Rättskällor med officiella primärkällor

Utskrivet ·

Hopp til innhold
Hopp til svaret

Agent · dora-2022-2554-6

DORA artikel 6: ICT risk management framework

Strukturelt tre: artikkelens egne punkter, ordrett.

CELEX 32022R2554 · 2026-08-18 · Vekt 86 · minimal-risk

ExtendedOperational weight but lower priority. Metered by volume, not per call, once metering is switched on.

DORAOffisiell kilde

Hva siden er
Agent, DORA artikel 6
Lest mot offisiell kilde
2026-08-18Fersk
Ansvarlig utgiver
ExploreWorld Legal, redaksjonenAnsvarsposisjon

Jurisdiksjon

Samme agent, lest med ett lands øyne.

Inndata

  • in_scopeThe article applies to the situationboolean
  • punktParagraph of the articleenum (1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10 | 11 | 12 | 13 | 14)

Regeltre

  1. Hvis: alla(in_scope = true, punkt = 1)

    Paragraph 1 applies

    1. Financial entities shall have a sound, comprehensive and well-documented ICT risk management framework as part of their overall risk management system, which enables them to address ICT risk quickly, efficiently and comprehensively and to ensure a high level of digital operational resilience.

    Punkt 1

  2. Hvis: alla(in_scope = true, punkt = 2)

    Paragraph 2 applies

    2. The ICT risk management framework shall include at least strategies, policies, procedures, ICT protocols and tools that are necessary to duly and adequately protect all information assets and ICT assets, including computer software, hardware, servers, as well as to protect all relevant physical components and infrastructures, such as premises, data centres and sensitive designated areas, to ensure that all informa…

    Punkt 2

  3. Hvis: alla(in_scope = true, punkt = 3)

    Paragraph 3 applies

    3. In accordance with their ICT risk management framework, financial entities shall minimise the impact of ICT risk by deploying appropriate strategies, policies, procedures, ICT protocols and tools. They shall provide complete and updated information on ICT risk and on their ICT risk management framework to the competent authorities upon their request.

    Punkt 3

  4. Hvis: alla(in_scope = true, punkt = 4)

    Paragraph 4 applies

    4. Financial entities, other than microenterprises, shall assign the responsibility for managing and overseeing ICT risk to a control function and ensure an appropriate level of independence of such control function in order to avoid conflicts of interest. Financial entities shall ensure appropriate segregation and independence of ICT risk management functions, control functions, and internal audit functions, accordi…

    Punkt 4

  5. Hvis: alla(in_scope = true, punkt = 5)

    Paragraph 5 applies

    5. The ICT risk management framework shall be documented and reviewed at least once a year, or periodically in the case of microenterprises, as well as upon the occurrence of major ICT-related incidents, and following supervisory instructions or conclusions derived from relevant digital operational resilience testing or audit processes. It shall be continuously improved on the basis of lessons derived from implementa…

    Punkt 5

  6. Hvis: alla(in_scope = true, punkt = 6)

    Paragraph 6 applies

    6. The ICT risk management framework of financial entities, other than microenterprises, shall be subject to internal audit by auditors on a regular basis in line with the financial entities’ audit plan. Those auditors shall possess sufficient knowledge, skills and expertise in ICT risk, as well as appropriate independence. The frequency and focus of ICT audits shall be commensurate to the ICT risk of the financial e…

    Punkt 6

  7. Hvis: alla(in_scope = true, punkt = 7)

    Paragraph 7 applies

    7. Based on the conclusions from the internal audit review, financial entities shall establish a formal follow-up process, including rules for the timely verification and remediation of critical ICT audit findings.

    Punkt 7

  8. Hvis: alla(in_scope = true, punkt = 8)

    Paragraph 8 applies

    8. The ICT risk management framework shall include a digital operational resilience strategy setting out how the framework shall be implemented. To that end, the digital operational resilience strategy shall include methods to address ICT risk and attain specific ICT objectives, by:

    Punkt 8

  9. Hvis: alla(in_scope = true, punkt = 9)

    Paragraph 9 applies

    (a)

    Punkt 9

  10. Hvis: alla(in_scope = true, punkt = 10)

    Paragraph 10 applies

    explaining how the ICT risk management framework supports the financial entity’s business strategy and objectives;

    Punkt 10

  11. Hvis: alla(in_scope = true, punkt = 11)

    Paragraph 11 applies

    (b)

    Punkt 11

  12. Hvis: alla(in_scope = true, punkt = 12)

    Paragraph 12 applies

    establishing the risk tolerance level for ICT risk, in accordance with the risk appetite of the financial entity, and analysing the impact tolerance for ICT disruptions;

    Punkt 12

  13. Hvis: alla(in_scope = true, punkt = 13)

    Paragraph 13 applies

    (c)

    Punkt 13

  14. Hvis: alla(in_scope = true, punkt = 14)

    Paragraph 14 applies

    setting out clear information security objectives, including key performance indicators and key risk metrics;

    Punkt 14

Hvis ingen regel treffer: The article is not stated to apply, or no paragraph is selected. The agent abstains rather than guesses.

