ICT Risk Management
Making ICT Risks Controllable, Verifiable and Reviewable
Structured target states for risk identification, protection needs, controls, acceptance, reporting and evidence.
Regulatory scope
DORA Chapter II · Art. 5–16
Prepared catalogue
15 evidence building blocks
Assurance boundary
Not compliance evidence
Management-Zusammenfassung
- DORA Chapter II (Art. 5–16) connects governance, ICT systems and assets, identification, protection and prevention, detection, response, recovery, learning and communication.
- The management body bears overall responsibility and approves strategy, risk appetite and budget for ICT resilience.
- These areas provide navigation and working structure; completeness and effectiveness require institution-specific decisions and verified evidence.
- Alignment with MaRisk (AT 4.3) and ISO/IEC 27001:2022 avoids duplication and ensures auditability.
End-to-end workflow
From management decisions to reliable evidence
Each workstream should connect accountable owners, affected functions and assets, risk decisions, controls, evidence, deadlines and review dates.
-
01 Art. 5–6
Mandate and framework
Approved roles, strategy, risk appetite and review cycle
-
02 Art. 7–8
Systems and dependencies
Inventory linking functions, assets, data, locations and dependencies
-
03 Art. 9–10
Protection and detection
Risk-based controls, thresholds and traceable alerts
-
04 Art. 11–12
Response and recovery
Scenarios, recovery objectives, backups and tested restoration
-
05 Art. 13–14
Learning and communication
Root-cause analyses, improvements and communication plans
-
06 Art. 15–16
Harmonisation and scope
Technical standards and documented assessment of the simplified framework
DORA workspace
Structure requirements, measures and evidence objects across Articles 5–16.
ICT risk register
Track risks, owners, residual-risk decisions and measures.
Target-measures catalogue
Work with control objectives and actionable measures linked to legal sources.
Evidence workflow
Request, review, version and schedule evidence for reassessment.
Detailed workspaces and aids
These detailed workspaces support individual implementation objects. Article references aid navigation and do not replace legal interpretation.
Overview
Overall overview of ICT risk management according to DORA Chapter II.
Open section → Art. 5–6Governance
Framework, roles, strategy and risk appetite for ICT risk management.
Open section → Art. 7–8Risk Inventory
Systematic recording, classification and assessment of all ICT risks.
Open section → Art. 8–9Protection Needs
Protection need assessment for ICT assets based on confidentiality, integrity and availability.
Open section → Art. 9–12Control System
Control objectives, controls, effectiveness testing and evidence.
Open section → Art. 10, 14Monitoring & Reporting
Early warning indicators, management reporting and escalation processes.
Open section → Art. 5–16Evidence
Evidence model and evidence register for ICT risk management.
Open section → Art. 6(5), 13Maturity
Maturity model, assessment and continuous improvement.
Open section →Note:
This content is a working structure for implementation preparation. It does not evidence completeness, effectiveness or regulatory compliance; the original sources and institution-specific legal, professional and audit assessments remain authoritative.
All content is regularly reviewed for currency. Status: May 2026.