{
    "authors": [
        "NC3 Team"
    ],
    "label": "Cyfun Important [EN]",
    "language": "EN",
    "refs": [
        "https://cyfun.eu/"
    ],
    "uuid": "afc0d217-c09b-4033-a053-792a06872138",
    "values": [
        {
            "category": "[Organisational Context] - The organisational mission is understood and informs cybersecurity risk management.",
            "code": "GV.OC-01.1",
            "label": "The organisation's mission shall be established, communicated and shall form the basis for information and cybersecurity risk management.",
            "referential": "afc0d217-c09b-4033-a053-792a06872138",
            "referential_label": "Cyfun Important [EN]",
            "uuid": "c6ea2c37-97d0-4869-a771-50bcfa3010bd"
        },
        {
            "category": "[Organisational Context] - Legal, regulatory, and contractual requirements regarding cybersecurity are understood and managed.",
            "code": "GV.OC-03.1",
            "label": "Legal and regulatory requirements regarding information and cybersecurity shall be identified and implemented.",
            "referential": "afc0d217-c09b-4033-a053-792a06872138",
            "referential_label": "Cyfun Important [EN]",
            "uuid": "ecbf77d3-1174-4b51-bfdf-d095b44df11f"
        },
        {
            "category": "[Organisational Context] - Legal, regulatory, and contractual requirements regarding cybersecurity are understood and managed.",
            "code": "GV.OC-03.2",
            "label": "Legal and regulatory obligations related to information and cybersecurity shall be continuously managed to ensure they remain accurate, up to date, and effectively applied.",
            "referential": "afc0d217-c09b-4033-a053-792a06872138",
            "referential_label": "Cyfun Important [EN]",
            "uuid": "90e33812-d244-4467-9096-15e0c6a20fc5"
        },
        {
            "category": "[Organisational Context] - Critical objectives, capabilities, and services that external stakeholders depend on or expect from the organisation are understood and communicated.",
            "code": "GV.OC-04.1",
            "label": "The organisation shall identify, document, and communicate the critical objectives, capabilities, and services relied upon by external stakeholders, prioritise them based on criticality, and integrate this prioritisation into the risk assessment process.",
            "referential": "afc0d217-c09b-4033-a053-792a06872138",
            "referential_label": "Cyfun Important [EN]",
            "uuid": "58423636-122b-44fc-be4e-ffe65c196f62"
        },
        {
            "category": "[Organisational Context] - Critical objectives, capabilities, and services that external stakeholders depend on or expect from the organisation are understood and communicated.",
            "code": "GV.OC-04.2",
            "label": "The organisation shall define and document cybersecurity requirements for essential operations, validate them through testing and audits, keep records of results and corrective actions, and regularly update requirements based on evolving risks.",
            "referential": "afc0d217-c09b-4033-a053-792a06872138",
            "referential_label": "Cyfun Important [EN]",
            "uuid": "485db582-7053-4f27-980a-ac4e36d95bb2"
        },
        {
            "category": "[Organisational Context] - Outcomes, capabilities, and services that the organisation depends on are understood and communicated.",
            "code": "GV.OC-05.1",
            "label": "The organisation shall identify, document, and communicate its role in the supply chain, including the external capabilities, services, and dependencies it relies on (upstream), as well as its interactions with downstream stakeholders..",
            "referential": "afc0d217-c09b-4033-a053-792a06872138",
            "referential_label": "Cyfun Important [EN]",
            "uuid": "24b40d12-b6fc-4d75-b0f5-4f73e5cb3c23"
        },
        {
            "category": "[Risk Management Strategy] - Risk management objectives are established and agreed to by organisational stakeholders.",
            "code": "GV.RM-01.1",
            "label": "Information and cybersecurity objectives shall be coherently established throughout the organisation and approved by senior management.",
            "referential": "afc0d217-c09b-4033-a053-792a06872138",
            "referential_label": "Cyfun Important [EN]",
            "uuid": "7b56098f-9bb9-46b6-99f5-ac4043e53ccc"
        },
        {
            "category": "[Risk Management Strategy] - Risk appetite and risk tolerance statements are established, communicated, and maintained.",
            "code": "GV.RM-02.1",
            "label": "Risk appetite and risk tolerance statements shall be defined, documented, approved by senior management, communicated, and maintained.",
            "referential": "afc0d217-c09b-4033-a053-792a06872138",
            "referential_label": "Cyfun Important [EN]",
            "uuid": "f7938e82-2378-4cb4-b57a-a06444eab1bd"
        },
        {
            "category": "[Risk Management Strategy] - Cybersecurity risk management activities and outcomes are included in enterprise risk management processes.",
            "code": "GV.RM-03.1",
            "label": "As part of the organisation-wide risk management strategy, a comprehensive strategy to manage information and cybersecurity risks shall be developed and updated when changes occur.",
            "referential": "afc0d217-c09b-4033-a053-792a06872138",
            "referential_label": "Cyfun Important [EN]",
            "uuid": "4afe1dda-751e-462d-adf1-9718063406a6"
        },
        {
            "category": "[Risk Management Strategy] - Cybersecurity risk management activities and outcomes are included in enterprise risk management processes.",
            "code": "GV.RM-03.2",
            "label": "Information and cybersecurity risks shall be documented, as part of the enterprise risk management processes, formally approved by senior management, and updated when changes occur.",
            "referential": "afc0d217-c09b-4033-a053-792a06872138",
            "referential_label": "Cyfun Important [EN]",
            "uuid": "6092e844-300f-46c5-a338-036e85d4878e"
        },
        {
            "category": "[Risk Management Strategy] - Strategic direction that describes appropriate risk response options is established and communicated.",
            "code": "GV.RM-04.1",
            "label": "A high-level plan or vision shall be formally established and clearly communicated to everyone involved on how to manage risks, including the different strategies the organisation can employ to deal with identified risks based on risk appetite or risk tolerance level.",
            "referential": "afc0d217-c09b-4033-a053-792a06872138",
            "referential_label": "Cyfun Important [EN]",
            "uuid": "a5cacded-7f41-4ee0-b7ad-0fbc41cb98fb"
        },
        {
            "category": "[Risk Management Strategy] - Lines of communication across the organisation are established for cybersecurity risks, including risks from suppliers and other third parties.",
            "code": "GV.RM-05.1",
            "label": "To support the high-level risk management vision, the organisation shall establish clear lines of communication for cybersecurity risks, including those arising from suppliers and third parties.",
            "referential": "afc0d217-c09b-4033-a053-792a06872138",
            "referential_label": "Cyfun Important [EN]",
            "uuid": "8a0a647c-d270-4c8e-a204-88eb8c0b9c2a"
        },
        {
            "category": "[Roles, Responsibilities and Authorities] - Roles, responsibilities, and authorities related to cybersecurity risk management are established, communicated, understood, and enforced.",
            "code": "GV.RR-02.1",
            "label": "Information security and cyber security roles, responsibilities and authorities for employees, suppliers, customers, and partners shall be documented, reviewed, authorised, kept up-to-date, communicated, and coordinated internally and externally.",
            "referential": "afc0d217-c09b-4033-a053-792a06872138",
            "referential_label": "Cyfun Important [EN]",
            "uuid": "4a89ee06-4680-42c0-80bc-5815374e1d9f"
        },
        {
            "category": "[Roles, Responsibilities and Authorities] - Adequate resources are allocated commensurate with the cybersecurity risk strategy, roles, responsibilities, and policies.",
            "code": "GV.RR-03.1",
            "label": "Sufficient resources shall be allocated in line with the cybersecurity risk strategy, roles, responsibilities and policies.",
            "referential": "afc0d217-c09b-4033-a053-792a06872138",
            "referential_label": "Cyfun Important [EN]",
            "uuid": "b8c589f5-3ff0-4d93-b59e-35a30f992287"
        },
        {
            "category": "[Roles, Responsibilities and Authorities] - Adequate resources are allocated commensurate with the cybersecurity risk strategy, roles, responsibilities, and policies.",
            "code": "GV.RR-03.2",
            "label": "The organisation shall assign roles and responsibilities for reviewing and updating response and recovery plans, ensuring they reflect changes in the risk environment and remain effective.",
            "referential": "afc0d217-c09b-4033-a053-792a06872138",
            "referential_label": "Cyfun Important [EN]",
            "uuid": "2d7b6e1b-4352-4f50-9396-8c142af74742"
        },
        {
