Skip to content

/dora-expert

DORA expert for EU financial entities. Deep knowledge of Digital Operational Resilience Act including 5 pillars, ICT risk management, incident reporting, resilience testing, third-party oversight, and information sharing for financial sector digital resilience.

shell
$ npx -y skills add GRCEngClub/claude-grc-engineering --skill dora-expert --agent claude-code

How it fires

How this skill gets triggered: by you, by Claude, or both.

  • Fires itselfAuto-invocation. Claude auto-loads it when your prompt matches the work.
  • You can call itInvoke it directly when you want it.
  • Slash command/dora-expert
How auto-invocation works

Context preview

The summary Claude sees to decide when to auto-load this skill.

DORA expert for EU financial entities. Deep knowledge of Digital Operational Resilience Act including 5 pillars, ICT risk management, incident reporting, resilience testing, third-party oversight, and information sharing for financial sector digital resilience.

SKILL.md

dora-expert.SKILL.md
name: dora-expert
description: DORA expert for EU financial entities. Deep knowledge of Digital Operational Resilience Act including 5 pillars, ICT risk management, incident reporting, resilience testing, third-party oversight, and information sharing for financial sector digital resilience.
allowed-tools: Read, Glob, Grep, Write

DORA Expert

Deep expertise in Digital Operational Resilience Act (DORA) for EU financial entities and ICT third-party service providers.

Expertise Areas

DORA Regulation Overview

**Regulation**: EU Regulation 2022/2554 on Digital Operational Resilience for the Financial Sector **Publication**: December 14, 2022 **Effective Date**: January 17, 2025 **Objective**: Harmonize ICT risk management across EU financial sector **Enforcement**: National competent authorities (NCAs) and European Supervisory Authorities (ESAs)

**Key Innovation**: First comprehensive EU-wide framework specifically addressing digital operational resilience in financial services

Scope and Applicability

**Financial Entities Subject to DORA**:

  • Credit institutions (banks)
  • Payment institutions and e-money institutions
  • Investment firms
  • Crypto-asset service providers (CASPs) under MiCA
  • Central securities depositories (CSDs)
  • Central counterparties (CCPs)
  • Trading venues (MTFs, OTFs)
  • Trade repositories
  • Managers of UCITS and AIFs
  • Insurance and reinsurance undertakings
  • Insurance intermediaries, reinsurance intermediaries, ancillary insurance intermediaries
  • Institutions for occupational retirement provision (IORPs)
  • Credit rating agencies
  • Administrators of critical benchmarks
  • Crowdfunding service providers
  • Securitization repositories

**ICT Third-Party Service Providers**:

  • Cloud service providers
  • Software providers
  • Data analytics providers
  • Data centers
  • Any provider of ICT services supporting critical or important functions

**Geographic Scope**:

  • All EU member states
  • Applies to entities operating in EU
  • Extraterritorial effect for third-party providers serving EU financial entities

Why DORA Matters

**Industry Drivers**:

  • Increasing cyber threats targeting financial sector
  • Growing dependence on ICT and third-party providers
  • Cloud concentration risk
  • Operational disruptions with systemic impact
  • Fragmented national approaches pre-DORA

**Regulatory Response**:

  • Harmonized requirements across EU
  • Enhanced oversight of critical third-party providers
  • Mandatory incident reporting
  • Regular resilience testing
  • Board-level accountability

**Business Impact**:

  • Significant compliance investment required
  • Contract renegotiations with ICT providers
  • Enhanced governance and risk management
  • Potential competitive advantage for compliant entities
  • Regulatory penalties for non-compliance

DORA's 5 Pillars

Pillar 1: ICT Risk Management (Articles 5-16)

**Objective**: Establish comprehensive, board-approved ICT risk management framework

Governance Requirements (Article 5)

**Management Body Responsibilities**:

  • Define, approve, and oversee digital operational resilience strategy
  • Approve and oversee ICT risk management framework
  • Allocate appropriate budget and resources
  • Ensure at least one member with sufficient ICT knowledge
  • Maintain clear roles and responsibilities
  • Establish reporting lines for ICT risks
  • Receive regular reporting on ICT risk profile

**Documentation**:

  • ICT strategy document
  • ICT risk management policy
  • Board minutes approving framework
  • Skills and training matrix for board members

ICT Risk Management Framework (Article 6)

**Framework Components**:

1. **Strategies, Policies, Procedures**:

  • ICT risk management strategy
  • ICT security policies
  • ICT operations procedures
  • Risk assessment methodology
  • Risk treatment procedures

2. **ICT Risk Management Function**:

  • Dedicated function with sufficient resources
  • Reporting to management body
  • Independence from IT operations (where feasible)
  • Clearly defined responsibilities

3. **Documentation and Reporting**:

  • Written framework document
  • Risk registers
  • Risk assessments
  • Risk treatment plans
  • Management reporting

**Proportionality Principle**:

  • Framework complexity proportionate to entity size
  • Smaller entities may adopt simplified approaches
  • Risk-based tailoring of requirements
  • Supervisory expectations vary by significance

Identification (Article 8)

**Asset Management**:

  • Inventory of all ICT assets
  • Hardware, software, network components
  • Cloud services and SaaS applications
  • ICT-supported business functions
  • Data assets and flows

**Business Impact Analysis (BIA)**:

  • Identify critical and important functions
  • Map ICT dependencies
  • Assess impact of disruptions
  • Determine recovery time objectives (RTO)
  • Determine recovery point objectives (RPO)

**Dependency Mapping**:

  • Internal system interdependencies
  • Third-party dependencies
  • Data flows (internal and external)
  • Critical supply chains

**Deliverables**:

  • ICT asset register
  • Business impact analysis report
  • Dependency maps
  • Data flow diagrams
  • Network architecture diagrams

Protection and Prevention (Article 9)

**Security Policies**:

  • Information security policy
  • Access control policy
  • Cryptography policy
  • Secure development policy
  • Physical security policy

**Technical Controls**:

  • **Identity and Access Management**:
  • Multi-factor authentication (MFA)
  • Privileged access management (PAM)
  • Least privilege principle
  • Regular access reviews
  • Strong password policies
  • **Encryption**:
  • Data at rest encryption
  • Data in transit encryption (TLS 1.2+)
  • Key management procedures
  • Cryptographic standards compliance
  • **Network Security**:
  • Network segmentation
  • Firewalls and DMZs
  • Intrusion prevention systems (IPS)
  • DDoS protection
  • Secure remote access (VPN, zero trust)
  • **Endpoint Protection**:
  • Anti-malware solutions

-

Read more
Read it on GitHub ↗

Showing the first part of this file.

Ships withtrust-center

Open-source GRC Engineering resource for Claude. claude-grc-engineering turns technical evidence from cloud, SaaS, code, and security tools into framework-aligned findings, gap reports, remediation guidance, evidence packages, and OSCAL workflows.

Get the whole plugin, auto-invoked