Cybersecurity requirements
Measures to manage the risks
Essential and important entities should take appropriate and proportionate technical, operational and organisational measures to manage the cybersecurity risks they face and prevent or minimise the impact of incidents on their services and on third-party services.
Such measures shall be based on all-risk planning aimed at protecting the network and information systems and their physical environment, including at least the following measures:
- Risk analysis and system security processes.
- Incident handling procedures.
- Business continuity, such as backup management and disaster recovery, and crisis management.
- Supply chain security
- Secure network and information systems, including the management and disclosure of vulnerabilities.
- Policies and procedures for assessing the effectiveness of cybersecurity risk management measures.
- Cyber hygiene practices and cybersecurity training
- Data security through cryptography and encryption
- Human resources security, access control policies and asset management.
- Improved identification and authentication.