/dora-expert
DORA expert for EU financial entities. Deep knowledge of Digital Operational Resilience Act including 5 pillars, ICT risk management, incident reporting, resilience testing, third-party oversight, and information sharing for financial sector digital resilience.
$ npx -y skills add GRCEngClub/claude-grc-engineering --skill dora-expert --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
- Fires itselfAuto-invocation. Claude auto-loads it when your prompt matches the work.
- You can call itInvoke it directly when you want it.
- Slash command
/dora-expert
Context preview
The summary Claude sees to decide when to auto-load this skill.
DORA expert for EU financial entities. Deep knowledge of Digital Operational Resilience Act including 5 pillars, ICT risk management, incident reporting, resilience testing, third-party oversight, and information sharing for financial sector digital resilience.
SKILL.md
dora-expert.SKILL.mdname: dora-expert
description: DORA expert for EU financial entities. Deep knowledge of Digital Operational Resilience Act including 5 pillars, ICT risk management, incident reporting, resilience testing, third-party oversight, and information sharing for financial sector digital resilience.
allowed-tools: Read, Glob, Grep, Write
DORA Expert
Deep expertise in Digital Operational Resilience Act (DORA) for EU financial entities and ICT third-party service providers.
Expertise Areas
DORA Regulation Overview
**Regulation**: EU Regulation 2022/2554 on Digital Operational Resilience for the Financial Sector **Publication**: December 14, 2022 **Effective Date**: January 17, 2025 **Objective**: Harmonize ICT risk management across EU financial sector **Enforcement**: National competent authorities (NCAs) and European Supervisory Authorities (ESAs)
**Key Innovation**: First comprehensive EU-wide framework specifically addressing digital operational resilience in financial services
Scope and Applicability
**Financial Entities Subject to DORA**:
- Credit institutions (banks)
- Payment institutions and e-money institutions
- Investment firms
- Crypto-asset service providers (CASPs) under MiCA
- Central securities depositories (CSDs)
- Central counterparties (CCPs)
- Trading venues (MTFs, OTFs)
- Trade repositories
- Managers of UCITS and AIFs
- Insurance and reinsurance undertakings
- Insurance intermediaries, reinsurance intermediaries, ancillary insurance intermediaries
- Institutions for occupational retirement provision (IORPs)
- Credit rating agencies
- Administrators of critical benchmarks
- Crowdfunding service providers
- Securitization repositories
**ICT Third-Party Service Providers**:
- Cloud service providers
- Software providers
- Data analytics providers
- Data centers
- Any provider of ICT services supporting critical or important functions
**Geographic Scope**:
- All EU member states
- Applies to entities operating in EU
- Extraterritorial effect for third-party providers serving EU financial entities
Why DORA Matters
**Industry Drivers**:
- Increasing cyber threats targeting financial sector
- Growing dependence on ICT and third-party providers
- Cloud concentration risk
- Operational disruptions with systemic impact
- Fragmented national approaches pre-DORA
**Regulatory Response**:
- Harmonized requirements across EU
- Enhanced oversight of critical third-party providers
- Mandatory incident reporting
- Regular resilience testing
- Board-level accountability
**Business Impact**:
- Significant compliance investment required
- Contract renegotiations with ICT providers
- Enhanced governance and risk management
- Potential competitive advantage for compliant entities
- Regulatory penalties for non-compliance
DORA's 5 Pillars
Pillar 1: ICT Risk Management (Articles 5-16)
**Objective**: Establish comprehensive, board-approved ICT risk management framework
Governance Requirements (Article 5)
**Management Body Responsibilities**:
- Define, approve, and oversee digital operational resilience strategy
- Approve and oversee ICT risk management framework
- Allocate appropriate budget and resources
- Ensure at least one member with sufficient ICT knowledge
- Maintain clear roles and responsibilities
- Establish reporting lines for ICT risks
- Receive regular reporting on ICT risk profile
**Documentation**:
- ICT strategy document
- ICT risk management policy
- Board minutes approving framework
- Skills and training matrix for board members
ICT Risk Management Framework (Article 6)
**Framework Components**:
1. **Strategies, Policies, Procedures**:
- ICT risk management strategy
- ICT security policies
- ICT operations procedures
- Risk assessment methodology
- Risk treatment procedures
2. **ICT Risk Management Function**:
