NIS2 Directive
NIS2 Chapter IV: Cybersecurity Risk-Management Measures (Article 21)

NIS2 Directive Art.21.2.f: Policies and procedures to assess the effectiveness of the cybersecurity risk-management measures

The entity has to be able to say whether its measures work, not merely that they exist. That calls for a defined assessment approach with a schedule, someone sufficiently independent of the people who operate the control doing the assessing, criteria for what effective means, and a route by which findings become tracked remediation. Testing, measurement and independent review all count; a maturity self-score does not, because it measures opinion. This point is the one that closes the loop back to Article 21(4), since the corrective-action duty is triggered by the entity finding it does not comply, and effectiveness assessment is how it finds out.

What else in your programme already covers this

This control maps to 70 controls across 20 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

APRA CPS 234 · 8 controls

  • CPS234-22 Systematic Control Testing Program
  • CPS234-25 Internal Audit Review of Information Security Controls
  • CPS234-32 Annual Review and Testing of Response Plans
  • CPS234-P17 Active Maintenance of Capability Against Change
  • CPS234-P28 Assessment of Reliance on Third Party Control Testing
  • CPS234-P30 Independence and Skill of Testing Personnel
  • CPS234-P31 Annual Review of Testing Program Sufficiency
  • CPS234-P33 Skill of Personnel Providing Control Assurance
  • NIST-CSF-GV.OV-02 The cybersecurity risk management strategy is reviewed and adjusted to ensure coverage of organizational requirements and risks
  • NIST-CSF-GV.RM-07 Strategic opportunities (i.e., positive risks) are characterized and are included in organizational cybersecurity risk discussions
  • NIST-CSF-ID.IM-01 Improvements are identified from evaluations
  • NIST-CSF-ID.IM-02 Improvements are identified from security tests and exercises, including those done in coordination with suppliers and relevant third parties
  • NIST-CSF-ID.RA-08 Processes for receiving, analyzing, and responding to vulnerability disclosures are established
  • NIST-CSF-ID.RA-09 The authenticity and integrity of hardware and software are assessed prior to acquisition and use

C5 (Germany) · 4 controls

  • C5-COM-03 Internal audits of the information security management system
  • C5-OPS-19 Managing Vulnerabilities, Malfunctions and Errors - Penetration Tests
  • C5-OPS-20 Managing Vulnerabilities, Malfunctions and Errors - Measurements, Analyses and Assessments of Procedures
  • C5-SP-02 Review and Approval of Policies and Instructions

DORA · 4 controls

  • DORA-Art.24 General requirements for the performance of digital operational resilience testing
  • DORA-Art.25 Testing of ICT tools and systems
  • DORA-Art.26 Advanced testing of ICT tools, systems and processes based on TLPT
  • DORA-Art.6 ICT risk management framework

FedRAMP High · 4 controls

  • CA-2 Control Assessments
  • CA-2(1) Independent Assessors
  • CA-7 Continuous Monitoring
  • CA-7(4) Continuous Monitoring | Risk Monitoring. Ensure risk monitoring is an integral part of the continuous monitoring strategy that includes the following: (a) Effectiveness monitoring; (b) Compliance monitoring; and (c) Change monitoring

FedRAMP Moderate · 4 controls

  • CA-2 Control Assessments
  • CA-2(1) Independent Assessors
  • CA-7 Continuous Monitoring
  • CA-7(4) Continuous Monitoring | Risk Monitoring. Ensure risk monitoring is an integral part of the continuous monitoring strategy that includes the following: (a) Effectiveness monitoring; (b) Compliance monitoring; and (c) Change monitoring

NIST SP 800-53 Rev 5 · 4 controls

  • NIST800-CA-2 Control assessments
  • NIST800-CA-7 Continuous monitoring
  • NIST800-PM-31 Continuous Monitoring Strategy. Develop an organization-wide continuous monitoring strategy and implement continuous monitoring programs that include: Establishing the following organization-wide metrics to be monitored: [organization-defined]; Establishing [organization-defined] and [organization-defined] for control effectiveness; Ongoing monitoring
  • NIST800-PM-6 Measures of Performance. Develop, monitor, and report on the results of information security and privacy measures of performance
  • CA-2 Control Assessments
  • CA-2(1) Independent Assessors
  • CA-7 Continuous Monitoring
  • CA-7(4) Continuous Monitoring | Risk Monitoring. Ensure risk monitoring is an integral part of the continuous monitoring strategy that includes the following: (a) Effectiveness monitoring; (b) Compliance monitoring; and (c) Change monitoring
  • CA-2 Control Assessments
  • CA-2(1) Independent Assessors
  • CA-7 Continuous Monitoring
  • CA-7(4) Continuous Monitoring | Risk Monitoring. Ensure risk monitoring is an integral part of the continuous monitoring strategy that includes the following: (a) Effectiveness monitoring; (b) Compliance monitoring; and (c) Change monitoring

PCI DSS 4.0 · 4 controls

  • 10.7.2 Critical security control failure detection (all entities)
  • 11.4.3 External penetration testing annually
  • 12.4.2 Quarterly PCI compliance reviews (SP)
  • 12.4.2.1 Documentation of quarterly reviews (SP)

CIS Controls v8 · 3 controls

  • CIS-18.1 Establish and Maintain a Penetration Testing Program
  • CIS-18.2 Perform Periodic External Penetration Tests
  • CIS-18.4 Validate Security Measures

ISO 27001:2022 · 3 controls

  • 5.35 Independent review of information security
  • 5.36 Compliance with policies, rules and standards for information security
  • 8.29 Security testing in development and acceptance

ISO 27002:2022 · 3 controls

  • 5.35 Independent review of information security
  • 5.36 Compliance with policies, rules and standards for information security
  • 8.29 Security testing in development and acceptance
  • CA-2 Control Assessments
  • CA-7 Continuous Monitoring
  • CA-7(4) Continuous Monitoring | Risk Monitoring. Ensure risk monitoring is an integral part of the continuous monitoring strategy that includes the following: (a) Effectiveness monitoring; (b) Compliance monitoring; and (c) Change monitoring

CMMC 2.0 · 2 controls

NIST SP 800-171 Rev 3 · 2 controls

SOC 2 · 2 controls

  • SOC2-CC4.1 COSO principle 16: Selects and develops ongoing and separate evaluations
  • SOC2-CC4.2 COSO principle 17: Evaluates and communicates deficiencies in a timely manner

EU AI Act · 1 control

  • EUAI-Art.72 Post-market monitoring by providers and post-market monitoring plan for high-risk AI systems

GDPR · 1 control

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in NIS2 Chapter IV: Cybersecurity Risk-Management Measures (Article 21)

You are reading one control. How much of NIS2 Directive have you already done?

NIS2 Directive Art.21.2.f is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIS2 Directive your existing evidence covers. Hold DORA and 17 of 28 NIS2 Directive controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the DORA pair alone.

Query this from an agent

The graph holds this control, the 70 it maps to, and the evidence behind each claim, over MCP and REST.