Digital Operational Resilience Act (DORA)
Table of Contents
Chapter I – General provisions
Chapter II – ICT risk management
Chapter III – ICT-related incident management, classification and reporting
Chapter IV – Digital operational resilience testing
Chapter V – Managing of ICT third-party risk
Chapter VI – Information-sharing arrangements
Chapter VII – Competent authorities
Chapter VIII – Delegated acts
Chapter IX – Transitional and final provisions
Recitals (106)
Recital 38
(38) As larger financial entities might enjoy wider resources and can swiftly deploy funds to develop governance structures and set up various corporate strategies, only financial entities that are not microenterprises in the sense of this Regulation should be required to establish more complex governance arrangements. Such entities are better equipped in particular to set up dedicated management functions for supervising arrangements with ICT third-party service providers or for dealing with crisis management, to organise their ICT risk management according to the three lines of defence model, or to set up an internal risk management and control model, and to submit their ICT risk management framework to internal audits.