DORA Art. 24-27 resilience testing management for AI agents. From annual test programme to AmpelOracle sync in one call.
| ID | Scenario | Article | Frequency | Method |
|---|---|---|---|---|
| SCN-01 | Vulnerability assessment | Art. 25(1)(a) | Quarterly | Automated scanning + manual validation |
| SCN-02 | Network security assessment | Art. 25(1)(b) | Yearly | Configuration review + traffic analysis |
| SCN-03 | Gap analysis | Art. 25(1)(c) | Yearly | Document review + interviews |
| SCN-04 | Physical security review | Art. 25(1)(d) | Yearly | Site inspection + access log review |
| SCN-05 | Source code review | Art. 25(1)(e) | Per release | SAST + manual code review |
| SCN-06 | Scenario-based testing | Art. 25(1)(f) | Yearly | Tabletop + simulation exercises |
| SCN-07 | Compatibility testing | Art. 25(1)(g) | Per change | Integration + regression testing |
| SCN-08 | Performance testing | Art. 25(1)(h) | Yearly | Load + stress testing |
| SCN-09 | End-to-end testing | Art. 25(1)(i) | Yearly | Full chain validation |
| SCN-10 | Penetration testing | Art. 25(1)(j) | Yearly | Black + grey + white box |
| SCN-11 | TLPT / Red team | Art. 26(1) | 3 years | TIBER-EU framework, external testers |
| SCN-12 | DR/BCM switchover | Art. 11(6) | Yearly | Live failover + recovery validation |