            "category": "[Roles, Responsibilities and Authorities] - Cybersecurity is included in human resources practices.",
            "code": "GV.RR-04.1",
            "label": "Personnel with access to the organisation\u2019s most critical information or technology shall be authenticated..",
            "referential": "afc0d217-c09b-4033-a053-792a06872138",
            "referential_label": "Cyfun Important [EN]",
            "uuid": "ae26c134-7a6e-4dc8-bbd0-47adf8c12b78"
        },
        {
            "category": "[Roles, Responsibilities and Authorities] - Cybersecurity is included in human resources practices.",
            "code": "GV.RR-04.2",
            "label": "A cybersecurity process for human resources shall be developed and maintained applicable at recruitment, during employment and at termination of employment.",
            "referential": "afc0d217-c09b-4033-a053-792a06872138",
            "referential_label": "Cyfun Important [EN]",
            "uuid": "7f11ab53-4237-449e-b3e5-9c4170490b9b"
        },
        {
            "category": "[Policy] - Policy for managing cybersecurity risks is established based on Organisational context, cybersecurity strategy, and priorities and is communicated and enforced.",
            "code": "GV.PO-01.1",
            "label": "Policies and procedures for managing information and cybersecurity shall be established, documented, reviewed, approved, updated when changes occur, communicated and enforced.",
            "referential": "afc0d217-c09b-4033-a053-792a06872138",
            "referential_label": "Cyfun Important [EN]",
            "uuid": "18deb346-dd38-4da9-8a7a-d590f812dbe5"
        },
        {
            "category": "[Policy] - Policy for managing cybersecurity risks is established based on Organisational context, cybersecurity strategy, and priorities and is communicated and enforced.",
            "code": "GV.PO-01.2",
            "label": "Organisational-wide information and cybersecurity policies and procedures shall include the use of cryptography and, where appropriate, encryption, reflect changes in requirements, threats, technology and organisational roles, and be approved by senior management, who oversee implementation.",
            "referential": "afc0d217-c09b-4033-a053-792a06872138",
            "referential_label": "Cyfun Important [EN]",
            "uuid": "8f0a730b-2eed-40b5-9abc-1444618ab20b"
        },
        {
            "category": "[Cybersecurity Supply Chain Risk Management] - Cybersecurity roles and responsibilities for suppliers, customers, and partners are established, communicated, and coordinated internally and externally.",
            "code": "GV.SC-02.1",
            "label": "Third-party providers shall notify any transfer, termination or transition of personnel with physical or logical access to business-critical system elements of the organisation.",
            "referential": "afc0d217-c09b-4033-a053-792a06872138",
            "referential_label": "Cyfun Important [EN]",
            "uuid": "ddfdb9ee-40bd-4c35-b926-fdcacedf1f19"
        },
        {
            "category": "[Cybersecurity Supply Chain Risk Management] - Requirements to address cybersecurity risks in supply chains are established, prioritised, and integrated into contracts and other types of agreements with suppliers and other relevant third parties.",
            "code": "GV.SC-05.1",
            "label": "Requirements for addressing cybersecurity risks and the sharing of sensitive information in supply chains shall be established, prioritised, integrated into contracts and other types of formal agreements, and enforced.",
            "referential": "afc0d217-c09b-4033-a053-792a06872138",
            "referential_label": "Cyfun Important [EN]",
            "uuid": "3df2e397-ab6e-4bb9-af21-7cd9d587d9fb"
        },
        {
            "category": "[Cybersecurity Supply Chain Risk Management] - The risks posed by a supplier, their products and services, and other third parties are understood, recorded, prioritised, assessed, responded to, and monitored over the course of the relationship.",
            "code": "GV.SC-07.1",
            "label": "The risks posed by a supplier, its products and services and other third parties shall be identified, documented, prioritised, mitigated and assessed at least annually and when changes occur during the relationship.",
            "referential": "afc0d217-c09b-4033-a053-792a06872138",
            "referential_label": "Cyfun Important [EN]",
            "uuid": "c00a35c9-cac3-4cec-981f-07c00efca32f"
        },
        {
            "category": "[Cybersecurity Supply Chain Risk Management] - Relevant suppliers and other third parties are included in incident planning, response, and recovery activities.",
            "code": "GV.SC-08.1",
            "label": "The organisation shall identify and document key personnel from relevant suppliers and other third parties to include them in incident planning, response, and recovery activities.",
            "referential": "afc0d217-c09b-4033-a053-792a06872138",
            "referential_label": "Cyfun Important [EN]",
            "uuid": "f96c5886-b66a-444a-abea-c866a4878d9b"
        },
        {
            "category": "[Asset Management] - Inventories of hardware managed by the organisation are maintained.",
            "code": "ID.AM-01.1",
            "label": "An inventory of physical and virtual infrastructure assets\u2014such as hardware, network devices, and cloud-hosted environments\u2014that support information processing shall be documented, reviewed, and updated as changes occur.",
            "referential": "afc0d217-c09b-4033-a053-792a06872138",
            "referential_label": "Cyfun Important [EN]",
            "uuid": "7361905d-1fe9-4f68-8c9c-a0c2e55d1378"
        },
        {
            "category": "[Asset Management] - Inventories of hardware managed by the organisation are maintained.",
            "code": "ID.AM-01.2",
            "label": "The inventory of enterprise assets associated with information and information processing facilities shall reflect changes in the organisation\u2019s context and include all information necessary for effective accountability.",
            "referential": "afc0d217-c09b-4033-a053-792a06872138",
            "referential_label": "Cyfun Important [EN]",
            "uuid": "9daebb2a-b9d7-4d34-bb31-b02aa495aa02"
        },
        {
            "category": "[Asset Management] - Inventories of hardware managed by the organisation are maintained.",
            "code": "ID.AM-01.3",
            "label": "When unauthorised hardware is detected, it shall be quarantined for possible exception handling, removed, or replaced, and the inventory shall be updated accordingly.",
            "referential": "afc0d217-c09b-4033-a053-792a06872138",
            "referential_label": "Cyfun Important [EN]",
            "uuid": "7e62e310-27ac-432e-a222-5a55fcf38164"
        },
        {
            "category": "[Asset Management] - Inventories of software, services, and systems managed by the organisation are maintained",
            "code": "ID.AM-02.1",
            "label": "An inventory of software, digital services, and business systems used within the organisation shall be documented, reviewed, and updated as changes occur.",
            "referential": "afc0d217-c09b-4033-a053-792a06872138",
            "referential_label": "Cyfun Important [EN]",
            "uuid": "a4cf6c3c-6307-4d60-bb48-ea6dcdbb34db"
        },
        {
            "category": "[Asset Management] - Inventories of software, services, and systems managed by the organisation are maintained",
            "code": "ID.AM-02.2",
            "label": "The inventory reflecting which software, services and systems are used in the organisation shall reflect changes in the organisation\u2019s context and include all information necessary for effective accountability.",
            "referential": "afc0d217-c09b-4033-a053-792a06872138",
            "referential_label": "Cyfun Important [EN]",
            "uuid": "14318b2f-ede9-4a9c-94a0-e4d0135824ab"
        },
        {
            "category": "[Asset Management] - Inventories of software, services, and systems managed by the organisation are maintained",
            "code": "ID.AM-02.3",
            "label": "The people responsible and accountable for managing software platforms and applications within the organisation shall be formally identified.",
            "referential": "afc0d217-c09b-4033-a053-792a06872138",
            "referential_label": "Cyfun Important [EN]",
            "uuid": "fb1c0b32-2ce4-4b44-81da-93aa5ba99720"
        },
        {
            "category": "[Asset Management] - Inventories of software, services, and systems managed by the organisation are maintained",
            "code": "ID.AM-02.4",
            "label": "When unauthorised software is detected, it shall be quarantined for possible exception handling, removed, or replaced, and the inventory shall be updated accordingly.",
            "referential": "afc0d217-c09b-4033-a053-792a06872138",
            "referential_label": "Cyfun Important [EN]",
            "uuid": "edd2495e-9ed8-432f-ab1a-deb1dbe57733"
        },
        {
            "category": "[Asset Management] - Representations of the organisation's authorised network communication and internal and external network data flows are maintained",
            "code": "ID.AM-03.2",
            "label": "The organisation's network communication and internal data flows shall be mapped, documented, authorised, and updated when changes occur.",
