{"id":7467,"date":"2026-08-17T14:14:45","date_gmt":"2026-08-17T12:14:45","guid":{"rendered":"https:\/\/arcad.lu\/?p=7467"},"modified":"2026-08-17T14:21:56","modified_gmt":"2026-08-17T12:21:56","slug":"audit-du-cyber-concilier-risques-et-exigences-applicables","status":"publish","type":"post","link":"https:\/\/arcad.lu\/en\/audit-du-cyber-concilier-risques-et-exigences-applicables\/","title":{"rendered":"Cybersecurity audit: balancing risks and applicable requirements"},"content":{"rendered":"<div data-elementor-type=\"wp-post\" data-elementor-id=\"7467\" class=\"elementor elementor-7467\" data-elementor-post-type=\"post\">\n\t\t\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-6db90f4 elementor-section-full_width elementor-section-height-default elementor-section-height-default\" data-id=\"6db90f4\" data-element_type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-ebfbb07\" data-id=\"ebfbb07\" data-element_type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-b898738 elementor-widget elementor-widget-html\" data-id=\"b898738\" data-element_type=\"widget\" data-widget_type=\"html.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<style>\n\/* =========================================================\n   ARCAD \u2014 ARTICLE CYBER\n   Version Elementor\n   Styles volontairement encapsul\u00e9s dans .arcad-cyber\n   ========================================================= *\/\n\n.arcad-cyber {\n    --arcad-navy: #182a49;\n    --arcad-navy-light: #2c4774;\n    --arcad-gold: #d2bc76;\n    --arcad-gold-soft: #f0e8cf;\n    --arcad-cream: #f7f4ed;\n    --arcad-white: #ffffff;\n    --arcad-ink: #24303c;\n    --arcad-muted: #667180;\n    --arcad-line: #e3ded2;\n\n    width: 100%;\n    color: var(--arcad-ink);\n    font-family: inherit;\n    font-size: 17px;\n    line-height: 1.72;\n}\n\n.arcad-cyber,\n.arcad-cyber * {\n    box-sizing: border-box;\n}\n\n.arcad-cyber a {\n    color: var(--arcad-navy-light);\n    text-decoration-thickness: 1px;\n    text-underline-offset: 3px;\n}\n\n.arcad-cyber a:hover {\n    color: var(--arcad-navy);\n}\n\n.arcad-cyber .arcad-shell {\n    width: 100%;\n    max-width: 1160px;\n    margin: 0 auto;\n}\n\n\/* =========================================================\n   HERO\n   ========================================================= *\/\n\n.arcad-cyber .arcad-hero {\n    position: relative;\n    overflow: hidden;\n    padding: clamp(44px, 7vw, 88px);\n    color: var(--arcad-white);\n    background:\n        linear-gradient(\n            125deg,\n            rgba(24, 42, 73, 0.99),\n            rgba(44, 71, 116, 0.95)\n        );\n    border-radius: 4px;\n    box-shadow: 0 24px 60px rgba(24, 42, 73, 0.16);\n}\n\n.arcad-cyber .arcad-hero::before,\n.arcad-cyber .arcad-hero::after {\n    content: \"\";\n    position: absolute;\n    pointer-events: none;\n    transform: rotate(35deg);\n}\n\n.arcad-cyber .arcad-hero::before {\n    width: 260px;\n    height: 260px;\n    right: -115px;\n    top: -120px;\n    border: 1px solid rgba(210, 188, 118, 0.45);\n}\n\n.arcad-cyber .arcad-hero::after {\n    width: 190px;\n    height: 190px;\n    right: 35px;\n    bottom: -130px;\n    background: rgba(210, 188, 118, 0.13);\n}\n\n.arcad-cyber .arcad-hero-content {\n    position: relative;\n    z-index: 1;\n    max-width: 930px;\n}\n\n.arcad-cyber .arcad-eyebrow {\n    margin: 0 0 18px;\n    color: var(--arcad-gold);\n    font-size: 13px;\n    font-weight: 700;\n    line-height: 1.4;\n    letter-spacing: 0.14em;\n    text-transform: uppercase;\n}\n\n.arcad-cyber .arcad-title {\n    margin: 0;\n    max-width: 950px;\n    color: var(--arcad-white);\n    font-size: clamp(36px, 5.5vw, 66px);\n    font-weight: 700;\n    line-height: 1.06;\n    letter-spacing: -0.035em;\n}\n\n.arcad-cyber .arcad-lead {\n    max-width: 850px;\n    margin: 25px 0 0;\n    color: rgba(255, 255, 255, 0.88);\n    font-size: clamp(19px, 2.2vw, 24px);\n    line-height: 1.55;\n}\n\n.arcad-cyber .arcad-meta {\n    display: flex;\n    flex-wrap: wrap;\n    gap: 10px 22px;\n    margin-top: 30px;\n    color: rgba(255, 255, 255, 0.72);\n    font-size: 14px;\n}\n\n\/* =========================================================\n   CONTENU\n   ========================================================= *\/\n\n.arcad-cyber .arcad-content {\n    max-width: 960px;\n    margin: 0 auto;\n    padding: clamp(48px, 7vw, 82px) 24px;\n}\n\n.arcad-cyber .arcad-intro {\n    margin: 0 0 38px;\n    font-size: 20px;\n    line-height: 1.7;\n}\n\n\/* =========================================================\n   REP\u00c8RES\n   ========================================================= *\/\n\n.arcad-cyber .arcad-facts {\n    display: grid;\n    grid-template-columns: repeat(3, minmax(0, 1fr));\n    gap: 18px;\n    margin: 38px 0 62px;\n}\n\n.arcad-cyber .arcad-fact {\n    padding: 25px;\n    background: var(--arcad-cream);\n    border-top: 3px solid var(--arcad-gold);\n}\n\n.arcad-cyber .arcad-fact strong {\n    display: block;\n    margin-bottom: 8px;\n    color: var(--arcad-navy);\n    font-size: 22px;\n    line-height: 1.25;\n}\n\n.arcad-cyber .arcad-fact span {\n    color: var(--arcad-muted);\n    font-size: 15px;\n    line-height: 1.55;\n}\n\n\/* =========================================================\n   SECTIONS\n   ========================================================= *\/\n\n.arcad-cyber .arcad-section {\n    display: grid;\n    grid-template-columns: 58px minmax(0, 1fr);\n    gap: 22px;\n    padding: 44px 0;\n    border-top: 1px solid var(--arcad-line);\n}\n\n.arcad-cyber .arcad-number {\n    color: var(--arcad-gold);\n    font-size: 15px;\n    font-weight: 700;\n    letter-spacing: 0.08em;\n}\n\n.arcad-cyber h2 {\n    margin: -7px 0 20px;\n    color: var(--arcad-navy);\n    font-size: clamp(27px, 3.5vw, 38px);\n    font-weight: 700;\n    line-height: 1.18;\n    letter-spacing: -0.025em;\n}\n\n.arcad-cyber h3 {\n    margin: 28px 0 10px;\n    color: var(--arcad-navy);\n    font-size: 21px;\n    line-height: 1.35;\n}\n\n.arcad-cyber p {\n    margin: 0 0 18px;\n}\n\n.arcad-cyber ul {\n    margin: 20px 0;\n    padding: 0;\n    list-style: none;\n}\n\n.arcad-cyber li {\n    position: relative;\n    margin: 11px 0;\n    padding-left: 27px;\n}\n\n.arcad-cyber li::before {\n    content: \"\";\n    position: absolute;\n    top: 0.72em;\n    left: 0;\n    width: 8px;\n    height: 8px;\n    background: var(--arcad-gold);\n    transform: rotate(45deg);\n}\n\n\/* =========================================================\n   ENCARTS\n   ========================================================= *\/\n\n.arcad-cyber .arcad-callout {\n    margin: 28px 0;\n    padding: 24px 28px;\n    background: var(--arcad-gold-soft);\n    border-left: 4px solid var(--arcad-gold);\n}\n\n.arcad-cyber .arcad-callout strong:first-child {\n    color: var(--arcad-navy);\n}\n\n\/* =========================================================\n   \u00c0 RETENIR\n   ========================================================= *\/\n\n.arcad-cyber .arcad-takeaway {\n    margin: 50px 0;\n    padding: clamp(30px, 5vw, 48px);\n    color: var(--arcad-white);\n    background: var(--arcad-navy);\n}\n\n.arcad-cyber .arcad-takeaway-label {\n    display: block;\n    margin: 0 0 12px;\n    color: var(--arcad-gold);\n    font-size: 13px;\n    font-weight: 700;\n    letter-spacing: 0.14em;\n    text-transform: uppercase;\n}\n\n.arcad-cyber .arcad-takeaway p {\n    margin: 0;\n    color: var(--arcad-white);\n    font-size: 18px;\n    line-height: 1.7;\n}\n\n\/* =========================================================\n   CTA\n   ========================================================= *\/\n\n.arcad-cyber .arcad-cta {\n    display: grid;\n    grid-template-columns: minmax(0, 1fr) auto;\n    align-items: center;\n    gap: 30px;\n    margin-top: 56px;\n    padding: clamp(30px, 5vw, 48px);\n    background: var(--arcad-cream);\n    border-top: 3px solid var(--arcad-gold);\n}\n\n.arcad-cyber .arcad-cta-title {\n    margin: 0 0 10px;\n    color: var(--arcad-navy);\n    font-size: clamp(25px, 3vw, 34px);\n    font-weight: 700;\n    line-height: 1.2;\n}\n\n.arcad-cyber .arcad-cta p {\n    margin: 0;\n    color: var(--arcad-muted);\n}\n\n.arcad-cyber .arcad-button {\n    display: inline-flex;\n    align-items: center;\n    justify-content: center;\n    min-height: 52px;\n    padding: 13px 22px;\n    color: var(--arcad-white) !important;\n    background: var(--arcad-navy);\n    border: 1px solid var(--arcad-navy);\n    text-decoration: none !important;\n    font-size: 15px;\n    font-weight: 700;\n    line-height: 1.4;\n    white-space: nowrap;\n    transition:\n        background-color 0.2s ease,\n        color 0.2s ease;\n}\n\n.arcad-cyber .arcad-button:hover {\n    color: var(--arcad-navy) !important;\n    background: transparent;\n}\n\n\/* =========================================================\n   SOURCES\n   ========================================================= *\/\n\n.arcad-cyber .arcad-sources {\n    margin-top: 60px;\n    padding-top: 34px;\n    border-top: 1px solid var(--arcad-line);\n}\n\n.arcad-cyber .arcad-sources h3 {\n    margin: 0 0 20px;\n    color: var(--arcad-navy);\n    font-size: 27px;\n    font-weight: 700;\n    line-height: 1.25;\n}\n\n.arcad-cyber .arcad-sources ul {\n    margin: 18px 0;\n    padding: 