Other tasks from the same security theme

Task name
Priority
Policy
Other requirements
Creating and maintaining risk management framework -report
Critical
High
Normal
Low
Risk management
6
requirements

Examples of other requirements this task affects

Article 5: Governance and organisation
DORA
Article 6: ICT risk management framework
DORA
Article 29: Information security policy and measures
DORA simplified RMF
See all related requirements and other information from tasks own page.
Go to >
Creating and maintaining risk management framework -report
Risk management policy -report publishing, informing and maintenance
Critical
High
Normal
Low
Risk management
2
requirements

Examples of other requirements this task affects

GV.PO-01: Policy for managing cybersecurity risks
NIST 2.0
GV.PO-02: Policy for managing cybersecurity risks
NIST 2.0
See all related requirements and other information from tasks own page.
Go to >
Risk management policy -report publishing, informing and maintenance
Identification and documentation of cyber security risks
Critical
High
Normal
Low
Risk management
82
requirements

Examples of other requirements this task affects

5. Principles relating to processing of personal data
GDPR
24. Responsibility of the controller
GDPR
13 §: Tietoaineistojen ja tietojärjestelmien tietoturvallisuus
TiHL
T04: Turvallisuusriskien hallinta
Katakri
ID.GV-4: Processes
NIST
See all related requirements and other information from tasks own page.
Go to >
Identification and documentation of cyber security risks
Risk management procedure -report publishing and maintenance
Critical
High
Normal
Low
Risk management
94
requirements

Examples of other requirements this task affects

5.1.1: Policies for information security
ISO 27001
T04: Turvallisuusriskien hallinta
Katakri
ID.GV-4: Processes
NIST
ID.RA-5: Risk evaluation
NIST
ID.RA-6: Risk responses
NIST
See all related requirements and other information from tasks own page.
Go to >
Risk management procedure -report publishing and maintenance
Annual cybersecurity assessment and reporting for critical infrastructure
Critical
High
Normal
Low
Risk management
1
requirements

Examples of other requirements this task affects

No items found.
See all related requirements and other information from tasks own page.
Go to >
Annual cybersecurity assessment and reporting for critical infrastructure
Identification and documentation of assets (Czech Republic)
Critical
High
Normal
Low
Risk management
3
requirements

Examples of other requirements this task affects

No items found.
See all related requirements and other information from tasks own page.
Go to >
Identification and documentation of assets (Czech Republic)
Training in risk assessment methodology
Critical
High
Normal
Low
Risk management
1
requirements

Examples of other requirements this task affects

No items found.
See all related requirements and other information from tasks own page.
Go to >
Training in risk assessment methodology
Risk assessment in technical documentation
Critical
High
Normal
Low
Risk management
1
requirements

Examples of other requirements this task affects

Article 13.4: Risk assessment in technical documentation
CRA
See all related requirements and other information from tasks own page.
Go to >
Risk assessment in technical documentation
Vulnerability management process
Critical
High
Normal
Low
Risk management
1
requirements

Examples of other requirements this task affects

Article 13.3: Documenting risk assessment
CRA
See all related requirements and other information from tasks own page.
Go to >
Vulnerability management process
Updating the risk assessment
Critical
High
Normal
Low
Risk management
1
requirements

Examples of other requirements this task affects

Article 13.3: Documenting risk assessment
CRA
See all related requirements and other information from tasks own page.
Go to >
Updating the risk assessment
Risk assessment of products
Critical
High
Normal
Low
Risk management
1
requirements

Examples of other requirements this task affects

Article 13.2: Risk assessment
CRA
See all related requirements and other information from tasks own page.
Go to >
Risk assessment of products
Risk rating system for logical control systems
Critical
High
Normal
Low
Risk management
1
requirements

Examples of other requirements this task affects

No items found.
See all related requirements and other information from tasks own page.
Go to >
Risk rating system for logical control systems
Defining the frequency and criteria for risk and vulnerability reassessment
Critical
High
Normal
Low
Risk management
1
requirements