            "referential": "afc0d217-c09b-4033-a053-792a06872138",
            "referential_label": "Cyfun Important [EN]",
            "uuid": "4c01bc85-86a3-4c1e-b7ef-f73eff2c4383"
        },
        {
            "category": "[Asset Management] - Inventories of services provided by suppliers are maintained.",
            "code": "ID.AM-04.1",
            "label": "Organisations shall keep a clear and up-to-date list of all external services it uses, including how they connect to their systems. These services shall be reviewed and approved before use, and the list shall be updated whenever changes happen.",
            "referential": "afc0d217-c09b-4033-a053-792a06872138",
            "referential_label": "Cyfun Important [EN]",
            "uuid": "908f6b91-1512-453e-821b-771ba921ebae"
        },
        {
            "category": "[Asset Management] - Assets are prioritised based on classification, criticality, resources, and impact on the mission.",
            "code": "ID.AM-05.1",
            "label": "The organisation\u2019s assets shall be prioritised based on classification, criticality, and business value.",
            "referential": "afc0d217-c09b-4033-a053-792a06872138",
            "referential_label": "Cyfun Important [EN]",
            "uuid": "631c1588-eb71-4d92-8df4-34de0a332811"
        },
        {
            "category": "[Asset Management] - Inventories of data and corresponding metadata for designated data types are maintained",
            "code": "ID.AM-07.1",
            "label": "Data that the organisation stores and uses shall be identified..",
            "referential": "afc0d217-c09b-4033-a053-792a06872138",
            "referential_label": "Cyfun Important [EN]",
            "uuid": "234d11f6-80bd-48a0-a8f3-90170822ab18"
        },
        {
            "category": "[Asset Management] - Inventories of data and corresponding metadata for designated data types are maintained",
            "code": "ID.AM-07.2",
            "label": "Inventories of data and associated metadata shall be maintained for designated data types.",
            "referential": "afc0d217-c09b-4033-a053-792a06872138",
            "referential_label": "Cyfun Important [EN]",
            "uuid": "59398b24-a16e-4ffd-96b6-307723d19c8e"
        },
        {
            "category": "[Asset Management] - Systems, hardware, software, services, and data are managed throughout their life cycles.",
            "code": "ID.AM-08.2",
            "label": "Patches and security updates for operating systems and critical system components shall be installed.",
            "referential": "afc0d217-c09b-4033-a053-792a06872138",
            "referential_label": "Cyfun Important [EN]",
            "uuid": "8bab598c-07c7-40ff-b2e6-6cee274734c6"
        },
        {
            "category": "[Asset Management] - Systems, hardware, software, services, and data are managed throughout their life cycles.",
            "code": "ID.AM-08.3",
            "label": "The organisation shall enforce accountability for all its business-critical assets throughout the system lifecycle, including removal, transfers, and disposal.",
            "referential": "afc0d217-c09b-4033-a053-792a06872138",
            "referential_label": "Cyfun Important [EN]",
            "uuid": "c9077d57-2917-4ad6-9c5f-8d4cc85aaddd"
        },
        {
            "category": "[Asset Management] - Systems, hardware, software, services, and data are managed throughout their life cycles.",
            "code": "ID.AM-08.4",
            "label": "The organisation shall ensure that the necessary measures are taken to deal with loss, misuse, damage, or theft of assets.",
            "referential": "afc0d217-c09b-4033-a053-792a06872138",
            "referential_label": "Cyfun Important [EN]",
            "uuid": "e051b93c-4b80-416e-9b30-64a894fdaa2a"
        },
        {
            "category": "[Asset Management] - Systems, hardware, software, services, and data are managed throughout their life cycles.",
            "code": "ID.AM-08.6",
            "label": "The organisation shall plan, perform and document preventive maintenance and repairs on its critical system components according to approved processes and tools.",
            "referential": "afc0d217-c09b-4033-a053-792a06872138",
            "referential_label": "Cyfun Important [EN]",
            "uuid": "aa5a82f8-3528-4a05-bff9-3e444531e1bc"
        },
        {
            "category": "[Asset Management] - Systems, hardware, software, services, and data are managed throughout their life cycles.",
            "code": "ID.AM-08.8",
            "label": "The organisation shall pre-approve, monitor and enforce maintenance tools for use on its critical systems.",
            "referential": "afc0d217-c09b-4033-a053-792a06872138",
            "referential_label": "Cyfun Important [EN]",
            "uuid": "fc2d89e7-5c9d-45b7-a49e-932ac6b8be58"
        },
        {
            "category": "[Asset Management] - Systems, hardware, software, services, and data are managed throughout their life cycles.",
            "code": "ID.AM-08.11",
            "label": "Remote maintenance and diagnostic activities of organisational assets shall be pre-approved and the performance logged.",
            "referential": "afc0d217-c09b-4033-a053-792a06872138",
            "referential_label": "Cyfun Important [EN]",
            "uuid": "99268c8f-8333-40d2-bb55-b17cee056ac0"
        },
        {
            "category": "[Asset Management] - Systems, hardware, software, services, and data are managed throughout their life cycles.",
            "code": "ID.AM-08.12",
            "label": "Setting up non-local maintenance and diagnostic sessions over remote network connections shall require strong authenticators and these connections shall be terminated when non-local maintenance is completed.",
            "referential": "afc0d217-c09b-4033-a053-792a06872138",
            "referential_label": "Cyfun Important [EN]",
            "uuid": "872aef4a-6b2f-44d7-994d-7d5a863c09e2"
        },
        {
            "category": "[Risk Assessment] - Vulnerabilities in assets are identified, validated, and recorded",
            "code": "ID.RA-01.1",
            "label": "Threats and vulnerabilities shall be identified in all relevant assets, including software, network and system architectures, and facilities that house critical computing assets.",
            "referential": "afc0d217-c09b-4033-a053-792a06872138",
            "referential_label": "Cyfun Important [EN]",
            "uuid": "00012e37-0a1e-4eb7-a0a3-036bc3bd06a2"
        },
        {
            "category": "[Risk Assessment] - Vulnerabilities in assets are identified, validated, and recorded",
            "code": "ID.RA-01.2",
            "label": "A process shall be established to continuously monitor, identify, and document vulnerabilities of the organisation's business critical systems.",
            "referential": "afc0d217-c09b-4033-a053-792a06872138",
            "referential_label": "Cyfun Important [EN]",
            "uuid": "67c618ab-1da9-4fd6-8a44-f7c25a6e3b1e"
        },
        {
            "category": "[Risk Assessment] - Vulnerabilities in assets are identified, validated, and recorded",
            "code": "ID.RA-01.3",
            "label": "The organisation shall establish and maintain a documented process that enables continuous review, analysis and remediation of vulnerabilities and provides for information sharing where applicable.",
            "referential": "afc0d217-c09b-4033-a053-792a06872138",
            "referential_label": "Cyfun Important [EN]",
            "uuid": "94fb3d6d-7658-4571-84c4-5bb728de3ca3"
        },
        {
            "category": "[Risk Assessment] - Vulnerabilities in assets are identified, validated, and recorded",
            "code": "ID.RA-01.5",
            "label": "Vulnerability scanning shall not adversely impact system functions.",
            "referential": "afc0d217-c09b-4033-a053-792a06872138",
            "referential_label": "Cyfun Important [EN]",
            "uuid": "6d86b534-00f5-49b0-bcf7-34ec9a4f7af6"
        },
        {
            "category": "[Risk Assessment] - Vulnerabilities in assets are identified, validated, and recorded",
            "code": "ID.RA-01.6",
            "label": "Vulnerabilities shall be identified and managed in all relevant assets, including software, network and system architectures, and facilities.",
            "referential": "afc0d217-c09b-4033-a053-792a06872138",
            "referential_label": "Cyfun Important [EN]",
            "uuid": "1474a7e5-544a-4092-a14a-5811db2a688c"
        },
        {
            "category": "[Risk Assessment] - Cyber threat intelligence is received from information sharing forums and sources.",
            "code": "ID.RA-02.1",
            "label": "A threat and vulnerability awareness programme that includes a cross-organisation information-sharing capability shall be implemented.",
            "referential": "afc0d217-c09b-4033-a053-792a06872138",
            "referential_label": "Cyfun Important [EN]",
            "uuid": "83a7ccd1-0d3c-4351-b382-0bdcdf5dc3cd"
        },
        {
            "category": "[Risk Assessment] - Internal and external threats to the organisation are identified and recorded.",
            "code": "ID.RA-03.1",
            "label": "Threats shall be identified and assessed in relation to all relevant assets, including software, network and system architectures, and facilities.",
