Toolkit
TPL-102PolicyOperational resilienceCyber resilience

ICT risk management framework

The document the board approves under Article 6.

A complete structure covering Articles 5 to 16: governance, digital resilience strategy, quantified ICT risk tolerance, identification, protection, detection, response and recovery, backups, learning, communication. Each section states the article it satisfies.

How to use it

  • Have the management body formally approve it
  • Review at least annually and after every major incident
  • Quantify the ICT risk tolerance, do not merely describe it

Courses that use it

Related templates