NIS2 Directive
NIS2 Chapter IV: Cybersecurity Risk-Management Measures (Article 21)

NIS2 Directive Art.21.2.e: Security in acquisition, development and maintenance, including vulnerability handling and disclosure

Two duties travel together in this point. The first is that security is built into how systems are acquired, developed and maintained: security requirements set before purchase or build, secure development practice, change control, and maintenance that does not quietly reintroduce weakness. The second is vulnerability handling and disclosure, meaning the entity can receive a vulnerability report about its own products or systems, triage it, fix it on a timescale that reflects severity, and handle disclosure. A published route for a finder to reach the entity is the part most often missing, and its absence is visible from outside. Note that the coordinator role and the European vulnerability database in Article 12 belong to the CSIRTs and ENISA; what binds the entity is its own handling and disclosure capability.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 73 controls across 17 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

C5 (Germany) · 10 controls

  • C5-AM-03 Commissioning of Hardware
  • C5-DEV-01 Policies for the development/procurement of information systems
  • C5-DEV-03 Policies for changes to information systems
  • C5-DEV-05 Risk assessment, categorisation and prioritisation of changes
  • C5-DEV-06 Testing changes
  • C5-DEV-09 Approvals for provision in the production environment
  • C5-OPS-18 Managing Vulnerabilities, Malfunctions and Errors - Concept
  • C5-OPS-22 Testing and Documentation of known Vulnerabilities
  • C5-PSS-02 Identification of Vulnerabilities of the Cloud Service
  • C5-PSS-03 Online Register of Known Vulnerabilities

ISO 27001:2022 · 8 controls

  • 5.8 Information security in project management
  • 8.25 Secure development life cycle
  • 8.26 Application security requirements
  • 8.27 Secure system architecture and engineering principles
  • 8.28 Secure coding
  • 8.29 Security testing in development and acceptance
  • 8.32 Change management
  • 8.8 Management of technical vulnerabilities

ISO 27002:2022 · 8 controls

  • 5.8 Information security in project management
  • 8.25 Secure development life cycle
  • 8.26 Application security requirements
  • 8.27 Secure system architecture and engineering principles
  • 8.28 Secure coding
  • 8.29 Security testing in development and acceptance
  • 8.32 Change management
  • 8.8 Management of technical vulnerabilities
  • NIST-CSF-ID.AM-08 Systems, hardware, software, services, and data are managed throughout their life cycles
  • NIST-CSF-ID.RA-01 Vulnerabilities in assets are identified, validated, and recorded
  • NIST-CSF-ID.RA-07 Changes and exceptions are managed, assessed for risk impact, recorded, and tracked
  • NIST-CSF-PR.PS-02 Software is maintained, replaced, and removed commensurate with risk
  • NIST-CSF-PR.PS-03 Hardware is maintained, replaced, and removed commensurate with risk
  • NIST-CSF-PR.PS-06 Secure software development practices are integrated, and their performance is monitored throughout the software development life cycle

CIS Controls v8 · 4 controls

  • CIS-16.1 Establish and Maintain a Secure Application Development Process
  • CIS-16.2 Establish and Maintain a Process to Accept and Address Software Vulnerabilities
  • CIS-16.6 Establish and Maintain a Severity Rating System and Process for Application Vulnerabilities
  • CIS-7.2 Establish and Maintain a Remediation Process

CMMC 2.0 · 4 controls

  • CCM-AIS-02 Application Security Baseline Requirements
  • CCM-AIS-04 Secure Application Design and Development
  • CCM-CCC-01 Change Management Policy and Procedures
  • CCM-TVM-01 Threat and Vulnerability Management Policy and Procedures

FedRAMP High · 4 controls

  • RA-5(11) Vulnerability Monitoring and Scanning | Public Disclosure Program (RA-5(11))
  • SA-3 System Development Life Cycle
  • SA-4 Acquisition Process
  • SI-2 Flaw Remediation

FedRAMP Moderate · 4 controls

  • RA-5(11) Vulnerability Monitoring and Scanning | Public Disclosure Program (RA-5(11))
  • SA-3 System Development Life Cycle
  • SA-4 Acquisition Process
  • SI-2 Flaw Remediation

NIST SP 800-171 Rev 3 · 4 controls

NIST SP 800-53 Rev 5 · 4 controls

PCI DSS 4.0 · 4 controls

  • 11.3.1 11.3.1 Quarterly internal vulnerability scans
  • 6.2.1 6.2.1 Secure development of bespoke and custom software
  • 6.2.3 6.2.3 Code review before release
  • 6.4.1 6.4.1 Public web application review or automated protection

DORA · 3 controls

SOC 2 · 3 controls

  • SOC2-CC5.2 CC5.2 General controls over technology (COSO principle 11)
  • SOC2-CC7.1 CC7.1 Detecting configuration changes and new vulnerabilities
  • SOC2-CC8.1 CC8.1 Managing changes to procedures, software, data and infrastructure

APRA CPS 234 · 1 control

  • CPS234-21 Implementation of Information Security Controls

EU AI Act · 1 control

GDPR · 1 control

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in NIS2 Chapter IV: Cybersecurity Risk-Management Measures (Article 21)

You are reading one control. How much of NIS2 Directive have you already done?

NIS2 Directive Art.21.2.e is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIS2 Directive your existing evidence covers. Hold DORA and 17 of 28 NIS2 Directive controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the DORA pair alone.

Query this from an agent

The graph holds this control, the 73 it maps to, and the evidence behind each claim, over MCP and REST.