Under active development Content is continuously updated and improved

Article 24.3Article 24.3

>Control Description

When conducting the digital operational resilience testing programme referred to in paragraph 1 of this Article, financial entities, other than microenterprises, shall follow a risk-based approach taking into account the criteria set out in Article 4(2) duly considering the evolving landscape of ICT risk, any specific risks to which the financial entity concerned is or might be exposed, the criticality of information assets and of services provided, as well as any other factor the financial entity deems appropriate.

>Cross-Framework Mappings

Ask AI

Configure your API key to use AI features.