NIS2 Directive
NIS2 Chapter IV: Governance (Article 20)

NIS2 Directive Art.20.2: Train the management body, and offer equivalent training to staff on a regular basis

Members of the management body are required to follow training, and the entity is expected to put comparable training in front of its employees regularly. The stated purpose sets the standard: the training has to leave the body able to identify risks and to assess cybersecurity risk-management practices and the effect those practices have on the services the entity provides. That is a judgement bar, not an attendance bar. Generic awareness content aimed at all staff will not reach it, because a board member is being asked to challenge a risk treatment decision rather than avoid a phishing email. Training also needs refreshing as the body changes; a director appointed after the last session is untrained for the purposes of this Article. The employee limb is expressed as an encouragement on Member States to require, so its national transposition is worth reading, but the entity-level expectation is regular and repeated rather than on induction only.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 30 controls across 15 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

FedRAMP High · 3 controls

  • AT-2 Literacy Training and Awareness
  • AT-3 Role-Based Training
  • AT-4 Training Records

FedRAMP Moderate · 3 controls

  • AT-2 Literacy Training and Awareness
  • AT-3 Role-Based Training
  • AT-4 Training Records
  • NIST-CSF-GV.RR-04 Cybersecurity is included in human resources practices
  • NIST-CSF-PR.AT-01 Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind
  • NIST-CSF-PR.AT-02 Individuals in specialized roles are provided with awareness and training so that they possess the knowledge and skills to perform relevant tasks with cybersecurity risks in mind

NIST SP 800-53 Rev 5 · 3 controls

C5 (Germany) · 2 controls

  • C5-DEV-04 Safety training and awareness programme regarding continuous software delivery and associated systems, components or tools
  • C5-HR-03 Security training and awareness programme

CIS Controls v8 · 2 controls

  • CIS-14.1 Establish and Maintain a Security Awareness Program
  • CIS-14.9 Conduct Role-Specific Security Awareness and Skills Training

CMMC 2.0 · 2 controls

DORA · 2 controls

NIST SP 800-171 Rev 3 · 2 controls

PCI DSS 4.0 · 2 controls

  • 12.6.1 12.6.1 Formal security awareness program
  • 12.6.3 12.6.3 Security awareness training on hire and annually with acknowledgment

APRA CPS 234 · 1 control

  • CPS234-P33 Skill of Personnel Providing Control Assurance

ISO 27001:2022 · 1 control

  • 6.3 Information security awareness, education and training

ISO 27002:2022 · 1 control

  • 6.3 Information security awareness, education and training

SOC 2 · 1 control

  • SOC2-CC1.4 CC1.4 Attracting, developing and retaining competent people (COSO principle 4)

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in NIS2 Chapter IV: Governance (Article 20)

You are reading one control. How much of NIS2 Directive have you already done?

NIS2 Directive Art.20.2 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIS2 Directive your existing evidence covers. Hold DORA and 17 of 28 NIS2 Directive controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the DORA pair alone.

Query this from an agent

The graph holds this control, the 30 it maps to, and the evidence behind each claim, over MCP and REST.