NIS2 Directive
NIS2 Chapter IV: Cybersecurity Risk-Management Measures (Article 21)

NIS2 Directive Art.21.2.b: Incident handling

Incident handling here is the internal capability to detect, triage, contain, eradicate, recover from and learn from incidents. It is separate from the reporting duty in Article 23: reporting tells the authority what happened, handling is what the entity does about it. The capability needs defined severity levels, an escalation path that reaches decision makers out of hours, named responsibilities, and evidence that it functions rather than exists on paper. Post-incident review matters because it is the link back to Article 21(2)(f), where the effectiveness of the measures is assessed. The classification scheme deserves particular attention, because the same triage has to be able to recognise a significant incident under Article 23(3) and start the 24-hour clock.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 77 controls across 17 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • NIST-CSF-DE.AE-02 Potentially adverse events are analyzed to better understand associated activities
  • NIST-CSF-DE.AE-06 Information on adverse events is provided to authorized staff and tools
  • NIST-CSF-DE.AE-08 Incidents are declared when adverse events meet the defined incident criteria
  • NIST-CSF-DE.CM-01 Networks and network services are monitored to find potentially adverse events
  • NIST-CSF-GV.RM-05 Lines of communication across the organization are established for cybersecurity risks, including risks from suppliers and other third parties
  • NIST-CSF-GV.SC-08 Relevant suppliers and other third parties are included in incident planning, response, and recovery activities
  • NIST-CSF-ID.IM-04 Incident response plans and other cybersecurity plans that affect operations are established, communicated, maintained, and improved
  • NIST-CSF-RC.RP-06 The end of incident recovery is declared based on criteria, and incident-related documentation is completed
  • NIST-CSF-RS.AN-03 Analysis is performed to establish what has taken place during an incident and the root cause of the incident
  • NIST-CSF-RS.MA-01 The incident response plan is executed in coordination with relevant third parties once an incident is declared
  • NIST-CSF-RS.MA-02 Incident reports are triaged and validated
  • NIST-CSF-RS.MA-03 Incidents are categorized and prioritized
  • NIST-CSF-RS.MA-04 Incidents are escalated or elevated as needed
  • NIST-CSF-RS.MI-01 Incidents are contained
  • NIST-CSF-RS.MI-02 Incidents are eradicated

ISO 27001:2022 · 6 controls

  • 5.24 Information security incident management planning and preparation 
  • 5.25 Assessment and decision on information security events
  • 5.26 Response to information security incidents
  • 5.27 Learning from information security incidents
  • 6.8 Information security event reporting
  • 8.16 Monitoring activities

ISO 27002:2022 · 6 controls

  • 5.24 Information security incident management planning and preparation
  • 5.25 Assessment and decision on information security events
  • 5.26 Response to information security incidents
  • 5.27 Learning from information security incidents
  • 6.8 Information security event reporting
  • 8.16 Monitoring activities

C5 (Germany) · 5 controls

  • C5-OPS-13 Logging and Monitoring - Identification of Events
  • C5-SIM-01 Policy for security incident management
  • C5-SIM-02 Processing of security incidents
  • C5-SIM-04 Duty of the users to report security incidents to a central body
  • C5-SIM-05 Evaluation and learning process

DORA · 5 controls

CIS Controls v8 · 4 controls

  • CIS-17.4 Establish and Maintain an Incident Response Process
  • CIS-17.7 Conduct Routine Incident Response Exercises
  • CIS-17.8 Conduct Post-Incident Reviews
  • CIS-17.9 Establish and Maintain Security Incident Thresholds

FedRAMP High · 4 controls

  • IR-3 Incident Response Testing
  • IR-4 Incident Handling
  • IR-5 Incident Monitoring
  • IR-8 Incident Response Plan

FedRAMP Moderate · 4 controls

  • IR-3 Incident Response Testing
  • IR-4 Incident Handling
  • IR-5 Incident Monitoring
  • IR-8 Incident Response Plan

NIST SP 800-171 Rev 3 · 4 controls

NIST SP 800-53 Rev 5 · 4 controls

PCI DSS 4.0 · 4 controls

  • 12.10.1 12.10.1 Incident response plan ready for activation
  • 12.10.2 12.10.2 Annual review and testing of the incident response plan
  • 12.10.3 12.10.3 Incident response personnel available 24/7
  • 12.10.6 12.10.6 Plan evolved from lessons learned and industry developments

SOC 2 · 4 controls

  • SOC2-CC7.2 CC7.2 Monitoring system components for anomalies
  • SOC2-CC7.3 CC7.3 Evaluating security events to identify incidents
  • SOC2-CC7.4 CC7.4 Responding to security incidents
  • SOC2-CC7.5 CC7.5 Recovering from security incidents

APRA CPS 234 · 3 controls

  • CPS234-30 Detection and Response Mechanisms
  • CPS234-P24 Information Security Response Plans
  • CPS234-P25 Response Plan Content and Escalation Mechanisms

CMMC 2.0 · 3 controls

EU AI Act · 1 control

GDPR · 1 control

  • GDPR-Art.33 Notification of a personal data breach to the supervisory authority

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in NIS2 Chapter IV: Cybersecurity Risk-Management Measures (Article 21)

You are reading one control. How much of NIS2 Directive have you already done?

NIS2 Directive Art.21.2.b is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIS2 Directive your existing evidence covers. Hold DORA and 17 of 28 NIS2 Directive controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the DORA pair alone.

Query this from an agent

The graph holds this control, the 77 it maps to, and the evidence behind each claim, over MCP and REST.