NIS2 Directive
NIS2 Chapter IV: Cybersecurity Risk-Management Measures (Article 21)

NIS2 Directive Art.21.2.g: Basic cyber hygiene practices and cybersecurity training

Cyber hygiene is the common baseline the Directive expects everywhere: keeping software and hardware updated, managing configuration of devices, controlling and limiting administrator-level accounts, managing new installations, changing credentials, segmenting networks and backing up data. The recitals also point at zero-trust principles and user awareness as part of the same baseline. Training here is the workforce limb, distinct from the management body training in Article 20(2), and it needs to reach the roles that actually handle the risk rather than being one annual module for everyone. The value of this category to an auditor is that it is measurable: patch currency, privileged account counts and training completion are all countable, and a claim of good hygiene that cannot produce those numbers is not evidenced.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 71 controls across 16 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

C5 (Germany) · 9 controls

  • C5-AM-02 Acceptable Use and Safe Handling of Assets Policy
  • C5-COS-02 Security requirements for connections in the Cloud Service Provider's network
  • C5-COS-03 Monitoring of connections in the Cloud Service Provider's network
  • C5-COS-04 Cross-network access
  • C5-IDM-06 Privileged access rights
  • C5-IDM-08 Confidentiality of authentication information
  • C5-OPS-05 Protection Against Malware - Implementation
  • C5-OPS-23 Managing Vulnerabilities, Malfunctions and Errors - System Hardening
  • C5-PSS-07 Confidentiality of Authentication Information

ISO 27001:2022 · 8 controls

  • 5.17 Authentication information
  • 6.3 Information security awareness, education and training
  • 8.1 User end point devices
  • 8.19 Installation of software on operational systems
  • 8.2 Privileged access rights
  • 8.22 Segregation of networks
  • 8.8 Management of technical vulnerabilities
  • 8.9 Configuration management

ISO 27002:2022 · 8 controls

  • 5.17 Authentication information
  • 6.3 Information security awareness, education and training
  • 8.1 User endpoint devices
  • 8.19 Installation of software on operational systems
  • 8.2 Privileged access rights
  • 8.22 Segregation of networks
  • 8.8 Management of technical vulnerabilities
  • 8.9 Configuration management
  • NIST-CSF-DE.CM-09 Computing hardware and software, runtime environments, and their data are monitored to find potentially adverse events
  • NIST-CSF-PR.AT-01 Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind
  • NIST-CSF-PR.IR-01 Networks and environments are protected from unauthorized logical access and usage
  • NIST-CSF-PR.PS-01 Configuration management practices are established and applied
  • NIST-CSF-PR.PS-05 Installation and execution of unauthorized software are prevented

CIS Controls v8 · 4 controls

  • CIS-14.1 Establish and Maintain a Security Awareness Program
  • CIS-4.1 Establish and Maintain a Secure Configuration Process
  • CIS-5.4 Restrict Administrator Privileges to Dedicated Administrator Accounts
  • CIS-7.3 Perform Automated Operating System Patch Management

CMMC 2.0 · 4 controls

FedRAMP High · 4 controls

  • AC-6 Least Privilege
  • AT-2 Literacy Training and Awareness
  • CM-6 Configuration Settings
  • SI-2 Flaw Remediation

FedRAMP Moderate · 4 controls

  • AC-6 Least Privilege
  • AT-2 Literacy Training and Awareness
  • CM-6 Configuration Settings
  • SI-2 Flaw Remediation

NIST SP 800-171 Rev 3 · 4 controls

NIST SP 800-53 Rev 5 · 4 controls

PCI DSS 4.0 · 4 controls

  • 12.6.3 12.6.3 Security awareness training on hire and annually with acknowledgment
  • 2.2.1 2.2.1 System configuration standards maintained
  • 2.2.2 2.2.2 Vendor default accounts managed
  • 7.2.2 7.2.2 User access assigned by job function and least privilege

DORA · 3 controls

SOC 2 · 3 controls

  • SOC2-CC6.6 CC6.6 Protection against threats from outside the system boundary
  • SOC2-CC6.8 CC6.8 Preventing and detecting unauthorised or malicious software
  • SOC2-CC7.1 CC7.1 Detecting configuration changes and new vulnerabilities

EU AI Act · 2 controls

APRA CPS 234 · 1 control

  • CPS234-21 Implementation of Information Security Controls

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in NIS2 Chapter IV: Cybersecurity Risk-Management Measures (Article 21)

You are reading one control. How much of NIS2 Directive have you already done?

NIS2 Directive Art.21.2.g is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIS2 Directive your existing evidence covers. Hold DORA and 17 of 28 NIS2 Directive controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the DORA pair alone.

Query this from an agent

The graph holds this control, the 71 it maps to, and the evidence behind each claim, over MCP and REST.