- Level 2 RTS specifying detailed contractual requirements for ICT services supporting critical or important functions.
References and citations
- Level 2 RTS specifying ICT risk management tools, methods, processes, policies, and the simplified framework referenced by DORA.
- Primary DORA requirements across the four main workstreams: ICT risk management (Chapter II), incident reporting (Chapter III), testing/TLPT (Chapter IV), and ICT third-party risk including contract clauses and the register of information (Chapter V).