Annex I · Objective 03

Protect

Protecting brings together controls that limit the probability and impact of incidents on people, processes and technology.

Complete structure

Categories and controls.

Select each category to see all the codes and titles that make up it.

PR.GAIdentity Management, Authentication and Access Control7 checks
  1. PR.GA-1

    Identity management life cycles are defined.

  2. PR.GA-2

    The entity shall verify the identity of the users and bind them to their credentials.

  3. PR.GA-3

    Authentication mechanisms for users, devices and other assets are defined.

  4. PR.GA-4

    Identity statements are protected, transmitted and verified.

  5. PR.GA-5

    Permissions, rights and authorizations are managed according to the lowest privilege and separation of functions.

  6. PR.GA-6

    Physical access controls are managed, monitored and applied according to risk.

  7. PR.GA-7

    The entity manages its remote accesses.

PR.FCTraining and Awareness2 checks
  1. PR.FC-1

    All personnel are sensitized and trained in cybersecurity matters.

  2. PR.FC-2

    Specialized staff and management bodies shall receive appropriate training in their duties.

PR.SDData Security5 checks
  1. PR.SD-1

    The entity protects the confidentiality, integrity and availability of data at rest.

  2. PR.SD-2

    The entity shall protect the confidentiality, integrity and availability of the data in transit.

  3. PR.SD-3

    The entity implements protections that avoid data exfiltration.

  4. PR.SD-4

    The entity protects the confidentiality, integrity and availability of the data in use.

  5. PR.SD-5

    Data backups are performed, maintained and tested.

PR.SPPlatform Security4 checks
  1. PR.SP-1

    A secure base configuration of networks and information systems is created and maintained.

  2. PR.SP-2

    Logs and activity history are documented, implemented and reviewed.

  3. PR.SP-3

    Unauthorized software installation and execution are prevented.

  4. PR.SP-4

    A safe software development life cycle is implemented.

PR.RIResilience of the Technological Infrastructure5 checks
  1. PR.RI-1

    The entity protects the integrity of communications networks.

  2. PR.RI-2

    The development and testing environments are separated from the production environments.

  3. PR.RI-3

    Technological assets are protected from natural threats.

  4. PR.RI-4

    Mechanisms are implemented to meet resilience requirements in adverse situations.

  5. PR.RI-5

    The entity shall plan appropriate capacity to ensure the availability of networks and systems.

Application

How to work every control.

  • Confirm full description in Annex I
  • Set scope and responsibility
  • Relating control with risk and critical services
  • Associate implementation and evidence
  • Record gaps, priority and deadline
  • Review implementation and effectiveness

Primary source

Regulation No. 756/2026, of 22 June — Annex I

The codes and titles reproduce the structure of Annex I. Please refer to the official act for the full description and normative references of each control.

Consult official act

Content and references checked on .

Complete cycle

Back to six goals.

Continue the course between Manage, Identify, Protect, Detect, Answer and Recover.

Return to Annex I