            "referential": "afc0d217-c09b-4033-a053-792a06872138",
            "referential_label": "Cyfun Important [EN]",
            "uuid": "1cbabd84-4950-4639-8c8b-d4553e1d0719"
        },
        {
            "category": "[Risk Assessment] - Threats, vulnerabilities, likelihoods, and impacts are used to understand inherent risk and inform risk response prioritisation.",
            "code": "ID.RA-05.1",
            "label": "The organisation shall conduct risk assessments in which risk is determined by threats, vulnerabilities and the impact on business processes and assets.",
            "referential": "afc0d217-c09b-4033-a053-792a06872138",
            "referential_label": "Cyfun Important [EN]",
            "uuid": "0d2249ba-6b5a-49d9-ae54-701a610af7c7"
        },
        {
            "category": "[Risk Assessment] - Threats, vulnerabilities, likelihoods, and impacts are used to understand inherent risk and inform risk response prioritisation.",
            "code": "ID.RA-05.2",
            "label": "The organisation shall conduct and document risk assessments in which risk is determined by threats, vulnerabilities, impact on business processes and assets, and likelihood of their occurrence.",
            "referential": "afc0d217-c09b-4033-a053-792a06872138",
            "referential_label": "Cyfun Important [EN]",
            "uuid": "38243e70-54f6-43bc-96d8-5bf789877cfa"
        },
        {
            "category": "[Risk Assessment] - Risk responses are chosen, prioritised, planned, tracked, and communicated.",
            "code": "ID.RA-06.1",
            "label": "Risk responses shall be identified, prioritised, planned, tracked and communicated.",
            "referential": "afc0d217-c09b-4033-a053-792a06872138",
            "referential_label": "Cyfun Important [EN]",
            "uuid": "36e067b7-fbb6-4a01-8d6a-e628689d1cfa"
        },
        {
            "category": "[Risk Assessment] - Processes for receiving, analysing, and responding to vulnerability disclosures are established .",
            "code": "ID.RA-08.1",
            "label": "The organisation shall establish and implement a vulnerability management plan to identify, analyse, assess, mitigate and communicate all types of vulnerabilities including in the form of a Coordinated Vulnerability Disclosure (CVD) according to applicable legal modalities.",
            "referential": "afc0d217-c09b-4033-a053-792a06872138",
            "referential_label": "Cyfun Important [EN]",
            "uuid": "6df53b45-e7f0-446d-b0ce-a035a4109a01"
        },
        {
            "category": "[Improvement] - Improvements are identified from security tests and exercises, including those made in coordination with suppliers and relevant third parties.",
            "code": "ID.IM-02.1",
            "label": "Security tests and exercises, including those conducted with suppliers and relevant third parties, shall be used to identify areas for improvement.",
            "referential": "afc0d217-c09b-4033-a053-792a06872138",
            "referential_label": "Cyfun Important [EN]",
            "uuid": "3957ae1c-3e47-4cf8-84fb-c5381bf969d2"
        },
        {
            "category": "[Improvement] - Improvements are identified from execution of operational processes, procedures, and activities.",
            "code": "ID.IM-03.1",
            "label": "The organisation shall conduct post-incident evaluations to analyse lessons learned from incident response and recovery, and consequently improve processes / procedures / technologies to enhance its cyber resilience.",
            "referential": "afc0d217-c09b-4033-a053-792a06872138",
            "referential_label": "Cyfun Important [EN]",
            "uuid": "7d6c9f96-2038-4031-8be0-245ad7ae94cc"
        },
        {
            "category": "[Improvement] - Improvements are identified from execution of operational processes, procedures, and activities.",
            "code": "ID.IM-03.2",
            "label": "The organisation shall incorporate lessons learned from incident handling activities into updated or new incident handling processes and/or procedures that are framed by appropriate training after review, approval and testing.",
            "referential": "afc0d217-c09b-4033-a053-792a06872138",
            "referential_label": "Cyfun Important [EN]",
            "uuid": "ae0b110e-ffad-4f3b-aa0a-09eef25cd99e"
        },
        {
            "category": "[Improvement] - Improvements are identified from execution of operational processes, procedures, and activities.",
            "code": "ID.IM-03.3",
            "label": "The organisation shall identify improvements derived from the monitoring, measurements, assessments, and lessons learned and consequently translate this into improved processes / procedures / technologies to enhance its cyber resilience (continuous improvement).",
            "referential": "afc0d217-c09b-4033-a053-792a06872138",
            "referential_label": "Cyfun Important [EN]",
            "uuid": "10bf1e2d-915f-48dc-8a95-ff2a557bca57"
        },
        {
            "category": "[Improvement] - Improvements are identified from execution of operational processes, procedures, and activities.",
            "code": "ID.IM-03.4",
            "label": "The organisation shall collaborate and share information about its critical system's related security incidents and mitigation measures with designated partners.",
            "referential": "afc0d217-c09b-4033-a053-792a06872138",
            "referential_label": "Cyfun Important [EN]",
            "uuid": "1e2c13f3-86d8-489b-ad34-7cf646d32ba4"
        },
        {
            "category": "[Improvement] - Improvements are identified from execution of operational processes, procedures, and activities.",
            "code": "ID.IM-03.5",
            "label": "Communication of effectiveness of protection technologies shall be shared with relevant stakeholders.",
            "referential": "afc0d217-c09b-4033-a053-792a06872138",
            "referential_label": "Cyfun Important [EN]",
            "uuid": "e5602ae5-3c27-40a9-9486-eafe273dffbb"
        },
        {
            "category": "[Improvement] - Improvements are identified from execution of operational processes, procedures, and activities.",
            "code": "ID.IM-03.6",
            "label": "The organisation shall implement, where feasible, automated mechanisms to facilitate the process of information sharing and collaboration.",
            "referential": "afc0d217-c09b-4033-a053-792a06872138",
            "referential_label": "Cyfun Important [EN]",
            "uuid": "19320324-5de2-4e1e-a3b6-c9b986197966"
        },
        {
            "category": "[Improvement] - Incident response plans and other cybersecurity plans that affect operations are established, communicated, maintained, and improved.",
            "code": "ID.IM-04.1",
            "label": "Contingency and continuity plans shall be established, communicated, maintained, tested, validated, and improved.",
            "referential": "afc0d217-c09b-4033-a053-792a06872138",
            "referential_label": "Cyfun Important [EN]",
            "uuid": "28913041-1889-4a2d-b722-b09a22086bb9"
        },
        {
            "category": "[Identity Management, Authentication, and Access Control] - Identities and credentials for authorised users, services, and hardware are managed by the organisation.",
            "code": "PR.AA-01.1",
            "label": "Identities and credentials for authorised users, services, and hardware shall be managed.",
            "referential": "afc0d217-c09b-4033-a053-792a06872138",
            "referential_label": "Cyfun Important [EN]",
            "uuid": "d1d9088a-9711-4cff-a225-9d46103b6b20"
        },
        {
            "category": "[Identity Management, Authentication, and Access Control] - Identities and credentials for authorised users, services, and hardware are managed by the organisation.",
            "code": "PR.AA-01.2",
            "label": "Identities and credentials for authorised users, services and hardware shall be managed through automated mechanisms whenever feasible.",
            "referential": "afc0d217-c09b-4033-a053-792a06872138",
            "referential_label": "Cyfun Important [EN]",
            "uuid": "34302094-ed45-4ec4-ad39-a686d0698c36"
        },
        {
            "category": "[Identity Management, Authentication, and Access Control] - Identities are proofed and bound to credentials based on the context of interactions.",
            "code": "PR.AA-02.1",
            "label": "The organisation shall implement documented procedures for verifying the identity of individuals before issuing credentials that provide access to the organisation's systems.",
            "referential": "afc0d217-c09b-4033-a053-792a06872138",
            "referential_label": "Cyfun Important [EN]",
            "uuid": "1b4693b3-f67b-415e-bc1f-94c87b0a83e3"
        },
        {
            "category": "[Identity Management, Authentication, and Access Control] - Users, services, and hardware are authenticated.",
            "code": "PR.AA-03.1",
            "label": "All wireless access points used by the organisation, including those providing guest access, shall be securely configured, managed, and monitored to prevent unauthorised access and ensure network integrity.",
            "referential": "afc0d217-c09b-4033-a053-792a06872138",
            "referential_label": "Cyfun Important [EN]",
            "uuid": "a635805f-1435-4644-bfc5-ffbe61a5ec30"
        },
        {
