Governance and organisation

Governance and organisation DORA (Regulation (EU) 2022/2554) introduces a new governance paradigm for ICT risk management that differs materially from the BAIT/VAIT architecture. The BaFin guidance highlights three core areas of change: DORA requires a new strategy for digital operational readiness (DOR Strategy) Reference: page 8 Key points Differences vs. BAIT/VAIT Operational implication Financial entities will have to maintain two strategy layers: ICT-specific internal governance and control framework Reference: page 9 DORA introduces a fully-fledged ICT governance framework focusing on the “effective and prudent management of ICT risk”. Key elements ICT security policies DORA (RTS RMF Art. 2(2)) prescribes a set of mandatory ICT security … Continue reading Governance and organisationRead More →