Belgium CyberFundamentals
Evidence request list. 44 controls, 44 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
Belgium CyberFundamentals: Detect
Network monitoring and defense. Implements CyFun DE.CM-1: the network is monitored to detect potential cybersecurity events.
- Network architecture and segmentation diagram
- Firewall rule review evidence
- IDS/IPS tuning records
- Session timeout configuration
- DoS mitigation runbooks
- Flat networks with limited segmentation
- Stale firewall rules and any-any allows
- Session timeouts too long or inconsistent
- DoS protections untested
Continuous monitoring strategy. Implements CyFun DE.CM: the information system and assets are monitored to identify cybersecurity events and verify the effectiveness of protective measures.
- Risk assessment methodology and register
- Vulnerability scan reports and remediation SLAs
- Threat intelligence feed inventory
- Continuous monitoring dashboard and KPI
- Risk acceptance approvals
- Risk register not refreshed at defined cadence
- Critical vulnerabilities exceeding SLA
- Threat intelligence not integrated into controls
- Continuous monitoring limited to a subset of systems
Audit event logging and storage. Implements CyFun PR.PT-1: audit and log records are determined, documented, implemented and retained in accordance with policy.
- Logging standard and event taxonomy
- SIEM coverage matrix
- Log retention policy and evidence
- Time synchronisation configuration
- Log integrity controls and hash records
- Critical systems not forwarding logs
- Retention shorter than regulatory minimum
- Time drift on legacy systems
- No tamper-evident protections on logs
Audit record review and analysis. Implements CyFun DE.AE-2: detected events are analysed to understand attack targets and methods.
- Logging standard and event taxonomy
- SIEM coverage matrix
- Log retention policy and evidence
- Time synchronisation configuration
- Log integrity controls and hash records
- Critical systems not forwarding logs
- Retention shorter than regulatory minimum
- Time drift on legacy systems
- No tamper-evident protections on logs
Time synchronization. Supports CyFun PR.PT-1: reliable, synchronised time sources underpin audit log integrity and event correlation.
- Logging standard and event taxonomy
- SIEM coverage matrix
- Log retention policy and evidence
- Time synchronisation configuration
- Log integrity controls and hash records
- Critical systems not forwarding logs
- Retention shorter than regulatory minimum
- Time drift on legacy systems
- No tamper-evident protections on logs
Audit log protection and retention. Implements CyFun PR.PT-1: audit and log records are protected from unauthorised access, modification and deletion, and retained per policy.
- Logging standard and event taxonomy
- SIEM coverage matrix
- Log retention policy and evidence
- Time synchronisation configuration
- Log integrity controls and hash records
- Critical systems not forwarding logs
- Retention shorter than regulatory minimum
- Time drift on legacy systems
- No tamper-evident protections on logs
Accountability and non-repudiation. Implements CyFun PR.PT-1 / PR.AC-1: actions are attributable to individual users to provide accountability and non-repudiation.
- Logging standard and event taxonomy
- SIEM coverage matrix
- Log retention policy and evidence
- Time synchronisation configuration
- Log integrity controls and hash records
- Critical systems not forwarding logs
- Retention shorter than regulatory minimum
- Time drift on legacy systems
- No tamper-evident protections on logs
Belgium CyberFundamentals: Identify
Risk assessment procedures. Implements CyFun ID.RA: asset vulnerabilities are identified, internal and external threats are identified, and risks (likelihood and impact) are determined.
- Risk assessment methodology and register
- Vulnerability scan reports and remediation SLAs
- Threat intelligence feed inventory
- Continuous monitoring dashboard and KPI
- Risk acceptance approvals
- Risk register not refreshed at defined cadence
- Critical vulnerabilities exceeding SLA
- Threat intelligence not integrated into controls
- Continuous monitoring limited to a subset of systems
Vulnerability scanning and management. Implements CyFun ID.RA-1 / DE.CM-8: vulnerability scans are performed and identified vulnerabilities are managed to remediation.
