Analyze/catalog/frameworks/dora.json
|
{
"key": "DORA", "order": 11, "name": "Digital Operational Resilience Act and its regulatory technical standards on the ICT risk management framework", "shortName": "DORA", "version": "(EU) 2022/2554 and 2024/1774", "publisher": "European Union", "type": "regulation", "url": "https://eur-lex.europa.eu/eli/reg/2022/2554/oj/eng", "download": "https://eur-lex.europa.eu/eli/reg_del/2024/1774/oj/eng", "retrieved": "2026-09-24", "mapping": "jsolve", "note": "Mapping by JSolve B.V.: which tests evidence a control is JSolve's assessment, not the publisher's. A control with tests is fully assessed only when they check everything about it that Azure configuration can show. Controls that do not concern the Azure environment (people, physical security, organization-wide governance, end-user devices, software development) are not applicable; the other controls without a test need evidence outside configuration. Only the articles of the regulation (Art.) and of its ICT risk management standard (RTS Art.) with a technical Azure side are in the catalog; governance, incident classification and reporting, resilience testing (including TLPT), contracts, the register of information and exit plans are processes. A test that maps to an article contributes to it; it does not mean the article is met.", "controls": { "Art. 7": {"title":"ICT systems, protocols and tools","coverage":"partial","tests":["AZ-BCK-012","AZ-GOV-012","AZ-NET-010"]}, "Art. 8": {"title":"Identification","coverage":"partial","tests":["AZ-APIM-007","AZ-APP-012","AZ-DEF-024","AZ-GOV-006","AZ-GOV-007","AZ-GOV-008","AZ-LOGIC-007","AZ-LOGIC-008","AZ-LOGIC-010","AZ-VM-009","AZ-VM-013"]}, "Art. 9": {"title":"Protection and prevention","coverage":"partial","tests":["AZ-ACI-001","AZ-ACR-002","AZ-ACR-003","AZ-ADX-001","AZ-ADX-002","AZ-ADX-003","AZ-AI-002","AZ-AI-003","AZ-AI-005","AZ-AI-006","AZ-AI-007","AZ-AKS-003","AZ-AKS-007","AZ-AKS-009","AZ-APIM-002","AZ-APIM-006","AZ-APP-001","AZ-APP-002","AZ-APP-003","AZ-APP-008","AZ-APP-009","AZ-APP-014","AZ-AUTO-001","AZ-AVD-001","AZ-BCK-001","AZ-BCK-002","AZ-BCK-003","AZ-BCK-005","AZ-BOT-001","AZ-BOT-003","AZ-CAPP-001","AZ-CAPP-002","AZ-COS-002","AZ-DB-001","AZ-DB-002","AZ-DBX-001","AZ-DBX-002","AZ-DBX-003","AZ-DBX-004","AZ-DBX-006","AZ-DEF-001","AZ-FUNC-004","AZ-GOV-001","AZ-GOV-002","AZ-GOV-004","AZ-GOV-009","AZ-IAM-024","AZ-IAM-026","AZ-IAM-027","AZ-KV-003","AZ-KV-004","AZ-LOGIC-001","AZ-MY-001","AZ-NET-001","AZ-NET-002","AZ-NET-003","AZ-NET-004","AZ-NET-005","AZ-NET-006","AZ-NET-007","AZ-NET-008","AZ-NET-009","AZ-NET-012","AZ-NET-013","AZ-NET-015","AZ-NET-016","AZ-NET-017","AZ-NET-018","AZ-PAAS-001","AZ-PAAS-003","AZ-PG-001","AZ-RED-001","AZ-SQL-005","AZ-SQL-006","AZ-SQL-007","AZ-STG-001","AZ-STG-002","AZ-STG-003","AZ-STG-004","AZ-STG-006","AZ-STG-007","AZ-STG-008","AZ-STG-009","AZ-STG-018","AZ-STG-019","AZ-STG-020","AZ-STG-025","AZ-STG-026","AZ-SYN-001","AZ-VM-001","AZ-VM-002","AZ-VM-011","AZ-VM-012"]}, "Art. 10": {"title":"Detection","coverage":"partial","tests":["AZ-DBX-005","AZ-DEF-002","AZ-DEF-003","AZ-DEF-004","AZ-DEF-005","AZ-DEF-006","AZ-DEF-007","AZ-DEF-008","AZ-DEF-009","AZ-DEF-010","AZ-DEF-011","AZ-DEF-012","AZ-DEF-013","AZ-DEF-016","AZ-DEF-023","AZ-LOG-001","AZ-LOG-002","AZ-LOG-003","AZ-LOG-004","AZ-LOG-005","AZ-LOG-006","AZ-LOG-007","AZ-LOG-008","AZ-LOG-009","AZ-LOG-010","AZ-LOG-011","AZ-LOG-012","AZ-LOG-013","AZ-LOG-014","AZ-LOG-015","AZ-LOG-017","AZ-LOG-018","AZ-LOG-020","AZ-LOG-021","AZ-LOG-023","AZ-MY-002","AZ-NET-020","AZ-PG-002","AZ-PG-003","AZ-SQL-001","AZ-VM-008"]}, "Art. 