The head of the organization is responsible for establishing a comprehensive information security management framework. This includes the mandatory registration of the organization with the cybersecurity authority (SZTFH), the classification of all electronic information systems into security levels (Basic, Significant, or High) and the formal appointment of a qualified Information Security Officer (ISO).
The organization's leadership should ensure security measures are proportionate to the identified risks and that an official Information Security Policy is issued and reviewed at least every two years. Management should also ensure at least 5% of IT development expenditure is dedicated to cybersecurity enhancements (where applicable) and that all staff, including leadership, undergo regular cybersecurity training to maintain organizational resilience.