- Risk assessment methodology and register
- Vulnerability scan reports and remediation SLAs
- Threat intelligence feed inventory
- Continuous monitoring dashboard and KPI
- Risk acceptance approvals
- Risk register not refreshed at defined cadence
- Critical vulnerabilities exceeding SLA
- Threat intelligence not integrated into controls
- Continuous monitoring limited to a subset of systems
Security categorization. Implements CyFun ID.AM-5: resources are prioritised based on their classification, criticality and business value.
- Risk assessment methodology and register
- Vulnerability scan reports and remediation SLAs
- Threat intelligence feed inventory
- Continuous monitoring dashboard and KPI
- Risk acceptance approvals
- Risk register not refreshed at defined cadence
- Critical vulnerabilities exceeding SLA
- Threat intelligence not integrated into controls
- Continuous monitoring limited to a subset of systems
Threat intelligence integration. Implements CyFun ID.RA-2: cyber threat intelligence is received from information-sharing forums and sources and integrated into risk processes.
- Risk assessment methodology and register
- Vulnerability scan reports and remediation SLAs
- Threat intelligence feed inventory
- Continuous monitoring dashboard and KPI
- Risk acceptance approvals
- Risk register not refreshed at defined cadence
- Critical vulnerabilities exceeding SLA
- Threat intelligence not integrated into controls
- Continuous monitoring limited to a subset of systems
System component inventory. Implements CyFun ID.AM-1 and ID.AM-2: physical devices, systems and software platforms within the organisation are inventoried.
- Secure configuration baselines per platform
- Change advisory board minutes
- CMDB extracts
- Configuration drift reports
- Software allow-list and usage records
- Baselines missing for newer platforms
- Emergency changes bypassing CAB
- CMDB out of sync with reality
- No automated drift detection
Asset management and data flow mapping. Implements CyFun ID.AM-3 / ID.AM-4: organisational communication and data flows are mapped and external information systems are catalogued.
- Data flow diagrams and network/system topology
- Catalogue of external information systems and connections
- Asset register linking data flows to systems and owners
- Data flows undocumented or outdated
- External/third-party connections not catalogued
- No owner assigned to mapped data flows
Business environment. Implements CyFun ID.BE: the organisation's mission, objectives, stakeholders, role in the supply chain, dependencies and critical functions are identified, communicated and used to inform cybersecurity roles and risk decisions.
- Documented mission, critical business functions and dependencies
- Identification of the organisation's role in the supply chain
- Resilience requirements for critical services (normal and stress)
- Critical functions and dependencies not identified
- Resilience requirements not defined for critical services
- Business context not feeding cybersecurity risk decisions
Cybersecurity governance and policy. Implements CyFun ID.GV: an organisational cybersecurity policy is established and communicated, cybersecurity roles and responsibilities are coordinated, legal and regulatory requirements are understood and managed, and governance and risk management processes address cybersecurity risks.
- Board-approved cybersecurity policy and supporting standards
- Register of legal, regulatory and contractual cybersecurity requirements (including NIS2 and privacy)
- Defined cybersecurity roles, responsibilities and governance forums
- Evidence of management review of the cybersecurity programme
- Policy not approved/communicated at leadership level
- Legal/regulatory obligations not tracked
- Governance forums not evidenced or not reviewing cyber risk
Supply chain risk management. Implements CyFun ID.SC: cyber supply chain risk management processes are identified, established and agreed; suppliers and third-party partners are assessed against contractual obligations; and supplier compliance is routinely monitored, audited and tested.
- Supply chain risk management policy and supplier risk register
- Security requirements embedded in supplier contracts
- Supplier assessments, audits and performance monitoring records
- Incident-response and exit provisions for critical suppliers
- Critical suppliers not risk-assessed
- Security requirements absent from contracts
- No ongoing monitoring or testing of supplier controls
Belgium CyberFundamentals: Protect
Account management and provisioning. Implements CyFun PR.AC-1: identities and credentials for authorised devices, users and processes are issued, managed, verified, revoked and audited.
- Access control policy and standard
- Joiner/mover/leaver workflow records
- Role and entitlement matrix
- Quarterly access review attestations
- MFA enrolment and exception register
- Stale or dormant accounts not deprovisioned
- Shared or generic accounts retained
- MFA not enforced for privileged or remote access
- Access reviews skipped or rubber-stamped
Access enforcement and least privilege. Implements CyFun PR.AC-4: access permissions and authorisations are managed, incorporating the principles of least privilege and separation of duties.
