Bibba TechBibba Tech
Powered byBibba TechBibba Tech© 2026 -DISCLAIMER
0 / 66 complete0%
Summary
← Back to home

Pillars

1. General Testing Programme0/42. Threat-Led Penetration Testing0/3

Complete Partial Untouched

General Testing Programme

Pillar 3
Arts. 24–27

Pillar 3 - Digital Operational Resilience Testing

General Testing Programme

0/7

DORA.TS-1

1. Annual digital operational resilience testing programme

Documentation

Implementation

DORA.TS-2

2. Vulnerability assessments and network security testing

Documentation

Implementation

DORA.TS-3

3. Gap analysis, remediation tracking and re-testing

Documentation

Implementation

DORA.TS-4

4. Testing of critical ICT applications and infrastructure

Documentation

Implementation

Maturity Scale

Score every question twice

Target: ≥ 3/5 for all categories

Documentation

Implementation

1
Initial

No process documentation or not formally approved by management.

Standard process does not exist. Actions are ad hoc and undocumented.

2
Repeatable

Formally approved process documentation exists but has not been reviewed in the previous 2 years.

Ad-hoc process exists and is performed informally. Results are inconsistent.

3
Defined

Formally approved process documentation exists; exceptions are documented and approved and make up less than 5% of activities.

Formal process exists and is implemented. Evidence available for most activities. Less than 10% process exceptions.

4
Managed

Formally approved process documentation exists; exceptions are documented and approved. Documented & approved less than 3% of activities.

Formal process fully implemented. Evidence available for all activities. Detailed metrics captured and reported. Less than 5% process exceptions.

5
Optimising

Formally approved process documentation exists; exceptions are documented and approved. Documented & approved less than 0.5% of activities.

Formal process fully implemented and continually improving. Minimal exceptions (<1%). Process improvements tracked and evidenced.