NIS2 risk-management measures vs ISO 27001, DORA and GDPR
In Malta, NIS2 obligations are laid down by S.L. 460.41; the cybersecurity risk-management measures are set out in article 19. The list of security-measure obligations in the national law contains 10 points.
The table maps the ten risk-management measures in Article 21(2) of the NIS2 Directive to the clauses and Annex A controls of ISO/IEC 27001:2022, to DORA (Regulation (EU) 2022/2554) and to the General Data Protection Regulation. The mapping is the same in every country — only the language of the page changes. Each cell shows the official control references, and the link in a cell opens the official source of that framework.
| What it requires | DORA | GDPR | ISO/IEC 27001:2022 | |
|---|---|---|---|---|
| art 21(2)(a) | policies on risk analysis and information system security [↗] | art 5, art 6, art 8 [↗] | art 24, art 32(1)-(2), art 35 [↗] | klausel 5.2, klausel 6.1.2, klausel 6.1.3, klausel 8.2-8.3, A.5.1 [↗] |
| art 21(2)(b) | incident handling [↗] | art 17, art 18, art 19 [↗] | art 33, art 34 [↗] | A.5.24, A.5.25, A.5.26, A.5.27, A.5.28, A.6.8 [↗] |
| art 21(2)(c) | business continuity (backup management, disaster recovery, crisis management) [↗] | art 11, art 12 [↗] | art 32(1)(c) [↗] | A.5.29, A.5.30, A.8.13, A.8.14 [↗] |
| art 21(2)(d) | supply chain security [↗] | art 28, art 29, art 30 [↗] | art 28, art 32 [↗] | A.5.19, A.5.20, A.5.21, A.5.22, A.5.23 [↗] |
| art 21(2)(e) | security in network and information systems acquisition, development and maintenance, including vulnerability handling and disclosure [↗] | art 9, art 25 [↗] | art 25, art 32(1)(d) [↗] | A.8.8, A.8.25, A.8.26, A.8.27, A.8.28, A.8.29, A.8.30, A.8.31 [↗] |
| art 21(2)(f) | policies and procedures to assess the effectiveness of cybersecurity risk-management measures [↗] | art 6(6), art 24-26 [↗] | art 32(1)(d), art 24(1) [↗] | klausel 9.1, klausel 9.2, klausel 9.3, klausel 10.1, A.5.35, A.5.36 [↗] |
| art 21(2)(g) | basic cyber hygiene practices and cybersecurity training [↗] | art 13(6) [↗] | art 39(1)(b), art 32(4) [↗] | A.6.3, A.5.10, A.8.7 [↗] |
| art 21(2)(h) | policies on the use of cryptography and encryption [↗] | art 9(2) [↗] | art 32(1)(a), art 34(3)(a) [↗] | A.8.24 [↗] |
| art 21(2)(i) | human resources security, access control policies and asset management [↗] | art 9(4)(c) [↗] | art 29, art 5(1)(f) [↗] | A.6.1, A.6.2, A.6.5, A.5.9, A.5.15, A.5.16, A.5.17, A.5.18, A.8.2 [↗] |
| art 21(2)(j) | multi-factor or continuous authentication, secured voice, video and text communications and secured emergency communication systems [↗] | art 9(4)(d) [↗] | art 32(1) [↗] | A.8.5, A.5.14, A.5.16 [↗] |
Frequently asked questions
How do the NIS2 Article 21(2) measures relate to ISO/IEC 27001, DORA and GDPR?
The table maps all 10 NIS2 Article 21(2) risk-management measures against the requirements of these frameworks. For example art 21(2)(a) — ISO/IEC 27001:2022 klausel 5.2, klausel 6.1.2, klausel 6.1.3, klausel 8.2-8.3, A.5.1; DORA art 5, art 6, art 8; GDPR art 24, art 32(1)-(2), art 35.
Security measures in the country's own law: Malta
The list below is quoted verbatim from the country's own legal act establishing the cybersecurity risk-management measures obligation. Where a match is unambiguous, each item carries a reference to the corresponding point of Article 21(2) of the directive.
S.L. 460.41, article 19 — cybersecurity risk-management measures
(2) The measures in sub-article (1) shall be based on an all- hazards approach that aims to protect network and information systems and the physical environment of those systems from incidents, and shall include at least the following:(a) policies on risk analysis and information system security
art 21(2)(a)(b) incident handling
art 21(2)(b)(c) business continuity, such as backup management and disaster recovery, and crisis management
art 21(2)(c)(d) supply chain security, including security-related aspects concerning the relationships between each entity and its direct suppliers or service providers
art 21(2)(d)(e) security in network and information systems acquisition, development and maintenance, including vulnerability handling and disclosure
art 21(2)(e)(f) policies and procedures to assess the effectiveness of cybersecurity risk-management measures
art 21(2)(f)(g) basic cyber hygiene practices and cybersecurity training
art 21(2)(g)(h) policies and procedures regarding the use of cryptography and, where appropriate, encryption
art 21(2)(h)(i) human resources security, insider risk management policy, access control policies and asset management
art 21(2)(i)(j) the use of multi-factor authentication or continuous authentication solutions, secured voice, video and text communications and secured emergency communication systems within the entity, where appropriate; and (k) logging and traceability of network and information systems.
art 21(2)(j)
Reference: S.L. 460.41, article 19 — View official source