The NIS2 directive brings a significant shift in the way organizations must approach their cybersecurity. As an internal auditor, it is essential to understand which measures you need to check now and how to effectively conduct an audit for NIS2 compliance. In this article, we discuss the key points, best practices, and common challenges in implementing NIS2.
What is NIS2 and why is it important?
NIS2, officially known as Directive (EU) 2022/2555, is the successor to the previous NIS directive and came into effect on January 16, 2023. The directive imposes stricter requirements for the cybersecurity of 'essential' and 'important' entities in the EU. This includes not only large companies but also SMEs that are part of vital supply chains.
What should internal auditors check?
Internal auditors play a crucial role in ensuring NIS2 compliance. The directive requires organizations to adopt a risk-based approach to their cybersecurity measures. This means that auditors should focus on several core areas:
Risk analysis: Organizations must conduct a thorough risk analysis and document the results. Auditors should verify whether these analyses are regularly updated and whether they reflect current threats and vulnerabilities.
Policy measures: It is essential that there are clear policy measures outlining the responsibilities of management and staff. Auditors should check whether these policy documents are accessible and actually adhered to.
Supply chain security: NIS2 emphasizes the security of the supply chain. Auditors should assess how organizations manage risks in their chains, especially concerning tier-2 and tier-3 suppliers.
Incident response: Organizations must have an effective incident response plan. Auditors should evaluate how incidents are documented, handled, and reported.
Resilience: The capacity of an organization to recover from incidents is crucial. Auditors should check whether there are continuity management plans and whether these are regularly tested.
External resources
The Foundation for Quality Innovation is a non-profit organization. They have released a set of standards specifically for companies that are not subject to NIS2 but are part of the supply chain of such companies, divided into 3 levels: SC10, SC20, and SC30. The standards lists are available on this site and are available for free.
The standards are fully auditable with auditreporter.io and are part of the standard set of standards in the application.
Best practices for internal auditors
To effectively audit the NIS2 implementation, there are some best practices you can follow:
Use the PDCA cycle: Applying the Plan-Do-Check-Act cycle helps structure audits and ensures continuous improvement of cybersecurity. This aligns with the recommendations of ENISA and ISO 27001.
Evidence: Ensure that you can provide evidence for each check, such as risk registers, implementation logs, and test results. This increases the credibility of your audit.
Self-assessment: Start with a gap analysis to determine where the organization stands in terms of NIS2 compliance. This helps identify weaknesses.
Interviews at all levels: Involve employees from different layers of the organization in interviews. This provides a broader perspective on the implementation and effectiveness of measures.
Reporting with clear KPIs: Ensure that reporting provides insight into the top 5 risks, incidents, and chain dependencies. This helps management prioritize. Auditreporter.io can assist you with this.
By taking the right measures and applying best practices, you can not only contribute to compliance with the NIS2 directive but also to the overall security and resilience of your organization.