News and developments
How to implement the NIS 2 Directive? Brief overview of required policies
The deadline for the implementation of NIS 2 Directive (17 October 2024) is just over six months away. It is therefore a good idea to start preparations now, including verify whether the organisation has policies and procedures in place to ensure compliance with the new regulation.
The provisions of the NIS 2 Directive alone provide no precise information as to what the implementation of adequate ‘cyber risk-management measures’ should look like. However, this does not mean that it is impossible to establish such measures. To this end, it is useful to refer to the requirements of the ISO/IEC 27000 series of standards (which are explicitly referred to in the NIS 2 Directive) and, by way of analogy, the provisions of the DORA Regulation, addressed to the financial market, which constitute lex specialis – more specific provisions – than the NIS 2 Directive.
The analysis of these acts shows that for the purpose of demonstrating compliance with the NIS 2 Directive, it may be helpful for an organisation to implement the following policies or procedures:
They can be part of the main security policy or be introduced in addition to it. Importantly, the above policies and procedures should be regularly reviewed, tested and, if necessary, updated.
As an aside, it is worth pointing out that the smooth implementation of the NIS 2 Directive is one of the priorities of the new Polish government. The announcements by the Ministry of Digitalisation suggest that the draft implementing law should be submitted to the Parliament as early as Q2 of this year.
Authors: Agnieszka Wachowska, Piotr Konieczny