Bibba TechBibba Tech
Powered byBibba TechBibba Tech© 2026 -DISCLAIMER
0 / 66 complete0%
Summary
← Back to home

Pillars

1. Governance and Organisation0/42. ICT Risk Management Framework0/53. ICT Systems, Protocols and Tools0/34. Identification0/45. Protection and Prevention0/86. Detection0/37. Response and Recovery0/48. Backup and Recovery0/39. Learning and Evolving0/310. Communication0/2

Complete Partial Untouched

Governance and Organisation

Pillar 1
Arts. 5–16

Art. 16 provides a simplified ICT risk management framework for qualifying small and non-interconnected entities. It is addressed via the proportionality setting on this assessment, rather than as separate measures below.

Pillar 1 - ICT Risk Management

Governance and Organisation

0/39

DORA.GV-1

1. Management body accountability for ICT risk management

Documentation

Implementation

DORA.GV-2

2. ICT risk management roles and responsibilities

Documentation

Implementation

DORA.GV-3

3. Budget allocation for digital operational resilience

Documentation

Implementation

DORA.GV-4

4. Management body training and awareness on ICT risks

Documentation

Implementation

Maturity Scale

Score every question twice

Target: ≥ 3/5 for all categories

Documentation

Implementation

1
Initial

No process documentation or not formally approved by management.

Standard process does not exist. Actions are ad hoc and undocumented.

2
Repeatable

Formally approved process documentation exists but has not been reviewed in the previous 2 years.

Ad-hoc process exists and is performed informally. Results are inconsistent.

3
Defined

Formally approved process documentation exists; exceptions are documented and approved and make up less than 5% of activities.

Formal process exists and is implemented. Evidence available for most activities. Less than 10% process exceptions.

4
Managed

Formally approved process documentation exists; exceptions are documented and approved. Documented & approved less than 3% of activities.

Formal process fully implemented. Evidence available for all activities. Detailed metrics captured and reported. Less than 5% process exceptions.

5
Optimising

Formally approved process documentation exists; exceptions are documented and approved. Documented & approved less than 0.5% of activities.

Formal process fully implemented and continually improving. Minimal exceptions (<1%). Process improvements tracked and evidenced.