This training entitles the participant to a certificate of participation issued by an approved professional training organisation under the number 10060172/3.
Goals
- Understand the key ICT and security risk management requirementsunder DORA and the applicable CSSF framework for both DORA and non-DORA entities.
- Identify the main components of an ICT risk management framework, from governance and ICT third-party risk management to identification, protection and detection.
- Understand the operational resilience mechanisms required to support business continuity, incident response and recovery, and structured crisis communication.
Program
- Governance & Digital Operational Resilience Strategy
- Management body responsibilities
- ICT risk management framework
- ICT risk tolerance
- Digital operational resilience strategy
- Managing ICT Third-Party Risk
- ICT third-party risk management
- Provider due diligence and monitoring
- Concentration risk
- Register of information
- Contractual requirements, audit rights and exit strategies
- ICT & Security Risk Management Framework
- Framework structure, documentation and review
- Protection and prevention
- Identity and Access Management
- Change and patch management
- Network security, cryptography and data protection
- Detection of anomalous activities and alert management
- Identifying Functions, Processes & Information Assets
- Identification and classification of ICT-supported business functions
- Mapping of dependencies
- Inventory and classification of information and ICT assets
- ICT risk assessment
- Legacy systems risk management
- Business Continuity, Response, Recovery & Backup
- ICT Business Continuity Policy
- ICT response and recovery plans
- RTOs and RPOs
- Business continuity testing
- Backup, restoration and redundancy
- Post-incident reviews and lessons learned
- Crisis communication
- Internal and external communication during ICT incidents
- Responsible disclosure
- Communication roles and responsibilities
- Crisis communication plan
- Coordination with incident reporting and the BCP
- Crisis communication testing and exercises
Duration
- 1h30
Language
- French/English
Practicalities
- Access sent within 24 hours
- 100% online training accessible from computer, tablet and smartphone
- Certificate of participation issued by an approved professional training organisation under the number 10060172/3.
Knowledge check
- Knowledge validation test at the end of each chapter
Learning method and pedagogy
- Theoretical presentations & practical cases
- Quizzes
- Animations, diagrams & summaries
Group discounts
Send your request by email to constance@easylearning.eu
- Between 11 and 25 accesses: 10 % discount + free reporting
- Between 26 and 50 accesses: 15% discount + free reporting
- Between 51 and 100 accesses: 20% discount + free reporting
- 100+ accesses: Ask for a tailor-made offer
Personalisation (Ask for a quote)
- Add your logo to the course
- Add your internal documents (procedure, risk analysis, etc.)
- Add practical case studies specific to your sector
- Creation of tailor-made training courses

