Font size
WorksheetsDORA Quiz (English)
Total questions: 29
Worksheet time: 15mins
What is the meaning of the acronym DORA in the context of the financial sector?
Digital Operational Resilience Act
Data Optimization and Risk Assessment
Digital Oversight Regulation Act
DORA the Explorer, Expert in Cyber-Risk
On what date did the DORA regulation come into effect or will it come into effect?
January 1, 2024
January 17, 2025
July 1, 2025
January 17, 2026
What is the main objective of the DORA regulation?
Harmonize tax rules in the EU
Strengthen the digital operational resilience of financial entities
Regulate digital transactions between member states
Ensure that no one panics when a server goes down
Is DORA a regulation or a directive?
A directive
A regulation
Both
What types of entities are covered by DORA?
Only banks
All financial entities, including their third-party ICT suppliers
Only technology companies
According to DORA, what should financial entities do to manage ICT risks?
Conduct annual assessments of ICT risks
Outsource all ICT risks to third parties
Ignore minor ICT risks
Install a free antivirus and hope for the best
What is the minimum frequency required to test digital operational resilience?
Every month
Once a year
Every three years
Every time a trainee clicks 'Delete all'.
What does the principle of proportionality mean in the context of DORA?
Apply the same rules to all companies, regardless of their size
Adapt the requirements based on the size, nature, and risk profile of the entities
Require a small business to have the same cybersecurity budget as a central bank.
What elements must be included in the TIC inventory (information register) according to DORA?
The critical functions supported by suppliers
The non-critical functions supported by suppliers
All TIC suppliers
What should financial entities do in the event of a major ICT-related incident?
Immediately inform the competent authorities
Wait until the incident is resolved before informing anyone
Not report the incident if it does not directly affect their clients
Light a candle and hope no one notices.
Which suppliers are specifically targeted by DORA?
All ICT suppliers, regardless of their role
Critical third-party suppliers for the essential functions of financial entities
What should contracts with third-party ICT include according to DORA?
Clauses on risk management and business continuity
A detailed description of the services provided
Only the cost of the service provided
No specific contract/addendum is required
What happens if a critical third-party provider does not comply with DORA?
The concerned financial entity may be sanctioned by the competent authorities.
The third-party provider is automatically excluded from the European market.
It receives a very polite but very threatening letter from the EU.
What is one of the key testing requirements according to DORA?
Test only after a major incident
Conduct regular digital operational resilience testing
Test until there is almost nothing that works
What types of incidents must be reported to the competent authorities according to DORA?
All incidents, even minor ones
Major incidents related to ICT and significant cyber threats
Should incident reports follow a standardized format under DORA?
Yes, in accordance with the technical standards established by European authorities.
No, each entity can define its own format.
Who is responsible for the implementation of DORA within a financial company?
The IT department / ITSO
The general management and the board of directors
Michel, a nice guy
Which authorities supervise compliance with DORA at the European level?
EBA, ESMA and EIOPA
The European Commission
The CAA
How does DORA promote the sharing of information on cyber threats?
By requiring all entities to share their customer data with their peers.
By encouraging a secure exchange of information between financial entities.
What does DORA foresee to improve cooperation between competent authorities in the EU?
The creation of a harmonized framework for supervision and enforcement of the regulation.
The complete delegation of supervision to the Member States.
DORA applies only to banks and large financial institutions.
True
False
DORA requires that all financial entities have a documented digital continuity plan.
True
False
DORA allows companies to completely outsource their responsibilities regarding ICT risks to their third-party suppliers.
True
False
The principle of proportionality means that the requirements of DORA may vary depending on the size and risk profile of the financial entity.
True
False
The sanctions for non-compliance with DORA may include fines for the concerned financial entity.
True
False
DORA imposes an explicit obligation for continuous training on ICT risk management for the relevant personnel.
True
False
DORA aims to improve digital operational resilience only within the national borders of the Member States.
True
False
Companies should test their digital resilience only after a major incident.
True
False
The DORA regulation replaces all other European regulations related to cybersecurity in the financial sector.
True
False
