Project: Date: Status:
Is this system in scope for NIS2?
Sector:
| Measure | Status | Notes | |---------|--------|-------| | Multi-factor authentication | ⬜ | | | Encryption at rest | ⬜ | | | Encryption in transit | ⬜ | | | Vulnerability management / patching | ⬜ | | | Network segmentation | ⬜ | | | Endpoint protection | ⬜ | | | Logging & monitoring (SIEM) | ⬜ | | | Penetration testing | ⬜ | | | Secure SDLC | ⬜ | | | Access control (least privilege) | ⬜ | | | Backup & restore tested | ⬜ | | | Supply chain security | ⬜ | |
Early warning (24h): Notification (72h): Final report (1 month):
Competent authority: CSIRT:
| Supplier | Criticality | Security assessment done? | DPA / SLA in place? | |----------|------------|--------------------------|---------------------| | | | | |
processes/disaster-recovery.md)| Gap | Priority | Owner | Target date | |-----|----------|-------|-------------| | | | | |
Reacties