Maintain Board-Approved ICT Risk Management Framework
What this control requires
The management body must formally approve, own and oversee a documented ICT risk management framework. It must cover identification, protection, detection, response and recovery. Reviewed annually and after major ICT incidents. The management body bears full accountability for ICT risk decisions.
Other DORA controls
DORA-A17-001-B - DORA Incident Classification and ManagementDORA-A5-001-B - Board ICT Risk AccountabilityDORA-GOV-002 - Designate Senior ICT Risk Function with Board-Level AccessDORA-GOV-003 - Implement Comprehensive ICT Risk Management FrameworkDORA-GOV-004 - Maintain Approved ICT Systems and Security Baseline StandardsDORA-ICT-001 - Conduct Annual ICT Asset Classification and Risk AssessmentDORA-ICT-002 - Deploy Multi-Layer ICT Protection and Prevention ControlsDORA-ICT-003 - Deploy 24/7 Security Monitoring and Threat DetectionDORA-ICT-004 - Maintain and Test Incident Response and Recovery PlansDORA-ICT-005 - Implement and Regularly Test Backup and Recovery ProceduresDORA-INC-001 - Establish DORA-Compliant ICT Incident Management ProcessDORA-INC-002 - Implement DORA Incident Classification and Severity Assessment