FrameworksNIS2 Measures
risk managementv2022Published
NIS2 Minimum Security Measures
NIS2 Measures
NIS2 Article 21 establishes 10 minimum cybersecurity risk management measures that essential and important entities must implement. ENISA provides guidance on implementation.
Issuing Body
European Union Agency for Cybersecurity (ENISA)
Version
2022
Published
2022-12-27
Controls
13
Mapped Laws
29
| Control ID | Title | Domain | Maturity |
|---|---|---|---|
| NIS2-Art.21(2)(a) | Policies on Risk Analysis and Information System Security Essential and important entities shall take appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of network and information systems. Policies on risk analysis and information system security are required. | — | managed |
| NIS2-Art.21(2)(b) | Incident Handling Measures for incident handling including prevention, detection and response to incidents. Entities must have documented incident response procedures and test them regularly. | — | managed |
| NIS2-Art.21(2)(c) | Business Continuity Business continuity measures such as backup management and disaster recovery, and crisis management. Entities must ensure continuity of operations during and after significant incidents. | — | managed |
| NIS2-Art.21(2)(d) | Supply Chain Security Security in supply chain including security-related aspects concerning the relationships between each entity and its direct suppliers or service providers. Entities must assess and manage supply chain cybersecurity risks. | — | managed |
| NIS2-Art.21(2)(e) | Security in Network and Information Systems Acquisition Security in network and information systems acquisition, development and maintenance, including vulnerability handling and disclosure. Secure development practices and vulnerability management are required. | — | managed |
| NIS2-Art.21(2)(f) | Policies and Procedures for Cryptography Policies and procedures to assess the effectiveness of cybersecurity risk-management measures, including the use of cryptography and, where appropriate, encryption. | — | managed |
| NIS2-Art.21(2)(g) | Human Resources Security Human resources security, access control policies and asset management. Entities must implement appropriate personnel security measures and manage access rights. | — | managed |
| NIS2-Art.21(2)(h) | Multi-Factor Authentication The use of multi-factor authentication or continuous authentication solutions, secured voice, video and text communications and secured emergency communication systems within the entity, where appropriate. | — | managed |
| NIS2-Art.23(1) | Notification of Significant Incidents Member States shall ensure that essential and important entities notify, without undue delay, the CSIRT or, where applicable, the competent authority of any incident having a significant impact on the provision of their services. Entities shall submit an early warning within 24 hours. | — | managed |
| NIS2-Art.23(4) | Notification Timeline Entities shall submit an early warning (within 24 hours), an incident notification (within 72 hours), and a final report (within 1 month) for significant incidents. | — | managed |
| NIS2-Art.20 | Governance Member States shall ensure that the management bodies of essential and important entities approve the cybersecurity risk-management measures taken by those entities, oversee its implementation and can be held liable for infringements. Management bodies must undergo cybersecurity training. | — | managed |
| NIS2-Art.24 | Use of European Cybersecurity Certification Schemes Member States shall, in order to demonstrate compliance with certain requirements set out in Article 21, require essential and important entities to use particular ICT products, ICT services and ICT processes that are certified under European cybersecurity certification schemes. | — | defined |
| NIS2-Art.26 | Jurisdiction and Registration Essential and important entities shall be deemed to fall under the jurisdiction of the Member State in which they are established. Entities providing services in the EU but not established in the EU must designate a representative. | — | defined |