The Presidency is tasked with ensuring that public institutions and critical infrastructures keep an inventory of all their assets, including a data inventory, and carry out a risk analysis for those assets, and with taking, or having them take, security measures according to the criticality of the assets. Assets include all information and processing facilities holding data in electronic or physical form, the personnel who use or carry the data and the physical premises that hold it (Article 3(1)(k)); critical infrastructure means infrastructure hosting information systems whose compromise could cause loss of life, large-scale economic damage, security gaps or disruption of public order (Article 3(1)(d)), with sectors designated by the Cybersecurity Board (Article 9(4)(ç)). The duty is framed as the Presidency's task; the inventory, risk analysis and measures are what the institutions must be able to show.
This control maps to 4 controls across 2 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 4 it maps to, and the evidence behind each claim, over MCP and REST.