            "category": "[Identity Management, Authentication, and Access Control] - Users, services, and hardware are authenticated.",
            "code": "PR.AA-03.2",
            "label": "Multi-Factor Authentication (MFA) shall be required to access the organisation's networks remotely.",
            "referential": "afc0d217-c09b-4033-a053-792a06872138",
            "referential_label": "Cyfun Important [EN]",
            "uuid": "06580765-b2e0-4fb7-b3aa-4a3222fb7138"
        },
        {
            "category": "[Identity Management, Authentication, and Access Control] - Users, services, and hardware are authenticated.",
            "code": "PR.AA-03.3",
            "label": "The organisation shall define, document, and implement usage restrictions, connection requirements, and authorisation procedures for remote access to its critical systems. These controls shall ensure that only approved users can connect, using secure methods, with access limited to what is necessary for their role.",
            "referential": "afc0d217-c09b-4033-a053-792a06872138",
            "referential_label": "Cyfun Important [EN]",
            "uuid": "695bc431-db2c-414f-8a72-e47a38e5048d"
        },
        {
            "category": "[Identity Management, Authentication, and Access Control] - Access permissions, entitlements, and authorisations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties.",
            "code": "PR.AA-05.1",
            "label": "Access permissions, rights, and authorisations shall be defined, managed, enforced and reviewed.",
            "referential": "afc0d217-c09b-4033-a053-792a06872138",
            "referential_label": "Cyfun Important [EN]",
            "uuid": "8fa339d5-25a2-4aeb-ad2f-053914f1f863"
        },
        {
            "category": "[Identity Management, Authentication, and Access Control] - Access permissions, entitlements, and authorisations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties.",
            "code": "PR.AA-05.2",
            "label": "It shall be determined who needs access to the organisation's business-critical information and technology and the means to gain access.",
            "referential": "afc0d217-c09b-4033-a053-792a06872138",
            "referential_label": "Cyfun Important [EN]",
            "uuid": "2c70be8c-390a-4eb6-9943-6dbd75acecf3"
        },
        {
            "category": "[Identity Management, Authentication, and Access Control] - Access permissions, entitlements, and authorisations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties.",
            "code": "PR.AA-05.3",
            "label": "Access rights, privileges and authorisations shall be restricted to the systems and specific information needed to perform the tasks (the principle of Least Privilege).",
            "referential": "afc0d217-c09b-4033-a053-792a06872138",
            "referential_label": "Cyfun Important [EN]",
            "uuid": "206917c6-a0a7-4904-a3d0-98642d8bfa0f"
        },
        {
            "category": "[Identity Management, Authentication, and Access Control] - Access permissions, entitlements, and authorisations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties.",
            "code": "PR.AA-05.4",
            "label": "No-one shall have administrative privileges for routine day-to-day tasks.",
            "referential": "afc0d217-c09b-4033-a053-792a06872138",
            "referential_label": "Cyfun Important [EN]",
            "uuid": "cd914ba0-56a8-4079-867f-c9e8bef2931e"
        },
        {
            "category": "[Identity Management, Authentication, and Access Control] - Access permissions, entitlements, and authorisations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties.",
            "code": "PR.AA-05.5",
            "label": "Where technically, operationally, and economically feasible\u2014without compromising system integrity, safety, or compliance\u2014automated mechanisms shall be implemented to manage user accounts on critical ICT and OT systems. Feasibility shall be determined based on system capabilities, integration potential, risk assessment, and business impact.",
            "referential": "afc0d217-c09b-4033-a053-792a06872138",
            "referential_label": "Cyfun Important [EN]",
            "uuid": "b31d3dfa-e79c-4fe1-84de-61855b7de32d"
        },
        {
            "category": "[Identity Management, Authentication, and Access Control] - Access permissions, entitlements, and authorisations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties.",
            "code": "PR.AA-05.6",
            "label": "Separation of duties (SoD) shall be ensured in the management of access rights.",
            "referential": "afc0d217-c09b-4033-a053-792a06872138",
            "referential_label": "Cyfun Important [EN]",
            "uuid": "1d00aa4a-c78c-419a-86d8-c939c02096be"
        },
        {
            "category": "[Identity Management, Authentication, and Access Control] - Access permissions, entitlements, and authorisations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties.",
            "code": "PR.AA-05.7",
            "label": "Privileged users shall be managed and monitored.",
            "referential": "afc0d217-c09b-4033-a053-792a06872138",
            "referential_label": "Cyfun Important [EN]",
            "uuid": "6abc2946-4255-42a1-8e20-d51ae4b6d4f5"
        },
        {
            "category": "[Identity Management, Authentication, and Access Control] - Physical access to assets is managed, monitored, and enforced commensurate with risk.",
            "code": "PR.AA-06.1",
            "label": "Physical access to all organisational assets, including critical zones, shall be managed, monitored, and enforced based on risk.",
            "referential": "afc0d217-c09b-4033-a053-792a06872138",
            "referential_label": "Cyfun Important [EN]",
            "uuid": "b755e434-5454-4234-8dbc-1f8a9a3de8bc"
        },
        {
            "category": "[Identity Management, Authentication, and Access Control] - Physical access to assets is managed, monitored, and enforced commensurate with risk.",
            "code": "PR.AA-06.2",
            "label": "Physical access controls shall include specific procedures for emergency situations, ensuring continued protection of critical and non-critical assets during such events.",
            "referential": "afc0d217-c09b-4033-a053-792a06872138",
            "referential_label": "Cyfun Important [EN]",
            "uuid": "67f0e032-834d-4feb-ba95-1154889502ee"
        },
        {
            "category": "[Awareness and Training] - Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind.",
            "code": "PR.AT-01.1",
            "label": "The organisation shall establish and maintain a cybersecurity awareness and training programme to ensure that all personnel understand how to perform their tasks securely and responsibly.",
            "referential": "afc0d217-c09b-4033-a053-792a06872138",
            "referential_label": "Cyfun Important [EN]",
            "uuid": "aac982c0-c211-4d85-b4fc-45d7a90970ac"
        },
        {
            "category": "[Awareness and Training] - Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind.",
            "code": "PR.AT-01.2",
            "label": "The organisation shall include insider threat awareness and reporting in its cybersecurity training to help personnel recognise and respond to potential internal risks.",
            "referential": "afc0d217-c09b-4033-a053-792a06872138",
            "referential_label": "Cyfun Important [EN]",
            "uuid": "05077f65-da30-4103-93b4-d61d29d345ac"
        },
        {
            "category": "[Awareness and Training] - Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind.",
            "code": "PR.AT-01.3",
            "label": "Personnel shall receive training to understand their specific roles, responsibilities, and priorities during a cybersecurity or information security incident, including the steps they need to follow to respond effectively.",
            "referential": "afc0d217-c09b-4033-a053-792a06872138",
            "referential_label": "Cyfun Important [EN]",
            "uuid": "e97eff3d-f7f6-4d4b-8b48-b6133995a272"
        },
        {
            "category": "[Awareness and Training] - Individuals in specialised roles are provided with awareness and training so that they possess the knowledge and skills to perform relevant tasks with cybersecurity risks in mind.",
            "code": "PR.AT-02.1",
            "label": "Members of management bodies shall be able to demonstrate that they have completed training that gives them a solid understanding of information and cybersecurity and risk management so that they can assess information and cyber security risks and their consequences and propose the necessary risk mitigation, considering their roles, responsibilities and authorities.",
            "referential": "afc0d217-c09b-4033-a053-792a06872138",
            "referential_label": "Cyfun Important [EN]",
            "uuid": "ca73eab6-932c-4718-bbf5-3866ae10bab9"
        },
        {
            "category": "[Awareness and Training] - Individuals in specialised roles are provided with awareness and training so that they possess the knowledge and skills to perform relevant tasks with cybersecurity risks in mind.",
            "code": "PR.AT-02.2",
            "label": "Individuals in specialised roles shall be provided with awareness and training before privileges are granted, so that they possess the knowledge and skills to perform relevant tasks with cybersecurity risks in mind.",
