Annex to the ActAnnex I - high-criticality sector
Competent CSIRTNational Cyber Security Centre (NCSC-HR)
The measures that carry most of the work in this sector
02Asset management
Networked medical devices are assets, and are rarely in the IT inventory.
10Cryptography
Health data is a special category under the GDPR and requires protection in transit and at rest.
11Incident handling
An incident involving health data almost always triggers a parallel 72-hour notification to the data protection authority.
12Business continuity
Unavailability of a hospital system is not commercial damage but a risk to patients.
What we most often find
- Networked medical devices absent from the asset inventory
- Shared ward accounts with no link to a person
- Backups reachable from the same network ransomware spreads through
- A continuity plan with no procedure for working without the information system
Check for yourself
Tri alata koja rade u pregledniku, bez registracije:
Entity categorisation check
Incident reporting deadline calculator
Readiness check against the 13 measures
Not sure where you stand?
Half an hour of conversation, with no obligation. By the end you know what needs doing and in what order.