Examples of other requirements this task affects

No items found.
See all related requirements and other information from tasks own page.
Go to >
Defining the frequency and criteria for risk and vulnerability reassessment
Risk assessment background information for participants
Critical
High
Normal
Low
Risk management
2
requirements

Examples of other requirements this task affects

12.2: Risk assessment measures
CER
See all related requirements and other information from tasks own page.
Go to >
Risk assessment background information for participants
Taking risk management into account in strategic decision making process
Critical
High
Normal
Low
Risk management
1
requirements

Examples of other requirements this task affects

No items found.
See all related requirements and other information from tasks own page.
Go to >
Taking risk management into account in strategic decision making process
Monitoring of risks
Critical
High
Normal
Low
Risk management
1
requirements

Examples of other requirements this task affects

No items found.
See all related requirements and other information from tasks own page.
Go to >
Monitoring of risks
Assesment of residual risks (DORA)
Critical
High
Normal
Low
Risk management
1
requirements

Examples of other requirements this task affects

No items found.
See all related requirements and other information from tasks own page.
Go to >
Assesment of residual risks (DORA)
Establishing risk tolerance level
Critical
High
Normal
Low
Risk management
1
requirements

Examples of other requirements this task affects

No items found.
See all related requirements and other information from tasks own page.
Go to >
Establishing risk tolerance level
Security management process for ePHI
Critical
High
Normal
Low
Risk management
1
requirements

Examples of other requirements this task affects

No items found.
See all related requirements and other information from tasks own page.
Go to >
Security management process for ePHI
Remediation plan for identified deficiencies
Critical
High
Normal
Low
Risk management
1
requirements

Examples of other requirements this task affects

12.5: Planul de măsuri pentru remedierea deficiențelor
NIS2 Romania
See all related requirements and other information from tasks own page.
Go to >
Remediation plan for identified deficiencies
Risk assessment for new acquisitions
Critical
High
Normal
Low
Risk management
1
requirements

Examples of other requirements this task affects

§ 9-4.1: Myndighet til å fatte vedtak ved anskaffelser til skjermingsverdig informasjonssystem, objekt og infrastruktur
Sikkerhetsloven
See all related requirements and other information from tasks own page.
Go to >
Risk assessment for new acquisitions
Personnel clearance procedure
Critical
High
Normal
Low
Risk management
1
requirements

Examples of other requirements this task affects

§ 8-2: Sikkerhetsklarering
Sikkerhetsloven
See all related requirements and other information from tasks own page.
Go to >
Personnel clearance procedure
Managing security authorization
Critical
High
Normal
Low
Risk management
1
requirements

Examples of other requirements this task affects

§ 8-10: Nedsettelse, suspensjon og tilbakekallelse av autorisasjon
Sikkerhetsloven
See all related requirements and other information from tasks own page.
Go to >
Managing security authorization
Personnel authorization procedure
Critical
High
Normal
Low
Risk management
3
requirements

Examples of other requirements this task affects

§ 8-1.2: Krav om konfidensiell og kritisk sikkerhetsklarering
Sikkerhetsloven
§ 8-9: Autorisasjon
Sikkerhetsloven
§ 8-1.1: Krav om sikkerhetsklarering, adgangsklarering og autorisasjon
Sikkerhetsloven
See all related requirements and other information from tasks own page.
Go to >
Personnel authorization procedure
Conduct and document a protective security analysis
Critical
High
Normal
Low
Risk management
1
requirements

Examples of other requirements this task affects

§ 2.1: Skyldigheter för den som bedriver säkerhetskänslig verksamhet
SSL
See all related requirements and other information from tasks own page.
Go to >
Conduct and document a protective security analysis
Procedure for security assessments in transfers of sensitive activities
Critical
High
Normal
Low
Risk management
2
requirements

