NIS2 Directive Art.21.2.g: Basic cyber hygiene practices and cybersecurity training
Cyber hygiene is the common baseline the Directive expects everywhere: keeping software and hardware updated, managing configuration of devices, controlling and limiting administrator-level accounts, managing new installations, changing credentials, segmenting networks and backing up data. The recitals also point at zero-trust principles and user awareness as part of the same baseline. Training here is the workforce limb, distinct from the management body training in Article 20(2), and it needs to reach the roles that actually handle the risk rather than being one annual module for everyone. The value of this category to an auditor is that it is measurable: patch currency, privileged account counts and training completion are all countable, and a claim of good hygiene that cannot produce those numbers is not evidenced.
Maintained by Gerard Blokdyk·Verified against the published standard ·Control text last updated
What else in your programme already covers this
This control maps to 71 controls across 16 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
NIST-CSF-DE.CM-09 Computing hardware and software, runtime environments, and their data are monitored to find potentially adverse events
NIST-CSF-PR.AT-01 Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind
NIST-CSF-PR.IR-01 Networks and environments are protected from unauthorized logical access and usage
NIST-CSF-PR.PS-01 Configuration management practices are established and applied
NIST-CSF-PR.PS-05 Installation and execution of unauthorized software are prevented
You are reading one control. How much of NIS2 Directive have you already done?
NIS2 Directive Art.21.2.g is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIS2 Directive your existing evidence covers. Hold DORA and 17 of 28 NIS2 Directive controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the DORA pair alone.