- Access control policy and standard
- Joiner/mover/leaver workflow records
- Role and entitlement matrix
- Quarterly access review attestations
- MFA enrolment and exception register
- Stale or dormant accounts not deprovisioned
- Shared or generic accounts retained
- MFA not enforced for privileged or remote access
- Access reviews skipped or rubber-stamped
Multi-factor authentication requirements. Implements CyFun PR.AC-7: users, devices and other assets are authenticated commensurate with the risk of the transaction, including multi-factor authentication.
- Access control policy and standard
- Joiner/mover/leaver workflow records
- Role and entitlement matrix
- Quarterly access review attestations
- MFA enrolment and exception register
- Stale or dormant accounts not deprovisioned
- Shared or generic accounts retained
- MFA not enforced for privileged or remote access
- Access reviews skipped or rubber-stamped
Remote access controls. Implements CyFun PR.AC-3: remote access to organisational systems is managed and secured.
- Access control policy and standard
- Joiner/mover/leaver workflow records
- Role and entitlement matrix
- Quarterly access review attestations
- MFA enrolment and exception register
- Stale or dormant accounts not deprovisioned
- Shared or generic accounts retained
- MFA not enforced for privileged or remote access
- Access reviews skipped or rubber-stamped
Wireless access restrictions. Implements CyFun PR.AC-3 / PR.PT-4: wireless access is managed and communications and control networks are protected.
- Access control policy and standard
- Joiner/mover/leaver workflow records
- Role and entitlement matrix
- Quarterly access review attestations
- MFA enrolment and exception register
- Stale or dormant accounts not deprovisioned
- Shared or generic accounts retained
- MFA not enforced for privileged or remote access
- Access reviews skipped or rubber-stamped
Identity proofing and verification. Implements CyFun PR.AC-6: identities are proofed and bound to credentials and asserted in interactions.
- Access control policy and standard
- Joiner/mover/leaver workflow records
- Role and entitlement matrix
- Quarterly access review attestations
- MFA enrolment and exception register
- Stale or dormant accounts not deprovisioned
- Shared or generic accounts retained
- MFA not enforced for privileged or remote access
- Access reviews skipped or rubber-stamped
Boundary protection and segmentation. Implements CyFun PR.AC-5 / PR.PT-4: network integrity is protected through network segregation and segmentation, and communications networks are protected.
- Network architecture and segmentation diagram
- Firewall rule review evidence
- IDS/IPS tuning records
- Session timeout configuration
- DoS mitigation runbooks
- Flat networks with limited segmentation
- Stale firewall rules and any-any allows
- Session timeouts too long or inconsistent
- DoS protections untested
Cryptographic protection of data. Implements CyFun PR.DS-1 and PR.DS-2: data-at-rest and data-in-transit are protected using cryptography.
- Cryptographic standards and algorithm catalogue
- Key management policy and KMS configuration
- TLS configuration and inventory
- Encryption at rest evidence per system
- Key rotation and escrow records
- Use of deprecated ciphers or self-signed certificates
- Keys stored alongside encrypted data
- No documented rotation schedule
- Inconsistent encryption coverage across data stores
Denial-of-service protection. Implements CyFun PR.DS-4 / PR.PT-4: adequate capacity to ensure availability is maintained and communications networks are protected against denial-of-service.
- Network architecture and segmentation diagram
- Firewall rule review evidence
- IDS/IPS tuning records
- Session timeout configuration
- DoS mitigation runbooks
- Flat networks with limited segmentation
- Stale firewall rules and any-any allows
- Session timeouts too long or inconsistent
- DoS protections untested
Transmission confidentiality and integrity. Implements CyFun PR.DS-2: data-in-transit is protected for confidentiality and integrity.
