Implement Comprehensive ICT Risk Management Framework
What this control requires
Establish a comprehensive ICT risk management framework covering: ICT strategy, risk appetite statement, risk assessment methodology, risk treatment procedures, residual risk acceptance process and continuous monitoring. The framework must be integrated into the overall risk management framework.
Other DORA controls
DORA-A17-001-B - DORA Incident Classification and ManagementDORA-A5-001-B - Board ICT Risk AccountabilityDORA-GOV-001 - Maintain Board-Approved ICT Risk Management FrameworkDORA-GOV-002 - Designate Senior ICT Risk Function with Board-Level AccessDORA-GOV-004 - Maintain Approved ICT Systems and Security Baseline StandardsDORA-ICT-001 - Conduct Annual ICT Asset Classification and Risk AssessmentDORA-ICT-002 - Deploy Multi-Layer ICT Protection and Prevention ControlsDORA-ICT-003 - Deploy 24/7 Security Monitoring and Threat DetectionDORA-ICT-004 - Maintain and Test Incident Response and Recovery PlansDORA-ICT-005 - Implement and Regularly Test Backup and Recovery ProceduresDORA-INC-001 - Establish DORA-Compliant ICT Incident Management ProcessDORA-INC-002 - Implement DORA Incident Classification and Severity Assessment