Glossary · DORA
ICT Risk Management Framework
The documented set of strategies, policies, and tools that DORA requires financial entities to maintain for managing ICT risk.
Explained in depth: DORA overview
Under DORA Articles 5 and 6, each financial entity must maintain a sound, comprehensive, and well-documented ICT risk management framework as part of its overall risk management system. The framework covers identification of ICT-supported functions and assets, protection and prevention measures, detection of anomalous activity, response and recovery plans, backup and restoration policies, learning from incidents, and communication plans. The management body bears full and final responsibility for the framework: it must approve it, review it periodically (at least yearly and after major incidents), and hold sufficient knowledge to understand ICT risk. Detailed content requirements are specified in regulatory technical standards (RTS) developed by the ESAs.
Why it matters
The framework is the backbone of DORA compliance; supervisors ask for it first. Its structure deliberately mirrors recognised standards, so entities with a mature ISO 27001 ISMS have a head start, but DORA's documentation and board-approval requirements are more explicit than most existing setups.