- Cryptographic standards and algorithm catalogue
- Key management policy and KMS configuration
- TLS configuration and inventory
- Encryption at rest evidence per system
- Key rotation and escrow records
- Use of deprecated ciphers or self-signed certificates
- Keys stored alongside encrypted data
- No documented rotation schedule
- Inconsistent encryption coverage across data stores
Session management controls. Implements CyFun PR.AC-7 / PR.PT-4: sessions are authenticated and managed to protect confidentiality and integrity.
- Network architecture and segmentation diagram
- Firewall rule review evidence
- IDS/IPS tuning records
- Session timeout configuration
- DoS mitigation runbooks
- Flat networks with limited segmentation
- Stale firewall rules and any-any allows
- Session timeouts too long or inconsistent
- DoS protections untested
Baseline configuration establishment. Implements CyFun PR.IP-1: a baseline configuration of information technology and control systems is created and maintained, incorporating security principles.
- Secure configuration baselines per platform
- Change advisory board minutes
- CMDB extracts
- Configuration drift reports
- Software allow-list and usage records
- Baselines missing for newer platforms
- Emergency changes bypassing CAB
- CMDB out of sync with reality
- No automated drift detection
Configuration change control. Implements CyFun PR.IP-3: configuration change control processes are established and applied.
- Secure configuration baselines per platform
- Change advisory board minutes
- CMDB extracts
- Configuration drift reports
- Software allow-list and usage records
- Baselines missing for newer platforms
- Emergency changes bypassing CAB
- CMDB out of sync with reality
- No automated drift detection
Security impact analysis. Implements CyFun PR.IP-3: changes are assessed for security impact before implementation under configuration change control.
- Secure configuration baselines per platform
- Change advisory board minutes
- CMDB extracts
- Configuration drift reports
- Software allow-list and usage records
- Baselines missing for newer platforms
- Emergency changes bypassing CAB
- CMDB out of sync with reality
- No automated drift detection
Software usage restrictions. Implements CyFun PR.IP-1 / PR.DS-6: authorised software usage is governed and integrity-checking mechanisms are used.
- Secure configuration baselines per platform
- Change advisory board minutes
- CMDB extracts
- Configuration drift reports
- Software allow-list and usage records
- Baselines missing for newer platforms
- Emergency changes bypassing CAB
- CMDB out of sync with reality
- No automated drift detection
Awareness and training. Implements CyFun PR.AT: all users are informed and trained, and privileged users, third-party stakeholders, senior executives and physical/information security personnel understand their roles and responsibilities.
- Security awareness programme and completion records
- Role-based training for privileged users and administrators
- Phishing simulation and awareness campaign results
- Training for senior leadership and third-party stakeholders
- Awareness training not completed by all users
- No role-based training for privileged/administrative users
- Effectiveness of awareness not measured
System maintenance. Implements CyFun PR.MA: maintenance and repair of organisational assets are performed and logged with approved and controlled tools, and remote maintenance is approved, logged and performed in a manner that prevents unauthorised access.
- Maintenance policy, schedule and maintenance logs
- Approval and logging records for remote maintenance sessions
- Control of maintenance tools and media
- Maintenance not logged or approved
- Remote maintenance performed without approval or monitoring
- Maintenance tools not controlled
Data security lifecycle management. Implements CyFun PR.DS-3 / PR.DS-5: assets are formally managed throughout removal, transfer and disposition, and protections against data leaks are implemented.
- Asset disposal/sanitisation records and procedures
- Data leakage prevention controls and monitoring
- Media handling, transfer and disposition policy
- Media not sanitised before disposal or reuse
- No data-leak protections for sensitive data
- Asset transfers not tracked
Belgium CyberFundamentals: Recover
Recovery planning. Implements CyFun RC.RP-1: a recovery plan is maintained and executed during or after a cybersecurity incident to restore systems and assets affected.
- Recovery plan and IT disaster-recovery procedures
- Recovery time and recovery point objectives (RTO/RPO)
- Recovery plan test results and restoration records
- Recovery plan untested
- RTO/RPO not defined or not met in tests
- Backups not validated for restorability
Recovery improvements. Implements CyFun RC.IM: recovery planning and processes are improved by incorporating lessons learned into future activities, and recovery strategies are updated.
