RISKORIA ADVISING & PROFESSIONAL SERVICES D.O.O. · ZAGREB+385 97 737 1345INFO@RISKORIA.EU

The thirteen measures, all in one place

The measures are set out in Annex II of Regulation NN 135/2024. The basic, medium and advanced levels are determined by the national risk assessment during categorisation, under Article 38 of the Regulation, not by the entity category.

LEGAL FRAMEWORKZKS NN 14/2024REGULATION NN 135/2024, ANNEX IINIS2 EU 2022/2555

Thirteen measures, 99 sub-measures, 137 controls

The thirteen risk management measures are broken down into 99 sub-measures, matched by 137 controls from the catalogue of the Information Systems Security Bureau. What is binding differs across the three levels, basic, medium and advanced. Of the 99 sub-measures, 59 are binding at the basic level, 80 at the medium level and 87 at the advanced level. The rest are voluntary or binding subject to a condition. Every control requires written evidence, and scoring follows the methodology of the Information Systems Security Bureau. The deadline for implementation is twelve months from delivery of the categorisation notice, under Article 26(5) of the Act.

How to read the tables

Each measure is broken down into sub-measures. For every sub-measure the table shows whether it is binding at the basic, medium and advanced level, and which controls from the ZSIS control catalogue the auditor checks alongside it, by their code.

OBLIGATION

A
Binding sub-measure at that level.
B
Binding subject to a condition Annex II sets out with the measure. The condition is stated below the relevant table.
C
Voluntary sub-measure. Implemented according to the entity’s risk assessment, and additionally credited in self-assessment and audit.

LEVELS AND CONTROLS

BAS
Basic level.
MED
Medium level.
ADV
Advanced level.
CONTROLS
Codes of the controls from the ZSIS control catalogue checked alongside that sub-measure.

The same catalogue control serves several sub-measures, for example NAD-002 sits with sub-measure 5.4 and with sub-measure 5.6. The CONTROLS column therefore holds 240 entries in total, while the number of unique controls is 137.

Jump to a measure

The thirteen measures of Annex II, each with its sub-measures.

01

Commitment and accountability of those responsible for implementing the measures

Cyber security becomes a management topic, not just an IT topic.

The Regulation requires the management body to adopt a strategic cyber security policy, provide the money, people and equipment to carry it out, assign roles and responsibilities, and receive an annual report on the state of cyber security. The evidence is not a slide deck but a decision, a set of minutes and a signature. From the medium level onwards it also requires separating roles that could create a conflict of interest and appointing a person operationally responsible for cyber security.

IDSUB-MEASUREBASMEDADVCONTROLS
1.1Strategic cyber security policy, adopted by the management body and reviewed annuallyBASAMEDAADVAPOL-001, ORG-001
1.2Making all employees and relevant third parties aware of the policyBASAMEDAADVAEDU-001, EDU-002
1.3Providing resources for implementation: financial, technical and human, assessed annuallyBASAMEDAADVARES-001, RES-003
1.4Establishing and maintaining cyber security roles and responsibilitiesBASAMEDAADVAORG-001, ORG-002
1.5Separating roles that could result in a conflict of interestBASCMEDAADVAPOL-002
1.6Appointing a person operationally responsible for cyber securityBASCMEDAADVAORG-003
1.7Annual reporting to the responsible persons on the state of cyber securityBASAMEDAADVAPOL-012
1.8Security metrics on the state of cyber securityBASCMEDAADVANAD-001
1.9Awareness raising for responsible persons through workshops, seminars and trainingBASCMEDAADVAEDU-001, EDU-003, EDU-004
1.10Mechanisms for responsible persons to take part in cyber security initiativesBASCMEDCADVAUPR-001
1.11Monitoring key indicators in near real timeBASCMEDCADVCNAD-002, NAD-003, NAD-004
02

Software and hardware asset management

You cannot protect what you do not know you have.

This measure requires an inventory of critical software and hardware assets with an identifier, location and owner, a list of critical data, and rules for removable media and for equipment used outside the entity's premises. The inventory has to be a living record. A table compiled once and then forgotten is spotted immediately during an audit, because it no longer matches what is actually in the server room.