Examples of other requirements this task affects

§ 4.14: Säkerhetsbedömning för sekretessbelagd information
SSL
§ 4.9: Lämplighetsprövningen
SSL
See all related requirements and other information from tasks own page.
Go to >
Procedure for security assessments in transfers of sensitive activities
Create and maintain a system architecture and risk assessment document
Critical
High
Normal
Low
Risk management
1
requirements

Examples of other requirements this task affects

13.4: Sikring af udsendelse af offentlige advarsler
NIS2 Denmark
See all related requirements and other information from tasks own page.
Go to >
Create and maintain a system architecture and risk assessment document
Conducting threat modeling
Critical
High
Normal
Low
Risk management
2
requirements

Examples of other requirements this task affects

16.14: Conduct Threat Modeling
CIS 18
See all related requirements and other information from tasks own page.
Go to >
Conducting threat modeling
Monitoring service providers
Critical
High
Normal
Low
Risk management
1
requirements

Examples of other requirements this task affects

15.6: Monitor Service Providers
CIS 18
See all related requirements and other information from tasks own page.
Go to >
Monitoring service providers
Assessing service providers
Critical
High
Normal
Low
Risk management
1
requirements

Examples of other requirements this task affects

15.5: Assess Service Providers
CIS 18
See all related requirements and other information from tasks own page.
Go to >
Assessing service providers
Evaluation of risk management strategy, results and performance
Critical
High
Normal
Low
Risk management
3
requirements

Examples of other requirements this task affects

GV.OV-01: Cybersecurity risk management strategy review
NIST 2.0
GV.OV-02: Coverage of organization requirements in cybersecurity risk management strategy
NIST 2.0
GV.OV-03: Organizational cybersecurity risk management performance
NIST 2.0
See all related requirements and other information from tasks own page.
Go to >
Evaluation of risk management strategy, results and performance
Strategic opportunities and positive risks
Critical
High
Normal
Low
Risk management
1
requirements

Examples of other requirements this task affects

GV.RM-07: Strategic opportunities in organizational cybersecurity risk discussions
NIST 2.0
See all related requirements and other information from tasks own page.
Go to >
Strategic opportunities and positive risks
Creating and maintaining risk assessment framework
Critical
High
Normal
Low
Risk management
1
requirements

Examples of other requirements this task affects

1.1.3: Identify the organisation’s processes for ICT risk management
NSM ICT-SP
See all related requirements and other information from tasks own page.
Go to >
Creating and maintaining risk assessment framework
Identification and assessment of risks based on the classification of data sets
Critical
High
Normal
Low
Risk management
0
requirements

Examples of other requirements this task affects

No items found.
See all related requirements and other information from tasks own page.
Go to >
Identification and assessment of risks based on the classification of data sets
Enabling asset-based risk management in the ISMS
Critical
High
Normal
Low
Risk management
8
requirements

Examples of other requirements this task affects

Article 8: Identification
DORA
2.5: Riskienhallinta
TiHL tietoturvavaatimukset
5.2.2: Seperation of testing and development environments
TISAX
1.1.3: Identify the organisation’s processes for ICT risk management
NSM ICT-SP
Article 31: ICT risk management
DORA simplified RMF
See all related requirements and other information from tasks own page.
Go to >
Enabling asset-based risk management in the ISMS
Assigning responsibility of ICT-risk management to appropriate function
Critical
High
Normal
Low
Risk management
1
requirements

Examples of other requirements this task affects

Article 6: ICT risk management framework
DORA
See all related requirements and other information from tasks own page.
Go to >
Assigning responsibility of ICT-risk management to appropriate function
Consideration of security-classified risks to information in risk management
Critical
High
Normal
Low
Risk management
2
requirements

Examples of other requirements this task affects

T-03: MANAGEMENT OF INFORMATION SECURITY RISKS
Katakri 2020
See all related requirements and other information from tasks own page.
Go to >
Consideration of security-classified risks to information in risk management
Regular internal monitoring of the implementation of the information security management system
Critical
High
Normal
Low
Risk management
49
requirements

