DORA-Art9-P1

Article
9 (1)
Pillar
ICT Risk Management
Regulation Ref
Regulation (EU) 2022/2554, Article 9(1)
Last Reviewed
2026-01-15

For the purposes of adequately protecting ICT systems and with a view to organising response measures, financial entities shall continuously monitor and control the security and functioning of ICT systems and tools and shall minimise the impact of ICT risk on ICT systems through the deployment of appropriate ICT security tools, policies and procedures.

Evidence Profiles

ICT Security Policy COMMON

Comprehensive security policy covering access controls, encryption, network security, patch management, and security monitoring as required by DORA Article 9.

Formats
DOCX PDF
Evidence Class
ict-security-policy
Availability
COMMON
Update Frequency
annual
Typical Author
CISO
Approval Chain
CISO → CIO

Content Sections

Expected Fields

Common Quality Issues

View Example

Generated example artifact using the default institution profile (COMMON availability, synthetic data only).

PLAIN_TEXT — Inline Preview
ICT SECURITY POLICY
Nordvik Bank AG
Policy Reference: POL-ICT-SEC-2025-001
Version 5.0 | Effective Date: 12 January 2025
Policy Owner: Chief Information Security Officer (CISO)
Review Date: 12 January 2026
Applicable Standards: ISO 27001:2022, NIST CSF 2.0, DORA (EU) 2022/2554
Classification: Internal — Restricted

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

1. PURPOSE AND SCOPE

This policy defines the ICT security requirements for Nordvik Bank AG ("the Bank")
to protect the confidentiality, integrity, and availability of ICT systems and data.
It applies to all employees, contractors, and third-party service providers with
access to the Bank's ICT systems, in accordance with DORA Article 9.

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

2. ACCESS CONTROL POLICY

2.1 Principles

Access to ICT systems shall be granted on the principle of least privilege and
need-to-know. All access shall be individually attributable and subject to periodic
review.

2.2 Authentication Requirements

  System Category     Minimum Authentication Requirement
  ─────────────────────────────────────────────────────────────────────────────
  Critical systems    Multi-factor authentication (MFA) mandatory
  Important systems   MFA mandatory for privileged access; strong password for
                      standard access
  Standard systems    Strong password (minimum 14 characters, complexity rules)
  Remote access       MFA mandatory for all remote connections (VPN, RDP, SSH)

2.3 Privileged Access Management

  — All privileged accounts shall be managed through the Privileged Access
    Management (PAM) solution (CyberArk)
  — Privileged sessions shall be recorded and retained for 12 months
  — Standing privileged access shall be reviewed quarterly
  — Emergency ("break-glass") access shall require dual authorisation and
    post-use review within 24 hours

2.4 Access Reviews

  — User access rights shall be reviewed quarterly for critical systems
  — Joiner/mover/leaver processes shall be completed within 24 hours of
    the triggering HR event
  — Dormant accounts (no login for 90 days) shall be automatically disabled

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

3. ENCRYPTION STANDARDS

3.1 Data at Rest

  — AES-256 encryption for all data classified as Confidential or above
  — Full-disk encryption on all endpoint devices (laptops, workstations)
  — Database-level Transparent Data Encryption (TDE) for production databases
  — Encryption keys managed through a dedicated Hardware Security Module (HSM)

3.2 Data in Transit

  — TLS 1.3 mandatory for all external-facing services
  — TLS 1.2 minimum for internal service-to-service communication
  — IPSec VPN for all site-to-site and remote access connections
  — SFTP or SCP for all file transfers containing sensitive data

3.3 Key Management

  — Cryptographic keys shall be rotated annually (or immediately upon
    suspected compromise)
  — Key generation shall use FIPS 140-2 Level 3 certified HSMs
  — Key escrow procedures shall be documented and tested annually

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

4. NETWORK SECURITY

4.1 Network Segmentation

The Bank's network is segmented into the following security zones:
  — DMZ: Customer-facing services (internet banking, API gateway)
  — Production Zone: Core banking, payment processing, databases
  — Management Zone: Administrative access, monitoring, backup
  — User Zone: Employee workstations and office services
  — Development Zone: Development and testing environments (isolated)

Inter-zone traffic is controlled by next-generation firewalls (Palo Alto) with
application-layer inspection. Default deny policy applies to all inter-zone traffic.