IDSUB-MEASUREBASMEDADVCONTROLS
2.1Asset management rules and responsibilities, and criteria for the critical asset inventoryBASAMEDAADVAINV-001, INV-002, INV-003
2.2Detailed inventory of critical assets with identifier, location and ownerBASAMEDAADVAINV-004
2.3Identifying the entity's critical dataBASAMEDAADVAPOD-001, INV-002
2.4Rules for removable media holding critical dataBASAMEDAADVAPOD-003, POD-004, KRIP-004
2.5Responsibilities for critical assets used outside the entity's premisesBASAMEDAADVAINV-006
2.6Extending the inventory to less critical assetsBASCMEDAADVAINV-007, RIZ-008
2.7Regular updating of the critical asset inventoryBASCMEDAADVAINV-008
2.8Secure disposal and transport of assets holding critical dataBASCMEDCADVAPOD-005, POD-006, POD-007
2.9Physical identification and labelling of assetsBASCMEDCADVAINV-005
03

Risk management

What is required is a process, not a single document.

The entity must describe how a risk is identified, how it is assessed, who owns it and what is done about it. The assessment follows an all hazards approach, so it covers fire, failure and human error, not just attacks. The result is kept in a risk register updated at least once a year.

CONDITION FROM ANNEX IISub-measure 3.8 is binding for an entity that already runs enterprise risk management. In that case sub-measures 3.1 to 3.7 are carried out within that framework.

IDSUB-MEASUREBASMEDADVCONTROLS
3.1Risk management process: assessment, level and criticality, treatment, risk owners, annual updateBASAMEDAADVAPOL-006
3.2Risk assessment of critical assets following an all hazards approachBASAMEDAADVAINV-004, RIZ-001, RIZ-002, RIZ-003
3.3Documenting identified risks and defining risk responsesBASAMEDAADVARIZ-004, RIZ-005
3.4Methods for risk analysis and assessment, and risk reportingBASAMEDAADVARIZ-006, RIZ-007
3.5Register of identified risksBASAMEDAADVARIZ-009
3.6Risk assessment when introducing solutions that increase exposureBASCMEDAADVARIZ-004, RIZ-007, RIZ-010
3.7Advanced software tools for risk assessment and monitoringBASCMEDCADVCRIZ-011
3.8Integration into enterprise risk managementBASBMEDBADVBRIZ-012
04

Human resources security and digital identities

It joins up HR records and access rights, which in practice are usually kept apart.

The measure requires verification of candidates' qualifications before hiring, documented training for people with security duties, regular cyber hygiene training for everyone, and disciplinary measures for breaking the rules. On the other side sit unique digital identities, rights assigned by job role on a need to know and least privilege basis, and timely removal of access when someone leaves or changes post.

IDSUB-MEASUREBASMEDADVCONTROLS
4.1Human resources security rules, including external staffBASAMEDAADVAEDU-001, EDU-002, ORG-001, ORG-002
4.2Verification of candidates' suitability and qualifications before hiringBASAMEDAADVARES-004, ORG-001
4.3Documented training for employees with security dutiesBASAMEDAADVAEDU-003, EDU-006
4.4Regular cyber hygiene training for all employeesBASAMEDAADVAEDU-001, EDU-003, EDU-007
4.5Disciplinary measures for failing to follow cyber security rulesBASAMEDAADVAORG-004
4.6Unique digital identities for all usersBASAMEDAADVADID-001, DID-002
4.7Rights by job role, on need to know, least privilege and segregation of dutiesBASAMEDAADVAORG-001, ORG-002, ORG-005, POL-002
4.8Timely granting, changing and revoking of digital identitiesBASAMEDAADVADID-001, DID-003
4.9Incident response training for key personnelBASCMEDAADVAEDU-006, EDU-008
4.10Remote digital learning systems for staff training and certificationBASCMEDAADVAEDU-009
4.11Social engineering testing and phishing simulationsBASCMEDCADVCEDU-003, EDU-007, EDU-010
4.12Integration of the HR system with identity and access managementBASCMEDCADVADID-003, DID-004, DID-005, DID-006
05

Basic cyber hygiene practices

The largest measure, and the one most visible in day to day work.

