/pillar-guidance
Deep dive guidance on DORA's 5 pillars and implementation requirements
$ npx -y skills add GRCEngClub/claude-grc-engineering --agent claude-codeHow it fires
How this command gets triggered: by you, by Claude, or both.
- Fires itselfClaude auto-loads it when your prompt matches the work.
- You can call itInvoke it directly when you want it.
- Slash command
/pillar-guidance
Context preview
What this command does when you run it.
Deep dive guidance on DORA's 5 pillars and implementation requirements
Command definition
pillar-guidance.mddescription: Deep dive guidance on DORA's 5 pillars and implementation requirements
DORA Pillar Guidance
Provides detailed implementation guidance for each of DORA's 5 pillars.
Arguments
- `$1` - Pillar (required: ict-risk, incident-management, resilience-testing, third-party-risk, information-sharing, all)
- `$2` - Detail level (optional: overview, implementation, evidence)
Pillar 1: ICT Risk Management (Articles 5-16)
Overview
Establishes comprehensive framework for managing ICT risks across financial entities.
**Legal Basis**: Articles 5-16 of DORA **Applicability**: All financial entities **Key Principle**: Proportionality to size, risk profile, and complexity
Core Requirements
1. ICT Risk Management Framework (Article 6)
**Must Include**:
- Strategies, policies, procedures, and protocols
- ICT risk management function with sufficient resources
- Documentation of ICT risk management framework
- Board approval and regular review
**Implementation**:
- Establish ICT risk management policy
- Define roles and responsibilities
- Create risk assessment methodology
- Implement controls and mitigation measures
- Monitor and report on ICT risks
2. Governance and Organization (Article 5)
**Board Responsibilities**:
- Define, approve, and oversee ICT risk management framework
- Allocate budget and resources
- Approve ICT strategy
- Approve policies for ICT service provision by third parties
- Receive regular reporting on ICT risk
**Management Body**:
- At least one member with sufficient knowledge and skills in ICT
- Regular training on ICT risks
- Oversight of senior management
3. Identification (Article 8)
**Requirements**:
- Identify all ICT-supported business functions
- Map dependencies and interdependencies
- Identify all ICT assets and configurations
- Document data flows
- Assess criticality of ICT assets
**Deliverables**:
- ICT asset inventory
- Business impact analysis (BIA)
- Data flow diagrams
- Network diagrams
- Dependency mapping
4. Protection and Prevention (Article 9)
**Requirements**:
- Implement security policies and procedures
- Regular ICT security awareness training
- Physical and environmental security
- Access control mechanisms
- Encryption of sensitive data
- Segregation of duties
- Network security controls
**Key Controls**:
- Multi-factor authentication
- Privileged access management
- Data loss prevention
- Endpoint protection
- Network segmentation
- Vulnerability management
- Patch management
5. Detection (Article 10)
**Requirements**:
- Continuous monitoring mechanisms
- Detection tools and systems
- Logging and log analysis
- Anomaly detection
- Intrusion detection/prevention systems (IDS/IPS)
- Security information and event management (SIEM)
**Capabilities**:
- Real-time alerting
- 24/7 monitoring (for significant entities)
- Threat intelligence integration
- Automated detection rules
6. Response and Recovery (Article 11)
**Business Continuity**:
- Business continuity policy
- Business continuity plans (BCPs)
- Disaster recovery plans (DRPs)
- Regular testing of BCPs/DRPs
- Communication plans during crises
**Incident Response**:
- Incident response plans
- Predefined incident response procedures
- Crisis management team
- Communication protocols
- Recovery time objectives (RTO)
- Recovery point objectives (RPO)
7. Learning and Evolving (Article 12)
**Requirements**:
- Post-incident reviews
- Lessons learned documentation
- Continuous improvement process
- Metrics and KPIs for ICT risk
- Regular framework updates
8. Communication (Article 13)
**Requirements**:
- Internal communication channels
- External communication (clients, authorities)
- Crisis communication plans
- Public relations protocols
- Media handling procedures
9. Backup Policies and Procedures (Article 12)
**Requirements**:
- Backup strategies and policies
- Regular backups of critical data and systems
- Backup testing and restoration
- Off-site backup storage
- Immutable backups (ransomware protection)
---
Pillar 2: Incident Management & Reporting (Articles 17-23)
Overview
Comprehensive framework for detecting, managing, classifying, and reporting ICT-related incidents.
