How test data management helps meet DORA’s resilience testing requirements


 

DORA requires financial institutions to run tests that prove their systems can withstand operational disruption without exposing sensitive data. This article explains how test data management practices can provide the realistic but safe data needed for resilience testing and the governance controls required under DORA’s ICT risk management rules. 

What is DORA?

For compliance, financial organizations must perform regular resilience testing – and sometimes even advanced threat-led penetration testing (TLPT) – of any systems supporting critical or important functions.

At the same time, as part of its Information and Communication Technology (ICT) risk management and governance framework, DORA demands high