Create an assessment and enhance digital resilience data
Create an assessment of the Information and Communication Technology (ICT) service in Digital resilience third-party registers. Add details such as the contractual arrangement reference number, identification code, and type of code for the ICT third-party service provider. You can then enhance its digital resilience information for compliance with DORA regulation.
Before you begin
Role required: sn_oper_res.manager
About this task
If you have the TPRM application, you can have third-party risk management assessments. If you don't have the TPRM application, you can still comply with the regulatory requirements by using the assessments table.
It's required that you review your contracts and third parties annually. You can provide the following assessment details on the assessment form:
- Contractual reference number, which helps identify the following details:
- Users of the contract
- Providers of the contract
- Other relevant details that are automatically pulled in
- Audit information:
- Has the third-party provider been audited?
- When was the audit last conducted?
- Exit strategy details:
- Existence of an exit plan
- Possibility of integrating with the ICT service provider if terminated
- Impact assessment of discontinuing the ICT service
- Identification of any alternatives
Procedure
What to do next
Once all details are captured, you can perform the following tasks:
- Download the information using the Microsoft Excel download feature
- Upload requests as needed