This is where passwords, multi-factor sign-in, anti-virus, patching, logging and regular vulnerability scanning sit. Logs are kept for at least ninety days and systems must have synchronised time so that logs can be correlated. All of the above is binding from the basic level onwards; central log storage, blocking known malicious sites and reducing the attack surface become binding only at the medium level.

CONDITION FROM ANNEX IISub-measure 5.7 is binding if the entity uses software it develops itself. Sub-measures 5.1 to 5.11 apply in full to IT systems; for operational technology all apply except 5.4, which depends on a risk assessment.

IDSUB-MEASUREBASMEDADVCONTROLS
5.1Basic cyber hygiene rules and user educationBASAMEDAADVAEDU-007, POL-008
5.2Password policy: at least 14 characters where multi-factor sign-in is not used, 16 for privileged and 24 for service accountsBASAMEDAADVAPOL-004, POL-005
5.3Multi-factor authenticationBASAMEDAADVADID-007, POL-004, POL-005
5.4Anti-virus on workstations and servers, with advanced protection subject to risk assessmentBASAMEDAADVARES-002, NAD-002, SKM-001, SKM-002, RIZ-010
5.5Timely and complete application of security patchesBASAMEDAADVARIZ-010, RIZ-013, SKM-003
5.6Logging of sign-ins and activity, retained at least 90 days, with synchronised timeBASAMEDAADVANAD-002, NAD-012, NAD-013, EDU-005, DID-006
5.7Vulnerability identification and management for in-house developmentBASCMEDBADVBSRZ-001, SKM-005
5.8Periodic vulnerability scanning of all systemsBASAMEDAADVARIZ-004, SKM-004, SKM-005
5.9Central storage of security relevant logsBASCMEDAADVANAD-015, NAD-016, DID-006
5.10Controls that block or detect access to known malicious websitesBASCMEDAADVANAD-005
5.11Reducing the attack surface: fewer publicly exposed services and privileged accountsBASCMEDAADVANAD-006, SKM-008, DID-010
06

Securing the network

The network is divided so that a breach in one part is not a breach of everything.

This requires a documented network architecture with protective measures, separation and segmentation, monitoring of network use and network accessible resources, and an annual comprehensive review of those measures. The measure has only five sub-measures but is among the more expensive in practice, because segmentation usually means reworking an existing network.

CONDITION FROM ANNEX IISub-measures 6.1, 6.3 and 6.5 apply in full to operational technology as well. Sub-measure 6.2 depends on a further assessment of data criticality in the OT environment, and 6.4 on assessing the effect of automatic blocking on the operation and safety of those systems.

IDSUB-MEASUREBASMEDADVCONTROLS
6.1Protective measures matched to the network architecture, separation and segmentationBASAMEDAADVAPOL-007
6.2Mandatory network protection measures and monitoring of network accessible resourcesBASAMEDAADVANAD-008, DID-008
6.3Annual comprehensive review of all network protection measuresBASAMEDAADVANAD-014
6.4Mechanisms for monitoring inbound and outbound network trafficBASCMEDAADVANAD-009
6.5Technical mechanisms for detecting network anomaliesBASCMEDCADVANAD-002, NAD-003, NAD-009
07

Physical and logical access control

Who may enter a room and who may enter an application are governed by the same rules.

Every application has an owner who approves user rights, rights are reviewed at least once a year, and privileged and administrator accounts have dedicated procedures and monitoring. The more advanced sub-measures, dynamic access control and user behaviour analytics, remain voluntary at all three levels.

IDSUB-MEASUREBASMEDADVCONTROLS
7.1Physical and logical access rulesBASAMEDAADVADID-001, DID-003, DID-005, ORG-005, RIZ-001, RIZ-003
7.2Application owners and approval of user rightsBASAMEDAADVAORG-005, DID-003, DID-009, NAD-012
7.3Review of user access rights at least once a yearBASAMEDAADVADID-003
7.4Monitoring access to critical systems and procedures for privileged accountsBASAMEDAADVADID-010
7.5Dynamic, risk based access control in real timeBASCMEDCADVCDID-011
7.6Advanced user behaviour analyticsBASCMEDCADVCNAD-010, NAD-013
08

Supply chain security

Responsibility does not stop at the front door.