0;\n    list-style: none;\n}\n\n.arcad-cyber .arcad-sources li {\n    margin: 12px 0;\n    padding-left: 27px;\n    color: var(--arcad-muted);\n    font-size: 15px;\n    line-height: 1.6;\n}\n\n.arcad-cyber .arcad-scope {\n    margin-top: 24px;\n    padding: 18px 20px;\n    color: var(--arcad-muted);\n    background: #faf9f6;\n    font-size: 14px;\n    line-height: 1.6;\n}\n\n.arcad-cyber .arcad-tag {\n    margin: 24px 0 0;\n    padding-top: 18px;\n    color: var(--arcad-muted);\n    border-top: 1px solid var(--arcad-line);\n    font-size: 13px;\n    font-weight: 700;\n    letter-spacing: 0.1em;\n    text-transform: uppercase;\n}\n\n\/* =========================================================\n   RESPONSIVE\n   ========================================================= *\/\n\n@media (max-width: 767px) {\n\n    .arcad-cyber {\n        font-size: 16px;\n    }\n\n    .arcad-cyber .arcad-hero {\n        padding: 38px 24px 42px;\n    }\n\n    .arcad-cyber .arcad-title {\n        font-size: clamp(34px, 11vw, 48px);\n    }\n\n    .arcad-cyber .arcad-content {\n        padding-left: 20px;\n        padding-right: 20px;\n    }\n\n    .arcad-cyber .arcad-facts,\n    .arcad-cyber .arcad-cta {\n        grid-template-columns: 1fr;\n    }\n\n    .arcad-cyber .arcad-section {\n        grid-template-columns: 1fr;\n        gap: 8px;\n        padding: 36px 0;\n    }\n\n    .arcad-cyber .arcad-number {\n        margin-bottom: 3px;\n    }\n\n    .arcad-cyber .arcad-button {\n        width: 100%;\n        white-space: normal;\n        text-align: center;\n    }\n}\n<\/style>\n\n<article class=\"arcad-cyber\" lang=\"fr\">\n\n    <div class=\"arcad-shell\">\n\n        <!-- HERO -->\n        <header class=\"arcad-hero\">\n            <div class=\"arcad-hero-content\">\n\n                <p class=\"arcad-eyebrow\">\n                    Cybersecurity \u00b7 Risk-based approach \u00b7 Frameworks\n                <\/p>\n\n                <h1 class=\"arcad-title\">\n                    Cybersecurity audit: balancing risks and applicable requirements\n                <\/h1>\n\n                <p class=\"arcad-lead\">\n                    Should we audit \u00abcybersecurity\u00bb, or the business risks that an IT failure would pose to the organisation? The debate has been running through the profession for years. The entry into force of the IIA's cybersecurity framework in February 2026 has changed the terms of the debate: the issue is no longer about choosing, but about combining them.\n                <\/p>\n\n                <div class=\"arcad-meta\">\n                    <span>Category: Internal audit<\/span>\n                    <span>Reading time: 7 minutes<\/span>\n                <\/div>\n\n            <\/div>\n        <\/header>\n\n\n        <div class=\"arcad-content\">\n\n            <!-- INTRODUCTION -->\n            <div class=\"arcad-intro\">\n                <p>\n                    An influential school of thought, championed in particular by experienced practitioners of the function, defends a distinct position: internal audit should not audit \u00abcybersecurity\u00bb as an entity in itself, but rather the way management identifies and handles the <em>business risk<\/em> that it covers.\n                <\/p>\n            <\/div>\n\n\n            <!-- REP\u00c8RES -->\n            <div class=\"arcad-facts\">\n\n                <div class=\"arcad-fact\">\n                    <strong>5 February 2026<\/strong>\n                    <span>Coming into force of the IIA cybersecurity framework<\/span>\n                <\/div>\n\n                <div class=\"arcad-fact\">\n                    <strong>Mission level<\/strong>\n                    <span>The framework applies to engagements, not the audit plan<\/span>\n                <\/div>\n\n                <div class=\"arcad-fact\">\n                    <strong>DORA<\/strong>\n                    <span>Regulatory baseline applicable since January 2025<\/span>\n                <\/div>\n\n            <\/div>\n\n\n            <!-- 01 -->\n            <section class=\"arcad-section\">\n\n                <div class=\"arcad-number\" aria-hidden=\"true\">\n                    01\n                <\/div>\n\n                <div>\n\n                    <h2>A long-standing and legitimate debate<\/h2>\n\n                    <p>\n                        The arguments are sound. Cybersecurity is too vast a field to be the subject of a credible overall opinion in a single assignment. It encompasses a multitude of controls whose failure would have only a marginal effect on the organisation's objectives. Above all, a technical weakness can be offset by other controls, manual or automated, located elsewhere in the processes: evaluating IT risk in isolation therefore leads to an overestimation of actual exposure.