NIS2 Directive
NIS2 Chapter IV: Cybersecurity Risk-Management Measures (Article 21)

NIS2 Directive Art.21.1: Take proportionate all-hazards measures calibrated to the entity's own risk exposure

Above the enumerated list in Article 21(2) sits a duty to size the whole programme correctly. Measures must be technical, operational and organisational together, must protect both the network and information systems and the physical environment those systems sit in, and must aim at preventing or minimising incident impact on the recipients of the entity's services and on other services downstream. Proportionality is defined rather than left open: the entity weighs the state of the art, relevant European and international standards where they apply, and the cost of implementation against its own degree of exposure to risk, its size, and the likelihood and severity of incidents including their societal and economic impact. The auditable artefact is therefore the reasoning, not just the control set. An entity that deployed a generic baseline can satisfy Article 21(2) point by point and still fail this paragraph, because nothing shows the level of security chosen was appropriate to the risks it actually faces.

Other controls in NIS2 Chapter IV: Cybersecurity Risk-Management Measures (Article 21)

You are reading one control. How much of NIS2 Directive have you already done?

NIS2 Directive Art.21.1 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIS2 Directive your existing evidence covers. Hold DORA and 17 of 28 NIS2 Directive controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the DORA pair alone.

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.