Annex to the ActAnnex I - high-criticality sector
Competent CSIRTNational Cyber Security Centre (NCSC-HR)
The measures that carry most of the work in this sector
01Commitment and accountability
The contact person must be an official or executive body member, not from IT.
02Asset management
Data delivery to NCSC-HR also requires the IP address ranges the entity uses.
04Digital identities
Large user numbers, frequent role changes and long-lived access rights.
11Incident handling
Access to the PiXi platform runs through the national identification system and must be sorted before an incident.
What we most often find
- A contact person appointed from IT instead of the management body
- An incomplete list of the IP ranges the body uses
- Access rights that persist after an internal transfer
- Nobody has access to the incident reporting platform
Check for yourself
Tri alata koja rade u pregledniku, bez registracije:
Entity categorisation check
Incident reporting deadline calculator
Readiness check against the 13 measures
Not sure where you stand?
Half an hour of conversation, with no obligation. By the end you know what needs doing and in what order.