Information systems are classified into five levels by the damage an incident could cause, from harm to organisations' or individuals' rights (level 1) to especially serious harm to national security (level 5). Every manager must determine the level, assess and manage cybersecurity risk, supervise protection, apply protection measures, report as required and raise awareness; level 3 and 4 managers must also set lifecycle security rules, apply standards, back up, audit compliance, monitor and respond to incidents; systems already classified under the 2015 Law must meet the new measures by 1 July 2027.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.