CyberTRIZPEDIA

Maintain and Test Incident Response and Recovery Plans

Control
DORA-ICT-004
Regulation
DORA
Category
operational
Priority
critical
Frequency
annually
Type
operational

What this control requires

Document ICT incident response plans with clear roles, procedures and communication protocols. Define RTO/RPO for all critical systems. Test response plans through tabletop exercises (quarterly) and full recovery tests (annually). Maintain lessons learned register. Plans must cover ransomware, data breach and DDoS scenarios.

Other DORA controls