A management system built against the 2013 control catalogue describes an organisation that in most cases no longer exists. Operations have moved to cloud services, code is written on platforms somebody else owns, and intelligence about current threats passes through without catching anywhere. The certificate is valid, but it answers yesterday's questions. The eleven new controls are to a large extent a description of exactly that shift.
The chapter opens with an overview of what changed in the 2022 version and why, which reality the standard was trying to catch up with. Then follow the eleven controls one by one, with the same structure for each so they can be compared. Threat intelligence, which links directly to the work in chapter 22. Cloud service security, which formalises the responsibility often assumed to sit with the supplier but rarely doing so in full. ICT readiness for business continuity, which ties the standard to chapter 23 on continuity planning and is the control where the difference between a plan and a capability most often becomes visible. Physical security monitoring. Configuration management, information deletion, data masking and data leakage prevention, which together concern control over where data actually ends up and how long it stays there. Then monitoring of activities, web filtering and secure coding. The chapter closes with the question of prioritisation, where an organisation reasonably starts when eleven new controls have to be introduced alongside everything already under way.
The question is current because the transition period from the 2013 version has expired, and because several of the controls answer to areas the Cybersecurity Act touches. Anyone working with both gains from treating it as one effort rather than two, since the underlying material is in practice the same. Several of the controls also describe conditions that already exist in the operation, which means the work more often concerns formalising than building new.
This page shows what the chapter covers and why the controls hang together. The control by control review and the order of priority are in chapter 15 of the book.
The standard gives you the list. The risk analysis tells you where to start.
Key insights
- The eleven controls are not new requirements but a codification of what had already become practice.
- Several of them cover areas the Cybersecurity Act touches, which makes them doubly valuable.
- ICT readiness for business continuity is the control that most often reveals that continuity work is a document.
- Prioritisation should come out of the risk analysis. The standard gives the list but not the order.
Tools that belong to this chapter
The templates and interactive tools are in the Toolbox, free of charge.
Control mapping
Appendix B, the controls mapped against the requirement areas of the Cybersecurity Act.
Read on
Next step
Where does your organisation stand?
The self-assessment gives you a maturity profile against the ten requirement areas of the Cybersecurity Act in a few minutes, right on screen.