Resources · Blog
Tag: CMDB
5 published posts.
Posts tagged “CMDB”
- GuideDORANIS2ISO 27001· 4 min read
Provider → service → function: the three links most third-party obligations read back to
DORA Art. 28, NIS2 Art. 21(2)(d) and ISO 27001 supplier controls all assume you know which provider delivers which service to which function. Model it once.
Read → - GuideDORANIS2ISO 27001· 5 min read
Applicability has five scopes — and "tenant-wide" is usually the wrong first answer
A requirement rarely applies to a whole organisation. Deciding applicability per asset, IT service, business solution or process makes "not applicable" hold up.
Read → - GuideDORA· 5 min read
The DORA testing programme is a scoping problem before it is a testing problem
DORA Article 24 asks for a yearly, risk-based testing programme. The hard part is not the test: it is deriving scope from the inventory and closing every gap.
Read → - GuideNIS2· 6 min read
NIS2 Article 21: ten measure areas, one inventory — where to start when the deadline has already passed
NIS2 Article 21 lists ten measure areas but never says which system they protect. Start from the inventory and the management-body decision, not a policy pack.
Read → - GuideDORA· 2 min read
The DORA register of information: what the ESAs actually ask for, and where the data has to come from
The DORA register is a prescribed template, not a product feature. Which linked records — providers, services, functions — must exist to fill it with no sheet.
Read →
See it on your own frameworks
A walkthrough on a workspace set up for your sector. No trial sign-up, no credit card.