4.2 Network Monitoring

  — All network traffic is monitored by the SIEM platform
  — Intrusion Detection/Prevention Systems (IDS/IPS) deployed at zone boundaries
  — NetFlow data collected and retained for 90 days for forensic analysis
  — DNS query logging enabled for all internal DNS resolvers

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

5. PATCH MANAGEMENT

5.1 Patching Timelines

  Severity     Timeline                    Scope
  ─────────────────────────────────────────────────────────────────────────────
  Critical     72 hours from release       All affected systems
  High         14 calendar days            All affected systems
  Medium       90 calendar days            All affected systems
  Low          Next maintenance window     All affected systems

5.2 Patch Process

  — Patches are tested in the development environment before production deployment
  — Emergency patches for critical vulnerabilities may bypass standard testing
    with CISO approval and post-deployment validation
  — Patch compliance is reported weekly to the CISO and monthly to the ICTRC
  — Systems that cannot be patched within SLA require a documented risk acceptance
    and compensating controls

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

6. SECURITY MONITORING

6.1 Security Operations Centre

The Bank operates a 24/7 Security Operations Centre (SOC) staffed by trained
security analysts. The SOC is responsible for:
  — Real-time monitoring of security events via the SIEM platform
  — Triage and initial response to security alerts
  — Escalation of confirmed incidents per the Incident Response Plan
  — Threat hunting activities based on intelligence feeds

6.2 Log Management

  — Security-relevant logs shall be collected from all critical and important systems
  — Log retention: minimum 12 months online, 5 years archived
  — Log integrity shall be protected through write-once storage or cryptographic
    chaining
  — Log sources shall be synchronised to a common NTP source (±1 second)

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

7. INCIDENT RESPONSE

Security incidents shall be managed in accordance with the ICT Incident Response
Plan (PLAN-IR-2025-001). This policy requires:
  — All suspected security incidents reported to the SOC within 1 hour
  — Incident classification within 2 hours of initial report
  — Major incidents escalated to CISO within 4 hours
  — Post-incident review completed within 10 business days

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

8. ACCEPTABLE USE

  — Bank ICT resources shall be used for authorised business purposes only
  — Personal use of ICT resources is permitted within reasonable limits and
    must not compromise security
  — Installation of unauthorised software is prohibited
  — Use of personal devices for Bank business requires MDM enrolment
  — All staff shall complete annual ICT security awareness training

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

Document History:
  v5.0  12 Jan 2025  Updated for DORA compliance; enhanced cloud security provisions
  v4.3  15 Jan 2024  Annual review; updated encryption standards
  v4.2  01 Jul 2023  Interim update; added remote access MFA requirement
  v4.0  12 Jan 2023  Major revision; aligned with ISO 27001:2022

Approved by: CIO
Signature:   [Chief Information Officer]
Date:        12 January 2025

Expected Structured Facts

Example structured facts that Detrixa would extract from this evidence (synthetic data, deterministic seed).

ict_security_controls_status — fs-ict-security-controls
{
  "factId": "c1d2e3f4-a5b6-7890-cdef-100000000009",
  "evidenceId": "a0b1c2d3-e4f5-6789-abcd-100000000009",
  "evidenceClassId": "ict-security-controls",
  "factType": "ict_security_controls_status",
  "data": {
    "assessment_date": "2025-01-10",
    "total_controls": 48,
    "implemented_controls": 45,
    "effective_controls": 42,
    "has_access_controls": true,
    "has_encryption": true,
    "has_network_security": true,
    "has_patch_management": true,
    "last_effectiveness_review": "2024-12-15"
  },
  "provenance": "deterministic",
  "extractorVersion": "dora-test-generator/0.1.0",
  "extractedAt": "2025-01-15T09:00:00Z",
  "supersededBy": null
}

ICT Security Controls Register PARTIAL

Structured JSON register of deployed ICT security controls, their implementation status, effectiveness ratings, and mapping to regulatory requirements.

Formats
JSON
Evidence Class
ict-security-controls
Availability
PARTIAL
Update Frequency
quarterly
Typical Author
Security Operations Manager
Approval Chain
Security Operations Manager → CISO

Content Sections

Expected Fields

Common Quality Issues

View Example

Generated example artifact using the default institution profile (COMMON availability, synthetic data only).