- Dedicated function with sufficient resources
- Reporting to management body
- Independence from IT operations (where feasible)
- Clearly defined responsibilities
3. **Documentation and Reporting**:
- Written framework document
- Risk registers
- Risk assessments
- Risk treatment plans
- Management reporting
**Proportionality Principle**:
- Framework complexity proportionate to entity size
- Smaller entities may adopt simplified approaches
- Risk-based tailoring of requirements
- Supervisory expectations vary by significance
Identification (Article 8)
**Asset Management**:
- Inventory of all ICT assets
- Hardware, software, network components
- Cloud services and SaaS applications
- ICT-supported business functions
- Data assets and flows
**Business Impact Analysis (BIA)**:
- Identify critical and important functions
- Map ICT dependencies
- Assess impact of disruptions
- Determine recovery time objectives (RTO)
- Determine recovery point objectives (RPO)
**Dependency Mapping**:
- Internal system interdependencies
- Third-party dependencies
- Data flows (internal and external)
- Critical supply chains
**Deliverables**:
- ICT asset register
- Business impact analysis report
- Dependency maps
- Data flow diagrams
- Network architecture diagrams
Protection and Prevention (Article 9)
**Security Policies**:
- Information security policy
- Access control policy
- Cryptography policy
- Secure development policy
- Physical security policy
**Technical Controls**:
- **Identity and Access Management**:
- Multi-factor authentication (MFA)
- Privileged access management (PAM)
- Least privilege principle
- Regular access reviews
- Strong password policies
- **Encryption**:
- Data at rest encryption
- Data in transit encryption (TLS 1.2+)
- Key management procedures
- Cryptographic standards compliance
- **Network Security**:
- Network segmentation
- Firewalls and DMZs
- Intrusion prevention systems (IPS)
- DDoS protection
- Secure remote access (VPN, zero trust)
- **Endpoint Protection**:
- Anti-malware solutions
-
Read more
name: dora-expert description: DORA expert for EU financial entities. Deep knowledge of Digital Operational Resilience Act including 5 pillars, ICT risk management, incident reporting, resilience testing, third-party oversight, and information sharing for financial sector digital resilience. allowed-tools: Read, Glob, Grep, Write
DORA Expert
Deep expertise in Digital Operational Resilience Act (DORA) for EU financial entities and ICT third-party service providers.
Expertise Areas
DORA Regulation Overview
**Regulation**: EU Regulation 2022/2554 on Digital Operational Resilience for the Financial Sector **Publication**: December 14, 2022 **Effective Date**: January 17, 2025 **Objective**: Harmonize ICT risk management across EU financial sector **Enforcement**: National competent authorities (NCAs) and European Supervisory Authorities (ESAs)
**Key Innovation**: First comprehensive EU-wide framework specifically addressing digital operational resilience in financial services
Scope and Applicability
**Financial Entities Subject to DORA**:
- Credit institutions (banks)
- Payment institutions and e-money institutions
- Investment firms
- Crypto-asset service providers (CASPs) under MiCA
- Central securities depositories (CSDs)
- Central counterparties (CCPs)
- Trading venues (MTFs, OTFs)
- Trade repositories
- Managers of UCITS and AIFs
- Insurance and reinsurance undertakings
- Insurance intermediaries, reinsurance intermediaries, ancillary insurance intermediaries
- Institutions for occupational retirement provision (IORPs)
- Credit rating agencies
- Administrators of critical benchmarks
- Crowdfunding service providers
- Securitization repositories
**ICT Third-Party Service Providers**:
- Cloud service providers
- Software providers
- Data analytics providers
- Data centers
- Any provider of ICT services supporting critical or important functions
**Geographic Scope**:
- All EU member states
- Applies to entities operating in EU
- Extraterritorial effect for third-party providers serving EU financial entities
Why DORA Matters
**Industry Drivers**:
- Increasing cyber threats targeting financial sector
- Growing dependence on ICT and third-party providers
- Cloud concentration risk
- Operational disruptions with systemic impact
- Fragmented national approaches pre-DORA
**Regulatory Response**:
- Harmonized requirements across EU
- Enhanced oversight of critical third-party providers
- Mandatory incident reporting
- Regular resilience testing
- Board-level accountability
**Business Impact**:
- Significant compliance investment required
- Contract renegotiations with ICT providers
- Enhanced governance and risk management
