The thirteen cyber risk management measures
The Croatian Cybersecurity Regulation (OG 135/2024) breaks the statutory duties into thirteen measures, set out across 99 sub-measures. Alongside them ZSIS published a catalogue of 132 controls with scoring thresholds for three levels of implementation. This is an overview of all thirteen, with the objective of each and what it asks for in practice.
Commitment and accountability of those responsible for implementing cyber risk management measures
11 sub-measuresObjective Ensure that those responsible for managing the measures treat cyber security as a core aspect of the business and take an active part in managing it, through integration into strategic plans and decisions.
- Board decision on the cyber security policy
- Appointment of responsible people
- Financial, technical and human resources secured
- Regular reporting to the board
Management of software and hardware assets
9 sub-measuresObjective Establish a structured approach to identifying and classifying software and hardware assets, and full control over them across the entire lifecycle, from use and storage through to deletion or destruction.
- Inventory of software and hardware assets
- Separate inventory of critical assets
- Data classification
- Rules for disposal and reuse of equipment
Risk management
8 sub-measuresObjective Establish an organisational framework for risk management so the entity identifies and responds to every risk threatening the security of its network and information systems.
- Documented risk assessment process
- All-hazards assessment approach
- Risk register with owners
- Risk treatment plan
Security of human resources and digital identities
12 sub-measuresObjective Establish a structured approach to hiring suitable people and to managing the access rights of employees and external staff to network and information systems.
- Pre-employment checks
- Contractual confidentiality duties
- Lifecycle management of access rights
- Separate administrator accounts
Basic cyber hygiene practices
11 sub-measuresObjective Ensure basic cyber hygiene practices are applied across all staff and all network and information systems, with regular awareness raising about cyber threats.
- Regular patching
- Backups with tested restore
- Endpoint protection
- Staff training with records
Securing network cyber security
5 sub-measuresObjective Ensure the integrity, confidentiality and availability of the entity's network resources.
- Network segmentation
- Perimeter protection
- Network traffic monitoring
- Secure network device configuration
Physical and logical access control to network and information systems
6 sub-measuresObjective Establish a comprehensive set of policies and procedures for controlling physical and logical access to network and information systems.
- Least privilege
- Multi-factor authentication
- Privileged access management
- Access records
Supply chain security
6 sub-measuresObjective Establish a clear and comprehensive policy for direct suppliers and service providers, with assessment of the risks arising from those relationships.
- Minimum security requirements for suppliers
- Contractual security clauses
- Third-party risk assessment
- Monitoring over time
Security in the development and maintenance of network and information systems
6 sub-measuresObjective Ensure the entity establishes, documents and continuously applies security requirements in the acquisition, development and maintenance of network and information systems.
- Security requirements in development
- Separated development, test and production environments
- Change management
- Testing before go-live
Cryptography
6 sub-measuresObjective Establish a comprehensive framework for the use of cryptography, in line with business needs and assessed risk.
- Rules on the use of cryptography
- Protection of data in transit
- Protection of data at rest
- Cryptographic key management
Incident handling
6 sub-measuresObjective Establish a comprehensive framework defining roles, responsibilities and procedures for detecting, responding to and reporting incidents.
- Incident significance criteria
- Incident response plan
- Notification to the competent CSIRT within deadlines
- Post-incident analysis
Business continuity and cyber crisis management
8 sub-measuresObjective Ensure that plans exist in advance to minimise the consequences of disruption and to recover the business after an incident or crisis.
- Business impact analysis
- Continuity and recovery plans
- Cyber crisis management
- Regular exercising of plans
Physical security
5 sub-measuresObjective Establish measures to prevent and monitor unauthorised physical access to areas holding network and information systems, and to protect them from environmental threats.
- Entry control to equipment areas
- Fire and water protection
- Power and cabling security
- Premises monitoring
Measure names and objectives are taken from Annex II of the Regulation and from Annex B of the ZSIS evaluation framework. The sub-measure count was taken from the same document and totals 99. The control catalogue contains 132 unique identifiers. Check which version of the framework is current before a formal self-assessment.
Not sure where you stand?
Half an hour of conversation, with no obligation. By the end you know what needs doing and in what order.