Adventure Spirit d.o.o. · Zagreb, Croatia +385 95 504 1496 info@adventurespirit.hr GRC Portal
Home›The 13 measures
The 13 measures

The thirteen cyber risk management measures

The Croatian Cybersecurity Regulation (OG 135/2024) breaks the statutory duties into thirteen measures, set out across 99 sub-measures. Alongside them ZSIS published a catalogue of 132 controls with scoring thresholds for three levels of implementation. This is an overview of all thirteen, with the objective of each and what it asks for in practice.

01

Commitment and accountability of those responsible for implementing cyber risk management measures

11 sub-measures

Objective Ensure that those responsible for managing the measures treat cyber security as a core aspect of the business and take an active part in managing it, through integration into strategic plans and decisions.

What it requires in practice
  • Board decision on the cyber security policy
  • Appointment of responsible people
  • Financial, technical and human resources secured
  • Regular reporting to the board
Services covering this measure
02

Management of software and hardware assets

9 sub-measures

Objective Establish a structured approach to identifying and classifying software and hardware assets, and full control over them across the entire lifecycle, from use and storage through to deletion or destruction.

What it requires in practice
  • Inventory of software and hardware assets
  • Separate inventory of critical assets
  • Data classification
  • Rules for disposal and reuse of equipment
03

Risk management

8 sub-measures

Objective Establish an organisational framework for risk management so the entity identifies and responds to every risk threatening the security of its network and information systems.

What it requires in practice
  • Documented risk assessment process
  • All-hazards assessment approach
  • Risk register with owners
  • Risk treatment plan
04

Security of human resources and digital identities

12 sub-measures

Objective Establish a structured approach to hiring suitable people and to managing the access rights of employees and external staff to network and information systems.

What it requires in practice
  • Pre-employment checks
  • Contractual confidentiality duties
  • Lifecycle management of access rights
  • Separate administrator accounts
05

Basic cyber hygiene practices

11 sub-measures

Objective Ensure basic cyber hygiene practices are applied across all staff and all network and information systems, with regular awareness raising about cyber threats.

What it requires in practice
  • Regular patching
  • Backups with tested restore
  • Endpoint protection
  • Staff training with records
Services covering this measure
06

Securing network cyber security

5 sub-measures

Objective Ensure the integrity, confidentiality and availability of the entity's network resources.

What it requires in practice
  • Network segmentation
  • Perimeter protection
  • Network traffic monitoring
  • Secure network device configuration
Services covering this measure
07

Physical and logical access control to network and information systems

6 sub-measures

Objective Establish a comprehensive set of policies and procedures for controlling physical and logical access to network and information systems.

What it requires in practice
  • Least privilege
  • Multi-factor authentication
  • Privileged access management
  • Access records
08

Supply chain security

6 sub-measures

Objective Establish a clear and comprehensive policy for direct suppliers and service providers, with assessment of the risks arising from those relationships.

What it requires in practice
  • Minimum security requirements for suppliers
  • Contractual security clauses
  • Third-party risk assessment
  • Monitoring over time
09

Security in the development and maintenance of network and information systems

6 sub-measures

Objective Ensure the entity establishes, documents and continuously applies security requirements in the acquisition, development and maintenance of network and information systems.

What it requires in practice
  • Security requirements in development
  • Separated development, test and production environments
  • Change management
  • Testing before go-live
10

Cryptography

6 sub-measures

Objective Establish a comprehensive framework for the use of cryptography, in line with business needs and assessed risk.

What it requires in practice
  • Rules on the use of cryptography
  • Protection of data in transit
  • Protection of data at rest
  • Cryptographic key management
11

Incident handling

6 sub-measures

Objective Establish a comprehensive framework defining roles, responsibilities and procedures for detecting, responding to and reporting incidents.

What it requires in practice
  • Incident significance criteria
  • Incident response plan
  • Notification to the competent CSIRT within deadlines
  • Post-incident analysis
12

Business continuity and cyber crisis management

8 sub-measures

Objective Ensure that plans exist in advance to minimise the consequences of disruption and to recover the business after an incident or crisis.

What it requires in practice
  • Business impact analysis
  • Continuity and recovery plans
  • Cyber crisis management
  • Regular exercising of plans
13

Physical security

5 sub-measures

Objective Establish measures to prevent and monitor unauthorised physical access to areas holding network and information systems, and to protect them from environmental threats.

What it requires in practice
  • Entry control to equipment areas
  • Fire and water protection
  • Power and cabling security
  • Premises monitoring

Measure names and objectives are taken from Annex II of the Regulation and from Annex B of the ZSIS evaluation framework. The sub-measure count was taken from the same document and totals 99. The control catalogue contains 132 unique identifiers. Check which version of the framework is current before a formal self-assessment.

Not sure where you stand?

Half an hour of conversation, with no obligation. By the end you know what needs doing and in what order.