Regulated Incident Management Ecosystem Versão portuguesa

Service sheet CSO-03

Risk Management Measures Programme

Design and follow-up of the technical, operational and organisational measures required from covered entities, with evidence for each area.

The problem it solves

Measures exist in slide decks, not in evidence. When the authority or a client asks for proof, the organisation finds it has none organised.

Who it is for

  • Essential and important entities;
  • Newly appointed cybersecurity officers;
  • IT teams that need priorities.

Deliverables

  • Gap assessment by area of measures;
  • Implementation plan prioritised by risk;
  • Baseline policies and procedures;
  • Evidence file and indicators.

Method

  1. 01

    Assess

    Current state by area.

  2. 02

    Prioritise

    Risk and effort.

  3. 03

    Implement

    Measures and policies.

  4. 04

    Evidence

    Organised proof.

Regulatory basis

  • Article 27 of Decree-Law 125/2025, on cybersecurity risk management measures;
  • Reference technical standards, in particular ISO/IEC 27001 and the Portuguese National Cybersecurity Reference Framework.

Expected results

  • Measures implemented and demonstrable;
  • Priorities grounded in risk;
  • Fast response to requests for proof.

An appointed role is not yet a role performed

Start by checking your organisation scope or ask for a proposal to structure the role.