\n                    <\/p>\n\n                    <div class=\"arcad-callout\">\n                        <strong>The heart of the reasoning:<\/strong> Technical standards measure the exposure of IT assets. Internal audit, on the other hand, must assess the risks to the organisation\u2019s objectives. These are on a different scale.\n                    <\/div>\n\n                <\/div>\n\n            <\/section>\n\n\n            <!-- 02 -->\n            <section class=\"arcad-section\">\n\n                <div class=\"arcad-number\" aria-hidden=\"true\">\n                    02\n                <\/div>\n\n                <div>\n\n                    <h2>What the IIA framework actually requires<\/h2>\n\n                    <p>\n                        On 5 February 2025, the Institute of Internal Auditors (IIA) published its thematic framework on cybersecurity (<em>Cybersecurity Specific Requirements<\/em>), which came into force on 5 February 2026. It sets out a minimum framework for assessment covering three areas: governance, risk management and control activities relating to cybersecurity.\n                    <\/p>\n\n                    <p>\n                        Three characteristics are worth noting, as they are often misunderstood:\n                    <\/p>\n\n                    <ul>\n                        <li>\n                            <strong>It is compulsory<\/strong> for assurance engagements of functions conforming to the Global Internal Audit Standards, and recommended for consulting engagements.\n                        <\/li>\n\n                        <li>\n                            <strong>It applies at mission level, not at plan level.<\/strong> It is triggered when the subject of an engagement is included in the audit plan, when a cyber risk is identified during the engagement, or when a request is made for an unplanned engagement.\n                        <\/li>\n\n                        <li>\n                            <strong>He accepts the exclusions, provided they are documented.<\/strong> Each requirement must be assessed for applicability; where a requirement is excluded, the justification must be documented and retained.\n                        <\/li>\n                    <\/ul>\n\n                    <p>\n                        An important point regarding quality assessments: compliance with the current thematic standards is assessed during evaluations carried out after their effective date.\n                    <\/p>\n\n                <\/div>\n\n            <\/section>\n\n\n            <!-- 03 -->\n            <section class=\"arcad-section\">\n\n                <div class=\"arcad-number\" aria-hidden=\"true\">\n                    03\n                <\/div>\n\n                <div>\n\n                    <h2>Why this contrast is partly misleading<\/h2>\n\n                    <p>\n                        Presenting the issue as a choice \u2014 a risk-based approach <em>or<\/em> referential \u2014 does not withstand a reading of the text. The referential does not dictate the content of the audit plan: it does not compel a function to include a cyber assignment, nor to rule on the entire domain. It defines what must be covered <em>when'<\/em>one of the tasks relates to cyber risk.\n                    <\/p>\n\n                    <p>\n                        In other words, the selection of assignments continues to be guided by the most significant risks to the organisation. It is the conduct of the assignment that is regulated. The two approaches operate at different levels and complement one another: the risk-based approach determines <em>what is audited<\/em>, the structural framework <em>How do you audit it?<\/em>.\n                    <\/p>\n\n                    <p>\n                        Indeed, the framework aligns with the concerns of proponents of the risk-based approach on one key point: it requires an assessment of whether the organisation\u2019s risk assessment processes take cyber threats into account <strong>and their impact on the achievement of strategic objectives<\/strong>. This requirement specifically prohibits a siloed reading.\n                    <\/p>\n\n                <\/div>\n\n            <\/section>\n\n\n            <!