Zum Inhalt springen

DORA Art. 10

Detection Capability Workspace

Detection is not just SIEM. Detection is the ability to identify deviations, vulnerabilities, cyber attacks and operational issues early and effectively translate them into response, recovery and reporting capability.

Note: These contents are generic implementation aids and do not constitute legal advice.

7

Detection Modules

22

Cross-References

21

Evidence Examples

Detection Coverage

Coverage percentage per domain — save your assessment and track progress.

Overall Coverage:

Detection Use Case Browser

Browse all detection use cases, filter by category and expand details.

Showing: of Use Cases

Detection Capability Map

DET-01

Übersicht über alle Erkennungsfähigkeiten pro kritischer Funktion, Asset-Klasse und Dienstleister.

Target Roles:
CISO SOC Lead IKT-Risikomanagement
Risk If Missing:

Unerkannte Angriffe, verspätete Incident-Erkennung, Prüffeststellungen

Monitoring Coverage Matrix

DET-02

Dokumentation, welche Systeme, Logquellen und Signale überwacht werden – und welche nicht.

Target Roles:
SOC Lead IT Operations CISO
Risk If Missing:

Blinde Flecken in kritischen Bereichen, unvollständige Forensik

Alert Threshold Register

DET-03

Zentrales Register aller Alarmschwellen, Trigger-Kriterien und Eskalationsstufen.

Target Roles:
SOC Lead Incident Manager CISO
Risk If Missing:

Fehlalarme oder verpasste kritische Alarme, keine konsistente Eskalation

Incident Trigger Catalogue

DET-04

Katalog aller Ereignisse, die automatisch einen Incident-Response-Prozess auslösen.

Target Roles:
Incident Manager SOC Lead IKT-Risikomanagement
Risk If Missing:

Verzögerte oder fehlende Reaktion auf sicherheitskritische Ereignisse

Detection Use Case Library

DET-05

Zentrale Bibliothek aller definierten Detection-Use-Cases mit Priorität, Status und Testing-Ergebnis.

Target Roles:
SOC Lead CISO Detection Engineer
Risk If Missing:

Unstrukturierte Detection-Entwicklung, Lücken in der Angriffserkennung

Vulnerability Detection Register

DET-06

Register für Schwachstellen-Scans, Identifikation wesentlicher Schwachstellen und Eskalation.

Target Roles:
IT Operations CISO IKT-Risikomanagement
Risk If Missing:

Kritische Schwachstellen bleiben unerkannt, Ausnutzung durch Angreifer

Detection Testing Plan

DET-07

Plan für regelmäßige Tests der Detection-Mechanismen gemäß Artikel 25.

Target Roles:
SOC Lead Detection Engineer Test-Manager
Risk If Missing:

Detection-Mechanismen altern, Wirksamkeit nicht nachgewiesen, Prüffeststellungen

Alert Threshold Configurator

Define risk-oriented thresholds for your alert levels and configure recommended response times.

Current Risk Level:

Blind-Spot Assessment

Assess your detection capabilities per module. Identify gaps and prioritize measures.

Score

Gaps

SIEM Use Case Matrix

Track the implementation status of all detection use cases and identify gaps.

Showing: /
Use Case Category Severity Status Action

Implemented

Planned

Missing

Management Questions

  • Are critical or important functions fully covered by monitoring?
  • Are there blind spots in cloud, SaaS, service providers or legacy systems?
  • Are vulnerabilities and anomalies detected quickly enough?
  • Are thresholds defined in a risk-oriented manner?
  • Is the detection capability tested regularly?
  • Can we demonstrate to auditors and regulators that detection works?