CyberTRIZPEDIA

Establish ICT Third-Party Risk Management Framework and Register

Control
DORA-TPR-001
Regulation
DORA
Category
operational
Priority
high
Frequency
annually
Type
operational

What this control requires

Maintain a comprehensive register of all ICT third-party providers including cloud services, software vendors and outsourced IT functions. Conduct pre-engagement security due diligence. Classify providers by criticality. Implement ongoing monitoring including annual security reviews for critical providers.

Other DORA controls