- Potential competitive advantage for compliant entities
- Regulatory penalties for non-compliance
DORA's 5 Pillars
Pillar 1: ICT Risk Management (Articles 5-16)
**Objective**: Establish comprehensive, board-approved ICT risk management framework
Governance Requirements (Article 5)
**Management Body Responsibilities**:
- Define, approve, and oversee digital operational resilience strategy
- Approve and oversee ICT risk management framework
- Allocate appropriate budget and resources
- Ensure at least one member with sufficient ICT knowledge
- Maintain clear roles and responsibilities
- Establish reporting lines for ICT risks
- Receive regular reporting on ICT risk profile
**Documentation**:
- ICT strategy document
- ICT risk management policy
- Board minutes approving framework
- Skills and training matrix for board members
ICT Risk Management Framework (Article 6)
**Framework Components**:
1. **Strategies, Policies, Procedures**:
- ICT risk management strategy
- ICT security policies
- ICT operations procedures
- Risk assessment methodology
- Risk treatment procedures
2. **ICT Risk Management Function**:
- Dedicated function with sufficient resources
- Reporting to management body
- Independence from IT operations (where feasible)
- Clearly defined responsibilities
3. **Documentation and Reporting**:
- Written framework document
- Risk registers
- Risk assessments
- Risk treatment plans
- Management reporting
**Proportionality Principle**:
- Framework complexity proportionate to entity size
- Smaller entities may adopt simplified approaches
- Risk-based tailoring of requirements
- Supervisory expectations vary by significance
Identification (Article 8)
**Asset Management**:
- Inventory of all ICT assets
- Hardware, software, network components
- Cloud services and SaaS applications
- ICT-supported business functions
- Data assets and flows
**Business Impact Analysis (BIA)**:
- Identify critical and important functions
- Map ICT dependencies
- Assess impact of disruptions
- Determine recovery time objectives (RTO)
- Determine recovery point objectives (RPO)
**Dependency Mapping**:
- Internal system interdependencies
- Third-party dependencies
- Data flows (internal and external)
- Critical supply chains
**Deliverables**:
- ICT asset register
- Business impact analysis report
- Dependency maps
- Data flow diagrams
- Network architecture diagrams
Protection and Prevention (Article 9)
**Security Policies**:
- Information security policy
- Access control policy
- Cryptography policy
- Secure development policy
- Physical security policy
**Technical Controls**:
- **Identity and Access Management**:
- Multi-factor authentication (MFA)
- Privileged access management (PAM)
- Least privilege principle
- Regular access reviews
- Strong password policies
- **Encryption**:
- Data at rest encryption
- Data in transit encryption (TLS 1.2+)
- Key management procedures
- Cryptographic standards compliance
- **Network Security**:
- Network segmentation
- Firewalls and DMZs
- Intrusion prevention systems (IPS)
- DDoS protection
- Secure remote access (VPN, zero trust)
- **Endpoint Protection**:
- Anti-malware solutions
-
Showing the first part of this file.
Open-source GRC Engineering resource for Claude. claude-grc-engineering turns technical evidence from cloud, SaaS, code, and security tools into framework-aligned findings, gap reports, remediation guidance, evidence packages, and OSCAL workflows.
Repo: GRCEngClub/claude-grc-engineering
Other skills on trust-center.
- /academic-research-companion
Guide a research project through the full academic lifecycle — from raw idea to concrete research question, literature grounding, methodology, writing, feedback, and publication. Use this skill whenever the user shares a research idea, asks to "flesh out" a topic, wants sources
Open skill - /aws-inspector-expert
Expertise in evaluating AWS accounts for compliance — what checks are meaningful, which SCF controls they map to, and how to interpret aws CLI output.
Open skill - /azure-inspector-expert
Expertise in evaluating Azure subscription findings from azure-inspector and mapping them to SCF controls.
Open skill - /crowdstrike-inspector-expert
Interpret CrowdStrike Falcon findings for sensor coverage, policy visibility, and host group scoping.
Open skill - /datadog-inspector-expert
Interpret datadog-inspector findings and translate Datadog monitoring, audit, log-retention, SSO, and RBAC results into GRC evidence and remediation.
Open skill - /drata-inspector-expert
Interpret drata-inspector findings generated from drata-cli workflows and turn Drata control, monitor, evidence, personnel, and integration posture into GRC action.
Open skill

