binding national and international legislation - minimum requirements
Latvia's mandatory cyber security requirements for state and critical infrastructure entities.
binding national and international laws and regulations (2018, renewed) - Latvia's mandatory cyber security requirements. Main conditions: 1) Security policy and risk register; 2) Responsible official (CISO equivalent); 3) User authentication - at least 12 symbols, MFA administrators; 4) Argon2 or bcrypt passwords hashing; 5) Network segmentation and firewalls; 6) Centralized collection of windows with retention of at least 12 months; 7) Backup with regular renewal tests; 8) Security updates; 9) Incident response plan; 10) Employee training; 11) Third party assessment. Irregularities can lead to administrative liability and sanctions.