The EU’s cybersecurity agency ENISA proposes measures today for organisations seeking to demonstrate compliance with risk management, incident handling, continuity planning and supply chain security under the NIS2 Directive, mapped against the frameworks ISO 27001 and NIST CSF.
The guidance (155 pages) can also help national authorities in their supervisory work — in Sweden, of the Cybersecurity Act.
The guidance relates to European Commission Implementing Regulation 2024/2690 of 17 October 2024, adopted to strengthen cybersecurity protection under the NIS2 Directive 2022/2555.
Measures
Recommendations
Compliance
Security protection
Risk management
Establish and maintain a risk management framework. Carry out and document risk assessments.
Use a risk management methodology and define risk acceptance levels in line with the organisation's risk tolerance.
A documented risk management process and risk assessment results. Approved risk management plans.
Consider alternative ways of treating risk (avoidance, transfer, acceptance). Review risk assessments annually and after major changes.
Incident handling
Create an incident management policy that defines roles, responsibilities and handling procedures.
Categorise incidents based on impact, and ensure all employees understand reporting channels for incidents.
A documented incident management policy, logs of incident reports and actions taken, and staff interviews about the processes.
Run regular incident simulations and rehearse escalation and reporting plans. Review processes after every major incident.
Continuity planning
Establish and regularly test continuity and disaster recovery plans.
Align the continuity plan with the incident management policy and ensure all critical systems are covered by the plan.
A documented continuity plan, exercise records from testing, management approvals, and backup plans.
Carry out regular tests and simulations. Ensure the plan covers both cyber incidents and other threats affecting continuity.
Supplier security
Develop a supplier security policy and assess all suppliers based on security risk.
Create a register of all suppliers and document the security requirements. Include specific requirements for incident reporting.
A list of suppliers with their security requirements, contracts and approved policies, and documented supplier security assessments.
Review supplier compliance regularly. Include incident management and vulnerability management in supplier contracts. Maintain an ongoing dialogue on security.
en
ISO 27001
Connection
Implementation
Risk management
Section 6.1.2 of ISO/IEC 27001 requires organisations to develop a systematic risk management process to identify and manage security risks. This includes setting risk acceptance levels and risk treatment plans, which aligns with the guidance's requirement to establish a risk management framework and document risk assessments.
Using ISO/IEC 27005, which provides detailed guidance on information security risk management, can make it easier to comply with both ISO/IEC 27001 and the guidance’s requirements.
Incident handling
Section A.16.1 of ISO/IEC 27001 covers information security incident management and requires a process for identifying, reporting and remediating security incidents. This corresponds to the guidance's requirement for an incident management policy with defined roles, responsibilities and procedures.
A documented incident management policy, including incident categorisation and escalation plans, meets the requirements of both standards and supports a fast, structured response to incidents.
Continuity planning
Section A.17 of ISO/IEC 27001 covers information security continuity management, requiring organisations to ensure their operations can continue in the event of security incidents. This aligns with the guidance's requirement to have continuity and disaster recovery plans in place.
Regular testing of continuity plans, together with documented exercises, satisfies the requirements of both ISO/IEC 27001 and ENISA's guidance.
Supplier security
Section A.15 of ISO/IEC 27001 requires organisations to manage security aspects of their relationships with external suppliers. This includes requirements for supplier assessment and information security agreements, which mirrors the guidance's recommendation to have a supplier security policy.
Establishing supplier agreements that specify security requirements, and regularly reviewing supplier compliance, helps meet the requirements of both ISO/IEC 27001 and the guidance.
en
NIST CSF
Connection
Implementation
Risk management
The NIST Identify function covers risk management and requires organisations to identify cybersecurity risks to systems, people, assets and data. This corresponds to ENISA's requirement to establish a risk management framework and document risk assessments.
The Risk Assessment (ID.RA) category sets out specific requirements, such as identifying threats and vulnerabilities and prioritising risks. This is in line with the guidance's recommendation to set risk acceptance levels and continuously assess risk.
Incident handling
The Respond function in the NIST framework covers incident handling and includes developing and executing response plans for security incidents. This closely matches ENISA's requirement to have an incident management policy with clearly defined roles, responsibilities and processes.
Under the Respond categories Response Planning (RS.RP) and Analysis (RS.AN), recommendations cover analysing and containing incidents, creating recovery plans, and providing regular employee training on incident handling. This mirrors ENISA's guidance and strengthens an organisation's ability to manage incidents in a structured way.
Continuity planning
The Recover function in the NIST CSF framework focuses on recovery and continuity, and emphasises the importance of developing and executing recovery plans after incidents. This resembles ENISA's requirement for continuity planning and disaster recovery plans.
The NIST Recovery Planning (RC.RP) category includes requirements to develop and regularly test continuity plans to ensure the organisation can recover after an incident. This corresponds to the guidance's focus on regularly testing continuity plans and ensuring management approves them.
Supplier security
Under the Protect function in the NIST framework, security measures involving third-party suppliers are emphasised through Supply Chain Risk Management (ID.SC). This is closely related to ENISA's requirement to have a supplier security policy covering supplier assessment and review.
The NIST Supply Chain Risk Management guidelines recommend that organisations identify, monitor and manage third-party risk to ensure suppliers meet security requirements. This matches ENISA's requirement to maintain a supplier register and ensure suppliers comply with security requirements.