|
a) Políticas de análise dos riscos e de segurança dos sistemas de informação
DL 125/2025: arts. 26.º e 29.º (sistema de gestão de riscos e risco residual)
|
- 5.1 - Policies for Information Security
- 5.7 - Threat Intelligence (NOVO 2022)
- 8.8 - Management of Technical Vulnerabilities
- 5.35 - Independent Review of Information Security
|
- GV.RM - Risk Management Strategy
- GV.PO - Policy
- ID.RA - Risk Assessment
- GV.OV - Oversight
|
|
b) Tratamento de incidentes
DL 125/2025: art. 27.º, al. a); notificação nos arts. 40.º a 44.º
|
- 5.24 - Incident Management Planning and Preparation
- 5.25 - Assessment and Decision on Information Security Events
- 5.26 - Response to Information Security Incidents
- 5.27 - Learning from Information Security Incidents
- 5.28 - Collection of Evidence
- 6.8 - Information Security Event Reporting
|
- DE.CM - Continuous Monitoring
- DE.AE - Adverse Event Analysis
- RS.MA - Incident Management
- RS.AN - Incident Analysis
- RS.CO - Incident Response Reporting
- RS.MI - Incident Mitigation
|
|
c) Continuidade das atividades, cópias de segurança, recuperação de desastres e gestão de crises
DL 125/2025: art. 27.º, al. b)
|
- 5.29 - Information Security During Disruption
- 5.30 - ICT Readiness for Business Continuity (NOVO 2022)
- 8.13 - Information Backup
- 8.14 - Redundancy of Information Processing Facilities
|
- PR.IR - Technology Infrastructure Resilience
- RC.RP - Incident Recovery Plan Execution
- RC.CO - Incident Recovery Communication
|
|
d) Segurança da cadeia de abastecimento
Relações com fornecedores e prestadores de serviços diretos. DL 125/2025: art. 27.º, al. c), e art. 28.º
|
- 5.19 - Information Security in Supplier Relationships
- 5.20 - Addressing Information Security Within Supplier Agreements
- 5.21 - Managing Information Security in the ICT Supply Chain
- 5.22 - Monitoring, Review and Change Management of Supplier Services
- 5.23 - Information Security for Use of Cloud Services (NOVO 2022)
|
- GV.SC - Cybersecurity Supply Chain Risk Management
- ID.AM - Asset Management
- ID.RA - Risk Assessment
|
|
e) Segurança na aquisição, desenvolvimento e manutenção, incluindo tratamento e divulgação de vulnerabilidades
DL 125/2025: art. 27.º, al. d)
|
- 8.25 - Secure Development Life Cycle
- 8.26 - Application Security Requirements
- 8.27 - Secure System Architecture and Engineering Principles
- 8.28 - Secure Coding (NOVO 2022)
- 8.29 - Security Testing in Development and Acceptance
- 8.30 - Outsourced Development
- 8.31 - Separation of Development, Test and Production
- 8.8 - Management of Technical Vulnerabilities
- 8.32 - Change Management
|
- PR.PS - Platform Security
- GV.SC - Supply Chain Risk Management
- ID.IM - Improvement
|
|
f) Políticas e procedimentos para avaliar a eficácia das medidas de gestão dos riscos
Auditorias, revisões e indicadores. DL 125/2025: art. 27.º, al. e)
|
- 5.35 - Independent Review of Information Security
- 5.36 - Compliance with Policies, Rules and Standards
- 8.34 - Protection of Information Systems During Audit Testing
- 8.16 - Monitoring Activities (NOVO 2022)
|
- GV.OV - Oversight
- ID.IM - Improvement
- DE.CM - Continuous Monitoring
|
|
g) Práticas básicas de ciber-higiene e formação em cibersegurança
DL 125/2025: art. 27.º, al. f) (inclui os titulares dos órgãos de gestão e os trabalhadores)
|
- 5.36 - Compliance with Policies, Rules and Standards
- 5.37 - Documented Operating Procedures
- 6.3 - Information Security Awareness, Education and Training
- 7.7 - Clear Desk and Clear Screen
- 8.1 - User Endpoint Devices
- 8.7 - Protection Against Malware
|
- GV.PO - Policy
- PR.AT - Awareness and Training
- PR.PS - Platform Security
- PR.DS - Data Security
|
|
h) Políticas e procedimentos relativos à utilização de criptografia e, se for caso disso, de cifragem
DL 125/2025: art. 27.º, al. g)
|
- 8.24 - Use of Cryptography
- 5.14 - Information Transfer
- 8.11 - Data Masking (NOVO 2022)
|
- PR.DS - Data Security
- PR.PS - Platform Security
|
|
i) Segurança dos recursos humanos, políticas de controlo do acesso e gestão de ativos
DL 125/2025: art. 27.º, al. h)
|
- 6.1 - Screening
- 6.2 - Terms and Conditions of Employment
- 6.4 - Disciplinary Process
- 6.5 - Responsibilities After Termination
- 6.6 - Confidentiality or Non-Disclosure Agreements
- 5.9 - Inventory of Information and Other Associated Assets
- 5.10 - Acceptable Use of Information and Other Associated Assets
- 5.15 - Access Control
- 5.16 - Identity Management
- 5.18 - Access Rights
- 8.2 - Privileged Access Rights
- 8.3 - Information Access Restriction
|
- GV.RR - Roles, Responsibilities, and Authorities
- ID.AM - Asset Management
- PR.AA - Identity Management, Authentication and Access Control
|
|
j) Autenticação multifatores ou contínua, comunicações seguras de voz, vídeo e texto e comunicações de emergência
DL 125/2025: art. 27.º, al. i)
|
- 5.17 - Authentication Information
- 8.5 - Secure Authentication
- 5.14 - Information Transfer
- 8.20 - Networks Security
- 8.21 - Security of Network Services
- 8.24 - Use of Cryptography
|
- PR.AA - Identity Management, Authentication and Access Control
- PR.DS - Data Security
- PR.IR - Technology Infrastructure Resilience
|