NIS2 Directive
NIS2 Chapter IV: Cybersecurity Risk-Management Measures (Article 21)

NIS2 Directive Art.21.2.i: Human resources security, access control policies and asset management

Three linked disciplines sit in one point because they fail together. Human resources security covers screening proportionate to the role, security terms in employment, and the leaver process. Access control policy covers how identities are created, what rights they carry, how privileged access is granted and reviewed, and how rights change when a person moves internally. Asset management covers knowing what the entity has, who owns it, how it is classified and what happens at disposal. The join between them is where evidence is usually thin: a leaver process that reclaims the laptop but not the cloud account, or an access review run against a directory that does not include the systems that matter. Internal movers are a sharper test than leavers, because accumulated rights are rarely removed.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 93 controls across 18 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

C5 (Germany) · 15 controls

  • C5-AM-01 Asset Inventory
  • C5-AM-04 Decommissioning of Hardware
  • C5-AM-05 Commitment to Permissible Use, Safe Handling and Return of Assets
  • C5-AM-06 Asset Classification and Labelling
  • C5-HR-01 Verification of qualification and trustworthiness
  • C5-HR-02 Employment terms and conditions
  • C5-HR-05 Responsibilities in the event of termination or change of employment
  • C5-IDM-01 Policy for user accounts and access rights
  • C5-IDM-02 Granting and change of user accounts and access rights
  • C5-IDM-04 Withdraw or adjust access rights as the task area changes
  • C5-IDM-05 Regular review of access rights
  • C5-PI-03 Secure deletion of data
  • C5-PS-04 Physical site access control
  • C5-PSS-08 Roles and Rights Concept
  • C5-PSS-09 Authorisation Mechanisms

ISO 27002:2022 · 13 controls

  • 5.11 Return of assets
  • 5.12 Classification of information
  • 5.15 Access control
  • 5.16 Identity management
  • 5.18 Access rights
  • 5.9 Inventory of information and other associated assets
  • 6.1 Screening
  • 6.2 Terms and conditions of employment
  • 6.5 Responsibilities after termination or change of employment
  • 7.10 Storage media
  • 7.14 Secure disposal or re-use of equipment
  • 8.2 Privileged access rights
  • 8.3 Information access restriction

ISO 27001:2022 · 12 controls

  • 5.11 Return of assets
  • 5.12 Classification of information
  • 5.15 Access control
  • 5.16 Identity management
  • 5.18 Access rights
  • 5.9 Inventory of information and other associated assets
  • 6.1 Screening
  • 6.2 Terms and conditions of employment
  • 6.5 Responsibilities after termination or change of employment
  • 7.14 Secure disposal or re-use of equipment
  • 8.2 Privileged access rights
  • 8.3 Information access restriction
  • NIST-CSF-GV.RR-04 Cybersecurity is included in human resources practices
  • NIST-CSF-ID.AM-01 Inventories of hardware managed by the organization are maintained
  • NIST-CSF-ID.AM-02 Inventories of software, services, and systems managed by the organization are maintained
  • NIST-CSF-ID.AM-05 Assets are prioritized based on classification, criticality, resources, and impact on the mission
  • NIST-CSF-ID.AM-07 Inventories of data and corresponding metadata for designated data types are maintained
  • NIST-CSF-PR.AA-01 Identities and credentials for authorized users, services, and hardware are managed by the organization
  • NIST-CSF-PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties
  • NIST-CSF-PR.AA-06 Physical access to assets is managed, monitored, and enforced commensurate with risk

CIS Controls v8 · 4 controls

  • CIS-1.1 Establish and Maintain Detailed Enterprise Asset Inventory
  • CIS-6.1 Establish an Access Granting Process
  • CIS-6.2 Establish an Access Revoking Process
  • CIS-6.8 Define and Maintain Role-Based Access Control

CMMC 2.0 · 4 controls

  • CCM-DCS-06 Assets Cataloguing and Tracking
  • CCM-HRS-01 Background Screening Policy and Procedures
  • CCM-IAM-01 Identity and Access Management Policy and Procedures
  • CCM-IAM-07 User Access Changes and Revocation

FedRAMP High · 4 controls

  • AC-1 Policy and Procedures
  • AC-6(7) Review of User Privileges
  • CM-8 System Component Inventory
  • PS-3 Personnel Screening

FedRAMP Moderate · 4 controls

  • AC-1 Policy and Procedures
  • AC-6(7) Review of User Privileges
  • CM-8 System Component Inventory
  • PS-3 Personnel Screening

NIST SP 800-171 Rev 3 · 4 controls

NIST SP 800-53 Rev 5 · 4 controls

PCI DSS 4.0 · 4 controls

  • 12.5.1 12.5.1 Inventory of in-scope system components
  • 12.7.1 12.7.1 Pre-hire screening of personnel with CDE access
  • 7.2.1 7.2.1 Access control model defined
  • 8.2.5 8.2.5 Terminated users' access revoked immediately

SOC 2 · 4 controls

  • SOC2-CC1.4 CC1.4 Attracting, developing and retaining competent people (COSO principle 4)
  • SOC2-CC6.1 CC6.1 Logical access security over protected information assets
  • SOC2-CC6.2 CC6.2 Registering and authorising users before issuing credentials
  • SOC2-CC6.3 CC6.3 Role-based access, least privilege and segregation of duties

GDPR · 3 controls

APRA CPS 234 · 2 controls

  • CPS234-20 Information Asset Classification
  • CPS234-P19 Policy Direction to All Responsible Parties

DORA · 2 controls

EU AI Act · 1 control

  • 5.1.c-ch Article 5(1)(ç): public institutions and critical infrastructures keep a full asset inventory, including data, and a risk analysis

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in NIS2 Chapter IV: Cybersecurity Risk-Management Measures (Article 21)

You are reading one control. How much of NIS2 Directive have you already done?

NIS2 Directive Art.21.2.i is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIS2 Directive your existing evidence covers. Hold DORA and 17 of 28 NIS2 Directive controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the DORA pair alone.

Query this from an agent

The graph holds this control, the 93 it maps to, and the evidence behind each claim, over MCP and REST.