NIS2 Directive Art.21.2.i: Human resources security, access control policies and asset management
Three linked disciplines sit in one point because they fail together. Human resources security covers screening proportionate to the role, security terms in employment, and the leaver process. Access control policy covers how identities are created, what rights they carry, how privileged access is granted and reviewed, and how rights change when a person moves internally. Asset management covers knowing what the entity has, who owns it, how it is classified and what happens at disposal. The join between them is where evidence is usually thin: a leaver process that reclaims the laptop but not the cloud account, or an access review run against a directory that does not include the systems that matter. Internal movers are a sharper test than leavers, because accumulated rights are rarely removed.
Maintained by Gerard Blokdyk·Verified against the published standard ·Control text last updated
What else in your programme already covers this
This control maps to 93 controls across 18 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
NIST-CSF-GV.RR-04 Cybersecurity is included in human resources practices
NIST-CSF-ID.AM-01 Inventories of hardware managed by the organization are maintained
NIST-CSF-ID.AM-02 Inventories of software, services, and systems managed by the organization are maintained
NIST-CSF-ID.AM-05 Assets are prioritized based on classification, criticality, resources, and impact on the mission
NIST-CSF-ID.AM-07 Inventories of data and corresponding metadata for designated data types are maintained
NIST-CSF-PR.AA-01 Identities and credentials for authorized users, services, and hardware are managed by the organization
NIST-CSF-PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties
NIST-CSF-PR.AA-06 Physical access to assets is managed, monitored, and enforced commensurate with risk
You are reading one control. How much of NIS2 Directive have you already done?
NIS2 Directive Art.21.2.i is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIS2 Directive your existing evidence covers. Hold DORA and 17 of 28 NIS2 Directive controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the DORA pair alone.