Rättskällor med officiella primärkällor

Utskrivet ·

Hopp til innhold
Hopp til svaret

Agent · dora-2022-2554-17

DORA artikel 17: ICT-related incident management process

Strukturelt tre: artikkelens egne punkter, ordrett.

CELEX 32022R2554 · 2026-08-18 · Vekt 86 · minimal-risk

ExtendedOperational weight but lower priority. Metered by volume, not per call, once metering is switched on.

DORAOffisiell kilde

Hva siden er
Agent, DORA artikel 17
Lest mot offisiell kilde
2026-08-18Fersk
Ansvarlig utgiver
ExploreWorld Legal, redaksjonenAnsvarsposisjon

Jurisdiksjon

Samme agent, lest med ett lands øyne.

Inndata

  • in_scopeThe article applies to the situationboolean
  • punktParagraph of the articleenum (1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10 | 11 | 12 | 13 | 14)

Regeltre

  1. Hvis: alla(in_scope = true, punkt = 1)

    Paragraph 1 applies

    1. Financial entities shall define, establish and implement an ICT-related incident management process to detect, manage and notify ICT-related incidents.

    Punkt 1

  2. Hvis: alla(in_scope = true, punkt = 2)

    Paragraph 2 applies

    2. Financial entities shall record all ICT-related incidents and significant cyber threats. Financial entities shall establish appropriate procedures and processes to ensure a consistent and integrated monitoring, handling and follow-up of ICT-related incidents, to ensure that root causes are identified, documented and addressed in order to prevent the occurrence of such incidents.

    Punkt 2

  3. Hvis: alla(in_scope = true, punkt = 3)

    Paragraph 3 applies

    3. The ICT-related incident management process referred to in paragraph 1 shall:

    Punkt 3

  4. Hvis: alla(in_scope = true, punkt = 4)

    Paragraph 4 applies

    (a)

    Punkt 4

  5. Hvis: alla(in_scope = true, punkt = 5)

    Paragraph 5 applies

    put in place early warning indicators;

    Punkt 5

  6. Hvis: alla(in_scope = true, punkt = 6)

    Paragraph 6 applies

    (b)

    Punkt 6

  7. Hvis: alla(in_scope = true, punkt = 7)

    Paragraph 7 applies

    establish procedures to identify, track, log, categorise and classify ICT-related incidents according to their priority and severity and according to the criticality of the services impacted, in accordance with the criteria set out in Article 18(1);

    Punkt 7

  8. Hvis: alla(in_scope = true, punkt = 8)

    Paragraph 8 applies

    (c)

    Punkt 8

  9. Hvis: alla(in_scope = true, punkt = 9)

    Paragraph 9 applies

    assign roles and responsibilities that need to be activated for different ICT-related incident types and scenarios;

    Punkt 9

  10. Hvis: alla(in_scope = true, punkt = 10)

    Paragraph 10 applies

    (d)

    Punkt 10

  11. Hvis: alla(in_scope = true, punkt = 11)

    Paragraph 11 applies

    set out plans for communication to staff, external stakeholders and media in accordance with Article 14 and for notification to clients, for internal escalation procedures, including ICT-related customer complaints, as well as for the provision of information to financial entities that act as counterparts, as appropriate;

    Punkt 11

  12. Hvis: alla(in_scope = true, punkt = 12)

    Paragraph 12 applies

    (e)

    Punkt 12

  13. Hvis: alla(in_scope = true, punkt = 13)

    Paragraph 13 applies

    ensure that at least major ICT-related incidents are reported to relevant senior management and inform the management body of at least major ICT-related incidents, explaining the impact, response and additional controls to be established as a result of such ICT-related incidents;

    Punkt 13

  14. Hvis: alla(in_scope = true, punkt = 14)

    Paragraph 14 applies

    (f)

    Punkt 14

Hvis ingen regel treffer: The article is not stated to apply, or no paragraph is selected. The agent abstains rather than guesses.

Artikkelteksten som ble lest

  1. 11. Financial entities shall define, establish and implement an ICT-related incident management process to detect, manage and notify ICT-related incidents.
  2. 22. Financial entities shall record all ICT-related incidents and significant cyber threats. Financial entities shall establish appropriate procedures and processes to ensure a consistent and integrated monitoring, handling and follow-up of ICT-related incidents, to ensure that root causes are identified, documented and addressed in order to prevent the occurrence of such incidents.
  3. 33. The ICT-related incident management process referred to in paragraph 1 shall:
  4. 4(a)
  5. 5put in place early warning indicators;
  6. 6(b)
  7. 7establish procedures to identify, track, log, categorise and classify ICT-related incidents according to their priority and severity and according to the criticality of the services impacted, in accordance with the criteria set out in Article 18(1);
  8. 8(c)
  9. 9assign roles and responsibilities that need to be activated for different ICT-related incident types and scenarios;
  10. 10(d)
  11. 11set out plans for communication to staff, external stakeholders and media in accordance with Article 14 and for notification to clients, for internal escalation procedures, including ICT-related customer complaints, as well as for the provision of information to financial entities that act as counterparts, as appropriate;
  12. 12(e)
  13. 13ensure that at least major ICT-related incidents are reported to relevant senior management and inform the management body of at least major ICT-related incidents, explaining the impact, response and additional controls to be established as a result of such ICT-related incidents;
  14. 14(f)

Opphav

treatyTFEU art. 288 (förordning)
act32022R2554
chapter
article17
paragraphs14
jurisdictionEuropean Union (EU)
supervisorFinansinspektionen — Sweden
national

Grensesnitt

callhttps://legal.exploreworldai.com/api/public/v1/agents/dora-2022-2554-17/run
methodGET
outputmatched, outcome, trace, missing, hash
Kvote60 anrop per minut och adress, utan nyckel
stabilityRegelträdet versioneras. En ändring byter artefakthash, aldrig adress.

Hasher

textsha256:d832b20e9fbb2e6c7d01244697eba776d01b7335738bda593699237161c419c1
scriptsha256:861642ce38df5abe2c888d07ac27e63c0544f7291a5a494441d75a6155aafeea
enginesha256:0a4bd50d21f8ec9be383fc091511008b76ad61909cbfb674eab56fe567fbd7a0
agentsha256:ba9583265fa48bfb49fbc585e14c803b2f52ec9b8a37649ff4e48f134404c02e
versionagent-engine-1+legal-2026-08-25 / ba9583265fa48bfb

Artefakter

Ingen rådgivning. Deterministisk regeluppslagning. Ingen juridisk rådgivning, inget efterlevnadsbeslut, ingen bedömning av ett enskilt ärende.

Sitering: 32022R2554 art. 17, ICT-related incident management process. ExploreWorld Legal, https://legal.exploreworldai.com/agent/dora-2022-2554/artikel-17 (hämtad 2026-08-18, bevis sha256:6e50efc85c4fa464, bygge legal-2026-08-25).