**Legal Basis**: Articles 17-23 **Key Innovation**: Mandatory reporting of major incidents to authorities **Timeline**: Strict reporting deadlines
Core Requirements
1. Incident Management Process (Article 17)
**Requirements**:
- Detection mechanisms
- Incident management procedures
- Incident classification criteria
- Escalation procedures
- Root cause analysis
- Remediation and recovery
**Process Steps**:
1. Detection and logging 2. Initial assessment and classification 3. Containment 4. Investigation and analysis 5. Remediation and recovery 6. Post-incident review 7. Reporting (if major incident)
2. Classification of Incidents (Article 18)
**Major Incident Criteria**:
- Significant impact on financial services provided
- Large number of clients/counterparties affected
- Geographical spread across multiple member states
- Duration exceeding thresholds
- Reputational impact
- Data loss affecting critical services
- Critical services unavailable
**Classification Factors**:
- Number of clients affected
- Duration of incident
- Geographical spread
- Economic impact
- Data loss severity
- Service criticality
- Reputational damage
3. Reporting to Authorities (Article 19)
**Major Incident Reporting Timeline**:
| Timeline | Report Type | Content | |----------|-------------|---------| | **4 hours** | Initial notification | Incident awareness, preliminary assessment | | **72 hours** | Intermediate report | Classification, impact assessment, mitigation actions | | **1 month** | Final report | Root cause, remediation, lessons learned |
**Additional Reports**:
- Significant updates when incident evolves
- Material changes to impact assessment
- Updates on remediation progress
**R
Read more
description: Deep dive guidance on DORA's 5 pillars and implementation requirements
DORA Pillar Guidance
Provides detailed implementation guidance for each of DORA's 5 pillars.
Arguments
- `$1` - Pillar (required: ict-risk, incident-management, resilience-testing, third-party-risk, information-sharing, all)
- `$2` - Detail level (optional: overview, implementation, evidence)
Pillar 1: ICT Risk Management (Articles 5-16)
Overview
Establishes comprehensive framework for managing ICT risks across financial entities.
**Legal Basis**: Articles 5-16 of DORA **Applicability**: All financial entities **Key Principle**: Proportionality to size, risk profile, and complexity
Core Requirements
1. ICT Risk Management Framework (Article 6)
**Must Include**:
- Strategies, policies, procedures, and protocols
- ICT risk management function with sufficient resources
- Documentation of ICT risk management framework
- Board approval and regular review
**Implementation**:
- Establish ICT risk management policy
- Define roles and responsibilities
- Create risk assessment methodology
- Implement controls and mitigation measures
- Monitor and report on ICT risks
2. Governance and Organization (Article 5)
**Board Responsibilities**:
- Define, approve, and oversee ICT risk management framework
- Allocate budget and resources
- Approve ICT strategy
- Approve policies for ICT service provision by third parties
- Receive regular reporting on ICT risk
**Management Body**:
- At least one member with sufficient knowledge and skills in ICT
- Regular training on ICT risks
- Oversight of senior management
3. Identification (Article 8)
**Requirements**:
- Identify all ICT-supported business functions
- Map dependencies and interdependencies
- Identify all ICT assets and configurations
- Document data flows
- Assess criticality of ICT assets
**Deliverables**:
- ICT asset inventory
- Business impact analysis (BIA)
- Data flow diagrams
- Network diagrams
- Dependency mapping
4. Protection and Prevention (Article 9)
**Requirements**:
- Implement security policies and procedures
- Regular ICT security awareness training
- Physical and environmental security
- Access control mechanisms
- Encryption of sensitive data
- Segregation of duties
- Network security controls
**Key Controls**:
- Multi-factor authentication
- Privileged access management
- Data loss prevention
- Endpoint protection
- Network segmentation
- Vulnerability management
- Patch management
5. Detection (Article 10)
**Requirements**:
- Continuous monitoring mechanisms
- Detection tools and systems
- Logging and log analysis
- Anomaly detection
