Estas medidas se aplicarán a los activos o sistemas que se utilicen para la prestación de sus servicios u operaciones y deberán figurar en un documento suscrito por el responsable de seguridad de la información denominado declaración de aplicabilidad de sistemas.
Dicho documento deberá remitirse a la autoridad de control correspondiente dentro de los seis meses siguientes a la adquisición de la condición de entidad esencial o importante.
Essential or important organizations must apply cybersecurity measures to all systems and equipment they use to deliver their services or run their operations. These applied security measures must be documented in a file called the “Statement of Applicability of Systems.” This document should: List which systems are in use Explain which security measures apply to each system Be signed by the Information Security Officer, who is responsible for overseeing cybersecurity in the organization This document must be sent to the appropriate supervisory authority within six months after the organization is officially classified as an essential or important entity.
Digiturvamallissa kaikki vaatimuskehikkojen vaatimukset kohdistetaan universaaleihin tietoturvatehtäviin, jotta voitte muodostaa yksittäisen suunnitelman, joka täyttää ison kasan vaatimuksia.