NIS2 Directive
NIS2 Chapter IV: Cybersecurity Risk-Management Measures (Article 21)

NIS2 Directive Art.21.1: Take proportionate all-hazards measures calibrated to the entity's own risk exposure

Above the enumerated list in Article 21(2) sits a duty to size the whole programme correctly. Measures must be technical, operational and organisational together, must protect both the network and information systems and the physical environment those systems sit in, and must aim at preventing or minimising incident impact on the recipients of the entity's services and on other services downstream. Proportionality is defined rather than left open: the entity weighs the state of the art, relevant European and international standards where they apply, and the cost of implementation against its own degree of exposure to risk, its size, and the likelihood and severity of incidents including their societal and economic impact. The auditable artefact is therefore the reasoning, not just the control set. An entity that deployed a generic baseline can satisfy Article 21(2) point by point and still fail this paragraph, because nothing shows the level of security chosen was appropriate to the risks it actually faces.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 49 controls across 16 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • NIST-CSF-DE.CM-02 The physical environment is monitored to find potentially adverse events
  • NIST-CSF-GV.OC-01 The organizational mission is understood and informs cybersecurity risk management
  • NIST-CSF-GV.OC-05 Outcomes, capabilities, and services that the organization depends on are understood and communicated
  • NIST-CSF-GV.RM-01 Risk management objectives are established and agreed to by organizational stakeholders
  • NIST-CSF-GV.RM-02 Risk appetite and risk tolerance statements are established, communicated, and maintained
  • NIST-CSF-ID.RA-04 Potential impacts and likelihoods of threats exploiting vulnerabilities are identified and recorded
  • NIST-CSF-ID.RA-05 Threats, vulnerabilities, likelihoods, and impacts are used to understand inherent risk and inform risk response prioritization
  • NIST-CSF-PR.IR-02 The organization's technology assets are protected from environmental threats

APRA CPS 234 · 5 controls

  • CPS234-13 Board Responsibility for Information Security
  • CPS234-15 Information Security Capability
  • CPS234-19 Information Security Policy Framework
  • CPS234-21 Implementation of Information Security Controls
  • CPS234-P17 Active Maintenance of Capability Against Change

C5 (Germany) · 4 controls

  • C5-OIS-01 Information Security Management System (ISMS)
  • C5-OIS-06 Risk Management Policy
  • C5-OIS-07 Application of the Risk Management Policy
  • C5-PS-01 Physical Security and Environmental Control Requirements

NIST SP 800-53 Rev 5 · 4 controls

FedRAMP High · 3 controls

  • PL-11 Baseline Tailoring. Tailor the selected control baseline by applying specified tailoring actions
  • RA-3 Risk Assessment
  • SA-2 Allocation of Resources

FedRAMP Moderate · 3 controls

  • PL-11 Baseline Tailoring. Tailor the selected control baseline by applying specified tailoring actions
  • RA-3 Risk Assessment
  • SA-2 Allocation of Resources

PCI DSS 4.0 · 3 controls

  • 12.3.1 12.3.1 Targeted risk analysis for flexible-frequency requirements
  • 12.3.2 12.3.2 Targeted risk analysis for each customized-approach requirement
  • 12.5.2 12.5.2 Annual and change-driven scope confirmation

SOC 2 · 3 controls

  • SOC2-CC3.1 CC3.1 Objectives specified clearly enough to assess risk (COSO principle 6)
  • SOC2-CC3.2 CC3.2 Identifying and analysing risks to objectives (COSO principle 7)
  • SOC2-CC5.1 CC5.1 Selecting control activities that mitigate risk (COSO principle 10)

CMMC 2.0 · 2 controls

DORA · 2 controls

GDPR · 2 controls

ISO 27001:2022 · 2 controls

  • 5.1 Policies for information security
  • 7.5 Protecting against physical and environmental threats

ISO 27002:2022 · 2 controls

  • 5.1 Policies for information security
  • 7.5 Protecting against physical and environmental threats

NIST SP 800-171 Rev 3 · 2 controls

  • 7.1.b-measures Article 7(1)(b): take the cybersecurity measures the legislation prescribes

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in NIS2 Chapter IV: Cybersecurity Risk-Management Measures (Article 21)

You are reading one control. How much of NIS2 Directive have you already done?

NIS2 Directive Art.21.1 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIS2 Directive your existing evidence covers. Hold DORA and 17 of 28 NIS2 Directive controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the DORA pair alone.

Query this from an agent

The graph holds this control, the 49 it maps to, and the evidence behind each claim, over MCP and REST.