Art. 21(2)(g)
Basic cyber hygiene practices
The baseline practices every entity must implement, alongside cybersecurity training.
The directive does not enumerate them, which is deliberate. Recital 89 points to zero-trust principles, software and device updates, network segmentation, identity and access management, user awareness, and staff training on cyber threats such as phishing and social engineering.
Related terms
- Essential entity · Art. 3(1)
- Important entity · Art. 3(2)
- Significant incident · Art. 23(3)
- Early warning · Art. 23(4)(a)
- Size-cap rule · Art. 2(1)
- CSIRT · Art. 10