Skip to content

DORAISO 27001 crosswalk

A control-by-control mapping between Digital Operational Resilience Act (EU 2022/2554) and ISO/IEC 27001:2022. 11 mappings.

DORAISO 27001RelationshipNotes
Art. 10
Detection
A.8.16
Monitoring activities
PartialCurated
Logging, monitoring & detection
Art. 10
Detection
A.8.15
Logging
PartialCurated
Logging, monitoring & detection
Art. 12
Backup policies and recovery procedures
A.8.13
Information backup
EquivalentCurated
Backup & recovery
Art. 17
ICT-related incident management process
A.5.24
Information security incident management planning and preparation
PartialCurated
Incident response & breach notification
Art. 17
ICT-related incident management process
A.5.26
Response to information security incidents
PartialCurated
Incident response & breach notification
Art. 19
Reporting of major ICT-related incidents
A.5.24
Information security incident management planning and preparation
PartialCurated
Incident response & breach notification
Art. 19
Reporting of major ICT-related incidents
A.5.26
Response to information security incidents
PartialCurated
Incident response & breach notification
Art. 6
ICT risk management framework
A.5.1
Policies for information security
RelatedCurated
Governance & security policy
Art. 9
Protection and prevention
A.5.15
Access control
PartialCurated
Access control & identity
Art. 9
Protection and prevention
A.5.16
Identity management
PartialCurated
Access control & identity
Art. 9
Protection and prevention
A.8.24
Use of cryptography
PartialCurated
Cryptography & data protection

Mappings marked “Official” derive from standards-body informative references; “Curated” mappings are authored by Cyber Compliance and provided for guidance only.