSCSI)" />
      </DependsOn>
    </System>

    <System id="SYS-012" name="Branch WAN (Swisscom)" criticality="Important"
            owner="Marta Novak" location="Nationwide">
      <DependsOn>
        <Dependency targetId="EXT-003" type="external_service" criticality="Important"
                    description="Swisscom MPLS network service" />
      </DependsOn>
    </System>

    <System id="SYS-013" name="Microsoft Azure AD" criticality="Important"
            owner="Henrik Dahl" location="Cloud (Microsoft)">
      <DependsOn>
        <Dependency targetId="EXT-004" type="cloud_infrastructure" criticality="Important"
                    description="Microsoft Azure identity services" />
      </DependsOn>
    </System>

    <System id="SYS-014" name="Palo Alto Firewall Pair" criticality="Critical"
            owner="Marta Novak" location="Zurich DC-1">
      <DependsOn />
    </System>
  </SystemDependencies>

  <!-- ═══════════════════════════════════════════════════════════════════════
       BUSINESS FUNCTION MAPPINGS
       Maps critical/important business functions to supporting ICT systems.
       ═══════════════════════════════════════════════════════════════════════ -->
  <BusinessFunctionMappings>
    <Function id="BF-001" name="Core Banking Operations" criticality="Critical"
              rtoHours="4" rpoHours="1">
      <SupportingSystems>
        <SystemRef id="SYS-001" role="primary" />
        <SystemRef id="SYS-002" role="data_store" />
        <SystemRef id="SYS-010" role="network" />
      </SupportingSystems>
    </Function>

    <Function id="BF-002" name="Payment Processing" criticality="Critical"
              rtoHours="2" rpoHours="0.5">
      <SupportingSystems>
        <SystemRef id="SYS-001" role="primary" />
        <SystemRef id="SYS-003" role="messaging" />
        <SystemRef id="SYS-002" role="data_store" />
      </SupportingSystems>
    </Function>

    <Function id="BF-003" name="Digital Banking Channels" criticality="Critical"
              rtoHours="4" rpoHours="1">
      <SupportingSystems>
        <SystemRef id="SYS-004" role="web_channel" />
        <SystemRef id="SYS-005" role="mobile_channel" />
        <SystemRef id="SYS-001" role="backend" />
      </SupportingSystems>
    </Function>

    <Function id="BF-004" name="AML/CFT Compliance" criticality="Critical"
              rtoHours="4" rpoHours="1">
      <SupportingSystems>
        <SystemRef id="SYS-006" role="primary" />
        <SystemRef id="SYS-002" role="data_store" />
      </SupportingSystems>
    </Function>

    <Function id="BF-005" name="Regulatory Reporting" criticality="Important"
              rtoHours="24" rpoHours="4">
      <SupportingSystems>
        <SystemRef id="SYS-008" role="primary" />
        <SystemRef id="SYS-002" role="data_store" />
      </SupportingSystems>
    </Function>

    <Function id="BF-006" name="ATM/Branch Services" criticality="Important"
              rtoHours="8" rpoHours="2">
      <SupportingSystems>
        <SystemRef id="SYS-009" role="primary" />
        <SystemRef id="SYS-012" role="network" />
        <SystemRef id="SYS-001" role="backend" />
      </SupportingSystems>
    </Function>

    <Function id="BF-007" name="Security Monitoring" criticality="Critical"
              rtoHours="1" rpoHours="0">
      <SupportingSystems>
        <SystemRef id="SYS-007" role="primary" />
        <SystemRef id="SYS-010" role="network" />
      </SupportingSystems>
    </Function>

    <Function id="BF-008" name="Identity and Access Management" criticality="Important"
              rtoHours="4" rpoHours="1">
      <SupportingSystems>
        <SystemRef id="SYS-013" role="primary" />
      </SupportingSystems>
    </Function>
  </BusinessFunctionMappings>

