IT Security Policy Template: The 11 Elements NIS2 Now Requires by Name
NIS2’s implementing regulation names 11 elements your IT security policy must contain. Five are missing from almost every free template – here they are.
NIS2 compliance guides and resources
NIS2’s implementing regulation names 11 elements your IT security policy must contain. Five are missing from almost every free template – here they are.
NIS2 sets no retention period and never uses the word version. Here is what CIR 2024/2690 Annex 1.1.1 binds you to, and how to derive a defensible schedule.
NIS2 change management policy sits under Article 21(2)(e), not (a). What Annex 6.4 binds you to in four sentences, and which ITIL extras are only ENISA advice.
NIS2 names retention three times and never gives a number. Here is how to build a data retention policy auditors accept — and defend the periods you set.
Policy as code for NIS2: CIR 2024/2690 lists 11 things your security policy must contain. A pipeline can generate 3 — 62 clauses still need a written reason.
One binding line names your maturity level; no rule scores it. What a NIS2 auditor can actually test about your model, and what to benchmark against.
NIST forbids periodic password expiry. NIS2 Annex 11.6.2(c) requires change at predefined intervals. The exact policy wording that satisfies both.
Residual risk appears zero times in the NIS2 Directive. Four CIR 2024/2690 clauses carry the duty, with two acceptance standards and one delegation rule.
ENISA names STRIDE once in 170 pages, and not under Article 21(2)(a). See what your threat model covers, and the artefacts an auditor asks for instead.
ENISA’s 170-page NIS2 guidance names PASTA zero times. Here’s what the PASTA threat model’s 7 stages cover under Article 21(2)(a), and the 7 records they don’t.