For the purposes of adequately protecting ICT systems and with a view to organising response measures, financial entities shall continuously monitor and control the security and functioning of ICT systems and tools and shall minimise the impact of ICT risk on ICT systems through the deployment of appropriate ICT security tools, policies and procedures.
Comprehensive security policy covering access controls, encryption, network security, patch management, and security monitoring as required by DORA Article 9.
ict-security-policyGenerated example artifact using the default institution profile (COMMON availability, synthetic data only).
ICT SECURITY POLICY
Nordvik Bank AG
Policy Reference: POL-ICT-SEC-2025-001
Version 5.0 | Effective Date: 12 January 2025
Policy Owner: Chief Information Security Officer (CISO)
Review Date: 12 January 2026
Applicable Standards: ISO 27001:2022, NIST CSF 2.0, DORA (EU) 2022/2554
Classification: Internal — Restricted
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
1. PURPOSE AND SCOPE
This policy defines the ICT security requirements for Nordvik Bank AG ("the Bank")
to protect the confidentiality, integrity, and availability of ICT systems and data.
It applies to all employees, contractors, and third-party service providers with
access to the Bank's ICT systems, in accordance with DORA Article 9.
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
2. ACCESS CONTROL POLICY
2.1 Principles
Access to ICT systems shall be granted on the principle of least privilege and
need-to-know. All access shall be individually attributable and subject to periodic
review.
2.2 Authentication Requirements
System Category Minimum Authentication Requirement
─────────────────────────────────────────────────────────────────────────────
Critical systems Multi-factor authentication (MFA) mandatory
Important systems MFA mandatory for privileged access; strong password for
standard access
Standard systems Strong password (minimum 14 characters, complexity rules)
Remote access MFA mandatory for all remote connections (VPN, RDP, SSH)
2.3 Privileged Access Management
— All privileged accounts shall be managed through the Privileged Access
Management (PAM) solution (CyberArk)
— Privileged sessions shall be recorded and retained for 12 months
— Standing privileged access shall be reviewed quarterly
— Emergency ("break-glass") access shall require dual authorisation and
post-use review within 24 hours
2.4 Access Reviews
— User access rights shall be reviewed quarterly for critical systems
— Joiner/mover/leaver processes shall be completed within 24 hours of
the triggering HR event
— Dormant accounts (no login for 90 days) shall be automatically disabled
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
3. ENCRYPTION STANDARDS
3.1 Data at Rest
— AES-256 encryption for all data classified as Confidential or above
— Full-disk encryption on all endpoint devices (laptops, workstations)
— Database-level Transparent Data Encryption (TDE) for production databases
— Encryption keys managed through a dedicated Hardware Security Module (HSM)
3.2 Data in Transit
— TLS 1.3 mandatory for all external-facing services
— TLS 1.2 minimum for internal service-to-service communication
— IPSec VPN for all site-to-site and remote access connections
— SFTP or SCP for all file transfers containing sensitive data
3.3 Key Management
— Cryptographic keys shall be rotated annually (or immediately upon
suspected compromise)
— Key generation shall use FIPS 140-2 Level 3 certified HSMs
— Key escrow procedures shall be documented and tested annually
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
4. NETWORK SECURITY
4.1 Network Segmentation
The Bank's network is segmented into the following security zones:
— DMZ: Customer-facing services (internet banking, API gateway)
— Production Zone: Core banking, payment processing, databases
— Management Zone: Administrative access, monitoring, backup
— User Zone: Employee workstations and office services
— Development Zone: Development and testing environments (isolated)
Inter-zone traffic is controlled by next-generation firewalls (Palo Alto) with
application-layer inspection. Default deny policy applies to all inter-zone traffic.
