NIS2 to ISO 27001:2022 Mapping Table

NIS2 to ISO 27001:2022 Mapping Table

Views: 2

Complete Control Mapping for Belgian Organizations

This comprehensive mapping shows how ISO 27001:2022 controls align with NIS2 Directive requirements, helping organizations leverage existing ISMS implementations for NIS2 compliance.


Risk Management Measures

1. Policies on Risk Analysis and Information System Security

NIS2 RequirementISO 27001:2022 ControlISO 27002:2022 ReferenceImplementation NotesGap Analysis
Risk analysis policies5.7 Threat intelligence
5.8 Information security in project management
5.7, 5.8ISO 27001 provides comprehensive risk assessment methodologyALIGNED – No significant gap
Information system security policies5.1 Policies for information security
5.10 Acceptable use of information
5.1, 5.10Document all security policies with management approvalALIGNED – Ensure regular review
Risk management frameworkClause 6.1.2 Information security risk assessment
Clause 6.1.3 Information security risk treatment
N/A (ISO 27001 main body)Risk assessment must be documented and regular⚠️ MINOR GAP – NIS2 requires sector-specific risk scenarios

2. Incident Handling

NIS2 RequirementISO 27001:2022 ControlISO 27002:2022 ReferenceImplementation NotesGap Analysis
Incident detection5.24 Information security incident management planning and preparation
5.25 Assessment and decision on information security events
5.24, 5.25Deploy SIEM/logging for continuous monitoring⚠️ SIGNIFICANT GAP – NIS2 requires 24-hour detection capability
Incident response5.26 Response to information security incidents5.26Document response procedures with clear escalationALIGNED – Enhance with NIS2 reporting templates
Incident reporting5.27 Learning from information security incidents5.27CRITICAL: Add NIS2-specific 24/72-hour reporting to CCB🔴 MAJOR GAP – ISO doesn’t specify external reporting timelines
Post-incident review5.28 Collection of evidence5.28Forensic capabilities and evidence preservationALIGNED – Ensure compliance with Belgian legal requirements

3. Business Continuity and Disaster Recovery

NIS2 RequirementISO 27001:2022 ControlISO 27002:2022 ReferenceImplementation NotesGap Analysis
Business continuity planning5.29 Information security during disruption
5.30 ICT readiness for business continuity
5.29, 5.30Document BCP with RTO/RPO for critical servicesALIGNED – Include NIS2 service criticality assessment
Backup management8.13 Information backup8.13Regular backups with tested restoration proceduresALIGNED – Ensure offline/immutable backups
Disaster recovery5.30 ICT readiness for business continuity5.30Test DR plans at least annuallyALIGNED – Document test results for CCB audits
Crisis management5.29 Information security during disruption5.29Crisis communication plans including stakeholder notification⚠️ MINOR GAP – Add NIS2 stakeholder notification requirements

4. Supply Chain Security

NIS2 RequirementISO 27001:2022 ControlISO 27002:2022 ReferenceImplementation NotesGap Analysis
Supplier security assessment5.19 Information security in supplier relationships
5.20 Addressing information security within supplier agreements
5.19, 5.20, 5.21, 5.22Conduct security due diligence on critical suppliers⚠️ SIGNIFICANT GAP – NIS2 requires detailed supplier risk assessment
Third-party risk management5.21 Managing information security in ICT supply chain
5.22 Monitoring, review and change management of supplier services
5.21, 5.22Continuous monitoring of supplier security posture🔴 MAJOR GAP – More extensive than ISO requirements
Contractual security requirements5.20 Addressing information security within supplier agreements5.20Include security SLAs, audit rights, incident notification⚠️ MINOR GAP – Add NIS2-specific breach notification clauses
Supply chain mapping5.21 Managing information security in ICT supply chain5.21Maintain inventory of critical suppliers and dependencies🔴 MAJOR GAP – ISO doesn’t require comprehensive supply chain mapping

5. Security in Network and Information Systems Acquisition, Development, and Maintenance

NIS2 RequirementISO 27001:2022 ControlISO 27002:2022 ReferenceImplementation NotesGap Analysis
Secure development lifecycle8.25 Secure development life cycle
8.26 Application security requirements
8.25, 8.26Implement security in SDLC (DevSecOps)ALIGNED – Document practices for audit
Secure procurement5.19 Information security in supplier relationships5.19Security requirements in RFPs and procurement⚠️ MINOR GAP – Add NIS2 compliance verification
Change management8.32 Change management8.32Documented change control with security reviewALIGNED – Ensure emergency change procedures
System hardening8.8 Management of technical vulnerabilities8.8Configuration baselines and hardening standardsALIGNED – Use CIS Benchmarks or similar
Secure deployment8.31 Separation of development, test and production environments8.31Isolated environments with controlled promotionALIGNED – Document deployment procedures

