SkarpSkarp

Chapter 3 of 5

The Annex in Action: Governance, Incidents, Continuity and Suppliers

The Annex turns the Regulation’s policy rationale into auditable organizational duties. This chapter follows the control system from management-approved security policies and risk treatment through incident response, crisis management, tested recovery and continuous oversight of direct suppliers.

26 min readen

1. From Policy to Evidence

What the Annex does

Annex points 1 to 5 translate cybersecurity risk management into organisational duties: policy, risk treatment, oversight, incident handling, continuity, crisis management, and supplier control.

Read the verbs carefully

Shall is mandatory. Conditions such as where appropriate, where applicable, and to the extent feasible limit the requirement and must not be removed.

A control loop

Policy and authority feed risk management; risk informs monitoring and response; incidents generate lessons; continuity and supplier controls sustain the whole system.

2. Policy, Authority, and Management Bodies

Policy content

Point 1.1.1 requires an approach, business alignment, security objectives, resources, communication, documented retention, topic-specific policies, maturity indicators, and formal approval date.

Continual improvement

The policy must include a commitment to continual improvement of the security of network and information systems. This is a required policy commitment, not an optional aspiration.

Annual review and accountability

The network and information system security policy shall be reviewed and, where appropriate, updated by management bodies at least annually and after specified significant events.

Direct reporting

Roles must be allocated and communicated. At least one person shall report directly to the management bodies on matters of network and information system security.

3. Risk Management: From Risk Identification to Treatment

Framework and plan

the relevant entities shall establish and maintain an appropriate risk management framework to identify and address the risks posed to the security of network and information systems.

Documented treatment

The relevant entities shall perform and document risk assessments and, based on the results, establish, implement and monitor a risk treatment plan.

What the process covers

The process includes methodology, tolerance, criteria, all-hazards identification, analysis, evaluation, prioritised treatment, implementation monitoring, ownership, timing, and residual-risk reasons.

Example: one identity provider

A single identity provider can be a single point of failure. Risk treatment may combine resilient design, fallback access, supplier controls, assigned owners, and documented residual-risk acceptance.

4. Risk Review, Compliance Monitoring, and Independent Review

When risk must be revisited

Point 2.1.4 requires review and possible update at planned intervals and at least annually, and when significant changes to operations or risks or significant incidents occur.

Compliance reporting

Compliance reviews cover policies, rules, and standards. Their reporting must give management bodies an informed view of the entity's current management of risks.

Independence protects objectivity

Internal reviewers must not be in the line of authority of the area reviewed. If size makes this impossible, alternative measures shall guarantee impartiality.

What follows review

Review results go to management bodies. The entity shall take corrective action or accept residual risk according to its risk acceptance criteria.

Quiz 1: Governance and Risk

Choose the statement that accurately reflects Annex points 1 and 2.

Which statement is correct?

  1. The security policy may be reviewed every two years if no incident has occurred.
  2. Risk treatment measures may be selected without assigning an implementation owner.
  3. The risk assessment results and risk treatment plan shall be reviewed and, where appropriate, updated at planned intervals and at least annually, and when significant changes to operations or risks or significant incidents occur.
  4. Independent reviewers may always report through the management chain of the area they review.
Show Answer

Answer: C) The risk assessment results and risk treatment plan shall be reviewed and, where appropriate, updated at planned intervals and at least annually, and when significant changes to operations or risks or significant incidents occur.

Point 2.1.4 contains this review frequency and these triggers. Point 2.1.2 also requires identification of who is responsible for implementing treatment measures and when. Point 2.3.2 protects review independence.

5. Incident Handling: Prepare, Detect, and Preserve Evidence

The incident-handling policy

The policy must set roles, responsibilities, and timely procedures for detection, analysis, containment or response, recovery, documentation, and reporting.

Coherence and testing

The policy shall be coherent with the business continuity and disaster recovery plan. Its roles, responsibilities, and procedures must be tested and reviewed.

Monitoring and logging

The relevant entities shall lay down procedures and use tools to monitor and log activities on their network and information systems to detect events that could be considered as incidents.

Log integrity

The relevant entities shall maintain and back up logs for a predefined period and shall protect them from unauthorised access or changes.

6. Incident Decisions: Report, Classify, Respond, Learn

From event to incident

Suspicious events must be assessed for incident status, nature, and severity using predefined criteria, triage, appropriate logs, correlation, analysis, and possible reclassification.

Quarterly recurring-incident check

Entities shall assess the existence of recurring incidents as referred to in Article 4 of this Regulation on a quarterly basis.

Response sequence

Procedures include incident containment, to prevent the consequences of the incident from spreading, then eradication, then recovery where necessary.

Learn after recovery

Where appropriate, reviews follow recovery. They identify root cause where possible and produce documented lessons learned that improve future controls.

7. Continuity and Disaster Recovery: Restore What Matters First

The mandatory plan

the relevant entities shall lay down and maintain a business continuity and disaster recovery plan to apply in the case of incidents.

What it can include

Where appropriate: activation conditions, contacts, roles, recovery order, operation-specific recovery objectives, required backups and redundancies, and return from temporary measures.

Business impact analysis

The relevant entities shall carry out a business impact analysis to assess the potential impact of severe disruptions to their business operations.

Test and improve

Plans must be tested, reviewed, and possibly updated at planned intervals and after listed significant triggers. Lessons from tests must be incorporated.

