DORA is ICT risk governance, not only a checklist
DORA combines ICT risk management, incident handling, resilience testing, third-party oversight and executive reporting into one regulatory operating model.
- ICT control model and decision ownership.
- Incident classification, escalation and reporting readiness.
- Critical supplier assessment and outsourced ICT oversight.
- Resilience testing and evidence of effectiveness.