This requires a list of all direct suppliers and service providers, security clauses in contracts covering the right to audit, vulnerability management and competence requirements, and regular checks on how suppliers meet them. It is the measure most likely to mean reopening existing contracts, so it pays to start earlier than seems necessary.

IDSUB-MEASUREBASMEDADVCONTROLS
8.1Supply chain security rulesBASAMEDAADVARIZ-003, RIZ-014
8.2Identification of all direct suppliers and service providersBASAMEDAADVARIZ-003, RIZ-015
8.3Security clauses in contracts: right to audit, vulnerability management, competenceBASAMEDAADVARIZ-016
8.4Monitoring, auditing and repeating supply chain checksBASAMEDAADVARIZ-014, RIZ-017
8.5Criteria and security requirements for selecting suppliers and awarding contractsBASCMEDAADVARIZ-018
8.6Incident response plans that include suppliers and service providersBASCMEDAADVAPOL-009, RIZ-015
09

Security in the development and maintenance of network and information systems

The focus is on system configuration across the whole life cycle.

Systems must have an established, documented and continuously monitored configuration, including the security settings of all software and hardware assets and of the external services and networks in use. Security requirements must also enter the technical specification and the procurement stage, and every change needs categorisation, approval and a rollback path.

CONDITION FROM ANNEX IISub-measures 9.4 and 9.5 are binding for entities that develop or maintain network and information systems themselves.

IDSUB-MEASUREBASMEDADVCONTROLS
9.1Analysis of security requirements in technical specifications and procurementBASAMEDAADVASRZ-002, SRZ-003, RIZ-010
9.2Configuration management across the life cycle, including external services and networksBASAMEDAADVASKM-006
9.3Change management: categorisation, priorities, approvals and rollbackBASAMEDAADVASKM-006, SKM-007
9.4Secure development rules, threat modelling and penetration testingBASCMEDBADVBSRZ-001, SRZ-002, SRZ-003, NAD-007, SKM-005
9.5Secure development practices and code reviewBASCMEDBADVBSRZ-001, SRZ-003
9.6Embedding security tools and processes into development operationsBASCMEDCADVCSRZ-001, SRZ-003, SKM-006, SKM-007
10

Cryptography

A written rule on when and how critical data is protected.

Critical data must be protected both in transit and at rest, under rules covering authenticity, integrity and confidentiality. In practice the sticking point is key management, because it is rarely written down anywhere, and the auditor asks for exactly that record: who issues the key, where it is held and how it is revoked.

IDSUB-MEASUREBASMEDADVCONTROLS
10.1Rules on using cryptography for authenticity, integrity and confidentiality of critical dataBASAMEDAADVAKRIP-001, RIZ-004
10.2Encryption of critical data in transitBASAMEDAADVAKRIP-002
10.3Secure cryptographic key managementBASAMEDAADVAKRIP-003
10.4Encryption of critical data at restBASAMEDAADVAKRIP-004
10.5Regular review and updating of cryptographic rulesBASCMEDAADVAKRIP-001
10.6Quantum resistant cryptography, subject to assessed riskBASCMEDCADVCKRIP-005
11

Incident handling

The procedure has to exist before the incident does.

It must be clear who triages a suspicious event, within what deadline it is reported internally, who decides and who notifies the competent CSIRT. Under the Regulation an early warning goes out without delay and no later than 24 hours after becoming aware, an initial notification within 72 hours, and a final report within 30 days of the initial notification. Trust service providers submit the initial notification within 24 hours.

IDSUB-MEASUREBASMEDADVCONTROLS
11.1Developing and documenting incident handling proceduresBASAMEDAADVAPOL-009, POL-010
11.2Basic handling procedures, including suppliers and service providersBASAMEDAADVAPOL-010, POL-011, UPR-003, UPR-004, UPR-005, UPR-006, UPR-007, UPR-008, UPR-009, UPR-010
11.3Training employees to recognise and report suspicious eventsBASAMEDAADVAEDU-007, EDU-008
11.4Detailed monitoring, analysis and response procedures, with internal reporting deadlines and triage rulesBASAMEDAADVAPOL-010, UPR-003, UPR-008, UPR-010, UPR-011
11.5Annual simulated incident exercisesBASCMEDAADVAPOL-010, UPR-009, UPR-012, EDU-008
11.6Specialised tools for automated detection and responseBASCMEDAADVANAD-011, NAD-012, UPR-011
12

Business continuity and cyber crisis management

The question is not whether a system will stop but how long it may stay down.

