Adventure Spirit d.o.o. · Zagreb, Croatia +385 95 504 1496 info@adventurespirit.hr GRC Portal
Home›Tools›Readiness check against the 13 measures
Tools

Readiness check against the 13 measures

Thirteen questions, one per measure of Annex II of the Croatian Cybersecurity Regulation. Not a substitute for the formal self-assessment against the ZSIS scoring framework, but it shows where you stand and what comes first.

For each measure choose the statement that best describes the actual state, not the intended one.

01Has the board formally adopted a cybersecurity policy, appointed responsible people and does it receive regular reports?

Commitment and accountability of those responsible for implementing cyber risk management measures · The board approves, appoints, provides resources and reviews. Without that the other measures have no owner.

02Is there a current inventory of software and hardware assets, with critical assets identified and data classified?

Management of software and hardware assets · The inventory is a precondition for risk assessment, monitoring and almost every other measure.

03Is there a documented risk assessment process, with a risk register, owners and a treatment plan?

Risk management · The Regulation requires an all-hazards approach, not just information threats.

04How do you manage access rights across the full lifecycle of employees and external staff?

Security of human resources and digital identities · From hiring and contractual duties through to revoking rights on departure, with separate administrator accounts.

05How do you stand on basic hygiene - patching, backups, endpoint protection and staff training?

Basic cyber hygiene practices · The measure with the most sub-measures after identity management, and the one that reduces real risk most.

06Is the network segmented, is the perimeter protected and is traffic monitored?

Securing network cyber security · Segmentation is the highest-return control because it limits reach without touching individual systems.

07Is least privilege applied, and multi-factor authentication on exposed interfaces?

Physical and logical access control to network and information systems · Particularly on remote access, email and administrator accounts.

08Do you set security requirements for suppliers and assess third-party risk?

Supply chain security · Contractual clauses, questionnaires, assessment and monitoring over time.

09Are there security requirements in system development and maintenance, with change management?

Security in the development and maintenance of network and information systems · Separated environments, testing before go-live, secure coding rules that also apply to acquired software.

10Do you have rules on cryptography, protection of data in transit and at rest, and key management?

Cryptography · The Regulation also asks you to consider quantum-resistant cryptography proportionate to assessed risk.

11Is there an incident response plan, a significance criterion and an established process for notifying the competent CSIRT?

Incident handling · The deadlines are 24 hours, 72 hours and 30 days, running from awareness. The process must exist before the incident.

12Is there a business impact analysis, continuity and recovery plans, and have they been exercised?

Business continuity and cyber crisis management · A plan that has never been exercised documents intent, not capability.

13Is physical access to areas holding equipment controlled, with fire, water and power protection?

Physical security · A standalone measure with its own sub-measures, not part of a wider control set.

The tool runs entirely in your browser. Your answers do not reach our server.

This is an informative maturity assessment, not a formal self-assessment. The formal self-assessment follows the ZSIS scoring framework, where each of the 13 measures is broken into 99 sub-measures and a catalogue of 132 controls, with a threshold per control and an additional average threshold per sub-measure. This tool gives one score per measure and serves for rough orientation.

How the formal self-assessment is scored →