Skip to main content
Logo
European Insurance and Occupational Pensions Authority
 

DORA 242 - 3347

Q&A

Question ID: DORA 242 - 3347

Regulation Reference: (EU) 2022/2554 - Digital Operational Resilience Act (DORA)

Topic: ICT third-party risk management (DORA)

Article: Article 13 Network security management(the use of a separate and dedicated network for the administration of ICT assets;)

Status: Final

Date of submission: 20 May 2025

Question

"For clarification, does the requirement for a 'separate and dedicated network for the administration of ICT assets' refer to a physically separate network, a logically segmented one ? Could you please clarify what is meant by 'administration of ICT assets' in the context , does this refer only to manual administrative activities, or does it also include automated processes

EIOPA answer

Article 13 of Commission Delegated Regulation (EU) 2024/1774 provides the requirement for financial entities to develop, document and implement policies procedures protocols and tools on network security management, including (c) the use of a separate and dedicated network for the administration of ICT assets. The decision on whether to use a physically or logically separated network is to be taken by financial entities taking into account the provisions of Article 4(1), Article 6(8), Article 7, Article 9(4) point (c) of Regulation (EU) 2022/2554 and Article 1 of Commission Delegated Regulation (EU) 2024/1774. Furthermore, in the context of said Article 13, “administration of ICT assets” should be interpreted with a broad spectrum including both manual and automated activities and processes. Furthermore, for completeness on a similar subject, please refer to: https://www.eba.europa.eu/single-rule-book-qa/qna/view/publicId/2024_7178.