A business impact analysis sets the recovery objectives: how much data may be lost and how long a service may be unavailable. Recovery and continuity plans describe how those objectives are met, and backups have to be verified, not merely taken. From the medium level plans are tested at least once a year.

CONDITION FROM ANNEX IISub-measure 12.6 becomes binding at the request of the competent authorities.

IDSUB-MEASUREBASMEDADVCONTROLS
12.1Business continuity and crisis management policiesBASAMEDAADVAUPR-002, UPR-018
12.2Business impact analysis, setting recovery objectivesBASAMEDAADVAUPR-004, ORG-006
12.3Cyber crisis management processesBASAMEDAADVAUPR-008, UPR-014, UPR-015, ORG-001, EDU-008
12.4Detailed disaster recovery and business continuity plans, and backupsBASAMEDAADVAUPR-016, UPR-017, ORG-006, POD-002
12.5Testing the plans at least once a yearBASCMEDAADVAUPR-005, UPR-008, UPR-013, ORG-007, POD-002
12.6Cyber crisis management exercisesBASBMEDBADVBUPR-006, UPR-013, UPR-014, UPR-015, POL-011
12.7Redundancy for critical network and information systemsBASCMEDAADVARES-005, RES-006, RES-007, RES-008, RES-009
12.8Redundant data centres with a documented geographic risk assessmentBASCMEDCADVARIZ-010, RIZ-019, RES-005, RES-006
13

Physical security

The same logic as system access control, applied at the door.

This requires a physical security policy matched to the risks of the environment the entity operates in, basic protection of premises and equipment, and regular review and updating of security protocols.

CONDITION FROM ANNEX IIFor entities in the digital infrastructure sector, Annex III of the Regulation sets out an extended set of physical security measures, under Article 46 of the Regulation.

IDSUB-MEASUREBASMEDADVCONTROLS
13.1Physical security policy matched to the entity's environmental risksBASAMEDAADVAPOL-003
13.2Basic physical protection measuresBASAMEDAADVAPOL-003, FIZ-001
13.3Regular review and updating of security protocolsBASAMEDAADVAPOL-003, RIZ-001, FIZ-002
13.4Advanced physical protection and records of access authorisationsBASCMEDAADVAPOL-003, RIZ-001, FIZ-003, NAD-012
13.5Real time monitoring of premises, subject to risk assessmentBASCMEDCADVARIZ-001, FIZ-004

Frequently asked questions

The questions most often asked about this list of measures.

Where do the thirteen measures come from?

From Annex II of Regulation NN 135/2024, which implements Act NN 14/2024. The Regulation breaks them into 99 sub-measures, and the ZSIS control catalogue into 137 controls that the auditor checks.

Do we have to implement all thirteen?

Yes. All of them apply to every categorised entity. What differs is the level of implementation, not the list of measures.

What do the marks A, B and C mean?

A is a binding sub-measure at that level. B is binding subject to a condition Annex II sets out with the measure, for example if the entity develops its own software. C is voluntary, implemented according to the risk assessment, and its implementation is additionally credited in self-assessment and audit.

How many sub-measures are binding at the basic level?

Marked A at the basic level are 59 of the 99 sub-measures. At the medium level it is 80, and at the advanced level 87. The rest are voluntary or binding subject to a condition.

How are the measures scored?

Under the methodology of the Information Systems Security Bureau, control by control, with written evidence required for each. The result is a scored maturity picture by measure.

Which measure is hardest in practice?

Supply chain security and business continuity, because they need records over time rather than a single document. Supply chain work usually also means reopening existing contracts.

Do all measures apply to operational technology?

Not in full. For measures 5 and 6, Annex II states which sub-measures apply to OT without restriction and which depend on a risk assessment. This is noted below the relevant tables.

Where to go next

The measures are a list of obligations. These pages cover how the evidence is built.

Let us check which measures you already have evidence for.

Half an hour, no obligation. We go measure by measure and separate what you already have from what still needs writing.

Book a callINFO@RISKORIA.EU · +385 97 737 1345