            "referential": "afc0d217-c09b-4033-a053-792a06872138",
            "referential_label": "Cyfun Important [EN]",
            "uuid": "65592498-adbf-46d1-b40d-9ceb142e3445"
        },
        {
            "category": "[Awareness and Training] - Individuals in specialised roles are provided with awareness and training so that they possess the knowledge and skills to perform relevant tasks with cybersecurity risks in mind.",
            "code": "PR.AT-02.3",
            "label": "Privileged users shall be qualified before privileges are granted, and these users shall be able to demonstrate the understanding of their roles, responsibilities, and authorities.",
            "referential": "afc0d217-c09b-4033-a053-792a06872138",
            "referential_label": "Cyfun Important [EN]",
            "uuid": "91c72d55-0c99-4162-a1c4-475741659e1b"
        },
        {
            "category": "[Data Security] - The confidentiality, integrity, and availability of data-at-rest are protected.",
            "code": "PR.DS-01.1",
            "label": "The organisation shall implement software, firmware, and information integrity checks to detect unauthorised changes to its critical system components during storage, transport, start-up and when determined necessary.",
            "referential": "afc0d217-c09b-4033-a053-792a06872138",
            "referential_label": "Cyfun Important [EN]",
            "uuid": "bbb58a63-8a6b-4075-9b48-b4d9f8cfa1d4"
        },
        {
            "category": "[Data Security] - The confidentiality, integrity, and availability of data-at-rest are protected.",
            "code": "PR.DS-01.4",
            "label": "The organisation shall define and enforce clear policies and practical safeguards to manage and restrict the use of portable storage media, in order to reduce the risk of data leakage, unauthorised access, and malware introduction.",
            "referential": "afc0d217-c09b-4033-a053-792a06872138",
            "referential_label": "Cyfun Important [EN]",
            "uuid": "930cc62e-32f9-49b2-9a5f-bec4285b658f"
        },
        {
            "category": "[Data Security] - The confidentiality, integrity, and availability of data-at-rest are protected.",
            "code": "PR.DS-01.5",
            "label": "The organisation shall only allow the use of removable media when absolutely necessary, and shall put technical measures in place to block automatic execution of files from these devices.",
            "referential": "afc0d217-c09b-4033-a053-792a06872138",
            "referential_label": "Cyfun Important [EN]",
            "uuid": "a099f0d3-3196-4fca-a8c4-f69b66cf7906"
        },
        {
            "category": "[Data Security] - The confidentiality, integrity, and availability of data-at-rest are protected.",
            "code": "PR.DS-01.9",
            "label": "Enterprise assets shall be disposed of safely.",
            "referential": "afc0d217-c09b-4033-a053-792a06872138",
            "referential_label": "Cyfun Important [EN]",
            "uuid": "f3bc185d-5721-4b22-b715-e4c4589eec19"
        },
        {
            "category": "[Data Security] - Backups of data are created, protected, maintained, and tested.",
            "code": "PR.DS-11.1",
            "label": "Backups for the organisation's business critical data shall be performed and stored on a different system from the device on which the original data resides.",
            "referential": "afc0d217-c09b-4033-a053-792a06872138",
            "referential_label": "Cyfun Important [EN]",
            "uuid": "7f2fb70c-6971-4af9-bde4-9a0a7df961ed"
        },
        {
            "category": "[Data Security] - Backups of data are created, protected, maintained, and tested.",
            "code": "PR.DS-11.2",
            "label": "The reliability and integrity of backups shall be verified and tested regularly.",
            "referential": "afc0d217-c09b-4033-a053-792a06872138",
            "referential_label": "Cyfun Important [EN]",
            "uuid": "35a74b8c-0409-4538-99e3-0b253a314448"
        },
        {
            "category": "[Data Security] - Backups of data are created, protected, maintained, and tested.",
            "code": "PR.DS-11.3",
            "label": "The organisation shall maintain secure backups of business-critical data in a separate storage location to ensure data availability in case of system failure or data loss. Backup storage shall apply equivalent security controls as the primary environment.",
            "referential": "afc0d217-c09b-4033-a053-792a06872138",
            "referential_label": "Cyfun Important [EN]",
            "uuid": "ea9af167-cd87-4052-be10-974aef27cfb9"
        },
        {
            "category": "[Platform Security] - Configuration management practices are established and applied.",
            "code": "PR.PS-01.1",
            "label": "The organisation shall develop, document, and maintain a baseline configuration for its business-critical systems.",
            "referential": "afc0d217-c09b-4033-a053-792a06872138",
            "referential_label": "Cyfun Important [EN]",
            "uuid": "a4afb185-bb4e-4bdb-9517-f0cef98cf80a"
        },
        {
            "category": "[Platform Security] - Software is maintained, replaced, and removed commensurate with risk.",
            "code": "PR.PS-02.1",
            "label": "The organisation shall enforce restrictions on software usage and installation, and ensure that software is maintained, replaced, or removed based on its associated risk.",
            "referential": "afc0d217-c09b-4033-a053-792a06872138",
            "referential_label": "Cyfun Important [EN]",
            "uuid": "796dba1a-2a0c-4b6e-89ea-d152138389a5"
        },
        {
            "category": "[Platform Security] - Hardware is maintained, replaced, and removed commensurate with risk.",
            "code": "PR.PS-03.1",
            "label": "Hardware used in business-critical environments shall be maintained, replaced, or removed based on its associated security and operational risk.",
            "referential": "afc0d217-c09b-4033-a053-792a06872138",
            "referential_label": "Cyfun Important [EN]",
            "uuid": "729e8725-d367-4557-967f-9bf9b1c726c9"
        },
        {
            "category": "[Platform Security] - Log records are generated and made available for continuous monitoring.",
            "code": "PR.PS-04.1",
            "label": "Logs shall be maintained, documented, and monitored.",
            "referential": "afc0d217-c09b-4033-a053-792a06872138",
            "referential_label": "Cyfun Important [EN]",
            "uuid": "a306a1b8-d885-4f22-b5c1-36c97d2e8ff4"
        },
        {
            "category": "[Platform Security] - Log records are generated and made available for continuous monitoring.",
            "code": "PR.PS-04.2",
            "label": "The organisation shall ensure that logbook records contain an authoritative time source or internal clock time stamp that is compared and synchronised with an authoritative time source.",
            "referential": "afc0d217-c09b-4033-a053-792a06872138",
            "referential_label": "Cyfun Important [EN]",
            "uuid": "d33d42b3-545b-48af-ab39-d6110f4945c7"
        },
        {
            "category": "[Platform Security] - Log records are generated and made available for continuous monitoring.",
            "code": "PR.PS-04.3",
            "label": "Audit data from the organisation's critical systems shall be moved to an alternative system.",
            "referential": "afc0d217-c09b-4033-a053-792a06872138",
            "referential_label": "Cyfun Important [EN]",
            "uuid": "d806fe05-6874-4526-be5e-e52e85d0db82"
        },
        {
            "category": "[Platform Security] - Installation and execution of unauthorised software are prevented.",
            "code": "PR.PS-05.1",
            "label": "Web and e-mail filters shall be installed and used.",
            "referential": "afc0d217-c09b-4033-a053-792a06872138",
            "referential_label": "Cyfun Important [EN]",
            "uuid": "1f6c946f-edae-415e-a904-f16a4df7a254"
        },
        {
            "category": "[Platform Security] - Installation and execution of unauthorised software are prevented.",
            "code": "PR.PS-05.2",
            "label": "Installation and execution of unauthorised software shall be prevented.",
            "referential": "afc0d217-c09b-4033-a053-792a06872138",
            "referential_label": "Cyfun Important [EN]",
            "uuid": "5bb1c385-9d4f-4db5-9402-63cc4ba7f588"
        },
        {
            "category": "[Platform Security] - Secure software development practices are integrated, and their performance is monitored throughout the software development life cycle.",
            "code": "PR.PS-06.1",
            "label": "Security shall be considered throughout the lifecycle of systems and applications, whether developed internally or acquired externally.",
            "referential": "afc0d217-c09b-4033-a053-792a06872138",
            "referential_label": "Cyfun Important [EN]",
            "uuid": "ea714ff5-5180-4fbc-b539-bf3c52cda611"
        },
        {
            "category": "[Platform Security] - Secure software development practices are integrated, and their performance is monitored throughout the software development life cycle.",
            "code": "PR.PS-06.2",
            "label": "Changes and exceptions shall be tested and validated before being implemented into operational systems.",