4.2 Network Monitoring
— All network traffic is monitored by the SIEM platform
— Intrusion Detection/Prevention Systems (IDS/IPS) deployed at zone boundaries
— NetFlow data collected and retained for 90 days for forensic analysis
— DNS query logging enabled for all internal DNS resolvers
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
5. PATCH MANAGEMENT
5.1 Patching Timelines
Severity Timeline Scope
─────────────────────────────────────────────────────────────────────────────
Critical 72 hours from release All affected systems
High 14 calendar days All affected systems
Medium 90 calendar days All affected systems
Low Next maintenance window All affected systems
5.2 Patch Process
— Patches are tested in the development environment before production deployment
— Emergency patches for critical vulnerabilities may bypass standard testing
with CISO approval and post-deployment validation
— Patch compliance is reported weekly to the CISO and monthly to the ICTRC
— Systems that cannot be patched within SLA require a documented risk acceptance
and compensating controls
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
6. SECURITY MONITORING
6.1 Security Operations Centre
The Bank operates a 24/7 Security Operations Centre (SOC) staffed by trained
security analysts. The SOC is responsible for:
— Real-time monitoring of security events via the SIEM platform
— Triage and initial response to security alerts
— Escalation of confirmed incidents per the Incident Response Plan
— Threat hunting activities based on intelligence feeds
6.2 Log Management
— Security-relevant logs shall be collected from all critical and important systems
— Log retention: minimum 12 months online, 5 years archived
— Log integrity shall be protected through write-once storage or cryptographic
chaining
— Log sources shall be synchronised to a common NTP source (±1 second)
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
7. INCIDENT RESPONSE
Security incidents shall be managed in accordance with the ICT Incident Response
Plan (PLAN-IR-2025-001). This policy requires:
— All suspected security incidents reported to the SOC within 1 hour
— Incident classification within 2 hours of initial report
— Major incidents escalated to CISO within 4 hours
— Post-incident review completed within 10 business days
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
8. ACCEPTABLE USE
— Bank ICT resources shall be used for authorised business purposes only
— Personal use of ICT resources is permitted within reasonable limits and
must not compromise security
— Installation of unauthorised software is prohibited
— Use of personal devices for Bank business requires MDM enrolment
— All staff shall complete annual ICT security awareness training
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
Document History:
v5.0 12 Jan 2025 Updated for DORA compliance; enhanced cloud security provisions
v4.3 15 Jan 2024 Annual review; updated encryption standards
v4.2 01 Jul 2023 Interim update; added remote access MFA requirement
v4.0 12 Jan 2023 Major revision; aligned with ISO 27001:2022
Approved by: CIO
Signature: [Chief Information Officer]
Date: 12 January 2025
Example structured facts that Detrixa would extract from this evidence (synthetic data, deterministic seed).
ict_security_controls_status — fs-ict-security-controls
{
"factId": "c1d2e3f4-a5b6-7890-cdef-100000000009",
"evidenceId": "a0b1c2d3-e4f5-6789-abcd-100000000009",
"evidenceClassId": "ict-security-controls",
"factType": "ict_security_controls_status",
"data": {
"assessment_date": "2025-01-10",
"total_controls": 48,
"implemented_controls": 45,
"effective_controls": 42,
"has_access_controls": true,
"has_encryption": true,
"has_network_security": true,
"has_patch_management": true,
"last_effectiveness_review": "2024-12-15"
},
"provenance": "deterministic",
"extractorVersion": "dora-test-generator/0.1.0",
"extractedAt": "2025-01-15T09:00:00Z",
"supersededBy": null
}
Structured JSON register of deployed ICT security controls, their implementation status, effectiveness ratings, and mapping to regulatory requirements.
ict-security-controlsGenerated example artifact using the default institution profile (COMMON availability, synthetic data only).