-- 04 -->\n            <section class=\"arcad-section\">\n\n                <div class=\"arcad-number\" aria-hidden=\"true\">\n                    04\n                <\/div>\n\n                <div>\n\n                    <h2>What the European framework brings to Luxembourg<\/h2>\n\n                    <p>\n                        For regulated financial sector entities, a third constraint applies \u2014 and it is non-negotiable. Regulation (EU) 2022\/2554, known as DORA (Digital Operational Resilience Act), applicable since 17 January 2025, imposes an IT risk management framework overseen by the management body, a register of agreements with IT service providers, enhanced contractual requirements and a resilience testing programme. The Commission de Surveillance du Secteur Financier (CSSF) ensures its monitoring.\n                    <\/p>\n\n                    <p>\n                        These obligations exist irrespective of any risk-based assessment: a regulated entity cannot decide that the matter does not warrant attention. On the other hand, the <em>depth<\/em> and the <em>priority<\/em> audit work on these devices is indeed a matter of risk-based judgement.\n                    <\/p>\n\n                    <div class=\"arcad-callout\">\n                        <strong>Practical consequence:<\/strong> in Luxembourg, the question is not \u00abshould we cover cyber?\u00bb \u2014 the answer is yes \u2014 but \u00abto what depth, on which risks as a priority, and with what documentation of choices?\u00bb.\n                    <\/div>\n\n                <\/div>\n\n            <\/section>\n\n\n            <!-- 05 -->\n            <section class=\"arcad-section\">\n\n                <div class=\"arcad-number\" aria-hidden=\"true\">\n                    05\n                <\/div>\n\n                <div>\n\n                    <h2>Bringing the three approaches together in practice<\/h2>\n\n                    <ul>\n\n                        <li>\n                            <strong>Start from the business risks.<\/strong> Identify IT failures capable of genuinely affecting the organisation's objectives, taking into account compensating controls existing elsewhere in the processes.\n                        <\/li>\n\n                        <li>\n                            <strong>Query the management risk assessment first.<\/strong> If this measures IT asset exposure without linking it to business objectives, that in itself is a finding to bring to the attention of management and the audit committee.\n                        <\/li>\n\n                        <li>\n                            <strong>Align the missions with the framework.<\/strong> As soon as a mission involves cyber risk, roll out the applicability assessment for each requirement \u2014 and document any exclusions.\n                        <\/li>\n\n                        <li>\n                            <strong>Treat DORA as a baseline, not a variable.<\/strong> Registers, contracts, governance and testing must be covered; their frequency and depth are adjusted according to the risk.\n                        <\/li>\n\n                        <li>\n                            <strong>Widen the scope when necessary.<\/strong> A mission involving a cyber risk often leads to the examination of downstream business controls: it is better to acknowledge this in the scoping phase than to discover it along the way.\n                        <\/li>\n\n                    <\/ul>\n\n                <\/div>\n\n            <\/section>\n\n\n            <!-- 06 -->\n            <section class=\"arcad-section\">\n\n                <div class=\"arcad-number\" aria-hidden=\"true\">\n                    06\n                <\/div>\n\n                <div>\n\n                    <h2>Common pitfalls<\/h2>\n\n                    <ul>\n\n                        <li>\n                            Treat the repository as a checklist to be run through entirely, without evaluating applicability \u2014 the opposite of its intended spirit.\n                        <\/li>\n\n                        <li>\n                            Use the risk-based approach to bypass applicable requirements without documenting the justification.\n                        <\/li>\n\n                        <li>\n                            Aiming for a global opinion on \u00abcybersecurity\u00bb, when the field is too vast for credible assurance in a single assignment.\n                        <\/li>\n\n                        <li>\n                            Relying solely on the IT provider's technical framework, which measures asset exposure rather than the achievement of objectives.\n                        <\/li>\n\n                        <li>\n                            Neglecting the documentation of design decisions, reviewed during external quality assessments.