DORA: digital resilience, a governance issue

DORA imposes a digital resilience framework on financial entities that places the management of IT risk, incidents, and ICT third-party providers under the direct responsibility of governance.
Cybersecurity audit: balancing risks and applicable requirements

The cyber audit must articulate an approach based on business risks, the requirements of the IIA cybersecurity framework and the DORA regulatory baseline applicable to regulated entities.