Zum Inhalt springen

ICT Risk Management

Making ICT Risks Controllable, Verifiable and Reviewable

Structured target states for risk identification, protection needs, controls, acceptance, reporting and evidence.

Regulatory scope

DORA Chapter II · Art. 5–16

Prepared catalogue

15 evidence building blocks

Assurance boundary

Not compliance evidence

Management-Zusammenfassung

  • DORA Chapter II (Art. 5–16) connects governance, ICT systems and assets, identification, protection and prevention, detection, response, recovery, learning and communication.
  • The management body bears overall responsibility and approves strategy, risk appetite and budget for ICT resilience.
  • These areas provide navigation and working structure; completeness and effectiveness require institution-specific decisions and verified evidence.
  • Alignment with MaRisk (AT 4.3) and ISO/IEC 27001:2022 avoids duplication and ensures auditability.

End-to-end workflow

From management decisions to reliable evidence

Each workstream should connect accountable owners, affected functions and assets, risk decisions, controls, evidence, deadlines and review dates.

  1. 01 Art. 5–6

    Mandate and framework

    Approved roles, strategy, risk appetite and review cycle

  2. 02 Art. 7–8

    Systems and dependencies

    Inventory linking functions, assets, data, locations and dependencies

  3. 03 Art. 9–10

    Protection and detection

    Risk-based controls, thresholds and traceable alerts

  4. 04 Art. 11–12

    Response and recovery

    Scenarios, recovery objectives, backups and tested restoration

  5. 05 Art. 13–14

    Learning and communication

    Root-cause analyses, improvements and communication plans

  6. 06 Art. 15–16

    Harmonisation and scope

    Technical standards and documented assessment of the simplified framework

Detailed workspaces and aids

These detailed workspaces support individual implementation objects. Article references aid navigation and do not replace legal interpretation.

Note:

This content is a working structure for implementation preparation. It does not evidence completeness, effectiveness or regulatory compliance; the original sources and institution-specific legal, professional and audit assessments remain authoritative.

All content is regularly reviewed for currency. Status: May 2026.