            "referential": "afc0d217-c09b-4033-a053-792a06872138",
            "referential_label": "Cyfun Important [EN]",
            "uuid": "1c4ec072-f437-49dd-b9d7-dc13f68f6497"
        },
        {
            "category": "[Technology Infrastructure Resilience] - Networks and environments are protected from unauthorised logical access and usage.",
            "code": "PR.IR-01.1",
            "label": "Firewalls shall be installed, configured, and actively maintained on all networks used by the organisation to protect against unauthorised access and cyber threats.",
            "referential": "afc0d217-c09b-4033-a053-792a06872138",
            "referential_label": "Cyfun Important [EN]",
            "uuid": "b7590468-2d17-42ab-bfcc-fe400ef93752"
        },
        {
            "category": "[Technology Infrastructure Resilience] - Networks and environments are protected from unauthorised logical access and usage.",
            "code": "PR.IR-01.2",
            "label": "To safeguard critical systems, organisations shall implement network segmentation and segregation aligned with trust boundaries and asset criticality, thereby limiting threat propagation and enforcing strict access control.",
            "referential": "afc0d217-c09b-4033-a053-792a06872138",
            "referential_label": "Cyfun Important [EN]",
            "uuid": "81318e0c-6b50-4b2e-80ee-56582893d965"
        },
        {
            "category": "[Technology Infrastructure Resilience] - Networks and environments are protected from unauthorised logical access and usage.",
            "code": "PR.IR-01.3",
            "label": "To ensure operational stability and security, the organisation shall, without exception, identify, document, and control connections between components of its critical systems.",
            "referential": "afc0d217-c09b-4033-a053-792a06872138",
            "referential_label": "Cyfun Important [EN]",
            "uuid": "186ec143-df64-4cda-8ef1-12d2afe119d4"
        },
        {
            "category": "[Technology Infrastructure Resilience] - Networks and environments are protected from unauthorised logical access and usage.",
            "code": "PR.IR-01.4",
            "label": "The organisation shall implement appropriate boundary protection measures to monitor and control communications at external and key internal boundaries of its critical systems, across both IT and OT environments, to ensure secure and reliable operations.",
            "referential": "afc0d217-c09b-4033-a053-792a06872138",
            "referential_label": "Cyfun Important [EN]",
            "uuid": "729db9e5-faf9-4545-b97f-bca15aaad2a9"
        },
        {
            "category": "[Technology Infrastructure Resilience] - The organisation's technology assets are protected from environmental threats.",
            "code": "PR.IR-02.1",
            "label": "The organisation shall define, implement and maintain policies and procedures related to emergency and safety systems, fire protection systems and environmental controls for its critical systems.",
            "referential": "afc0d217-c09b-4033-a053-792a06872138",
            "referential_label": "Cyfun Important [EN]",
            "uuid": "c5257a40-f08a-4634-8403-50bb47df7edb"
        },
        {
            "category": "[Technology Infrastructure Resilience] - Adequate resource capacity to ensure availability is maintained.",
            "code": "PR.IR-04.1",
            "label": "Adequate resource capacity planning shall ensure that availability of organisation's critical system information processing, networking, telecommunications, and data storage is maintained.",
            "referential": "afc0d217-c09b-4033-a053-792a06872138",
            "referential_label": "Cyfun Important [EN]",
            "uuid": "e57320ee-df31-4a22-8c77-22230fbd6274"
        },
        {
            "category": "[Continuous Monitoring] - Networks and network services are monitored to find potentially adverse events.",
            "code": "DE.CM-01.1",
            "label": "Firewalls shall be installed and operated at the network boundaries, including endpoint firewalls.",
            "referential": "afc0d217-c09b-4033-a053-792a06872138",
            "referential_label": "Cyfun Important [EN]",
            "uuid": "8f6bfa8e-83e2-4aa8-9a9a-692c64fc21a7"
        },
        {
            "category": "[Continuous Monitoring] - Networks and network services are monitored to find potentially adverse events.",
            "code": "DE.CM-01.2",
            "label": "Anti-virus, -spyware, and other -malware programs shall be installed and updated.",
            "referential": "afc0d217-c09b-4033-a053-792a06872138",
            "referential_label": "Cyfun Important [EN]",
            "uuid": "a09c0dbf-69d4-43f6-b39f-1583e2bcd347"
        },
        {
            "category": "[Continuous Monitoring] - Networks and network services are monitored to find potentially adverse events.",
            "code": "DE.CM-01.3",
            "label": "The organisation shall monitor and identify unauthorised use of its business-critical systems through the detection of unauthorised local connections, network connections and remote connections.",
            "referential": "afc0d217-c09b-4033-a053-792a06872138",
            "referential_label": "Cyfun Important [EN]",
            "uuid": "4ccf8845-01dc-4cbb-86d4-d7b00ec66c4b"
        },
        {
            "category": "[Continuous Monitoring] - The physical environment is monitored to find potentially adverse events.",
            "code": "DE.CM-02.1",
            "label": "The physical environment shall be monitored to find potentially adverse events.",
            "referential": "afc0d217-c09b-4033-a053-792a06872138",
            "referential_label": "Cyfun Important [EN]",
            "uuid": "0fba8b81-7768-4bcd-be49-c2e549c6d5d3"
        },
        {
            "category": "[Continuous Monitoring] - Personnel activity and technology usage are monitored to find potentially adverse events.",
            "code": "DE.CM-03.1",
            "label": "End point and network protection tools to monitor end-user behaviour for dangerous activity shall be implemented.",
            "referential": "afc0d217-c09b-4033-a053-792a06872138",
            "referential_label": "Cyfun Important [EN]",
            "uuid": "b0b4c086-ff2a-47b2-bb18-55048e09a896"
        },
        {
            "category": "[Continuous Monitoring] - Personnel activity and technology usage are monitored to find potentially adverse events.",
            "code": "DE.CM-03.2",
            "label": "End point and network protection tools that monitor end-user behaviour for dangerous activity shall be managed.",
            "referential": "afc0d217-c09b-4033-a053-792a06872138",
            "referential_label": "Cyfun Important [EN]",
            "uuid": "cebf767c-c614-41e1-a4b2-995b0c724e51"
        },
        {
            "category": "[Continuous Monitoring] - External service provider activities and services are monitored to find potentially adverse events.",
            "code": "DE.CM-06.1",
            "label": "External service provider activities and services shall be secured and monitored to find potentially adverse events.",
            "referential": "afc0d217-c09b-4033-a053-792a06872138",
            "referential_label": "Cyfun Important [EN]",
            "uuid": "60e1f8d9-c240-4042-a3cd-c37dd60d2799"
        },
        {
            "category": "[Continuous Monitoring] - External service provider activities and services are monitored to find potentially adverse events.",
            "code": "DE.CM-06.2",
            "label": "External service providers' conformance with personnel security policies and procedures and contract security requirements shall be monitored relative to their cybersecurity risks.",
            "referential": "afc0d217-c09b-4033-a053-792a06872138",
            "referential_label": "Cyfun Important [EN]",
            "uuid": "a1ef7e2d-1594-4851-862e-6024f7420b2e"
        },
        {
            "category": "[Continuous Monitoring] - Computing hardware and software, runtime environments, and their data are monitored to find potentially adverse events.",
            "code": "DE.CM-09.1",
            "label": "The organisation shall monitor computing hardware, software, runtime environments, and their data to detect potentially adverse events.",
            "referential": "afc0d217-c09b-4033-a053-792a06872138",
            "referential_label": "Cyfun Important [EN]",
            "uuid": "3ea07727-8f91-4b7a-abb6-54b2ddae58d4"
        },
        {
            "category": "[Adverse Event Analysis] - Potentially adverse events are analysed to better understand associated activities.",
            "code": "DE.AE-02.1",
            "label": "Cybersecurity and information security events shall be reviewed and analysed to identify potential attack targets and methods, in accordance with applicable laws, regulations, standards, and policies.",
            "referential": "afc0d217-c09b-4033-a053-792a06872138",
            "referential_label": "Cyfun Important [EN]",
            "uuid": "afaa14ac-f265-4136-b8ae-44a084a04b4b"
        },
        {
            "category": "[Adverse Event Analysis] - Information is correlated from multiple sources.",
            "code": "DE.AE-03.1",
            "label": "The logging functionality of protection and detection tools shall be enabled. Logs shall be backed up and retained for a predefined period, and regularly reviewed to identify unusual or potentially harmful activity.",
