Skip to content

ICT Risk Management

What is ICT Risk Management?

The process of identifying, assessing, and managing risks associated with information and communication technology. ICT risk management is central to DORA, CPS 234, and other technology-focused regulations.

Risk Management

Each of these is named in at least one of the same controls as ict risk management. The number is how many controls name both.

What the standards actually require on ict risk management

Requirements naming ict risk management across 3 standards, quoted from the control text.

DORA5 controls

Specified smaller and non-interconnected financial entities are subject to a simplified ICT risk management framework with proportionate requirements (sound systems, monitoring, business continuity, incident handling and testing).

DORA-Art.16 · Simplified ICT risk management framework

Article 99 obliges Member States to ensure adequate + effective out-of-court complaint + redress procedures for disputes between PSUs and PSPs. Article 100 designates competent authorities.

PSD2-Art.99_103 · Out-of-court redress, competent authorities and penalties (PSD2 Articles 99-103)

Greece Law 4624/2019 2024-2025 regulatory pipeline + EU integration. NIS2 TRANSPOSITION (deadline 17 October 2024 + Greek law expected 2024-2025): Directive (EU) 2022/2555 NIS2 transposition into Greek law expanding cybersecurity scope from NIS1 to 18 critical...

GR-DPA-2024-2025-Pipeline-NIS2-DORA-AIAct-DataAct · Greece Law 4624/2019 2024-2025 Pipeline - NIS2 + DORA + AI Act + Data Act + EDPB Coordination

Questions people ask about ict risk management

What is ICT Risk Management?
The process of identifying, assessing, and managing risks associated with information and communication technology. ICT risk management is central to DORA, CPS 234, and other technology-focused regulations.
Why is ICT Risk Management important for compliance?
ICT Risk Management is a key concept in Risk Management. Understanding ict risk management helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address ICT Risk Management?
ICT Risk Management appears in the requirement text of DORA, EU Payment Services Directive (PSD2), Greece Law 4624/2019 - Hellenic Data Protection Authority (HDPA) Implementation Act. Across these standards we have identified 7 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about ICT Risk Management?
Explore our compliance framework pages to see how ict risk management applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how ICT Risk Management applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.