Guide
DORA: mapping your ICT third parties
The register to produce, criticality criteria, and contractual requirements.
The minimum register
- Legal name, LEI, country of headquarters
- Description of the ICT service provided
- Function supported and criticality
- Location of processing and storage
- Subcontractors (chain of subcontractors)
- Date of last assessment
Criticality criteria
- Impact on critical or important functions
- Substitutability of the provider
- Complexity of the relationship
- Volume and sensitivity of data
Use this resource in BeeLink
Create your organization and import this template into your compliance workspace in one click.
Create an accountIn the same category
Getting started with ISO 27001 in 30 days
A concrete, week-by-week plan to lay the foundations of an ISO 27001:2022-compliant ISMS.
nFADP: what really changes
The 12 structural changes between the old FADP (1992) and the new Act (2023).
FINMA Circ. 2023/1 for non-lawyers
A plain-language breakdown of the operational risks and resilience circular.