Protection and prevention
Summary
Financial entities shall continuously monitor and control the security of ICT systems, minimise ICT risk impact, and implement documented information security, access, authentication, change-management and patching policies.
protectionpreventioninformation securityaccess controlchange management
Read the full official text: https://www.digital-operational-resilience-act.com/Article_9.html
Track DORA article 9 as evidence
eurocompliant maps this obligation to a checklist task and the evidence that satisfies it, alongside every other framework you follow.
Start free trial