DORA Art. 10
Detection Capability Workspace
Detection is not just SIEM. Detection is the ability to identify deviations, vulnerabilities, cyber attacks and operational issues early and effectively translate them into response, recovery and reporting capability.
7
Detection Modules
22
Cross-References
21
Evidence Examples
Detection Coverage
Coverage percentage per domain — save your assessment and track progress.
Detection Use Case Browser
Browse all detection use cases, filter by category and expand details.
SIEM Technique:
Linked Module:
Evidence Example:
No use cases found.
Showing: of Use Cases
Detection Capability Map
DET-01Übersicht über alle Erkennungsfähigkeiten pro kritischer Funktion, Asset-Klasse und Dienstleister.
Unerkannte Angriffe, verspätete Incident-Erkennung, Prüffeststellungen
Monitoring Coverage Matrix
DET-02Dokumentation, welche Systeme, Logquellen und Signale überwacht werden – und welche nicht.
Blinde Flecken in kritischen Bereichen, unvollständige Forensik
Alert Threshold Register
DET-03Zentrales Register aller Alarmschwellen, Trigger-Kriterien und Eskalationsstufen.
Fehlalarme oder verpasste kritische Alarme, keine konsistente Eskalation
Incident Trigger Catalogue
DET-04Katalog aller Ereignisse, die automatisch einen Incident-Response-Prozess auslösen.
Verzögerte oder fehlende Reaktion auf sicherheitskritische Ereignisse
Detection Use Case Library
DET-05Zentrale Bibliothek aller definierten Detection-Use-Cases mit Priorität, Status und Testing-Ergebnis.
Unstrukturierte Detection-Entwicklung, Lücken in der Angriffserkennung
Vulnerability Detection Register
DET-06Register für Schwachstellen-Scans, Identifikation wesentlicher Schwachstellen und Eskalation.
Kritische Schwachstellen bleiben unerkannt, Ausnutzung durch Angreifer
Detection Testing Plan
DET-07Plan für regelmäßige Tests der Detection-Mechanismen gemäß Artikel 25.
Detection-Mechanismen altern, Wirksamkeit nicht nachgewiesen, Prüffeststellungen
Alert Threshold Configurator
Define risk-oriented thresholds for your alert levels and configure recommended response times.
Current Risk Level:
Blind-Spot Assessment
Assess your detection capabilities per module. Identify gaps and prioritize measures.
Score
Gaps
SIEM Use Case Matrix
Track the implementation status of all detection use cases and identify gaps.
| Use Case | Category | Severity | Status | Action |
|---|---|---|---|---|
No entries found.
Implemented
Planned
Missing
Management Questions
- → Are critical or important functions fully covered by monitoring?
- → Are there blind spots in cloud, SaaS, service providers or legacy systems?
- → Are vulnerabilities and anomalies detected quickly enough?
- → Are thresholds defined in a risk-oriented manner?
- → Is the detection capability tested regularly?
- → Can we demonstrate to auditors and regulators that detection works?