b) Risk management
c)
Security policy
d) Organisational security
e) Setting security requirements for suppliers
f)
Asset management
g) Human resources security
h) Operation and communication management of a critical information infrastructure or
important information system
i)
Access control to a critical information infrastructure or an important information system
j)
Acquisitions, development and maintenance of a critical information infrastructure and
important information systems
k) Cyber security events and cyber security incident management
l)
Business continuity management
m) Critical information infrastructure and important information systems control and audit
(3) Technical measures are as follows:
a) Physical security
b) Communication network integrity protection tools
c) User identity verification tools
d) Access authorization management tools
e) Malicious code protection tools
f)
Tools for recording the activities of a critical information infrastructure and important
information systems, and the activities of their users and administrators
g) Cyber security event detection tools
h) Acquisition and evaluation of cyber security events tools
i)
Application security
j)
Cryptographic devices
k) Tools for ensuring a level of information availability
l)
Industrial and management system security
Section 6
The implementing legal regulation shall set out the following:
a) Content of the security measures
b) Content and structure of the security documentation
c) Extent of security measures for public authorities and legal or natural persons specified in Section
3, letters c) to f)