- Intrusion detection/prevention systems (IDS/IPS)
- Security information and event management (SIEM)
**Capabilities**:
- Real-time alerting
- 24/7 monitoring (for significant entities)
- Threat intelligence integration
- Automated detection rules
6. Response and Recovery (Article 11)
**Business Continuity**:
- Business continuity policy
- Business continuity plans (BCPs)
- Disaster recovery plans (DRPs)
- Regular testing of BCPs/DRPs
- Communication plans during crises
**Incident Response**:
- Incident response plans
- Predefined incident response procedures
- Crisis management team
- Communication protocols
- Recovery time objectives (RTO)
- Recovery point objectives (RPO)
7. Learning and Evolving (Article 12)
**Requirements**:
- Post-incident reviews
- Lessons learned documentation
- Continuous improvement process
- Metrics and KPIs for ICT risk
- Regular framework updates
8. Communication (Article 13)
**Requirements**:
- Internal communication channels
- External communication (clients, authorities)
- Crisis communication plans
- Public relations protocols
- Media handling procedures
9. Backup Policies and Procedures (Article 12)
**Requirements**:
- Backup strategies and policies
- Regular backups of critical data and systems
- Backup testing and restoration
- Off-site backup storage
- Immutable backups (ransomware protection)
---
Pillar 2: Incident Management & Reporting (Articles 17-23)
Overview
Comprehensive framework for detecting, managing, classifying, and reporting ICT-related incidents.
**Legal Basis**: Articles 17-23 **Key Innovation**: Mandatory reporting of major incidents to authorities **Timeline**: Strict reporting deadlines
Core Requirements
1. Incident Management Process (Article 17)
**Requirements**:
- Detection mechanisms
- Incident management procedures
- Incident classification criteria
- Escalation procedures
- Root cause analysis
- Remediation and recovery
**Process Steps**:
1. Detection and logging 2. Initial assessment and classification 3. Containment 4. Investigation and analysis 5. Remediation and recovery 6. Post-incident review 7. Reporting (if major incident)
2. Classification of Incidents (Article 18)
**Major Incident Criteria**:
- Significant impact on financial services provided
- Large number of clients/counterparties affected
- Geographical spread across multiple member states
- Duration exceeding thresholds
- Reputational impact
- Data loss affecting critical services
- Critical services unavailable
**Classification Factors**:
- Number of clients affected
- Duration of incident
- Geographical spread
- Economic impact
- Data loss severity
- Service criticality
- Reputational damage
3. Reporting to Authorities (Article 19)
**Major Incident Reporting Timeline**:
| Timeline | Report Type | Content | |----------|-------------|---------| | **4 hours** | Initial notification | Incident awareness, preliminary assessment | | **72 hours** | Intermediate report | Classification, impact assessment, mitigation actions | | **1 month** | Final report | Root cause, remediation, lessons learned |
**Additional Reports**:
- Significant updates when incident evolves
- Material changes to impact assessment
- Updates on remediation progress
**R
Open-source GRC Engineering resource for Claude. claude-grc-engineering turns technical evidence from cloud, SaaS, code, and security tools into framework-aligned findings, gap reports, remediation guidance, evidence packages, and OSCAL workflows.
Repo: GRCEngClub/claude-grc-engineering
Other commands on trust-center.
- /research
Start or resume an academic research project — idea through literature, methodology, writing, feedback, and publishing
Open command - /collect
Query AWS for compliance-relevant configuration across IAM, S3, CloudTrail, EBS, and emit findings conforming to the v1 contract.
Open command - /setup
Install the frdocx-to-froscal-ssp Python pipeline and verify its dependencies. Idempotent.
Open command - /status
Check the deployment status of the trust center.
Open command - /scan
Run testssl.sh against one or more HTTPS endpoints and emit v1 Findings mapped to SOC 2, NIST 800-53, PCI DSS 4.0.1, ISO 27001, and SCF controls.
Open command - /compliance-posture
Serve a localhost compliance posture dashboard from monitor-continuous JSON
Open command

