CyberTRIZPEDIA

Implement Comprehensive ICT Risk Management Framework

Control
DORA-GOV-003
Regulation
DORA
Category
operational
Priority
high
Frequency
annually
Type
operational

What this control requires

Establish a comprehensive ICT risk management framework covering: ICT strategy, risk appetite statement, risk assessment methodology, risk treatment procedures, residual risk acceptance process and continuous monitoring. The framework must be integrated into the overall risk management framework.

Other DORA controls