- Question ID
-
DORA272
- Topic
- ICT risk management
- Subject matter
-
Scope of the regulation
- Question
-
Why are the outsourcing requirements of Article 28(3) RTS (S)RMF concerning the simplified ICT risk management framework (Art. 16 DORA) more stringent than those of the regular ICT risk management framework? Would an alignment of Art. 6(10) DORA and Art. 28(3) RTS (S)RMF concerning this point be feasible?
- Final publishing date
-
- Receiving ESA
-
EIOPA
- URL