JSON — Inline Preview
{
  "controlsRegister": {
    "registerId": "CTRL-REG-2025-001",
    "institution": "Nordvik Bank AG",
    "lastUpdated": "2025-01-10",
    "assessedBy": "Security Operations Manager",
    "totalControls": 48,
    "implementedControls": 45,
    "effectiveControls": 42
  },
  "controls": [
    {
      "controlId": "CTRL-AC-001",
      "controlName": "Multi-Factor Authentication (MFA)",
      "controlCategory": "Access Control",
      "controlType": "Preventive",
      "implementationStatus": "Implemented",
      "effectivenessRating": "Effective",
      "description": "MFA enforced for all privileged accounts, remote access, and critical system access using hardware tokens and mobile authenticator apps.",
      "lastTested": "2024-12-15",
      "testMethod": "Penetration test and configuration review",
      "regulatoryMapping": ["DORA Art.9(1)", "ISO 27001 A.8.5"],
      "owner": "Identity and Access Management Team"
    },
    {
      "controlId": "CTRL-AC-002",
      "controlName": "Privileged Access Management (PAM)",
      "controlCategory": "Access Control",
      "controlType": "Preventive",
      "implementationStatus": "Implemented",
      "effectivenessRating": "Effective",
      "description": "CyberArk PAM solution managing all privileged accounts with session recording, credential vaulting, and just-in-time access provisioning.",
      "lastTested": "2024-11-20",
      "testMethod": "Configuration audit and access review",
      "regulatoryMapping": ["DORA Art.9(1)", "ISO 27001 A.8.2"],
      "owner": "Identity and Access Management Team"
    },
    {
      "controlId": "CTRL-AC-003",
      "controlName": "Role-Based Access Control (RBAC)",
      "controlCategory": "Access Control",
      "controlType": "Preventive",
      "implementationStatus": "Implemented",
      "effectivenessRating": "Partially Effective",
      "description": "RBAC implemented across core banking and digital channels. Some legacy applications still use individual permission grants pending migration.",
      "lastTested": "2024-10-30",
      "testMethod": "Access rights review",
      "regulatoryMapping": ["DORA Art.9(1)", "ISO 27001 A.5.15"],
      "owner": "Identity and Access Management Team"
    },
    {
      "controlId": "CTRL-EN-001",
      "controlName": "Encryption at Rest (AES-256)",
      "controlCategory": "Encryption",
      "controlType": "Preventive",
      "implementationStatus": "Implemented",
      "effectivenessRating": "Effective",
      "description": "AES-256 encryption applied to all databases, file shares, and endpoint devices storing Confidential or Strictly Confidential data.",
      "lastTested": "2024-12-01",
      "testMethod": "Configuration scan and key management audit",
      "regulatoryMapping": ["DORA Art.9(1)", "ISO 27001 A.8.24"],
      "owner": "Infrastructure Security Team"
    },
    {
      "controlId": "CTRL-EN-002",
      "controlName": "TLS 1.3 for External Services",
      "controlCategory": "Encryption",
      "controlType": "Preventive",
      "implementationStatus": "Implemented",
      "effectivenessRating": "Effective",
      "description": "TLS 1.3 enforced on all external-facing web services, APIs, and customer portals. TLS 1.2 accepted as fallback for legacy integrations.",
      "lastTested": "2024-12-15",
      "testMethod": "SSL/TLS configuration scan (Qualys SSL Labs)",
      "regulatoryMapping": ["DORA Art.9(1)", "ISO 27001 A.8.24"],
      "owner": "Infrastructure Security Team"
    },
    {
      "controlId": "CTRL-NS-001",
      "controlName": "Network Segmentation",
      "controlCategory": "Network Security",
      "controlType": "Preventive",
      "implementationStatus": "Implemented",
      "effectivenessRating": "Effective",
      "description": "Network segmented into five security zones (DMZ, Production, Management, User, Development) with next-generation firewall enforcement at zone boundaries.",
      "lastTested": "2024-11-15",
      "testMethod": "Network penetration test and firewall rule review",
      "regulatoryMapping": ["DORA Art.9(1)", "ISO 27001 A.8.22"],
      "owner": "Network Operations Team"
    },
    {
      "controlId": "CTRL-NS-002",
      "controlName": "Intrusion Detection/Prevention System (IDS/IPS)",
      "controlCategory": "Network Security",
      "controlType": "Detective",
      "implementationStatus": "Implemented",
      "effectivenessRating": "Effective",
      "description": "Palo Alto IDS/IPS deployed at all zone boundaries with signature and behavioural detection. Signatures updated daily.",
      "lastTested": "2024-12-01",
      "testMethod": "Detection efficacy test with simulated attacks",
      "regulatoryMapping": ["DORA Art.10(1)", "ISO 27001 A.8.16"],
      "owner": "Security Operations Centre"
    },
    {
      "controlId": "CTRL-DT-001",
      "controlName": "SIEM Platform (Splunk Enterprise)",
      "controlCategory": "Detection and Monitoring",
      "controlType": "Detective",
      "implementationStatus": "Implemented",
      "effectivenessRating": "Effective",
      "description": "Centralised SIEM collecting logs from all critical and important systems. 342 correlation rules active. 24/7 SOC monitoring.",
      "lastTested": "2024-12-20",
      "testMethod": "Detection rule validation with purple team exercise",
      "regulatoryMapping": ["DORA Art.10(1)", "ISO 27001 A.8.15"],
      "owner": "Security Operations Centre"
    },
    {
      "controlId": "CTRL-DT-002",
      "controlName": "Endpoint Detection and Response (EDR)",
      "controlCategory": "Detection and Monitoring",
      "controlType": "Detective",
      "implementationStatus": "Implemented",
      "effectivenessRating": "Effective",
      "description": "CrowdStrike Falcon EDR deployed on all servers and workstations. Behavioural detection with automated containment for high-confidence threats.",
      "lastTested": "2024-12-15",
      "testMethod": "Simulated malware execution and lateral movement",
      "regulatoryMapping": ["DORA Art.10(1)", "ISO 27001 A.8.7"],
      "owner": "Security Operations Centre"
    },
    {
      "controlId": "CTRL-PM-001",
      "controlName": "Automated Patch Management",
      "controlCategory": "Patch Management",
      "controlType": "Preventive",
      "implementationStatus": "Implemented",
      "effectivenessRating": "Partially Effective",
      "description": "WSUS and SCCM for Windows patching; Ansible for Linux. Critical patches within 72h SLA. Two legacy systems require manual patching.",
      "lastTested": "2025-01-05",
      "testMethod": "Patch compliance scan",
      "regulatoryMapping": ["DORA Art.9(1)", "ISO 27001 A.8.8"],
      "owner": "IT Operations Team"
    },
    {
      "controlId": "CTRL-DLP-001",
      "controlName": "Data Loss Prevention (DLP)",
      "controlCategory": "Data Protection",
      "controlType": "Detective",
      "implementationStatus": "Implemented",
      "effectivenessRating": "Partially Effective",
      "description": "DLP policies enforced on email, web uploads, and USB transfers. Coverage gaps exist for cloud storage services — remediation planned Q1 2025.",
      "lastTested": "2024-11-30",
      "testMethod": "DLP policy bypass testing",
      "regulatoryMapping": ["DORA Art.9(1)", "ISO 27001 A.8.12"],
      "owner": "Information Security Team"
    },
    {
      "controlId": "CTRL-BC-001",
      "controlName": "Backup and Recovery Procedures",
      "controlCategory": "Business Continuity",
      "controlType": "Corrective",
      "implementationStatus": "Implemented",
      "effectivenessRating": "Effective",
      "description": "Daily incremental and weekly full backups for all critical systems. Offsite replication to Geneva DC-2. Restoration tested quarterly.",
      "lastTested": "2024-12-10",
      "testMethod": "Full restoration test of core banking database",
      "regulatoryMapping": ["DORA Art.13(1)", "ISO 27001 A.8.13"],
      "owner": "IT Operations Team"
    }
  ]
}

