Ensure DORA-Compliant ICT Third-Party Contracts
What this control requires
Review and update all ICT third-party contracts to include mandatory DORA provisions: full service descriptions and SLAs, audit and inspection rights, incident notification obligations, business continuity requirements, data location and processing restrictions, exit clauses and transition assistance, sub-contractor disclosure and approval rights.
Other DORA controls
DORA-A17-001-B - DORA Incident Classification and ManagementDORA-A5-001-B - Board ICT Risk AccountabilityDORA-GOV-001 - Maintain Board-Approved ICT Risk Management FrameworkDORA-GOV-002 - Designate Senior ICT Risk Function with Board-Level AccessDORA-GOV-003 - Implement Comprehensive ICT Risk Management FrameworkDORA-GOV-004 - Maintain Approved ICT Systems and Security Baseline StandardsDORA-ICT-001 - Conduct Annual ICT Asset Classification and Risk AssessmentDORA-ICT-002 - Deploy Multi-Layer ICT Protection and Prevention ControlsDORA-ICT-003 - Deploy 24/7 Security Monitoring and Threat DetectionDORA-ICT-004 - Maintain and Test Incident Response and Recovery PlansDORA-ICT-005 - Implement and Regularly Test Backup and Recovery ProceduresDORA-INC-001 - Establish DORA-Compliant ICT Incident Management Process