← Toolkit
TPL-102PolicyOperational resilienceCyber resilience
ICT risk management framework
The document the board approves under Article 6.
A complete structure covering Articles 5 to 16: governance, digital resilience strategy, quantified ICT risk tolerance, identification, protection, detection, response and recovery, backups, learning, communication. Each section states the article it satisfies.
How to use it
- Have the management body formally approve it
- Review at least annually and after every major incident
- Quantify the ICT risk tolerance, do not merely describe it
Courses that use it
Related templates
TPL-050
Important business services register
Client-side phrasing, owner, tolerance, measured capability, gap.
TPL-051
Annual resilience self-assessment
The document the board approves and the supervisor requests.
TPL-052
End-to-end dependency map
Six layers, one row per dependency, sortable by substitutability.
TPL-053
Single point of failure register
Qualification, treatment or explicit acceptance, with review date.