NIS 2 Directive (Directive (EU) 2022/2555)

Jurisdiction
European Union
Region
Europe
Requirement
Required *Coming Soon
Organization
European Parliament / Commission / Council
Provision
Article 21.2(e)
Applies to
Important and essential entities (as defined, similar to critical infrastructure)
Date
October 17, 2024
Description

2. The measures referred to in paragraph 1 shall be based on an all-hazards approach that aims to protect network and information systems and the physical environment of those systems from incidents, and shall include at least the following: (a) policies on risk analysis and information system security; (b) incident handling; (c) business continuity, such as backup management and disaster recovery, and crisis management; (d) supply chain security, including security-related aspects concerning the relationships between each entity and its direct suppliers or service providers; (e) security in network and information systems acquisition, development and maintenance, including vulnerability handling and disclosure;