11": {"title":"Response and recovery","coverage":"partial","tests":["AZ-BCK-010","AZ-BCK-011"]}, "Art. 12": {"title":"Backup policies and procedures, restoration and recovery procedures and methods","coverage":"partial","tests":["AZ-BCK-001","AZ-BCK-002","AZ-BCK-003","AZ-BCK-004","AZ-BCK-005","AZ-BCK-006","AZ-BCK-007","AZ-BCK-008","AZ-BCK-009","AZ-BCK-010","AZ-BCK-011","AZ-BCK-012","AZ-GOV-004","AZ-STG-014","AZ-STG-015","AZ-STG-016","AZ-STG-017","AZ-STG-022","AZ-VM-010"]}, "Art. 17": {"title":"ICT-related incident management process","coverage":"partial","tests":["AZ-DEF-018","AZ-DEF-019","AZ-DEF-020","AZ-DEF-021","AZ-DEF-022"]}, "Art. 28": {"title":"General principles","coverage":"partial","tests":["AZ-IAM-021","AZ-IAM-025"]}, "RTS Art. 4": {"title":"ICT asset management policy","coverage":"partial","tests":["AZ-DEF-024","AZ-GOV-006","AZ-GOV-007","AZ-LOGIC-007","AZ-LOGIC-008","AZ-LOGIC-010","AZ-NET-022","AZ-VM-013"]}, "RTS Art. 5": {"title":"ICT asset management procedure","coverage":"partial","tests":["AZ-GOV-011","AZ-VM-013"]}, "RTS Art. 6": {"title":"Encryption and cryptographic controls","coverage":"partial","tests":["AZ-ADX-002","AZ-ADX-003","AZ-AKS-009","AZ-APIM-006","AZ-APP-002","AZ-AUTO-001","AZ-MY-001","AZ-NET-013","AZ-PAAS-003","AZ-PG-001","AZ-SQL-006","AZ-SQL-007","AZ-SQL-008","AZ-STG-002","AZ-STG-018","AZ-STG-019","AZ-STG-020","AZ-STG-021","AZ-VM-001","AZ-VM-002"]}, "RTS Art. 7": {"title":"Cryptographic key management","coverage":"partial","tests":["AZ-AKS-009","AZ-KV-001","AZ-KV-005","AZ-KV-007","AZ-KV-008","AZ-KV-010","AZ-SQL-008","AZ-STG-021"]}, "RTS Art. 9": {"title":"Capacity and performance management","coverage":"partial","tests":["AZ-GOV-012"]}, "RTS Art. 10": {"title":"Vulnerability and patch management","coverage":"partial","tests":["AZ-AKS-006","AZ-APIM-007","AZ-APP-012","AZ-DEF-001","AZ-DEF-003","AZ-DEF-008","AZ-DEF-009","AZ-DEF-015","AZ-DEF-017","AZ-DFA-002","AZ-DFA-003","AZ-GOV-008","AZ-GOV-010","AZ-SQL-009","AZ-VM-005","AZ-VM-009"]}, "RTS Art. 11": {"title":"Data and system security","coverage":"partial","tests":["AZ-AKS-004","AZ-APIM-001","AZ-APP-005","AZ-APP-007","AZ-BCK-005","AZ-DEF-014","AZ-DEF-025","AZ-DFA-001","AZ-DFA-004","AZ-NET-014","AZ-SQL-010","AZ-STG-010","AZ-VM-003","AZ-VM-006","AZ-VM-007"]}, "RTS Art. 12": {"title":"Logging","coverage":"partial","tests":["AZ-DBX-005","AZ-LOG-001","AZ-LOG-002","AZ-LOG-014","AZ-LOG-015","AZ-LOG-016","AZ-LOG-017","AZ-LOG-018","AZ-LOG-019","AZ-LOG-020","AZ-LOG-021","AZ-LOG-022","AZ-LOG-023","AZ-LOG-024","AZ-LOG-025","AZ-LOG-026","AZ-MY-002","AZ-NET-024","AZ-NET-025","AZ-PG-002","AZ-PG-003","AZ-SQL-001","AZ-SQL-002","AZ-VM-008"]}, "RTS Art. 13": {"title":"Network security