Čo je smernica NIS 2?
Smernica NIS 2 Európskej komisie obsahuje súbor kybernetických bezpečnostných opatrení a návrhov, ktorých cieľom je ďalší rozvoj proaktívnej obrany a stratégií riadenia incidentov v spolupráci s príslušnými orgánmi a verejnými aj súkromnými organizáciami.
Bola navrhnutá ako náhrada pôvodnej smernice NIS, ktorej implementácia zlyhala počas pandémie COVID‑19, ktorá výrazne zmenila vzťah spoločnosti k digitálnemu svetu.
Smernica NIS 2 je v súlade s ambíciou Európskej komisie chrániť Európu v digitálnom veku a zabezpečiť dlhodobú odolnosť hospodárstva.
Bola prijatá Európskym parlamentom 10. novembra 2022 a Radou EÚ 28. novembra 2022, čím sa začal proces zrušenia predchádzajúcej smernice NIS.
Na koho sa smernica NIS 2 vzťahuje?
Smernica NIS 2 sa vzťahuje na organizácie pôsobiace vo verejnom aj súkromnom sektore v Európskej únii. Patria sem okrem iného oblasti: zdravotníctvo energetika doprava digitálna infraštruktúra
The European Union currently has 27 European countries: Austria, Belgium, Bulgaria, Cyprus, Czech Republic, Denmark, Estonia, Finland, France, Greece, Netherlands, Croatia, Ireland, Latvia, Lithuania, Luxembourg, Malta, Poland, Hungary, Germany, Italy, Portugal, Romania, Slovakia, Slovenia, Spain and Sweden.
The NIS 2 Directive applies to all of these areas and should be implemented by all organizations operating in these areas according to the following timetable:
The NIS 2 Directive applies to organisations operating in the private and public sectors in the European Union. This includes, among others, healthcare, energy, transport and digital infrastructure..
The European Commission sets out the technical and methodological requirements in all cybersecurity areas covered by the NIS 2 Directive. All Member States of the European Union must adopt and publish measures to comply with this.
Member States must apply the measures from that date. From that date, the previous NIS Directive will cease to apply.
On this day, the NIS Cooperation Group will establish a framework based on which assessments will be carried out by cybersecurity experts designated by the Member States.
Each Member State must submit a list of core organisations, as well as those providing services related to domain name registration. This list will be updated every two years.
Starting from today, and every 36 months thereafter, the European Commission will evaluate the effectiveness of the NIS 2 Directive and report to the European Parliament and the Council.
COMPLIANCE
SECOPS
IT
TO WHICH IT APPLIES
NIS 2 Directive Objectives and Components
The main objective of the NIS 2 Directive is to provide EU Member State organisations with the tools to prepare for and protect against cybersecurity incidents in a manner that is consistent with the current digital environment. To this end, it covers areas such as:
Incident management
Asset and vulnerability management
Access management
Risk analysis and management policy
Supply chain security
MFA and encryption
Disaster recovery and data backup
Cybersecurity training
Areas covered by Heimdal according to NIS 2 directive
Areas detected by Heimdal® in accordance with NIS 2 directive
NIS compliance with Heimdal
START YOUR CYBERSECURITY MEASURES IN ADVANCE