NIS2 Directive
NIS2 Chapter IV: Cybersecurity Risk-Management Measures (Article 21)

NIS2 Directive Art.21.2.f: Policies and procedures to assess the effectiveness of the cybersecurity risk-management measures

The entity has to be able to say whether its measures work, not merely that they exist. That calls for a defined assessment approach with a schedule, someone sufficiently independent of the people who operate the control doing the assessing, criteria for what effective means, and a route by which findings become tracked remediation. Testing, measurement and independent review all count; a maturity self-score does not, because it measures opinion. This point is the one that closes the loop back to Article 21(4), since the corrective-action duty is triggered by the entity finding it does not comply, and effectiveness assessment is how it finds out.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 59 controls across 17 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

APRA CPS 234 · 8 controls

  • CPS234-22 Systematic Control Testing Program
  • CPS234-25 Internal Audit Review of Information Security Controls
  • CPS234-32 Annual Review and Testing of Response Plans
  • CPS234-P17 Active Maintenance of Capability Against Change
  • CPS234-P28 Assessment of Reliance on Third Party Control Testing
  • CPS234-P30 Independence and Skill of Testing Personnel
  • CPS234-P31 Annual Review of Testing Program Sufficiency
  • CPS234-P33 Skill of Personnel Providing Control Assurance
  • NIST-CSF-GV.OV-02 The cybersecurity risk management strategy is reviewed and adjusted to ensure coverage of organizational requirements and risks
  • NIST-CSF-GV.RM-07 Strategic opportunities (i.e., positive risks) are characterized and are included in organizational cybersecurity risk discussions
  • NIST-CSF-ID.IM-01 Improvements are identified from evaluations
  • NIST-CSF-ID.IM-02 Improvements are identified from security tests and exercises, including those done in coordination with suppliers and relevant third parties
  • NIST-CSF-ID.RA-08 Processes for receiving, analyzing, and responding to vulnerability disclosures are established
  • NIST-CSF-ID.RA-09 The authenticity and integrity of hardware and software are assessed prior to acquisition and use

C5 (Germany) · 4 controls

  • C5-COM-03 Internal audits of the information security management system
  • C5-OPS-19 Managing Vulnerabilities, Malfunctions and Errors - Penetration Tests
  • C5-OPS-20 Managing Vulnerabilities, Malfunctions and Errors - Measurements, Analyses and Assessments of Procedures
  • C5-SP-02 Review and Approval of Policies and Instructions

DORA · 4 controls

  • DORA-Art.24 General requirements for the performance of digital operational resilience testing
  • DORA-Art.25 Testing of ICT tools and systems
  • DORA-Art.26 Advanced testing of ICT tools, systems and processes based on TLPT
  • DORA-Art.6 ICT risk management framework

FedRAMP High · 4 controls

  • CA-2 Control Assessments
  • CA-2(1) Independent Assessors
  • CA-7 Continuous Monitoring
  • CA-7(4) Continuous Monitoring | Risk Monitoring (CA-7(4))

FedRAMP Moderate · 4 controls

  • CA-2 Control Assessments
  • CA-2(1) Independent Assessors
  • CA-7 Continuous Monitoring
  • CA-7(4) Continuous Monitoring | Risk Monitoring (CA-7(4))

NIST SP 800-53 Rev 5 · 4 controls

PCI DSS 4.0 · 4 controls

  • 10.7.2 10.7.2 Detect and alert on critical security control failures
  • 11.4.3 11.4.3 External penetration testing annually and after change
  • 12.4.2 12.4.2 Quarterly reviews that personnel follow security procedures
  • 12.4.2.1 12.4.2.1 Documentation of quarterly operational reviews

CIS Controls v8 · 3 controls

  • CIS-18.1 Establish and Maintain a Penetration Testing Program
  • CIS-18.2 Perform Periodic External Penetration Tests
  • CIS-18.4 Validate Security Measures

ISO 27001:2022 · 3 controls

  • 5.35 Independent review of information security
  • 5.36 Compliance with policies, rules and standards for information security
  • 8.29 Security testing in development and acceptance

ISO 27002:2022 · 3 controls

  • 5.35 Independent review of information security
  • 5.36 Compliance with policies, rules and standards for information security
  • 8.29 Security testing in development and acceptance

CMMC 2.0 · 2 controls

NIST SP 800-171 Rev 3 · 2 controls

SOC 2 · 2 controls

  • SOC2-CC4.1 CC4.1 Ongoing and separate evaluations of control (COSO principle 16)
  • SOC2-CC4.2 CC4.2 Evaluating and communicating control deficiencies (COSO principle 17)

EU AI Act · 1 control

  • EUAI-Art.72 Post-market monitoring by providers and post-market monitoring plan for high-risk AI systems

GDPR · 1 control

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in NIS2 Chapter IV: Cybersecurity Risk-Management Measures (Article 21)

You are reading one control. How much of NIS2 Directive have you already done?

NIS2 Directive Art.21.2.f is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIS2 Directive your existing evidence covers. Hold DORA and 17 of 28 NIS2 Directive controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the DORA pair alone.

Query this from an agent

The graph holds this control, the 59 it maps to, and the evidence behind each claim, over MCP and REST.