The DORA RTS on simplified ICT risk management describes the key elements that financial entities subject to lower scale, risk, size and complexity need to have in place to manage risks.
Related organizations shall e.g. maintain a sound and documented ICT risk management framework, continuously monitor the security and functioning of all ICT systems, identify key dependencies on ICT third-party service providers, and minimise the impact of ICT risk through the use of sound, resilient and updated protections.