Board ICT Risk Accountability
What this control requires
Management body must formally approve ICT risk management framework, define ICT risk tolerance, and receive quarterly ICT risk reporting. Conduct annual ICT training for management body members.
Other DORA controls
DORA-A17-001-B - DORA Incident Classification and ManagementDORA-GOV-001 - Maintain Board-Approved ICT Risk Management FrameworkDORA-GOV-002 - Designate Senior ICT Risk Function with Board-Level AccessDORA-GOV-003 - Implement Comprehensive ICT Risk Management FrameworkDORA-GOV-004 - Maintain Approved ICT Systems and Security Baseline StandardsDORA-ICT-001 - Conduct Annual ICT Asset Classification and Risk AssessmentDORA-ICT-002 - Deploy Multi-Layer ICT Protection and Prevention ControlsDORA-ICT-003 - Deploy 24/7 Security Monitoring and Threat DetectionDORA-ICT-004 - Maintain and Test Incident Response and Recovery PlansDORA-ICT-005 - Implement and Regularly Test Backup and Recovery ProceduresDORA-INC-001 - Establish DORA-Compliant ICT Incident Management ProcessDORA-INC-002 - Implement DORA Incident Classification and Severity Assessment