Examples of other requirements this task affects

18.2.2: Compliance with security policies and standards
ISO 27001
5.36: Compliance with policies, rules and standards for information security
ISO 27001
4.4: Information security management system
ISO 27001
12: Digiturvan tilan seuraaminen
Digiturvan kokonaiskuvapalvelu
20.2: Top management monitoring for training
NIS2
See all related requirements and other information from tasks own page.
Go to >
Regular internal monitoring of the implementation of the information security management system
Documentation of linked risks for identified security incidents
Critical
High
Normal
Low
Risk management
34
requirements

Examples of other requirements this task affects

5. Principles relating to processing of personal data
GDPR
24. Responsibility of the controller
GDPR
T05: Jatkuvuuden hallinta
Katakri
21.2.a: Risk management and information system security
NIS2
8.3: Information security risk treatment
ISO 27001
See all related requirements and other information from tasks own page.
Go to >
Documentation of linked risks for identified security incidents
List of work tasks requiring the handling of confidential information
Critical
High
Normal
Low
Risk management
4
requirements

Examples of other requirements this task affects

T12: Tiedonsaantitarve ja käsittelyoikeudet
Katakri
HAL-10: Henkilöstön luotettavuuden arviointi
Julkri
T-13: NEED-TO-KNOW AND ACCESS RIGHTS
Katakri 2020
I-06: THE PRINCIPLE OF LEAST PRIVILEGE – MANAGEMENT OF ACCESS RIGHTS
Katakri 2020
See all related requirements and other information from tasks own page.
Go to >
List of work tasks requiring the handling of confidential information
Yleiset muutostenhallintamenettelyt (ST IV-III)
Critical
High
Normal
Low
Risk management
1
requirements

Examples of other requirements this task affects

I20: Muutoshallintamenettelyt
Katakri
See all related requirements and other information from tasks own page.
Go to >
Yleiset muutostenhallintamenettelyt (ST IV-III)
Yleiset muutostenhallintamenettelyt (ST II)
Critical
High
Normal
Low
Risk management
1
requirements

Examples of other requirements this task affects

I20: Muutoshallintamenettelyt
Katakri
See all related requirements and other information from tasks own page.
Go to >
Yleiset muutostenhallintamenettelyt (ST II)
Evaluation process and documentation of significant security-related changes
Critical
High
Normal
Low
Risk management
61
requirements

Examples of other requirements this task affects

12.1.2: Change management
ISO 27001
6.5: Tietojärjestelmien asennus, ylläpito ja päivitys
Omavalvontasuunnitelma
PR.IP-3: Configuration change control processes
NIST
TEK-17: Muutoshallintamenettelyt
Julkri
8.32: Change management
ISO 27001
See all related requirements and other information from tasks own page.
Go to >
Evaluation process and documentation of significant security-related changes
Treatment process and documentation of identified non-conformities
Critical
High
Normal
Low
Risk management
29
requirements

Examples of other requirements this task affects

10.2: Non-conformity and corrective action
ISO 27001
23: Häiriöiden- ja poikkeamienhallintaprosessi
Digiturvan kokonaiskuvapalvelu
21.4: Non-conformities and corrective actions
NIS2
CC4.2: Evaluation and communication of internal control deficiencies
SOC 2
P8.1: Periodic monitoring of privacy compliance
SOC 2
See all related requirements and other information from tasks own page.
Go to >
Treatment process and documentation of identified non-conformities
Taking the results of risk management into account in audit procedures
Critical
High
Normal
Low
Risk management
3
requirements

Examples of other requirements this task affects

Article 6: ICT risk management framework
DORA
1.4.1: Management of Information Security Risks
TISAX
See all related requirements and other information from tasks own page.
Go to >
Taking the results of risk management into account in audit procedures
Consideration of risk management results in continuity planning
Critical
High
Normal
Low
Risk management
7
requirements

