Designate Senior ICT Risk Function with Board-Level Access
What this control requires
Designate a senior function (CISO or equivalent) with explicit accountability for ICT risk and digital resilience. The function must have a direct reporting line to the management body, adequate resources, authority and independence. Document the mandate, responsibilities and escalation rights.
Other DORA controls
DORA-A17-001-B - DORA Incident Classification and ManagementDORA-A5-001-B - Board ICT Risk AccountabilityDORA-GOV-001 - Maintain Board-Approved ICT Risk Management FrameworkDORA-GOV-003 - Implement Comprehensive ICT Risk Management FrameworkDORA-GOV-004 - Maintain Approved ICT Systems and Security Baseline StandardsDORA-ICT-001 - Conduct Annual ICT Asset Classification and Risk AssessmentDORA-ICT-002 - Deploy Multi-Layer ICT Protection and Prevention ControlsDORA-ICT-003 - Deploy 24/7 Security Monitoring and Threat DetectionDORA-ICT-004 - Maintain and Test Incident Response and Recovery PlansDORA-ICT-005 - Implement and Regularly Test Backup and Recovery ProceduresDORA-INC-001 - Establish DORA-Compliant ICT Incident Management ProcessDORA-INC-002 - Implement DORA Incident Classification and Severity Assessment