CIS Controls v8 → DORA crosswalk
A control-by-control mapping between CIS Critical Security Controls v8 and Digital Operational Resilience Act (EU 2022/2554). 4 mappings.
| CIS Controls v8 | DORA | Relationship | Notes |
|---|---|---|---|
| 11.1 Establish and maintain a data recovery process | Art. 12 Backup policies and recovery procedures | EquivalentCurated | Backup & recovery |
| 3.11 Encrypt sensitive data at rest | Art. 9 Protection and prevention | PartialCurated | Cryptography & data protection |
| 6.1 Establish an access granting process | Art. 9 Protection and prevention | PartialCurated | Access control & identity |
| 8.1 Establish and maintain an audit log management process | Art. 10 Detection | PartialCurated | Logging, monitoring & detection |
Mappings marked “Official” derive from standards-body informative references; “Curated” mappings are authored by Cyber Compliance and provided for guidance only.