  <!-- ═══════════════════════════════════════════════════════════════════════
       THIRD-PARTY DEPENDENCIES
       Maps dependencies on external ICT service providers.
       ═══════════════════════════════════════════════════════════════════════ -->
  <ThirdPartyDependencies>
    <Provider id="EXT-001" name="SWIFT SCRL" criticality="Critical"
              serviceType="Payment Messaging Network"
              contractExpiry="2027-12-31"
              hasExitStrategy="true">
      <DependentSystems>
        <SystemRef id="SYS-003" />
      </DependentSystems>
    </Provider>

    <Provider id="EXT-002" name="Amazon Web Services" criticality="Critical"
              serviceType="Cloud Infrastructure (IaaS)"
              contractExpiry="2026-06-30"
              hasExitStrategy="false">
      <DependentSystems>
        <SystemRef id="SYS-004" />
        <SystemRef id="SYS-005" />
      </DependentSystems>
      <ConcentrationRisk level="High"
          note="Hosts 4 of 8 critical business functions. Exit strategy under development." />
    </Provider>

    <Provider id="EXT-003" name="Swisscom AG" criticality="Important"
              serviceType="WAN Connectivity (MPLS)"
              contractExpiry="2026-03-31"
              hasExitStrategy="true">
      <DependentSystems>
        <SystemRef id="SYS-012" />
      </DependentSystems>
    </Provider>

    <Provider id="EXT-004" name="Microsoft Corporation" criticality="Important"
              serviceType="Identity Services (Azure AD)"
              contractExpiry="2026-12-31"
              hasExitStrategy="true">
      <DependentSystems>
        <SystemRef id="SYS-013" />
      </DependentSystems>
    </Provider>
  </ThirdPartyDependencies>

  <!-- ═══════════════════════════════════════════════════════════════════════
       CRITICAL PATH ANALYSIS
       Identifies critical dependency chains and single points of failure.
       ═══════════════════════════════════════════════════════════════════════ -->
  <CriticalPathAnalysis>
    <CriticalPath id="CP-001" name="Payment Processing Chain">
      <PathNodes>
        <Node systemId="SYS-001" step="1" description="Core banking generates payment instruction" />
        <Node systemId="SYS-003" step="2" description="SWIFT gateway formats and transmits" />
        <Node providerId="EXT-001" step="3" description="SWIFT network delivers to counterparty" />
      </PathNodes>
      <SinglePointOfFailure systemId="SYS-003"
          description="Single SWIFT Alliance Gateway without automated failover"
          mitigationPlan="Deploy secondary gateway — target Q3 2025" />
    </CriticalPath>

    <CriticalPath id="CP-002" name="Digital Banking Access">
      <PathNodes>
        <Node providerId="EXT-002" step="1" description="AWS hosts application tier" />
        <Node systemId="SYS-004" step="2" description="Internet banking serves customer requests" />
        <Node systemId="SYS-001" step="3" description="Core banking processes transactions" />
        <Node systemId="SYS-002" step="4" description="Database persists transaction data" />
      </PathNodes>
      <SinglePointOfFailure providerId="EXT-002"
          description="AWS region failure would disable all digital channels"
          mitigationPlan="Multi-region deployment evaluation — target Q2 2025" />
    </CriticalPath>

    <CriticalPath id="CP-003" name="Security Monitoring Pipeline">
      <PathNodes>
        <Node systemId="SYS-010" step="1" description="Network infrastructure generates logs" />
        <Node systemId="SYS-007" step="2" description="SIEM ingests and correlates events" />
      </PathNodes>
    </CriticalPath>
  </CriticalPathAnalysis>

  <SinglePointsOfFailureSummary total="3">
    <SPOF systemId="SYS-003" description="Single SWIFT Alliance Gateway" severity="High" />
    <SPOF providerId="EXT-002" description="AWS single-region deployment for digital channels" severity="High" />
    <SPOF systemId="SYS-011" description="SAN storage without cross-site replication" severity="Medium" />
  </SinglePointsOfFailureSummary>

