Skip to content

RTS (EU) 2024/1774 – ICT Risk Management

PropertyValue
NumberDelegated Regulation (EU) 2024/1774
DORA ArticleArt. 15 (empowerment)
PillarP1 – ICT Risk Management
Publication25.06.2024 (Official Journal of the EU)
Applicable since17.01.2025
EUR-LexLink

Content

The RTS specifies the complete ICT risk management framework including:

  • Governance – Roles, responsibilities, reporting lines
  • ICT asset inventory – Identification, classification, documentation
  • Risk assessment – Methodology, thresholds, updates
  • Security controls – Access control, cryptography, network security
  • BCP/DRP – Business continuity, disaster recovery, RPO/RTO
  • Simplified framework – For microenterprises under Art. 16

Policies (Minimum Content)

The RTS defines minimum content for the following policies:

  1. ICT security policy
  2. Access control policy (incl. MFA, PAM)
  3. Cryptography policy
  4. ICT project management policy (SDLC security)
  5. ICT procurement policy
  6. Physical security policy
  7. Capacity management policy
  8. ICT change management policy

BAUER GROUP Relevance

As an ICT service provider, BAUER GROUP must be able to demonstrate that its own internal processes comply with these standards – particularly in response to audit requests from financial sector clients.

→ Implementation details: P1: ICT Risk Management

Documentation licensed under CC BY-NC 4.0 · Code licensed under MIT