For the financial entities concerned, the European DORA regulation significantly strengthens the requirements related to the management of ICT risks and incidents.
DORA specifically requires that financial entities have processes in place to detect, manage and notify ICT-related incidents and that they record significant ICT incidents and cyber threats.
The technical documents associated with DORA also specify requirements regarding logging, including:
- events to log
- storage periods
- log protection
- access controls
- anomaly detection
- time synchronization
- event monitoring.
In this context, a SIEM can be a particularly important component of the monitoring architecture of a financial organization.
But again:
A SIEM does not automatically mean DORA compliance.
Compliance depends on the entire governance, risk management, control and security framework.