Skip to content
Security
Command

/pillar-guidance

Deep dive guidance on DORA's 5 pillars and implementation requirements

From plugin
trust-center
367139 skills139 commands1 MCP
Install
$ npx -y skills add GRCEngClub/claude-grc-engineering --agent claude-code

How it fires

How this command gets triggered: by you, by Claude, or both.

  • Fires itselfClaude auto-loads it when your prompt matches the work.
  • You can call itInvoke it directly when you want it.
  • Slash command/pillar-guidance

Context preview

What this command does when you run it.

Deep dive guidance on DORA's 5 pillars and implementation requirements

Command definition

pillar-guidance.md
description: Deep dive guidance on DORA's 5 pillars and implementation requirements

DORA Pillar Guidance

Provides detailed implementation guidance for each of DORA's 5 pillars.

Arguments

  • `$1` - Pillar (required: ict-risk, incident-management, resilience-testing, third-party-risk, information-sharing, all)
  • `$2` - Detail level (optional: overview, implementation, evidence)

Pillar 1: ICT Risk Management (Articles 5-16)

Overview

Establishes comprehensive framework for managing ICT risks across financial entities.

**Legal Basis**: Articles 5-16 of DORA **Applicability**: All financial entities **Key Principle**: Proportionality to size, risk profile, and complexity

Core Requirements

1. ICT Risk Management Framework (Article 6)

**Must Include**:

  • Strategies, policies, procedures, and protocols
  • ICT risk management function with sufficient resources
  • Documentation of ICT risk management framework
  • Board approval and regular review

**Implementation**:

  • Establish ICT risk management policy
  • Define roles and responsibilities
  • Create risk assessment methodology
  • Implement controls and mitigation measures
  • Monitor and report on ICT risks

2. Governance and Organization (Article 5)

**Board Responsibilities**:

  • Define, approve, and oversee ICT risk management framework
  • Allocate budget and resources
  • Approve ICT strategy
  • Approve policies for ICT service provision by third parties
  • Receive regular reporting on ICT risk

**Management Body**:

  • At least one member with sufficient knowledge and skills in ICT
  • Regular training on ICT risks
  • Oversight of senior management

3. Identification (Article 8)

**Requirements**:

  • Identify all ICT-supported business functions
  • Map dependencies and interdependencies
  • Identify all ICT assets and configurations
  • Document data flows
  • Assess criticality of ICT assets

**Deliverables**:

  • ICT asset inventory
  • Business impact analysis (BIA)
  • Data flow diagrams
  • Network diagrams
  • Dependency mapping

4. Protection and Prevention (Article 9)

**Requirements**:

  • Implement security policies and procedures
  • Regular ICT security awareness training
  • Physical and environmental security
  • Access control mechanisms
  • Encryption of sensitive data
  • Segregation of duties
  • Network security controls

**Key Controls**:

  • Multi-factor authentication
  • Privileged access management
  • Data loss prevention
  • Endpoint protection
  • Network segmentation
  • Vulnerability management
  • Patch management

5. Detection (Article 10)

**Requirements**:

  • Continuous monitoring mechanisms
  • Detection tools and systems
  • Logging and log analysis
  • Anomaly detection
  • Intrusion detection/prevention systems (IDS/IPS)
  • Security information and event management (SIEM)

**Capabilities**:

  • Real-time alerting
  • 24/7 monitoring (for significant entities)
  • Threat intelligence integration
  • Automated detection rules

6. Response and Recovery (Article 11)

**Business Continuity**:

  • Business continuity policy
  • Business continuity plans (BCPs)
  • Disaster recovery plans (DRPs)
  • Regular testing of BCPs/DRPs
  • Communication plans during crises

**Incident Response**:

  • Incident response plans
  • Predefined incident response procedures
  • Crisis management team
  • Communication protocols
  • Recovery time objectives (RTO)
  • Recovery point objectives (RPO)

7. Learning and Evolving (Article 12)

**Requirements**:

  • Post-incident reviews
  • Lessons learned documentation
  • Continuous improvement process
  • Metrics and KPIs for ICT risk
  • Regular framework updates

8. Communication (Article 13)

**Requirements**:

  • Internal communication channels
  • External communication (clients, authorities)
  • Crisis communication plans
  • Public relations protocols
  • Media handling procedures

9. Backup Policies and Procedures (Article 12)

**Requirements**:

  • Backup strategies and policies
  • Regular backups of critical data and systems
  • Backup testing and restoration
  • Off-site backup storage
  • Immutable backups (ransomware protection)

---

Pillar 2: Incident Management & Reporting (Articles 17-23)

Overview

Comprehensive framework for detecting, managing, classifying, and reporting ICT-related incidents.

**Legal Basis**: Articles 17-23 **Key Innovation**: Mandatory reporting of major incidents to authorities **Timeline**: Strict reporting deadlines

Core Requirements

1. Incident Management Process (Article 17)

**Requirements**:

  • Detection mechanisms
  • Incident management procedures
  • Incident classification criteria
  • Escalation procedures
  • Root cause analysis
  • Remediation and recovery

**Process Steps**:

1. Detection and logging 2. Initial assessment and classification 3. Containment 4. Investigation and analysis 5. Remediation and recovery 6. Post-incident review 7. Reporting (if major incident)

2. Classification of Incidents (Article 18)

**Major Incident Criteria**:

  • Significant impact on financial services provided
  • Large number of clients/counterparties affected
  • Geographical spread across multiple member states
  • Duration exceeding thresholds
  • Reputational impact
  • Data loss affecting critical services
  • Critical services unavailable

**Classification Factors**:

  • Number of clients affected
  • Duration of incident
  • Geographical spread
  • Economic impact
  • Data loss severity
  • Service criticality
  • Reputational damage

3. Reporting to Authorities (Article 19)

**Major Incident Reporting Timeline**:

| Timeline | Report Type | Content | |----------|-------------|---------| | **4 hours** | Initial notification | Incident awareness, preliminary assessment | | **72 hours** | Intermediate report | Classification, impact assessment, mitigation actions | | **1 month** | Final report | Root cause, remediation, lessons learned |

**Additional Reports**:

  • Significant updates when incident evolves
  • Material changes to impact assessment
  • Updates on remediation progress

**R

Read more
Ships withtrust-center

Open-source GRC Engineering resource for Claude. claude-grc-engineering turns technical evidence from cloud, SaaS, code, and security tools into framework-aligned findings, gap reports, remediation guidance, evidence packages, and OSCAL workflows.

Get the whole plugin, auto-invoked
Stats
367
Stars
0
Views
82
Forks
Active
Maintenance
JavaScript
Language
1d ago
Last commit
7mo ago
Created

Repo: GRCEngClub/claude-grc-engineering