
Regulation
DORA
Reg. (EU) 2022/2554, Art. 9(4)(c)
Hold physical and logical access to information and ICT assets down to what legitimate, approved functions and activities actually require, and run the access rights behind that on a proper set of policies, procedures and controls.

