Source: OJ L, 2025/1190, 18.6.2025Current language: EN
- Digital operational resilience in the financial sector
Digital operational resilience testing
- RTS on threat-led penetration testing
Annex II Content of the scope specification document (Article 9(6))
The scope specification document shall contain a list of all critical or important functions identified by the financial entity.
For each identified critical or important function, the following information shall be included:
where the critical or important function is not included in the scope of the TLPT, the explanation of the reasons for which it is not included;
where the critical or important function is included in the scope of the TLPT:
the explanation of the reasons for its inclusion;
the identified ICT system(s) supporting that critical or important function;
for each identified ICT system:
whether it is outsourced and if so, the name of the ICT third party service provider;
the jurisdictions in which the ICT system is used;
a high-level description of preliminary flag(s), indicating which security aspect of confidentiality, integrity, authenticity or availability is covered by each flag.
Springlex and this text is meant purely as a documentation tool and has no legal effect. No liability is assumed for its content. The authentic version of this act is the one published in the Official Journal of the European Union.