\n                        <\/li>\n\n                    <\/ul>\n\n                <\/div>\n\n            <\/section>\n\n\n            <!-- 07 -->\n            <section class=\"arcad-section\">\n\n                <div class=\"arcad-number\" aria-hidden=\"true\">\n                    07\n                <\/div>\n\n                <div>\n\n                    <h2>The ARCAD approach<\/h2>\n\n                    <p>\n                        ARCAD conducts IT and DORA audits based on the organisation's business risks, framed by applicable requirements and documented for quality assessment purposes. Our starting point is the entity's actual exposure \u2014 not a generic technical control checklist applied indiscriminately.\n                    <\/p>\n\n                <\/div>\n\n            <\/section>\n\n\n            <!-- \u00c0 RETENIR -->\n            <aside class=\"arcad-takeaway\">\n\n                <span class=\"arcad-takeaway-label\">\n                    To remember\n                <\/span>\n\n                <p>\n                    Risk-based approaches and frameworks do not oppose one another: the former decides what is audited, the latter structures the conduct of engagements, and DORA establishes an essential baseline for regulated entities. The expected competency of an internal audit function lies in bringing all three together\u2014and documenting its trade-offs.\n                <\/p>\n\n            <\/aside>\n\n\n            <!-- CTA -->\n            <section class=\"arcad-cta\">\n\n                <div>\n\n                    <div class=\"arcad-cta-title\">\n                        Build a useful and compliant cyber audit.\n                    <\/div>\n\n                    <p>\n                        ARCAD designs IT and DORA assignments tailored to your actual risks and applicable requirements.\n                    <\/p>\n\n                <\/div>\n\n                <a\n                    class=\"arcad-button\"\n                    href=\"mailto:administration@arcad.lu?subject=Demande%20d'\u00e9change%20-%20Audit%20du%20risque%20cyber\"\n                >\n                    Schedule an exchange \u2192\n                <\/a>\n\n            <\/section>\n\n\n            <!-- SOURCES -->\n            <section class=\"arcad-sources\">\n\n                <h3>References &amp; further reading<\/h3>\n\n                <ul>\n\n                    <li>\n                        <a href=\"https:\/\/www.theiia.org\/en\/standards\/2024-standards\/topical-requirements\/cybersecurity\/\">\n                            Cybersecurity Specific Requirements\n                        <\/a>, Institute of Internal Auditors \u2014 published on 5 February 2025, effective from 5 February 2026.\n                    <\/li>\n\n                    <li>\n                        <a href=\"https:\/\/www.theiia.org\/en\/standards\/2024-standards\/topical-requirements\/\">\n                            Topical Requirements\n                        <\/a> Global Internal Audit Standards, Institute of Internal Auditors.\n                    <\/li>\n\n                    <li>\n                        <a href=\"https:\/\/eur-lex.europa.eu\/eli\/reg\/2022\/2554\/oj\">\n                            Regulation (EU) 2022\/2554 (DORA)\n                        <\/a> \u2014 EUR-Lex; tracking ensured in Luxembourg by the CSSF.\n                    <\/li>\n\n                <\/ul>\n\n                <p class=\"arcad-scope\">\n                    Note: methodological synthesis verified on 12 August 2026. Other IIA thematic frameworks come into effect in 2026 and 2027; their applicability must be verified separately. Good practices to be adapted to the profile and regulatory framework of each organisation.\n                <\/p>\n\n                <p class=\"arcad-tag\">\n                    Internal audit\n                <\/p>\n\n            <\/section>\n\n        <\/div>\n\n    <\/div>\n\n<\/article>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<\/div>","protected":false},"excerpt":{"rendered":"<p>The cyber audit must articulate an approach based on business risks, the requirements of the IIA cybersecurity framework and the DORA regulatory baseline applicable to regulated entities.<\/p>","protected":false},"author":2,"featured_media":7472,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"footnotes":""},"categories":[1],"tags":[28,27],"class_list":["post-7467","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-audit-interne","tag-ict"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v25.3.1 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>audit-cyber-risques-referentiel-iia-dora<\/title>\n<meta name=\"description\" content=\"Comment auditer le cyber en conciliant risques m\u00e9tier, r\u00e9f\u00e9rentiel cybers\u00e9curit\u00e9 de l\u2019IIA et exigences DORA applicables aux entit\u00e9s r\u00e9gul\u00e9es ?