Translations:Digital Operational Resilienec Act (DORA)/28/en
Aus RI Wiki
Significant financial entities are required to conduct threat-led penetration tests (TLPT). These tests — also conducted in the production environment — target the company’s core IT systems. This enables obligated entities to identify weaknesses, deficiencies, and gaps in digital operational resilience and take corrective actions immediately. The tests must be conducted by independent parties to ensure objective evaluation. They are to be performed at least annually on ICT systems or applications that support critical or important functions. The aim is to ensure continuous resilience in these key areas.