What is needed: 10 NIS2 risk management measures
NIS2 defines 10 cyber security risk management measures that regulated entities must implement. Organizations should implement measures proportionate to the risk presented by cyber threats. And they should implement additional measures to protect against any hazards that could impact information systems and their physical environment, ranging from actual cyber-attacks to power outages and natural disasters.
1. Risk analysis and information system security policies
Organizations must develop comprehensive information security policies and implement risk management procedures which provide the foundation for information security framework.
2. Incident handling
Incident handling includes any actions aimed at preventing, detecting, analyzing, containing, responding to, and recovering from a security incident.
3. Business continuity
Organizations should take steps to ensure they can continue to operate even in the event of a cyber-attack or natural disaster. Beyond having a data backup strategy in place, requirements and processes for responding to disruptions should be developed to ensure business continuity.
4. Supply chain security
Supply chain security focuses on managing risks relating to external vendors and suppliers. Organizations should assess the quality, resilience, and cyber security practice of the third-party products and services they use.
5. Security in network and information systems acquisition, development, and maintenance
Organizations must implement measures to enhance security throughout the full lifecycle of network and information systems, including vulnerability handling and disclosure
6. Assessing the efficacy of risk management measures
Organizations should continuously monitor and refine implemented risk management measures, such as using key performance indicators (KPIs) and conduct periodic risk assessments to ensure security measures are operating correctly and consistently.
7. Training and basic cyber hygiene
Organizations should provide regular cybersecurity training to both management and employees, equipping them to identify risks and evaluate risk management practices. Additionally, they must implement fundamental cyber hygiene measures, including Zero Trust principles, software updates, secure configurations, network segmentation, identity management, access controls, and regular data backups.
8. Cryptography and encryption
Organizations should establish processes for encryption key management in aspect of key generation, distribution, storage, and deletion.
9. Human resources security, access control, and asset management
Human resources security can be understood as protecting sensitive employee data and ensuring that only authorized and vetted personnel have access to an organization’s physical sites and information systems.
10. Multi-factor authentication and secure/emergency communications
Multi-factor authentication (MFA) provides stronger identity verification than passwords alone, using methods such as physical tokens, security questions, or one-time codes. Additionally, organizations must establish secure backup communication channels to maintain contact during incidents or outages if primary channels fail.