management","coverage":"partial","tests":["AZ-ACI-001","AZ-ACR-003","AZ-ADX-001","AZ-AI-002","AZ-AI-003","AZ-AI-005","AZ-AI-006","AZ-AI-007","AZ-AKS-003","AZ-AKS-007","AZ-APP-008","AZ-AVD-001","AZ-BOT-001","AZ-CAPP-002","AZ-COS-002","AZ-DB-001","AZ-DB-002","AZ-DBX-001","AZ-DBX-002","AZ-DBX-003","AZ-DBX-004","AZ-DBX-006","AZ-KV-003","AZ-KV-004","AZ-NET-001","AZ-NET-002","AZ-NET-003","AZ-NET-004","AZ-NET-005","AZ-NET-006","AZ-NET-007","AZ-NET-008","AZ-NET-009","AZ-NET-010","AZ-NET-011","AZ-NET-012","AZ-NET-015","AZ-NET-016","AZ-NET-017","AZ-NET-018","AZ-NET-019","AZ-NET-020","AZ-NET-022","AZ-NET-023","AZ-PAAS-001","AZ-SQL-005","AZ-STG-006","AZ-STG-007","AZ-STG-008","AZ-STG-009","AZ-SYN-001","AZ-VM-011","AZ-VM-012"]}, "RTS Art. 14": {"title":"Securing information in transit","coverage":"partial","tests":["AZ-APIM-002","AZ-APIM-005","AZ-APIM-006","AZ-APP-001","AZ-APP-002","AZ-APP-003","AZ-BOT-003","AZ-CAPP-001","AZ-MY-001","AZ-NET-013","AZ-PAAS-003","AZ-PG-001","AZ-RED-001","AZ-SQL-006","AZ-STG-001","AZ-STG-002","AZ-STG-018","AZ-STG-019"]}, "RTS Art. 16": {"title":"ICT systems acquisition, development, and maintenance","applicability":"manual"}, "RTS Art. 17": {"title":"ICT change management","coverage":"partial","tests":["AZ-ADF-002"]}, "RTS Art. 20": {"title":"Identity management","coverage":"partial","tests":["AZ-ACR-001","AZ-ACR-004","AZ-ACR-005","AZ-AI-001","AZ-AI-007","AZ-AKS-001","AZ-AKS-002","AZ-AKS-008","AZ-APP-004","AZ-APP-006","AZ-AUTO-002","AZ-BOT-002","AZ-COS-001","AZ-FUNC-002","AZ-IAM-006","AZ-IAM-007","AZ-IAM-020","AZ-IAM-022","AZ-LOGIC-003","AZ-LOGIC-005","AZ-LOGIC-006","AZ-MSG-001","AZ-MY-003","AZ-PAAS-002","AZ-PG-004","AZ-RED-002","AZ-SQL-003","AZ-SQL-004","AZ-STG-005","AZ-STG-011","AZ-STG-023"]}, "RTS Art. 21": {"title":"Access control","coverage":"partial","tests":["AZ-ACR-001","AZ-ACR-002","AZ-ACR-004","AZ-ACR-005","AZ-ADF-001","AZ-AI-001","AZ-AI-007","AZ-AKS-001","AZ-AKS-002","AZ-AKS-005","AZ-APIM-003","AZ-APIM-004","AZ-APP-004","AZ-APP-009","AZ-APP-014","AZ-AUTO-001","AZ-BOT-002","AZ-COS-001","AZ-COS-003","AZ-FUNC-004","AZ-GOV-005","AZ-IAM-001","AZ-IAM-002","AZ-IAM-003","AZ-IAM-004","AZ-IAM-005","AZ-IAM-008","AZ-IAM-009","AZ-IAM-010","AZ-IAM-011","AZ-IAM-012","AZ-IAM-013","AZ-IAM-014","AZ-IAM-015","AZ-IAM-016","AZ-IAM-017","AZ-IAM-018","AZ-IAM-019","AZ-IAM-023","AZ-IAM-024","AZ-IAM-026","AZ-IAM-027","AZ-IAM-029","AZ-IAM-030","AZ-KV-002","AZ-KV-006","AZ-KV-009","AZ-KV-011","AZ-LOGIC-001","AZ-LOGIC-004","AZ-MSG-001","AZ-MY-003","AZ-NET-001","AZ-NET-002","AZ-NET-011","AZ-NET-021","AZ-NET-023","AZ-PAAS-002","AZ-PG-004","AZ-RED-002","AZ-SEC-001","AZ-SEC-002","AZ-SEC-003","AZ-SEC-004","AZ-SQL-003","AZ-SQL-004","AZ-STG-003","AZ-STG-004","AZ-STG-005","AZ-STG-011","AZ-STG-012","AZ-STG-013","AZ-STG-023","AZ-STG-024","AZ-VM-004"]}, "RTS Art. 22": {"title":"ICT-related incident management policy","applicability":"manual"}, "RTS Art. 23": {"title":"Anomalous activities detection and criteria for ICT-related incidents detection and response","coverage":"partial","tests":["AZ-DEF-002","AZ-DEF-003","AZ-DEF-004","AZ-DEF-005","AZ-DEF-006","AZ-DEF-007","AZ-DEF-008","AZ-DEF-009","AZ-DEF-010","AZ-DEF-011","AZ-DEF-012","AZ-DEF-013","AZ-DEF-018","AZ-DEF-019","AZ-DEF-020","AZ-DEF-021","AZ-DEF-023","AZ-LOG-003","AZ-LOG-004","AZ-LOG-005","AZ-LOG-006","AZ-LOG-007","AZ-LOG-008","AZ-LOG-009","AZ-LOG-010","AZ-LOG-011","AZ-LOG-012","AZ-NET-019","AZ-NET-020"]}, "RTS Art. 25": {"title":"Testing of the ICT business continuity plans","coverage":"partial","tests":["AZ-BCK-010"]}, "RTS Art. 26": {"title":"ICT response and recovery plans","coverage":"partial","tests":["AZ-BCK-010","AZ-BCK-011"]} } } |