DORA · Chapter II — ICT risk management
Art. 6 ICT risk management framework
Maintain a sound, comprehensive and well-documented ICT risk-management framework as part of the overall risk-management system.
Mapped across 16 provisions
Equivalent and related requirements in other frameworks and regulations.
- CCPA / CPRARelatedCurated§1798.100 Consumers' right to know and notice at collection
Governance & security policy
- CCPA / CPRARelatedCurated§1798.150 Duty to implement reasonable security
Risk assessment & management
- GDPRRelatedCuratedArt. 25 Data protection by design and by default
Governance & security policy
- GLBARelatedCurated§314.4(a) Designate a qualified individual
Governance & security policy
- HIPAARelatedCurated§164.308(a)(1) Security management process
Risk assessment & management
- ISO 27001RelatedCuratedA.5.1 Policies for information security
Governance & security policy
- LGPDRelatedCuratedArt. 50 Good practices and governance rules
Governance & security policy
- LGPDRelatedCuratedArt. 46 Security measures
Risk assessment & management
- NIS2RelatedCuratedArt. 21(2)(a) Risk analysis and information system security policies
Governance & security policy
- NIST 800-171RelatedCurated3.11.1 Periodically assess risk
Risk assessment & management
- NIST 800-53RelatedCuratedPM-1 Information security program plan
Governance & security policy
- NIST 800-53RelatedCuratedRA-3 Risk assessment
Risk assessment & management
- NIST CSF 2.0RelatedCuratedGV.OC-01 Organizational mission and security role understood
Governance & security policy
- NIST CSF 2.0RelatedCuratedID.RA-01 Vulnerabilities identified and recorded
Risk assessment & management
- PCI DSSRelatedCuratedReq. 12 Support information security with organizational policies and programs
Governance & security policy
- SOC 2RelatedCuratedCC1.1 Integrity and ethical values
Governance & security policy