RJCS · Articles 26 to 29
Risk and measures: from inventory to residual risk
The minimum measures are a starting point. The organization needs to understand assets, threats, dependencies and impact to justify appropriate measures and treat the risk that remains.
For whom
When this article must enter into the plan.
Entities subject to risk management obligations and cybersecurity measures, in proportion to their context and qualification.
Brief tutorial
Four steps to start with method.
Adapt the depth, the responsible and the evidence to the concrete framework of the entity.
- 01
Set context
Identify critical services, assets, information, dependencies, responsible and impact criteria.
- 02
Evaluate the risk
Register existing scenarios, threats, vulnerabilities, probability, impact and controls.
- 03
Select measures
Relate legal and technical measures with each risk and supply chain.
- 04
Treat residual
Reassess the risk after measures, define additional treatment or formal acceptance and periodically review.
Proof
Evidence to prepare.
- Inventory of assets and services
- Methodology and risk matrix
- Treatment plan
- Residual risk record and acceptances
Warning
Errors that weaken implementation.
- Confused checklist of measures with risk assessment
- Ignore suppliers and dependencies
- Accept risk without decision and revision deadline
Quick control
Initial checklist.
- Documented context
- Risks assessed
- Related measures
- Third parties concerned
- Residual risk determined
Frequently Asked Questions
Two key answers.
Is compliance with the minimum measures sufficient?
Not necessarily. The residual risk shall be assessed and treated in accordance with the entity's context.
Does the supply chain enter the analysis?
Yes. Article 28 integrates supply chain security into the risk approach.
Primary source
Decree-Law No. 125/2025 of 4 December
Information tutorial. Always confirm the official text, the applicable regulations and the specific framework of the organization.