CS-014
Staff with privileged or administrative access to the application complete cybersecurity awareness training at least annually.
CS-013
An up-to-date asset inventory exists for all hardware and software components of the application.
CS-012
Penetration testing is performed at least annually, or after major changes, to assess the effectiveness of implemented controls.
CS-011
Backups are encrypted, tested for restorability, and stored in a geographically separate location.
CS-010
Security incidents involving the application can be escalated to support the 24-hour early-warning notification deadline under Article 23.
CS-009
Role-based access control is implemented and access is provisioned on a least-privilege basis.
CS-008
Direct suppliers and service providers supporting this application are risk-assessed for cybersecurity practices prior to onboarding.