Examples of other requirements this task affects

29: Jatkuvuuteen liittyvien riskien arviointi
Digiturvan kokonaiskuvapalvelu
30: Riskeihin perustuvat jatkuvuussuunnitelmat
Digiturvan kokonaiskuvapalvelu
1.4.1: Management of Information Security Risks
TISAX
28.(1): Kiberriska pārvaldības un nepārtrauktības plāni
NIS2 Latvia
§ 10: Krav om sikkerhet for tilbydere av digitale tjenester
NIS2 NO
See all related requirements and other information from tasks own page.
Go to >
Consideration of risk management results in continuity planning
Practicing disaster plans
Critical
High
Normal
Low
Risk management
3
requirements

Examples of other requirements this task affects

§ 13.3: Beredskapsplanlegging og øvelser
NIS2 NO
See all related requirements and other information from tasks own page.
Go to >
Practicing disaster plans
Process for including information security aspects in project management
Critical
High
Normal
Low
Risk management
5
requirements

Examples of other requirements this task affects

6.1.5: Information security in project management
ISO 27001
5.8: Information security in project management
ISO 27001
1.2.3: Information Security requirements in projects
TISAX
See all related requirements and other information from tasks own page.
Go to >
Process for including information security aspects in project management
Assessment of the impact and likelihood of the risks and the scales used
Critical
High
Normal
Low
Risk management
13
requirements

Examples of other requirements this task affects

ID.RA-4: Impacts on business
NIST
Article 6: ICT risk management framework
DORA
2.5: Riskienhallinta
TiHL tietoturvavaatimukset
1.4.1: Management of Information Security Risks
TISAX
ID.RA-5: Threats, vulnerabilities, likelihoods, and impacts are used to determine risk
CyberFundamentals
See all related requirements and other information from tasks own page.
Go to >
Assessment of the impact and likelihood of the risks and the scales used
Approval of the risk management procedure description
Critical
High
Normal
Low
Risk management
9
requirements

Examples of other requirements this task affects

ID.RM-1: Risk management processes
NIST
Article 6: ICT risk management framework
DORA
1.4.1: Management of Information Security Risks
TISAX
ID.RM-1: Risk management processes are established, managed, and agreed to by organizational stakeholders.
CyberFundamentals
GV.RM-01: Establishing and agreeing on risk management objectives with stakeholders
NIST 2.0
See all related requirements and other information from tasks own page.
Go to >
Approval of the risk management procedure description
Risk level accepted by the organization
Critical
High
Normal
Low
Risk management
43
requirements

Examples of other requirements this task affects

ID.RM-2: Risk tolerance
NIST
ID.RM-3: Informing of risk tolerance
NIST
6.1: Information security risk management
ISO 27001
RISK-1: Establish and Maintain Cyber Risk Management Strategy and Program
C2M2
21.2.a: Risk management and information system security
NIS2
See all related requirements and other information from tasks own page.
Go to >
Risk level accepted by the organization
Evaluation of the information security measures defined in the risk management phase
Critical
High
Normal
Low
Risk management
5
requirements

Examples of other requirements this task affects

HAL-06: Riskienhallinta
Julkri
RISK-4: Respond to Cyber Risk
C2M2
CC5.1: Control activities for mitigation of risks
SOC 2
1.4.1: Management of Information Security Risks
TISAX
Article 31: ICT risk management
DORA simplified RMF
See all related requirements and other information from tasks own page.
Go to >
Evaluation of the information security measures defined in the risk management phase
Legal risks related to the service
Critical
High
Normal
Low
Risk management
1
requirements

Examples of other requirements this task affects

HAL-06.1: Riskienhallinta - lainsäädäntöjohdannaiset riskit
Julkri
See all related requirements and other information from tasks own page.
Go to >
Legal risks related to the service
Assessment of physical security risks
Critical
High
Normal
Low
Risk management
3
requirements

Examples of other requirements this task affects

FYY-01: Fyysisen turvallisuuden riskien arviointi
Julkri
F-02: RISK ASSESSMENT OF PHYSICAL SECURITY MEASURES
Katakri 2020
8 §: Kyberturvallisuutta koskeva riskienhallinnan toimintamalli
Kyberturvallisuuslaki
See all related requirements and other information from tasks own page.
Go to >
Assessment of physical security risks
Change management procedures in information processing environments (CL IV)
Critical
High
Normal
Low
Risk management
2
requirements

Examples of other requirements this task affects

TEK-17.3: Muutoshallintamenettelyt
Julkri
I-16: SECURITY THROUGHOUT THE INFORMATION PROCESSING ENVIRONMENT LIFE CYCLE - CHANGE MANAGEMENT
Katakri 2020
See all related requirements and other information from tasks own page.
Go to >
Change management procedures in information processing environments (CL IV)
Immediate reporting of critical risks to top management
Critical
High
Normal
Low
Risk management
3
requirements

Examples of other requirements this task affects

18: Kriittisten riskien raportointi
Digiturvan kokonaiskuvapalvelu
1.1.3: Identify the organisation’s processes for ICT risk management
NSM ICT-SP
See all related requirements and other information from tasks own page.
Go to >
Immediate reporting of critical risks to top management
Monitoring the status of risk management
Critical
High
Normal
Low
Risk management
9
requirements

Examples of other requirements this task affects

19: Riskienhallinan tilanteen seuraaminen
Digiturvan kokonaiskuvapalvelu
CC5.1: Control activities for mitigation of risks
SOC 2
Article 6: ICT risk management framework
DORA
2.5: Riskienhallinta
TiHL tietoturvavaatimukset
1.1.3: Identify the organisation’s processes for ICT risk management
NSM ICT-SP
See all related requirements and other information from tasks own page.
Go to >
Monitoring the status of risk management
Consideration of critical functions in risk management
Critical
High
Normal
Low
Risk management
4
requirements

Examples of other requirements this task affects

74: Kriittisten palveluiden riskien arviointi ja hallinta
Digiturvan kokonaiskuvapalvelu
ID.BE-4: Dependencies and critical functions for delivery of critical services are established.
CyberFundamentals
31: Besondere Anforderungen an die Risikomanagementmaßnahmen von Betreibern kritischer Anlagen
NIS2 Germany
12.1: Risk assessments
CER
See all related requirements and other information from tasks own page.
Go to >
Consideration of critical functions in risk management
Identification of risks endangering the continuity of operations and their handling plans
Critical
High
Normal
Low
Risk management
2
requirements

Examples of other requirements this task affects

CC9.1: Treatment plans for business disruption risks
SOC 2
28.(1): Kiberriska pārvaldības un nepārtrauktības plāni
NIS2 Latvia
See all related requirements and other information from tasks own page.
Go to >
Identification of risks endangering the continuity of operations and their handling plans
Consideration of information security goals in risk assessment
Critical
High
Normal
Low
Risk management
4
requirements

Examples of other requirements this task affects

CC5.1: Control activities for mitigation of risks
SOC 2
30 § 2°: Évaluation des risques et mesures de gestion
NIS2 Belgium
§ 7: Risikovurdering
NIS2 NO
See all related requirements and other information from tasks own page.
Go to >
Consideration of information security goals in risk assessment
Segregation of tasks in information security risk management
Critical
High
Normal
Low
Risk management
1
requirements

Examples of other requirements this task affects

CC5.1: Control activities for mitigation of risks
SOC 2
See all related requirements and other information from tasks own page.
Go to >
Segregation of tasks in information security risk management
Regular external auditing of security practices
Critical
High
Normal
Low
Risk management
30
requirements

Examples of other requirements this task affects

18.2.1: Independent review of information security
ISO 27001
5.35: Independent review of information security
ISO 27001
51: Tietoturvallisuuden auditointi
Digiturvan kokonaiskuvapalvelu
21.2.f: Assessing effectiveness of security measures
NIS2
CC4.1: Evaluation of internal controls
SOC 2
See all related requirements and other information from tasks own page.
Go to >
Regular external auditing of security practices
Detection of non-compliance with the change management procedure
Critical
High
Normal
Low
Risk management
4
requirements

