Skip to content

Glossary

ICT risk management

DORA's first pillar: the governance, protection and continuity framework every financial entity must put in place.

DORA's first pillar (Articles 5 to 16), ICT risk management requires every financial entity to put in place an internal framework covering:

  • governance and oversight by the management body,
  • identification and mapping of information assets,
  • protection and risk prevention,
  • anomaly detection,
  • response and business continuity,
  • learning and continuous improvement after an incident.

Smaller entities benefit from a simplified framework (Article 16) proportionate to their risk profile.