Why ESA created RTSs?
Regulation (EU) 2022/2554 of the European Parliament and of the Council of 14 December 2022 on digital operational resilience for the financial sector (DORA) under its Article 15 requires to develop of draft regulatory technical standards ('RTSs') aiming at 'further harmonisation of ICT risk management tools, methods, processes and policies' and under its Article 16, to develop simplified ICT risk management framework for certain financial entities.
Draft RTSs developed under Article 15 and Article 16(3) of DORA need to be understood as an essential part of the regulations.
The good news:
ESA considers that the RTSs should remain “technology-neutral” and not identify specific products or technologies.
ESA also did not reinvent the wheel, and we all should be really grateful that RTSs broadly follow the industry's best practices and established security frameworks (ISO-IEC 27000 family standards and NIST) and align with other existing regulations (NIS2 and EIOPA Guidelines on ICT security and governance etc.).
When will RTSs be released?
The final report and the submission of the RTSs to the European Commission are expected by 17 January 2024.
The Risk Management technical standards are under a broad umbrella for the following security-related controls, split into standard and simplified requirements.
Let's break down the proposed RTS (Title I) and highlight the challenges of Article 15 in this review.