NIS2 Directive
NIS2 Chapter IV: Cybersecurity Risk-Management Measures (Article 21)

NIS2 Directive Art.21.2.a: Policies on risk analysis and on information system security

The first of the ten minimum measure categories requires both a method for analysing risk and the security policy set that the analysis feeds. Risk analysis has to be an actual repeatable method with criteria for assessing and accepting risk, applied to the network and information systems the entity relies on for its operations and for delivering its services, with results that are recorded and revisited. The information system security policies are the codified decisions that follow: what is protected, to what level, who owns each decision, and what happens when the policy cannot be met. Both limbs are needed. A risk register with no policy leaves nothing binding on the organisation, and a policy library with no risk analysis behind it cannot show why it says what it says.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 56 controls across 17 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • NIST-CSF-GV.PO-01 Policy for managing cybersecurity risks is established based on organizational context, cybersecurity strategy, and priorities and is communicated and enforced
  • NIST-CSF-GV.PO-02 Policy for managing cybersecurity risks is reviewed, updated, communicated, and enforced to reflect changes in requirements, threats, technology, and organizational mission
  • NIST-CSF-GV.RM-06 A standardized method for calculating, documenting, categorizing, and prioritizing cybersecurity risks is established and communicated
  • NIST-CSF-GV.RR-02 Roles, responsibilities, and authorities related to cybersecurity risk management are established, communicated, understood, and enforced
  • NIST-CSF-ID.RA-05 Threats, vulnerabilities, likelihoods, and impacts are used to understand inherent risk and inform risk response prioritization

APRA CPS 234 · 4 controls

  • CPS234-14 Definition of Information Security Roles and Responsibilities
  • CPS234-15 Information Security Capability
  • CPS234-19 Information Security Policy Framework
  • CPS234-P19 Policy Direction to All Responsible Parties

C5 (Germany) · 4 controls

  • C5-OIS-02 Information Security Policy
  • C5-OIS-06 Risk Management Policy
  • C5-SP-01 Documentation, communication and provision of policies and instructions
  • C5-SP-03 Exceptions from Existing Policies and Instructions

FedRAMP High · 4 controls

  • PL-1 Policy and Procedures
  • PL-2 System Security and Privacy Plans
  • RA-1 Policy and Procedures
  • RA-3 Risk Assessment

FedRAMP Moderate · 4 controls

  • PL-1 Policy and Procedures
  • PL-2 System Security and Privacy Plans
  • RA-1 Policy and Procedures
  • RA-3 Risk Assessment

NIST SP 800-53 Rev 5 · 4 controls

PCI DSS 4.0 · 4 controls

  • 12.1.1 12.1.1 Overall information security policy established and disseminated
  • 12.1.2 12.1.2 Security policy reviewed annually and updated as needed
  • 12.1.3 12.1.3 Security roles defined and acknowledged by all personnel
  • 12.3.1 12.3.1 Targeted risk analysis for flexible-frequency requirements

SOC 2 · 4 controls

  • SOC2-CC3.1 CC3.1 Objectives specified clearly enough to assess risk (COSO principle 6)
  • SOC2-CC3.2 CC3.2 Identifying and analysing risks to objectives (COSO principle 7)
  • SOC2-CC5.1 CC5.1 Selecting control activities that mitigate risk (COSO principle 10)
  • SOC2-CC5.3 CC5.3 Deploying controls through policies and procedures (COSO principle 12)

GDPR · 3 controls

ISO 27001:2022 · 3 controls

  • 5.1 Policies for information security
  • 5.2 Information security roles and responsibilities
  • 5.37 Documented operating procedures

ISO 27002:2022 · 3 controls

  • 5.1 Policies for information security
  • 5.2 Information security roles and responsibilities
  • 5.37 Documented operating procedures

NIST SP 800-171 Rev 3 · 3 controls

CMMC 2.0 · 2 controls

DORA · 2 controls

EU AI Act · 2 controls

  • 5.1.c-ch Article 5(1)(ç): public institutions and critical infrastructures keep a full asset inventory, including data, and a risk analysis

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in NIS2 Chapter IV: Cybersecurity Risk-Management Measures (Article 21)

You are reading one control. How much of NIS2 Directive have you already done?

NIS2 Directive Art.21.2.a is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIS2 Directive your existing evidence covers. Hold DORA and 17 of 28 NIS2 Directive controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the DORA pair alone.

Query this from an agent

The graph holds this control, the 56 it maps to, and the evidence behind each claim, over MCP and REST.