EBA · 2025_7369 Rejected question

Exist a definition of information security standards

Regulation
Regulation (EU) No 2022/2554 (DORA Reg)
Article
28, para. 5
Topic
ICT third-party risk management
Submitted by
Credit institution
Submitted
2025-03-06

Question

In DORA Article 28 (5), reference is made to "appropriate information security standards" and "of the most up-to-date and highest quality information security standards". Is There a definition of which standards are applicable here, or can credit institutions define the desired requirements themselves?"

Background

So far, the term "standard" has been equated with ISO27xx. Before DORA for ICT service providers, selected security requirements have previously been defined by the Sparkasse. For small service providers in particular, certification according to ISO27001 would be an exclusion criterion.
No answer published yet.

Original source: European Banking Authority, Q&A ID 2025_7369

This Q&A is published by European Banking Authority and is non-binding. It does not constitute legal advice. Updated weekly from official ESA sources.

Similar Q&As

More Q&As on this topic

📋 Track EU financial regulation continuously

Forseti monitors EU financial regulation and delivers personalised alerts anchored to verified official sources.

14-day free trial. No credit card required.