The Digital Operational Resilience Act for Financial Services: A Comparative Gap Analysis and Literature Review


연구 분야: Strategies



학회: European, Mediterranean, and Middle Eastern Conference on Information Systems


초록

Regulatory bodies, driven by enhanced speed of digital transformations, seek to strengthen the resilience of information and communication technologies (ICT) to ensure their operational integrity. As a result, The Digital Operational Resilience Act (DORA) was recently proposed to unify and enhance ICT risk management of financial institutions by recommending stricter rules. ICT risk management has to date been mainly governed by ISO 27001:2013 standard in the context of information security governance. Based on qualitative content analysis, we firstly mapped ISO 27001:2013 to DORA and identified nine gaps in ISO 27001:2013 in relation to six general DORA requirements. While we find sufficient support in academic literature for six of the nine extensions suggested by DORA, three areas seem less supported: Threat-led penetration testing, major incident management, and ICT third-party risk management. We argue that these topics should serve academic interest to further our understanding of digital operational resilience in theory and practice.


Author Profile
Anita Neumannová

Institute for Information Management and Control Vienna University of Economics and Business (WU Vienna) Welthandelsplatz 1/D2/C 1020 Vienna Austria

Andorra
Author Profile
Edward W. N. Bernroider

Institute for Information Management and Control Vienna University of Economics and Business (WU Vienna) Welthandelsplatz 1/D2/C 1020 Vienna Austria

Andorra
Author Profile
Christoph Elshuber

NTT DATA Deutschland GmbH Hans-Döllgast-Straße 26 80807 Munich Germany

Germany

📄 논문 정보

발행 연도 2023년
인용수 0
출판 국가 Germany, Andorra
사이트 Springer
좋아요 수 0

연관 논문 목록 (53건)