Examples of other requirements this task affects

CC3.4: Identification and assesment of changes
SOC 2
ID.IM-01: Improvements from evaluations
NIST 2.0
See all related requirements and other information from tasks own page.
Go to >
Detection of non-compliance with the change management procedure
Rules for deviating from the change management procedure
Critical
High
Normal
Low
Risk management
4
requirements

Examples of other requirements this task affects

CC3.4: Identification and assesment of changes
SOC 2
5.2.1: Change management
TISAX
See all related requirements and other information from tasks own page.
Go to >
Rules for deviating from the change management procedure
Regular communication of the general risk situation to the organization's management
Critical
High
Normal
Low
Risk management
5
requirements

Examples of other requirements this task affects

17: Riskitilanteen raportointi johdolle
Digiturvan kokonaiskuvapalvelu
CC3.2: Identification of risks related to objectives
SOC 2
1.1.4: Identify the organisation’s tolerances for ICT risk
NSM ICT-SP
GV.RM-05: Communication lines for cybersecurity risks across the organization
NIST 2.0
See all related requirements and other information from tasks own page.
Go to >
Regular communication of the general risk situation to the organization's management
Assessment of residual risks
Critical
High
Normal
Low
Risk management
30
requirements

Examples of other requirements this task affects

20: Jäännösriskien arviointi
Digiturvan kokonaiskuvapalvelu
21.2.a: Risk management and information system security
NIS2
2.5: Riskienhallinta
TiHL tietoturvavaatimukset
7 §: Riskienhallinta
Kyberturvallisuuslaki
ID.GV-4: Governance and risk management processes address cybersecurity risks.
CyberFundamentals
See all related requirements and other information from tasks own page.
Go to >
Assessment of residual risks
Continuous improvement of the risk management process
Critical
High
Normal
Low
Risk management
32
requirements

Examples of other requirements this task affects

21: Riskienhallintaprosessin kehittäminen
Digiturvan kokonaiskuvapalvelu
21.2.a: Risk management and information system security
NIS2
Article 6: ICT risk management framework
DORA
1.4.1: Management of Information Security Risks
TISAX
8 §: Kyberturvallisuutta koskeva riskienhallinnan toimintamalli
Kyberturvallisuuslaki
See all related requirements and other information from tasks own page.
Go to >
Continuous improvement of the risk management process
Consideration of partner risks in information security risk management
Critical
High
Normal
Low
Risk management
5
requirements

Examples of other requirements this task affects

CC9.2: Partner risk management
SOC 2
1.3.3: Use of approved external IT services
TISAX
30 § 2°: Évaluation des risques et mesures de gestion
NIS2 Belgium
19.2.i (risk management): Insider risk management
NIS2 Malta
12.1: Mesures de sécurité et gestion des risques
NIS2 Luxembourg
See all related requirements and other information from tasks own page.
Go to >
Consideration of partner risks in information security risk management

Never duplicate effort. Do it once - improve compliance across frameworks.

Reach multi-framework compliance in the simplest possible way
Security frameworks tend to share the same core requirements - like risk management, backup, malware, personnel awareness or access management.
Cyberday maps all frameworks’ requirements into shared tasks - one single plan that improves all frameworks’ compliance.
Do it once - we automatically apply it to all current and future frameworks.
Get to know Cyberday
Start your free trial
Cyberday is your all-in-one solution for building a secure and compliant organization. Whether you're setting up a cyber security plan, evaluating policies, implementing tasks, or generating automated reports, Cyberday simplifies the entire process.
With AI-driven insights and a user-friendly interface, it's easier than ever to stay ahead of compliance requirements and focus on continuous improvement.
Clear framework compliance plans
Activate relevant frameworks and turn them into actionable policies tailored to your needs.
Credible reports to proof your compliance
Use guided tasks to ensure secure implementations and create professional reports with just a few clicks.
AI-powered improvement suggestions
Focus on the most impactful improvements in your compliance with help from Cyberday AI.
No items found.