\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/arcad.lu\/en\/audit-du-cyber-concilier-risques-et-exigences-applicables\/\" \/>\n<meta property=\"og:locale\" content=\"en_GB\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"audit-cyber-risques-referentiel-iia-dora\" \/>\n<meta property=\"og:description\" content=\"Comment auditer le cyber en conciliant risques m\u00e9tier, r\u00e9f\u00e9rentiel cybers\u00e9curit\u00e9 de l\u2019IIA et exigences DORA applicables aux entit\u00e9s r\u00e9gul\u00e9es ?\" \/>\n<meta property=\"og:url\" content=\"https:\/\/arcad.lu\/en\/audit-du-cyber-concilier-risques-et-exigences-applicables\/\" \/>\n<meta property=\"og:site_name\" content=\"ARCAD\" \/>\n<meta property=\"article:published_time\" content=\"2026-08-17T12:14:45+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-08-17T12:21:56+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/arcad.lu\/wp-content\/uploads\/2026\/08\/image-cyber.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1152\" \/>\n\t<meta property=\"og:image:height\" content=\"611\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Bastien Decerfou\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Bastien Decerfou\" \/>\n\t<meta name=\"twitter:label2\" content=\"Estimated reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"7 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/arcad.lu\/audit-du-cyber-concilier-risques-et-exigences-applicables\/\",\"url\":\"https:\/\/arcad.lu\/audit-du-cyber-concilier-risques-et-exigences-applicables\/\",\"name\":\"audit-cyber-risques-referentiel-iia-dora\",\"isPartOf\":{\"@id\":\"https:\/\/arcad.lu\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/arcad.lu\/audit-du-cyber-concilier-risques-et-exigences-applicables\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/arcad.lu\/audit-du-cyber-concilier-risques-et-exigences-applicables\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/arcad.lu\/wp-content\/uploads\/2026\/08\/image-cyber.png\",\"datePublished\":\"2026-08-17T12:14:45+00:00\",\"dateModified\":\"2026-08-17T12:21:56+00:00\",\"author\":{\"@id\":\"https:\/\/arcad.lu\/#\/schema\/person\/a087acd8a15d5a534096ac1bf3efc524\"},\"description\":\"Comment auditer le cyber en conciliant risques m\u00e9tier, r\u00e9f\u00e9rentiel cybers\u00e9curit\u00e9 de l\u2019IIA et exigences DORA applicables aux entit\u00e9s r\u00e9gul\u00e9es ?\",\"breadcrumb\":{\"@id\":\"https:\/\/arcad.lu\/audit-du-cyber-concilier-risques-et-exigences-applicables\/#breadcrumb\"},\"inLanguage\":\"en-GB\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/arcad.lu\/audit-du-cyber-concilier-risques-et-exigences-applicables\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-GB\",\"@id\":\"https:\/\/arcad.lu\/audit-du-cyber-concilier-risques-et-exigences-applicables\/#primaryimage\",\"url\":\"https:\/\/arcad.lu\/wp-content\/uploads\/2026\/08\/image-cyber.png\",\"contentUrl\":\"https:\/\/arcad.lu\/wp-content\/uploads\/2026\/08\/image-cyber.png\",\"width\":1152,\"height\":611},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/arcad.lu\/audit-du-cyber-concilier-risques-et-exigences-applicables\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Accueil\",\"item\":\"https:\/\/arcad.lu\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Audit du cyber : concilier risques et exigences applicables\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/arcad.lu\/#website\",\"url\":\"https:\/\/arcad.lu\/\",\"name\":\"ARCAD\",\"description\":\"\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/arcad.lu\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-GB\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/arcad.lu\/#\/schema\/person\/a087acd8a15d5a534096ac1bf3efc524\",\"name\":\"Bastien Decerfou\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-GB\",\"@id\":\"https:\/\/arcad.lu\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/2a433ec2c9f0bf45bb4133ffe92fc6404b0bb82145096ad97e743c259599c627?