Expected Structured Facts

Example structured facts that Detrixa would extract from this evidence (synthetic data, deterministic seed).

ict_security_controls_status — fs-ict-security-controls
{
  "factId": "c1d2e3f4-a5b6-7890-cdef-100000000009",
  "evidenceId": "a0b1c2d3-e4f5-6789-abcd-100000000009",
  "evidenceClassId": "ict-security-controls",
  "factType": "ict_security_controls_status",
  "data": {
    "assessment_date": "2025-01-10",
    "total_controls": 48,
    "implemented_controls": 45,
    "effective_controls": 42,
    "has_access_controls": true,
    "has_encryption": true,
    "has_network_security": true,
    "has_patch_management": true,
    "last_effectiveness_review": "2024-12-15"
  },
  "provenance": "deterministic",
  "extractorVersion": "dora-test-generator/0.1.0",
  "extractedAt": "2025-01-15T09:00:00Z",
  "supersededBy": null
}

Fact Schemas

ict_security_controls_status

Schema ID
fs-ict-security-controls
Control
DORA-Art9-P1

Valid Ranges

assessment_date
within last 6 months
implemented_controls
should equal total_controls for full compliance

Related Schemas

JSON Schema

{
  "properties": {
    "assessment_date": {
      "format": "date",
      "type": "string"
    },
    "effective_controls": {
      "minimum": 0,
      "type": "integer"
    },
    "has_access_controls": {
      "type": "boolean"
    },
    "has_encryption": {
      "type": "boolean"
    },
    "has_network_security": {
      "type": "boolean"
    },
    "has_patch_management": {
      "type": "boolean"
    },
    "implemented_controls": {
      "minimum": 0,
      "type": "integer"
    },
    "last_effectiveness_review": {
      "format": "date",
      "type": "string"
    },
    "total_controls": {
      "minimum": 0,
      "type": "integer"
    }
  },
  "required": [
    "assessment_date",
    "total_controls",
    "implemented_controls",
    "has_access_controls",
    "has_encryption"
  ],
  "type": "object"
}