</ICTDependencyMapping>

Expected Structured Facts

Example structured facts that Detrixa would extract from this evidence (synthetic data, deterministic seed).

ict_risk_assessment_status — fs-ict-risk-assessment
{
  "factId": "c1d2e3f4-a5b6-7890-cdef-100000000006",
  "evidenceId": "a0b1c2d3-e4f5-6789-abcd-100000000006",
  "evidenceClassId": "ict-risk-assessment",
  "factType": "ict_risk_assessment_status",
  "data": {
    "assessment_date": "2025-01-08",
    "scope_complete": true,
    "methodology": "ISO 31000:2018 / NIST Cybersecurity Framework v2.0 aligned",
    "total_risks_identified": 42,
    "high_risks_count": 5,
    "medium_risks_count": 14,
    "low_risks_count": 23,
    "includes_third_party_risks": true,
    "next_assessment_date": "2026-01-08"
  },
  "provenance": "deterministic",
  "extractorVersion": "dora-test-generator/0.1.0",
  "extractedAt": "2025-01-15T09:00:00Z",
  "supersededBy": null
}
ict_dependency_mapping_status — fs-ict-dependency-mapping
{
  "factId": "c1d2e3f4-a5b6-7890-cdef-100000000007",
  "evidenceId": "a0b1c2d3-e4f5-6789-abcd-100000000007",
  "evidenceClassId": "ict-dependency-mapping",
  "factType": "ict_dependency_mapping_status",
  "data": {
    "mapping_date": "2025-01-08",
    "systems_mapped": 14,
    "dependencies_documented": 28,
    "has_critical_path_analysis": true,
    "single_points_of_failure_identified": 3,
    "third_party_dependencies_mapped": true
  },
  "provenance": "deterministic",
  "extractorVersion": "dora-test-generator/0.1.0",
  "extractedAt": "2025-01-15T09:00:00Z",
  "supersededBy": null
}

Fact Schemas

ict_risk_assessment_status

Schema ID
fs-ict-risk-assessment
Control
DORA-Art8-P1

Valid Ranges

assessment_date
within last 12 months
next_assessment_date
within 12 months of assessment_date

Related Schemas

JSON Schema

{
  "properties": {
    "assessment_date": {
      "format": "date",
      "type": "string"
    },
    "high_risks_count": {
      "minimum": 0,
      "type": "integer"
    },
    "includes_third_party_risks": {
      "type": "boolean"
    },
    "low_risks_count": {
      "minimum": 0,
      "type": "integer"
    },
    "medium_risks_count": {
      "minimum": 0,
      "type": "integer"
    },
    "methodology": {
      "minLength": 1,
      "type": "string"
    },
    "next_assessment_date": {
      "format": "date",
      "type": "string"
    },
    "scope_complete": {
      "type": "boolean"
    },
    "total_risks_identified": {
      "minimum": 0,
      "type": "integer"
    }
  },
  "required": [
    "assessment_date",
    "scope_complete",
    "methodology",
    "total_risks_identified",
    "high_risks_count"
  ],
  "type": "object"
}

ict_dependency_mapping_status

Schema ID
fs-ict-dependency-mapping
Control
DORA-Art8-P1

Valid Ranges

mapping_date
within last 6 months
systems_mapped
should cover all critical and important ICT systems

Related Schemas

JSON Schema

{
  "properties": {
    "dependencies_documented": {
      "minimum": 0,
      "type": "integer"
    },
    "has_critical_path_analysis": {
      "type": "boolean"
    },
    "mapping_date": {
      "format": "date",
      "type": "string"
    },
    "single_points_of_failure_identified": {
      "minimum": 0,
      "type": "integer"
    },
    "systems_mapped": {
      "minimum": 0,
      "type": "integer"
    },
    "third_party_dependencies_mapped": {
      "type": "boolean"
    }
  },
  "required": [
    "mapping_date",
    "systems_mapped",
    "has_critical_path_analysis",
    "single_points_of_failure_identified"
  ],
  "type": "object"
}