{
"controlsRegister": {
"registerId": "CTRL-REG-2025-001",
"institution": "Nordvik Bank AG",
"lastUpdated": "2025-01-10",
"assessedBy": "Security Operations Manager",
"totalControls": 48,
"implementedControls": 45,
"effectiveControls": 42
},
"controls": [
{
"controlId": "CTRL-AC-001",
"controlName": "Multi-Factor Authentication (MFA)",
"controlCategory": "Access Control",
"controlType": "Preventive",
"implementationStatus": "Implemented",
"effectivenessRating": "Effective",
"description": "MFA enforced for all privileged accounts, remote access, and critical system access using hardware tokens and mobile authenticator apps.",
"lastTested": "2024-12-15",
"testMethod": "Penetration test and configuration review",
"regulatoryMapping": ["DORA Art.9(1)", "ISO 27001 A.8.5"],
"owner": "Identity and Access Management Team"
},
{
"controlId": "CTRL-AC-002",
"controlName": "Privileged Access Management (PAM)",
"controlCategory": "Access Control",
"controlType": "Preventive",
"implementationStatus": "Implemented",
"effectivenessRating": "Effective",
"description": "CyberArk PAM solution managing all privileged accounts with session recording, credential vaulting, and just-in-time access provisioning.",
"lastTested": "2024-11-20",
"testMethod": "Configuration audit and access review",
"regulatoryMapping": ["DORA Art.9(1)", "ISO 27001 A.8.2"],
"owner": "Identity and Access Management Team"
},
{
"controlId": "CTRL-AC-003",
"controlName": "Role-Based Access Control (RBAC)",
"controlCategory": "Access Control",
"controlType": "Preventive",
"implementationStatus": "Implemented",
"effectivenessRating": "Partially Effective",
"description": "RBAC implemented across core banking and digital channels. Some legacy applications still use individual permission grants pending migration.",
"lastTested": "2024-10-30",
"testMethod": "Access rights review",
"regulatoryMapping": ["DORA Art.9(1)", "ISO 27001 A.5.15"],
"owner": "Identity and Access Management Team"
},
{
"controlId": "CTRL-EN-001",
"controlName": "Encryption at Rest (AES-256)",
"controlCategory": "Encryption",
"controlType": "Preventive",
"implementationStatus": "Implemented",
"effectivenessRating": "Effective",
"description": "AES-256 encryption applied to all databases, file shares, and endpoint devices storing Confidential or Strictly Confidential data.",
"lastTested": "2024-12-01",
"testMethod": "Configuration scan and key management audit",
"regulatoryMapping": ["DORA Art.9(1)", "ISO 27001 A.8.24"],
"owner": "Infrastructure Security Team"
},
{
"controlId": "CTRL-EN-002",
"controlName": "TLS 1.3 for External Services",
"controlCategory": "Encryption",
"controlType": "Preventive",
"implementationStatus": "Implemented",
"effectivenessRating": "Effective",
"description": "TLS 1.3 enforced on all external-facing web services, APIs, and customer portals. TLS 1.2 accepted as fallback for legacy integrations.",
"lastTested": "2024-12-15",
"testMethod": "SSL/TLS configuration scan (Qualys SSL Labs)",
"regulatoryMapping": ["DORA Art.9(1)", "ISO 27001 A.8.24"],
"owner": "Infrastructure Security Team"
},
{
"controlId": "CTRL-NS-001",
"controlName": "Network Segmentation",
"controlCategory": "Network Security",
"controlType": "Preventive",
"implementationStatus": "Implemented",
"effectivenessRating": "Effective",
"description": "Network segmented into five security zones (DMZ, Production, Management, User, Development) with next-generation firewall enforcement at zone boundaries.",
"lastTested": "2024-11-15",
"testMethod": "Network penetration test and firewall rule review",
"regulatoryMapping": ["DORA Art.9(1)", "ISO 27001 A.8.22"],
"owner": "Network Operations Team"
},
{
"controlId": "CTRL-NS-002",
"controlName": "Intrusion Detection/Prevention System (IDS/IPS)",
"controlCategory": "Network Security",
"controlType": "Detective",
"implementationStatus": "Implemented",
"effectivenessRating": "Effective",
"description": "Palo Alto IDS/IPS deployed at all zone boundaries with signature and behavioural detection. Signatures updated daily.",
"lastTested": "2024-12-01",
"testMethod": "Detection efficacy test with simulated attacks",
"regulatoryMapping": ["DORA Art.10(1)", "ISO 27001 A.8.16"],
"owner": "Security Operations Centre"
},
{
"controlId": "CTRL-DT-001",
