Meeting Third-Party Risk Requirements of DORA in 2024 | UpGuard
ID: 475733be-8b4a-5b4b-9f43-3d07281ffa8a
STIX ID: report--475733be-8b4a-5b4b-9f43-3d07281ffa8a
Feed Name: UpGuard Blog
A compliance guide to the EU Digital Operational Resilience Act (DORA) focused on Third-Party Risk Management, summarizing requirements across strategy, due diligence, information security standards, contractual and audit provisions, termination and exit planning, and ESA-led standards development, and offering a six-step framework to achieve compliance: align with ESA RTS, map ICT assets and attack surface, conduct realistic incident and disaster recovery tests, build an organization-wide resilience culture, establish a single source of truth for policies and procedures, and tier vendors by criticality; the piece also notes oversight of Critical Third Party Providers and highlights how a VRM platform like UpGuard can assist with automated compliance mapping and reporting.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
