CyberTRIZPEDIA

Conduct Annual ICT Asset Classification and Risk Assessment

Control
DORA-ICT-001
Regulation
DORA
Category
operational
Priority
high
Frequency
annually
Type
operational

What this control requires

Perform comprehensive ICT risk assessments at least annually. Classify all ICT assets by criticality and sensitivity. Map critical business functions to supporting ICT systems. Identify single points of failure. Document all ICT dependencies including cloud and third-party services.

Other DORA controls