Pillar 1 of DORA (Articles 5–16) requires a documented ICT risk management framework, owned and overseen by the management body. It runs from governance and identification through protection, detection, response and recovery, to continuous learning.
This is the foundation everything else in DORA rests on. Get the framework right and the other pillars become far more manageable.
Governance and the management body
DORA makes ICT risk a board-level responsibility. The management body must define, approve, oversee and remain accountable for the framework, and keep its own knowledge current. See DORA governance and board responsibility.
Identification
Firms must identify and map their ICT-supported business functions, information assets and dependencies — including the critical or important functions that drive testing and third-party scope. See Mapping critical or important functions.
Protection and prevention
Appropriate security controls, policies and tools to protect ICT systems — access management, encryption, secure configuration, change management and more.
Detection
Mechanisms to detect anomalous activity and ICT-related incidents promptly, feeding into the incident-management process.
Response and recovery
Business continuity and disaster-recovery arrangements — backup and restoration policies, response plans, and communication — so the firm can keep critical functions running and recover quickly.
Learning and review
The framework must be reviewed and improved over time, incorporating lessons from incidents and testing.
Want to assess your framework against DORA? Book a readiness assessment.