- Post-recovery review reports and lessons-learned register
- Updates to recovery plans and strategies following incidents/tests
- Tracking of recovery improvement actions to closure
- Lessons learned not captured after recovery events
- Recovery plans not updated following tests/incidents
- Improvement actions not tracked
Recovery communications. Implements CyFun RC.CO: public relations are managed, reputation is repaired after an incident, and recovery activities are communicated to internal and external stakeholders and executive and management teams.
- Crisis communication plan and stakeholder contact lists
- Records of recovery communications to internal/external parties
- Public-relations and reputation-management procedures
- No crisis communication plan
- Stakeholders not informed during recovery
- Regulatory/customer notification obligations missed
Belgium CyberFundamentals: Respond
Incident response planning and testing. Implements CyFun RS.RP-1: a response plan is maintained, tested and executed during or after a cybersecurity incident.
- Incident response plan and playbooks
- Tabletop exercise reports
- Incident ticket history with timelines
- Forensic toolkit and chain-of-custody log
- Post-incident review minutes
- Playbooks untested for major scenarios
- Unclear escalation thresholds
- Forensic readiness lacking outside core systems
- Lessons learned never closed out
Incident handling and containment. Implements CyFun RS.MI-1 / RS.MI-2: incidents are contained and mitigated.
- Incident response plan and playbooks
- Tabletop exercise reports
- Incident ticket history with timelines
- Forensic toolkit and chain-of-custody log
- Post-incident review minutes
- Playbooks untested for major scenarios
- Unclear escalation thresholds
- Forensic readiness lacking outside core systems
- Lessons learned never closed out
Incident reporting and notification. Implements CyFun RS.CO-2 / RS.CO-3: incidents are reported consistent with established criteria and information is shared with internal and external stakeholders.
- Incident response plan and playbooks
- Tabletop exercise reports
- Incident ticket history with timelines
- Forensic toolkit and chain-of-custody log
- Post-incident review minutes
- Playbooks untested for major scenarios
- Unclear escalation thresholds
- Forensic readiness lacking outside core systems
- Lessons learned never closed out
Forensic analysis capabilities. Implements CyFun RS.AN-1 / RS.AN-3: detection notifications are investigated and forensic analysis is performed.
- Incident response plan and playbooks
- Tabletop exercise reports
- Incident ticket history with timelines
- Forensic toolkit and chain-of-custody log
- Post-incident review minutes
- Playbooks untested for major scenarios
- Unclear escalation thresholds
- Forensic readiness lacking outside core systems
- Lessons learned never closed out
Lessons learned and improvement. Implements CyFun RS.IM-1 / RS.IM-2: response activities incorporate lessons learned and response strategies are updated.
- Incident response plan and playbooks
- Tabletop exercise reports
- Incident ticket history with timelines
- Forensic toolkit and chain-of-custody log
- Post-incident review minutes
- Playbooks untested for major scenarios
- Unclear escalation thresholds
- Forensic readiness lacking outside core systems
- Lessons learned never closed out
Belgium CyberFundamentals: Scoping and Regulatory Alignment
Assurance level selection and scoping. Core to CyFun: the organisation selects the appropriate assurance level (BASIC, IMPORTANT or ESSENTIAL) proportionate to the cyber risk of its activities and defines the scope of the systems and processes to which the key measures apply.
- Documented selection and justification of the CyFun assurance level
- Defined assessment scope (systems, processes, locations)
- Risk rationale linking activity criticality to the chosen level
- Assurance level not justified against risk
- Scope undefined or inconsistent with the assessment
- Critical systems excluded from scope
NIS2 alignment. Core to CyFun: the CyberFundamentals key measures are mapped to the obligations of the NIS2 Directive (as transposed in Belgian law), and the CCB recognises attainment of CyFun assurance levels as a means to demonstrate compliance with NIS2 risk-management and reporting obligations.
- Mapping of implemented CyFun key measures to NIS2 obligations
- Evidence of NIS2 incident-notification readiness and timelines
- Management body approval and oversight of cybersecurity risk-management measures (NIS2 governance)
- CyFun implementation not mapped to NIS2 obligations
- Incident-notification process not aligned to NIS2 timelines
- Management-body accountability for NIS2 not evidenced
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.