"controlName": "SIEM Platform (Splunk Enterprise)",
"controlCategory": "Detection and Monitoring",
"controlType": "Detective",
"implementationStatus": "Implemented",
"effectivenessRating": "Effective",
"description": "Centralised SIEM collecting logs from all critical and important systems. 342 correlation rules active. 24/7 SOC monitoring.",
"lastTested": "2024-12-20",
"testMethod": "Detection rule validation with purple team exercise",
"regulatoryMapping": ["DORA Art.10(1)", "ISO 27001 A.8.15"],
"owner": "Security Operations Centre"
},
{
"controlId": "CTRL-DT-002",
"controlName": "Endpoint Detection and Response (EDR)",
"controlCategory": "Detection and Monitoring",
"controlType": "Detective",
"implementationStatus": "Implemented",
"effectivenessRating": "Effective",
"description": "CrowdStrike Falcon EDR deployed on all servers and workstations. Behavioural detection with automated containment for high-confidence threats.",
"lastTested": "2024-12-15",
"testMethod": "Simulated malware execution and lateral movement",
"regulatoryMapping": ["DORA Art.10(1)", "ISO 27001 A.8.7"],
"owner": "Security Operations Centre"
},
{
"controlId": "CTRL-PM-001",
"controlName": "Automated Patch Management",
"controlCategory": "Patch Management",
"controlType": "Preventive",
"implementationStatus": "Implemented",
"effectivenessRating": "Partially Effective",
"description": "WSUS and SCCM for Windows patching; Ansible for Linux. Critical patches within 72h SLA. Two legacy systems require manual patching.",
"lastTested": "2025-01-05",
"testMethod": "Patch compliance scan",
"regulatoryMapping": ["DORA Art.9(1)", "ISO 27001 A.8.8"],
"owner": "IT Operations Team"
},
{
"controlId": "CTRL-DLP-001",
"controlName": "Data Loss Prevention (DLP)",
"controlCategory": "Data Protection",
"controlType": "Detective",
"implementationStatus": "Implemented",
"effectivenessRating": "Partially Effective",
"description": "DLP policies enforced on email, web uploads, and USB transfers. Coverage gaps exist for cloud storage services — remediation planned Q1 2025.",
"lastTested": "2024-11-30",
"testMethod": "DLP policy bypass testing",
"regulatoryMapping": ["DORA Art.9(1)", "ISO 27001 A.8.12"],
"owner": "Information Security Team"
},
{
"controlId": "CTRL-BC-001",
"controlName": "Backup and Recovery Procedures",
"controlCategory": "Business Continuity",
"controlType": "Corrective",
"implementationStatus": "Implemented",
"effectivenessRating": "Effective",
"description": "Daily incremental and weekly full backups for all critical systems. Offsite replication to Geneva DC-2. Restoration tested quarterly.",
"lastTested": "2024-12-10",
"testMethod": "Full restoration test of core banking database",
"regulatoryMapping": ["DORA Art.13(1)", "ISO 27001 A.8.13"],
"owner": "IT Operations Team"
}
]
}
Example structured facts that Detrixa would extract from this evidence (synthetic data, deterministic seed).
ict_security_controls_status — fs-ict-security-controls
{
"factId": "c1d2e3f4-a5b6-7890-cdef-100000000009",
"evidenceId": "a0b1c2d3-e4f5-6789-abcd-100000000009",
"evidenceClassId": "ict-security-controls",
"factType": "ict_security_controls_status",
"data": {
"assessment_date": "2025-01-10",
"total_controls": 48,
"implemented_controls": 45,
"effective_controls": 42,
"has_access_controls": true,
"has_encryption": true,
"has_network_security": true,
"has_patch_management": true,
"last_effectiveness_review": "2024-12-15"
},
"provenance": "deterministic",
"extractorVersion": "dora-test-generator/0.1.0",
"extractedAt": "2025-01-15T09:00:00Z",
"supersededBy": null
}
fs-ict-security-controlsDORA-Art9-P1assessment_dateimplemented_controls{
"properties": {
"assessment_date": {
"format": "date",
"type": "string"
},
"effective_controls": {
"minimum": 0,
"type": "integer"
},
"has_access_controls": {
"type": "boolean"
},
"has_encryption": {
"type": "boolean"
},
"has_network_security": {
"type": "boolean"
},
"has_patch_management": {
"type": "boolean"
},
"implemented_controls": {
"minimum": 0,
"type": "integer"
},
"last_effectiveness_review": {
"format": "date",
"type": "string"
},
"total_controls": {
"minimum": 0,
"type": "integer"
}
},
"required": [
"assessment_date",
"total_controls",
"implemented_controls",
"has_access_controls",
"has_encryption"
],
"type": "object"
}