EIOPA · DORA 242 - 3347

ICT third-party risk management (DORA)

Regulation
(EU) 2022/2554 - Digital Operational Resilience Act (DORA)
Article
Article 13 Network security management
Topic
ICT third-party risk management (DORA)
Submitted
2025-05-20
Answered
2025-11-20

Question

"For clarification, does the requirement for a 'separate and dedicated network for the administration of ICT assets' refer to a physically separate network, a logically segmented one ? Could you please clarify what is meant by 'administration of ICT assets' in the context , does this refer only to manual administrative activities, or does it also include automated processes

Answer

Article 13 of Commission Delegated Regulation (EU) 2024/1774 provides the requirement for financial entities to develop, document and implement policies procedures protocols and tools on network security management, including (c) the use of a separate and dedicated network for the administration of ICT assets. The decision on whether to use a physically or logically separated network is to be taken by financial entities taking into account the provisions of Article 4(1), Article 6(8), Article 7, Article 9(4) point (c) of Regulation (EU) 2022/2554 and Article 1 of Commission Delegated Regulation (EU) 2024/1774. Furthermore, in the context of said Article 13, “administration of ICT assets” should be interpreted with a broad spectrum including both manual and automated activities and processes. Furthermore, for completeness on a similar subject, please refer to: https://www.eba.europa.eu/single-rule-book-qa/qna/view/publicId/2024_7178.

This Q&A is published by European Insurance and Occupational Pensions Authority and is non-binding. It does not constitute legal advice. Updated weekly from official ESA sources.

Similar Q&As

More Q&As on this topic

📋 Track EU financial regulation continuously

Forseti monitors EU financial regulation and delivers personalised alerts anchored to verified official sources.

14-day free trial. No credit card required.