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/2a433ec2c9f0bf45bb4133ffe92fc6404b0bb82145096ad97e743c259599c627?s=96&d=mm&r=g\",\"caption\":\"Bastien Decerfou\"},\"url\":\"https:\/\/arcad.lu\/en\/author\/bdecerf\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"cyber-risk audit IIA DORA framework","description":"How to audit cyber by reconciling business risks, the IIA cybersecurity framework and the DORA requirements applicable to regulated entities?","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/arcad.lu\/en\/audit-du-cyber-concilier-risques-et-exigences-applicables\/","og_locale":"en_GB","og_type":"article","og_title":"audit-cyber-risques-referentiel-iia-dora","og_description":"Comment auditer le cyber en conciliant risques m\u00e9tier, r\u00e9f\u00e9rentiel cybers\u00e9curit\u00e9 de l\u2019IIA et exigences DORA applicables aux entit\u00e9s r\u00e9gul\u00e9es ?","og_url":"https:\/\/arcad.lu\/en\/audit-du-cyber-concilier-risques-et-exigences-applicables\/","og_site_name":"ARCAD","article_published_time":"2026-08-17T12:14:45+00:00","article_modified_time":"2026-08-17T12:21:56+00:00","og_image":[{"width":1152,"height":611,"url":"https:\/\/arcad.lu\/wp-content\/uploads\/2026\/08\/image-cyber.png","type":"image\/png"}],"author":"Bastien Decerfou","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Bastien Decerfou","Estimated reading time":"7 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/arcad.lu\/audit-du-cyber-concilier-risques-et-exigences-applicables\/","url":"https:\/\/arcad.lu\/audit-du-cyber-concilier-risques-et-exigences-applicables\/","name":"cyber-risk audit IIA DORA framework","isPartOf":{"@id":"https:\/\/arcad.lu\/#website"},"primaryImageOfPage":{"@id":"https:\/\/arcad.lu\/audit-du-cyber-concilier-risques-et-exigences-applicables\/#primaryimage"},"image":{"@id":"https:\/\/arcad.lu\/audit-du-cyber-concilier-risques-et-exigences-applicables\/#primaryimage"},"thumbnailUrl":"https:\/\/arcad.lu\/wp-content\/uploads\/2026\/08\/image-cyber.png","datePublished":"2026-08-17T12:14:45+00:00","dateModified":"2026-08-17T12:21:56+00:00","author":{"@id":"https:\/\/arcad.lu\/#\/schema\/person\/a087acd8a15d5a534096ac1bf3efc524"},"description":"How to audit cyber by reconciling business risks, the IIA cybersecurity framework and the DORA requirements applicable to regulated entities?","breadcrumb":{"@id":"https:\/\/arcad.lu\/audit-du-cyber-concilier-risques-et-exigences-applicables\/#breadcrumb"},"inLanguage":"en-GB","potentialAction":[{"@type":"ReadAction","target":["https:\/\/arcad.lu\/audit-du-cyber-concilier-risques-et-exigences-applicables\/"]}]},{"@type":"ImageObject","inLanguage":"en-GB","@id":"https:\/\/arcad.lu\/audit-du-cyber-concilier-risques-et-exigences-applicables\/#primaryimage","url":"https:\/\/arcad.lu\/wp-content\/uploads\/2026\/08\/image-cyber.png","contentUrl":"https:\/\/arcad.lu\/wp-content\/uploads\/2026\/08\/image-cyber.png","width":1152,"height":611},{"@type":"BreadcrumbList","@id":"https:\/\/arcad.lu\/audit-du-cyber-concilier-risques-et-exigences-applicables\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Accueil","item":"https:\/\/arcad.lu\/"},{"@type":"ListItem","position":2,"name":"Audit du cyber : concilier risques et exigences applicables"}]},{"@type":"WebSite","@id":"https:\/\/arcad.lu\/#website","url":"https:\/\/arcad.lu\/","name":"ARCAD","description":"","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/arcad.lu\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-GB"},{"@type":"Person","@id":"https:\/\/arcad.lu\/#\/schema\/person\/a087acd8a15d5a534096ac1bf3efc524","name":"Bastien Decerfou","image":{"@type":"ImageObject","inLanguage":"en-GB","@id":"https:\/\/arcad.lu\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/2a433ec2c9f0bf45bb4133ffe92fc6404b0bb82145096ad97e743c259599c627?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/2a433ec2c9f0bf45bb4133ffe92fc6404b0bb82145096ad97e743c259599c627?s=96&d=mm&r=g","caption":"Bastien Decerfou"},"url":"https:\/\/arcad.lu\/en\/author\/bdecerf\/"}]}},"_links":{"self":[{"href":"https:\/\/arcad.lu\/en\/wp-json\/wp\/v2\/posts\/7467","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/arcad.lu\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/arcad.lu\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/arcad.lu\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/arcad.lu\/en\/wp-json\/wp\/v2\/comments?post=7467"}],"version-history":[{"count":5,"href":"https:\/\/arcad.lu\/en\/wp-json\/wp\/v2\/posts\/7467\/revisions"}],"predecessor-version":[{"id":7474,"href":"https:\/\/arcad.lu\/en\/wp-json\/wp\/v2\/posts\/7467\/revisions\/7474"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/arcad.lu\/en\/wp-json\/wp\/v2\/media\/7472"}],"wp:attachment":[{"href":"https:\/\/arcad.lu\/en\/wp-json\/wp\/v2\/media?parent=7467"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/arcad.lu\/en\/wp-json\/wp\/v2\/categories?post=7467"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/arcad.lu\/en\/wp-json\/wp\/v2\/tags?post=7467"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}