            "referential": "afc0d217-c09b-4033-a053-792a06872138",
            "referential_label": "Cyfun Important [EN]",
            "uuid": "ce578957-717e-4875-8cbd-88116c8f3ddd"
        },
        {
            "category": "[Adverse Event Analysis] - Information is correlated from multiple sources.",
            "code": "DE.AE-03.2",
            "label": "The organisation shall ensure that event data from critical systems is collected and correlated using information from multiple relevant sources.",
            "referential": "afc0d217-c09b-4033-a053-792a06872138",
            "referential_label": "Cyfun Important [EN]",
            "uuid": "3b1a37fa-4041-489b-b8c8-592870962041"
        },
        {
            "category": "[Adverse Event Analysis] - Information on adverse events is provided to authorised staff and tools.",
            "code": "DE.AE-06.1",
            "label": "Information about adverse events shall be promptly delivered to authorised personnel and systems to enable timely detection, investigation, and response.",
            "referential": "afc0d217-c09b-4033-a053-792a06872138",
            "referential_label": "Cyfun Important [EN]",
            "uuid": "0ed37d99-f76f-45e4-a797-f026c831fe71"
        },
        {
            "category": "[Adverse Event Analysis] - Incidents are declared when adverse events meet the defined incident criteria.",
            "code": "DE.AE-08.1",
            "label": "Incidents shall be reported when adverse events meet defined and documented incident criteria.",
            "referential": "afc0d217-c09b-4033-a053-792a06872138",
            "referential_label": "Cyfun Important [EN]",
            "uuid": "8bee5487-0a18-4806-befa-c930f56dae11"
        },
        {
            "category": "[Incident Management] - The incident response plan is executed in coordination with relevant third parties once an incident is declared.",
            "code": "RS.MA-01.1",
            "label": "An incident response plan, including defined roles, responsibilities, and authorities, shall be executed during or after a cybersecurity event affecting the organisation's critical systems.",
            "referential": "afc0d217-c09b-4033-a053-792a06872138",
            "referential_label": "Cyfun Important [EN]",
            "uuid": "7681504b-d6a4-4aed-9086-1e8198995cbc"
        },
        {
            "category": "[Incident Management] - The incident response plan is executed in coordination with relevant third parties once an incident is declared.",
            "code": "RS.MA-01.2",
            "label": "The organisation shall coordinate information/cybersecurity incident response actions with all predefined stakeholders.",
            "referential": "afc0d217-c09b-4033-a053-792a06872138",
            "referential_label": "Cyfun Important [EN]",
            "uuid": "581f32f5-8cf9-4b07-a270-c2e9d2e92441"
        },
        {
            "category": "[Incident Management] - Incident reports are triaged and validated.",
            "code": "RS.MA-02.1",
            "label": "Information/cybersecurity incident reports shall be triaged and validated in accordance with the organisation\u2019s incident response procedures.",
            "referential": "afc0d217-c09b-4033-a053-792a06872138",
            "referential_label": "Cyfun Important [EN]",
            "uuid": "4dbe23e9-27ed-4ad3-95f8-2da7f2cb19f6"
        },
        {
            "category": "[Incident Management] - Incidents are categorised and prioritised.",
            "code": "RS.MA-03.1",
            "label": "Information/cybersecurity incidents shall be categorised, prioritised and escalated as specified in the incident response plan.",
            "referential": "afc0d217-c09b-4033-a053-792a06872138",
            "referential_label": "Cyfun Important [EN]",
            "uuid": "6106c70d-0d25-48e5-ae1f-29f360a13f9a"
        },
        {
            "category": "[Incident Management] - The criteria for initiating incident recovery are applied.",
            "code": "RS.MA-05.1",
            "label": "Clear criteria shall be defined and applied to determine when incident recovery processes need to be initiated.",
            "referential": "afc0d217-c09b-4033-a053-792a06872138",
            "referential_label": "Cyfun Important [EN]",
            "uuid": "8e84dc5c-65a8-4d71-b8ab-efa13dabbf23"
        },
        {
            "category": "[Incident Response Reporting and Communication] - Internal and external stakeholders are notified of incidents.",
            "code": "RS.CO-02.1",
            "label": "Information about cybersecurity incidents shall be communicated to employees in a way that is clear and easy to understand.",
            "referential": "afc0d217-c09b-4033-a053-792a06872138",
            "referential_label": "Cyfun Important [EN]",
            "uuid": "8be136e0-a78c-496c-972b-c7b2391c05a2"
        },
        {
            "category": "[Incident Response Reporting and Communication] - Internal and external stakeholders are notified of incidents.",
            "code": "RS.CO-02.2",
            "label": "Cybersecurity incidents shall be shared with relevant external stakeholders within the timeframes defined in the Incident Response Plan, including reporting significant incidents to authorities as required by law.",
            "referential": "afc0d217-c09b-4033-a053-792a06872138",
            "referential_label": "Cyfun Important [EN]",
            "uuid": "59e845ed-59a8-4225-aead-2dfafa6ac173"
        },
        {
            "category": "[Incident Mitigation] - Incidents are contained.",
            "code": "RS.MI-01.1",
            "label": "Cybersecurity incidents shall be contained and eliminated. Any decision to accept and retain certain cybersecurity risks shall be formally documented.",
            "referential": "afc0d217-c09b-4033-a053-792a06872138",
            "referential_label": "Cyfun Important [EN]",
            "uuid": "db637f16-37a7-4585-9aae-b6bb7294e0c1"
        },
        {
            "category": "[Incident Mitigation] - Incidents are contained.",
            "code": "RS.MI-01.2",
            "label": "The organisation shall detect unauthorised access or data leakage and take appropriate mitigation actions, including monitoring of critical systems at external boundaries and key internal points.",
            "referential": "afc0d217-c09b-4033-a053-792a06872138",
            "referential_label": "Cyfun Important [EN]",
            "uuid": "3f3c35e2-dbc2-45db-9abc-fe33c010fbef"
        },
        {
            "category": "[Incident Recovery Plan Execution] - The recovery portion of the incident response plan is executed once initiated from the incident response process.",
            "code": "RC.RP-01.1",
            "label": "A recovery process for disasters and information/cybersecurity incidents shall be developed and executed.",
            "referential": "afc0d217-c09b-4033-a053-792a06872138",
            "referential_label": "Cyfun Important [EN]",
            "uuid": "d9726407-fc61-4d9b-8c24-cd99f876fea9"
        },
        {
            "category": "[Incident Recovery Plan Execution] - The integrity of restored assets is verified, systems and services are restored, and normal operating status is confirmed.",
            "code": "RC.RP-05.1",
            "label": "The integrity of restored systems and assets shall be verified before they are returned to service. Systems and services shall be fully restored, and normal operations shall be confirmed.",
            "referential": "afc0d217-c09b-4033-a053-792a06872138",
            "referential_label": "Cyfun Important [EN]",
            "uuid": "7f0a9735-42eb-4b86-850b-628cc4527d2c"
        },
        {
            "category": "[Incident Recovery Plan Execution] - The end of incident recovery is declared based on criteria, and incident-related documentation is completed.",
            "code": "RC.RP-06.1",
            "label": "The end of incident recovery shall be formally declared based on predefined criteria, and all incident-related documentation shall be completed and reviewed.",
            "referential": "afc0d217-c09b-4033-a053-792a06872138",
            "referential_label": "Cyfun Important [EN]",
            "uuid": "4545dbf1-3224-4718-8c1f-31ce3b3af2d0"
        },
        {
            "category": "[Incident Recovery Communication] - Recovery activities and progress in restoring operational capabilities are communicated to designated internal and external stakeholders.",
            "code": "RC.CO-03.1",
            "label": "Recovery activities and progress in restoring operational capabilities shall be communicated to designated internal and external stakeholders in accordance with established communication procedures.",
            "referential": "afc0d217-c09b-4033-a053-792a06872138",
            "referential_label": "Cyfun Important [EN]",
            "uuid": "465b7478-8894-4639-9430-6329ac3f5dff"
        },
        {
            "category": "[Incident Recovery Communication] - Public updates on incident recovery are shared using approved methods and messaging.",
            "code": "RC.CO-04.1",
            "label": "Public updates on incident recovery shall be shared using approved communication methods and messaging, in accordance with established procedures.",
            "referential": "afc0d217-c09b-4033-a053-792a06872138",
            "referential_label": "Cyfun Important [EN]",
            "uuid": "41da07e7-5686-4b4c-851d-a14bcc080728"
        }
    ],
    "version": 1,
    "version_ext": "CyFun\u00ae2025"
}