Core areas that need to work in practice
uKSC requires essential and important entities to implement appropriate and proportionate cybersecurity risk-management measures. In practice this means connecting governance, processes, technology and evidence.
- risk management and security policies,
- security in acquisition, development, maintenance and operation of systems,
- human resources security and access control,
- business continuity, backups and recovery,
- ICT supply-chain security,
- incident management and reporting to the relevant CSIRT,
- document control and regular review.