CyberTRIZPEDIA

Maintain Board-Approved ICT Risk Management Framework

Control
DORA-GOV-001
Regulation
DORA
Category
operational
Priority
critical
Frequency
annually
Type
operational

What this control requires

The management body must formally approve, own and oversee a documented ICT risk management framework. It must cover identification, protection, detection, response and recovery. Reviewed annually and after major ICT incidents. The management body bears full accountability for ICT risk decisions.

Other DORA controls