Artikkelteksten som ble lest

  1. 11. Financial entities shall have a sound, comprehensive and well-documented ICT risk management framework as part of their overall risk management system, which enables them to address ICT risk quickly, efficiently and comprehensively and to ensure a high level of digital operational resilience.
  2. 22. The ICT risk management framework shall include at least strategies, policies, procedures, ICT protocols and tools that are necessary to duly and adequately protect all information assets and ICT assets, including computer software, hardware, servers, as well as to protect all relevant physical components and infrastructures, such as premises, data centres and sensitive designated areas, to ensure that all information assets and ICT assets are adequately protected from risks including damage and unauthorised access or usage.
  3. 33. In accordance with their ICT risk management framework, financial entities shall minimise the impact of ICT risk by deploying appropriate strategies, policies, procedures, ICT protocols and tools. They shall provide complete and updated information on ICT risk and on their ICT risk management framework to the competent authorities upon their request.
  4. 44. Financial entities, other than microenterprises, shall assign the responsibility for managing and overseeing ICT risk to a control function and ensure an appropriate level of independence of such control function in order to avoid conflicts of interest. Financial entities shall ensure appropriate segregation and independence of ICT risk management functions, control functions, and internal audit functions, according to the three lines of defence model, or an internal risk management and control model.
  5. 55. The ICT risk management framework shall be documented and reviewed at least once a year, or periodically in the case of microenterprises, as well as upon the occurrence of major ICT-related incidents, and following supervisory instructions or conclusions derived from relevant digital operational resilience testing or audit processes. It shall be continuously improved on the basis of lessons derived from implementation and monitoring. A report on the review of the ICT risk management framework shall be submitted to the competent authority upon its request.
  6. 66. The ICT risk management framework of financial entities, other than microenterprises, shall be subject to internal audit by auditors on a regular basis in line with the financial entities’ audit plan. Those auditors shall possess sufficient knowledge, skills and expertise in ICT risk, as well as appropriate independence. The frequency and focus of ICT audits shall be commensurate to the ICT risk of the financial entity.
  7. 77. Based on the conclusions from the internal audit review, financial entities shall establish a formal follow-up process, including rules for the timely verification and remediation of critical ICT audit findings.
  8. 88. The ICT risk management framework shall include a digital operational resilience strategy setting out how the framework shall be implemented. To that end, the digital operational resilience strategy shall include methods to address ICT risk and attain specific ICT objectives, by:
  9. 9(a)
  10. 10explaining how the ICT risk management framework supports the financial entity’s business strategy and objectives;
  11. 11(b)
  12. 12establishing the risk tolerance level for ICT risk, in accordance with the risk appetite of the financial entity, and analysing the impact tolerance for ICT disruptions;
  13. 13(c)
  14. 14setting out clear information security objectives, including key performance indicators and key risk metrics;

Opphav

treatyTFEU art. 288 (förordning)
act32022R2554
chapter
article6
paragraphs14
jurisdictionEuropean Union (EU)
supervisorFinansinspektionen — Sweden
national

Grensesnitt

callhttps://legal.exploreworldai.com/api/public/v1/agents/dora-2022-2554-6/run
methodGET
outputmatched, outcome, trace, missing, hash
Kvote60 anrop per minut och adress, utan nyckel
stabilityRegelträdet versioneras. En ändring byter artefakthash, aldrig adress.

Hasher

textsha256:91bf28528f2f64d55e4a513a432b23f23a32b4f21f9aafa7e1406a5ed416665c
scriptsha256:f14755f69bd6aadf3a182760e6d046811376c63a353d3c750d9183029ef0088a
enginesha256:0a4bd50d21f8ec9be383fc091511008b76ad61909cbfb674eab56fe567fbd7a0
agentsha256:ce00136fb4b631cbb47e7645f83003bf42720eda27ad3800d9c89fbd2ab650d4
versionagent-engine-1+legal-2026-08-25 / ce00136fb4b631cb

Artefakter

Ingen rådgivning. Deterministisk regeluppslagning. Ingen juridisk rådgivning, inget efterlevnadsbeslut, ingen bedömning av ett enskilt ärende.

Sitering: 32022R2554 art. 6, ICT risk management framework. ExploreWorld Legal, https://legal.exploreworldai.com/agent/dora-2022-2554/artikel-6 (hämtad 2026-08-18, bevis sha256:3d0b93d61bc51814, bygge legal-2026-08-25).