8. Backups, Redundancy, and Crisis Management

Separated backups

Backup plans require storing backup copies (online or offline) in a safe location or locations, which are not in the same network as the system and far enough from the main site.

Backup reliability

The relevant entities shall perform regular integrity checks on the backup copies. Recovery testing must cover copies, processes, and knowledge needed for effective recovery.

Redundancy

At least partial redundancy is required, based on risk and continuity planning, for systems, assets, competent personnel, and appropriate communication channels.

Crisis management

The relevant entities shall put in place a process for crisis management. It includes roles, authority communication, security measures, and use of CSIRT or authority information.

9. Supply Chain Security: Select, Contract, Monitor

Direct-supplier focus

The policy governs relations with direct suppliers and service providers to mitigate identified network and information system security risks.

Selection criteria

Criteria include cybersecurity practice, ability to meet specifications, product and service resilience, embedded risk measures, and vendor lock-in limits where applicable.

Contract protections

Where appropriate, contracts specify incident notification without undue delay, audit rights or audit reports, vulnerability handling, subcontracting conditions, and termination obligations.

Ongoing oversight

Supplier oversight is continuing: review the policy, monitor implementation reports where applicable, review incidents, assess unscheduled reviews, analyse changes, and mitigate timely.

10. Flashcards: Essential Annex Phrases

Flip each card and recall both the required action and the condition attached to it.

Policy review frequency
The policy is reviewed and, where appropriate, updated by management bodies at least annually and when significant incidents or significant changes to operations or risks occur. The result is documented.
Residual risk
Risk assessment results and residual risks are accepted by management bodies or, where applicable, authorised accountable persons, provided adequate reporting to management bodies is ensured.
Monitoring automation
To the extent feasible, monitoring is automated and continuous or periodic, subject to business capabilities, while minimising false positives and false negatives.
Incident response stages
Containment to stop spread; eradication to stop continuation or recurrence; and recovery where necessary.
Business impact analysis
It assesses the potential impact of severe disruptions to business operations and supports continuity requirements for network and information systems.
Supplier registry
A current registry of direct suppliers and service providers, including contact points and the ICT products, ICT services, and ICT processes each provides.

11. Supplier Monitoring and the Registry

Procurement is part of security

Points 5.1.2 and 5.1.3 selection criteria must inform both new-supplier selection and the procurement process referred to in point 6.1.

Monitor change

Entities shall monitor, evaluate, and where necessary act on supplier cybersecurity-practice changes at planned intervals and following the listed significant triggers.

Unscheduled review

Entities shall assess the need for unscheduled reviews, document findings comprehensibly, analyse risks from supplier ICT changes, and mitigate in a timely manner where appropriate.

The supplier registry

The relevant entities shall maintain and keep up to date a registry of their direct suppliers and service providers with contact points and lists of supplied ICT products, services, and processes.

12. Quiz 2: Recovery and Suppliers

Test whether you can distinguish mandatory requirements from conditional details.

Which option most accurately states the Annex requirement?

  1. Backups may stay on the same network if they are encrypted.
  2. Every supplier contract must always contain every listed term, regardless of the phrase 'where appropriate'.
  3. Relevant entities shall carry out regular testing of recovery of backup copies and redundancies, document test results, and, where needed, take corrective action.
  4. A supplier registry only needs product names and can omit supplier contact points.
Show Answer

Answer: C) Relevant entities shall carry out regular testing of recovery of backup copies and redundancies, document test results, and, where needed, take corrective action.

Point 4.2.6 requires regular recovery testing of backup copies and redundancies, documentation of test results, and corrective action where needed. Point 4.2.2(c) requires backup locations not in the same network as the system. Point 5.1.4 retains the qualification 'where appropriate', while point 5.2 expressly requires contact points and lists of supplied ICT products, services, and processes.

Key Terms

redundancy
Sufficient alternative resources, including systems, assets, personnel, and communication channels, used to support availability and recovery.
residual risk
Risk remaining after treatment measures. Under point 2.1.1, it must be accepted by management bodies or, where applicable, authorised accountable persons, with adequate reporting to management bodies.
vendor lock-in
Dependence on one supplier that makes switching or diversifying difficult. Point 5.1.2(d) requires consideration of limiting it where applicable.
suspicious event
An event reported or detected that must be assessed under point 3.4.1 to determine whether it constitutes an incident and, if so, its nature and severity.
management bodies
The governing body or bodies referenced throughout the Annex. They formally approve the security policy, receive direct security reporting and regular reporting, and have specified responsibilities for review and risk acceptance.
independent review
A review of security management and implementation across people, processes, and technologies, conducted with audit competence and organisational impartiality.
risk treatment plan
A documented plan based on risk assessment results that establishes, implements, and monitors chosen treatment measures, owners, timing, and reasons for any residual-risk acceptance.
incident containment
A required incident-response stage intended to prevent the consequences of an incident from spreading.
compliance monitoring
Regular review of compliance with security policies, topic-specific policies, rules, and standards, supported by reporting that gives management bodies an informed view of current risk management.
single point of failure
A component or dependency whose failure can disrupt a system or service. Point 2.1.2(d) requires identification of single points of failure as part of all-hazards risk identification.
business impact analysis
An assessment of the potential impact of severe disruptions to business operations that supports continuity requirements for network and information systems.
direct supplier or service provider
A supplier or service provider that supplies the relevant entity directly. Point 5.2 requires an up-to-date registry of these parties.

Finished reading?

Test your understanding with a custom practice exam on this chapter.

Test yourself