DORA Article 45 Information Sharing

The DORA information-sharing surface prepares operator-controlled outbound cyber-threat and incident information-sharing batches. Stella supplies minimisation, STIX/TAXII-aligned batch construction, DSSE signing, dedicated Notify channel purpose routing, and audit evidence. The operator owns the sharing arrangement, subscriber authorization, transfer basis, and decision to deliver each batch.

This is a surface of the DORA Operational Resilience Pack.

Claim boundary: operator-support.

Source Docs

Runtime Boundary

General Notify channels must not be reused for DORA peer sharing. Use a Notify channel whose purpose is dora-info-sharing so minimisation, signing, and audit evidence stay separated from ordinary notifications.

The Notifier worker has a purpose-specific path for enabled DORA information sharing channels. It bypasses generic webhook/template dispatch, builds the connector request from channel collection/subscriber settings plus frozen source events, verifies the DSSE envelope before delivery, and persists delivery plus receipt metadata through the durable delivery ledger.

Handoff And Delivery Modes

Supported modes:

The target Assurance export profile id is dora.info-sharing. Current compatibility routes are stella export dora-info-sharing, stella verify dora-info-sharing, and the purpose-specific Notify channel runtime. The generic ExportCenter registry does not currently publish this profile as a built-in export.

Required Operator Setup

Before enabling a subscriber channel, the operator must configure:

Notify stores only references and public metadata. It must not store raw credentials, private keys, or broad PII allowlists in channel JSON.

Minimisation

Default profile: dora-info-sharing-strict-v1.

Strict mode removes source-event PII fields and free-text descriptions before canonicalization. Explicit-authorisation mode requires an approval reference and a concrete PII field allowlist. Operators should treat explicit authorization as exceptional and time-bounded.

Blocking Conditions

Do not deliver a batch when: