Implement DORA Incident Classification and Severity Assessment
What this control requires
Maintain an incident classification framework aligned with DORA severity criteria including: number of clients affected, data loss, service unavailability duration, reputational impact, financial losses and geographic spread. Train incident response team on classification. Conduct quarterly calibration exercises.
Other DORA controls
DORA-A17-001-B - DORA Incident Classification and ManagementDORA-A5-001-B - Board ICT Risk AccountabilityDORA-GOV-001 - Maintain Board-Approved ICT Risk Management FrameworkDORA-GOV-002 - Designate Senior ICT Risk Function with Board-Level AccessDORA-GOV-003 - Implement Comprehensive ICT Risk Management FrameworkDORA-GOV-004 - Maintain Approved ICT Systems and Security Baseline StandardsDORA-ICT-001 - Conduct Annual ICT Asset Classification and Risk AssessmentDORA-ICT-002 - Deploy Multi-Layer ICT Protection and Prevention ControlsDORA-ICT-003 - Deploy 24/7 Security Monitoring and Threat DetectionDORA-ICT-004 - Maintain and Test Incident Response and Recovery PlansDORA-ICT-005 - Implement and Regularly Test Backup and Recovery ProceduresDORA-INC-001 - Establish DORA-Compliant ICT Incident Management Process