6. Policies and Procedures to Assess Effectiveness

NIS2 RequirementISO 27001:2022 ControlISO 27002:2022 ReferenceImplementation NotesGap Analysis
Security metrics and KPIsClause 9.1 Monitoring, measurement, analysis and evaluationN/A (ISO 27001 main body)Define security metrics aligned with business objectivesALIGNED – Ensure metrics cover NIS2 requirements
Internal auditsClause 9.2 Internal auditN/A (ISO 27001 main body)Annual internal audits of ISMS effectivenessALIGNED – Include NIS2-specific controls
Management reviewClause 9.3 Management reviewN/A (ISO 27001 main body)Regular management review of security program⚠️ MINOR GAP – Document board-level accountability
Security testing8.8 Management of technical vulnerabilities8.8Regular vulnerability assessments and penetration testing⚠️ MINOR GAP – NIS2 may require more frequent testing
Continuous improvementClause 10 ImprovementN/A (ISO 27001 main body)Implement corrective actions from audits and incidentsALIGNED – Track improvements for CCB

7. Cybersecurity Hygiene Practices and Training

NIS2 RequirementISO 27001:2022 ControlISO 27002:2022 ReferenceImplementation NotesGap Analysis
Security awareness training6.3 Information security awareness, education and training6.3Annual security awareness for all staffALIGNED – Include NIS2-specific topics
Management training6.3 Information security awareness, education and training6.3CRITICAL: Board/management cybersecurity training🔴 MAJOR GAP – ISO doesn’t mandate management training
Phishing awareness6.3 Information security awareness, education and training6.3Regular phishing simulations and trainingALIGNED – Document training completion rates
Security hygiene practices5.16 Identity management
5.17 Authentication information
8.5 Secure authentication
5.16, 5.17, 8.5Password policies, clean desk, device securityALIGNED – Ensure regular reminders

8. Cryptography and Encryption Policies

NIS2 RequirementISO 27001:2022 ControlISO 27002:2022 ReferenceImplementation NotesGap Analysis
Cryptographic controls8.24 Use of cryptography8.24Define encryption requirements for data at rest and in transitALIGNED – Use current standards (TLS 1.3, AES-256)
Key management8.24 Use of cryptography8.24Secure key generation, distribution, storage, and destructionALIGNED – Consider HSM for critical keys
Encryption implementation8.24 Use of cryptography8.24Encrypt sensitive data, communications, and backupsALIGNED – Document encryption inventory

9. Human Resources Security, Access Control, and Asset Management

NIS2 RequirementISO 27001:2022 ControlISO 27002:2022 ReferenceImplementation NotesGap Analysis
Human resources security6.1 Screening
6.2 Terms and conditions of employment
6.4 Disciplinary process
6.5 Responsibilities after termination
6.1-6.8Background checks, NDAs, offboarding proceduresALIGNED – Ensure Belgian labor law compliance
Access control policy5.15 Access control
5.16 Identity management
5.18 Access rights
5.15-5.18, 8.2-8.6Implement least privilege and need-to-knowALIGNED – Regular access reviews required
Privileged access management5.18 Access rights
8.2 Privileged access rights
5.18, 8.2Control and monitor privileged accountsALIGNED – Implement PAM solution
Asset inventory5.9 Inventory of information and other associated assets
5.10 Acceptable use of information and other associated assets
5.9, 5.10Comprehensive inventory of hardware, software, dataALIGNED – Include criticality ratings
Asset classification5.12 Classification of information
5.13 Labelling of information
5.12, 5.13Define classification scheme and handling requirementsALIGNED – Align with NIS2 service criticality

10. Multi-Factor Authentication and Secure Communications

NIS2 RequirementISO 27001:2022 ControlISO 27002:2022 ReferenceImplementation NotesGap Analysis
Multi-factor authentication5.17 Authentication information
5.18 Access rights
5.17, 5.18MFA for remote access and privileged accounts (minimum)⚠️ MINOR GAP – NIS2 strongly recommends MFA for all users
Secure communications5.14 Information transfer
8.24 Use of cryptography
5.14, 8.24Encrypted email, VPN, secure messagingALIGNED – Document approved communication channels
Network security8.20 Networks security
8.21 Security of network services
8.22 Segregation of networks
8.20-8.23Firewalls, network segmentation, intrusion detectionALIGNED – Regular security reviews

Management and Governance Requirements

Management Accountability

NIS2 RequirementISO 27001:2022 ControlISO 27002:2022 ReferenceImplementation NotesGap Analysis
Board oversightClause 5.1 Leadership and commitmentN/A (ISO 27001 main body)Management must approve security measures🔴 MAJOR GAP – NIS2 requires explicit board accountability
Management training6.3 Information security awareness, education and training6.3MANDATORY: Board cybersecurity training with evidence🔴 MAJOR GAP – Must document management training completion
Security budgetClause 7.1 ResourcesN/A (ISO 27001 main body)Adequate resources allocated to security⚠️ MINOR GAP – Document budget decisions for audit
Management liabilityN/AN/ANEW: Personal liability for management non-compliance🔴 MAJOR GAP – Legal/insurance considerations needed

Incident Reporting Compliance

NIS2 RequirementISO 27001:2022 ControlISO 27002:2022 ReferenceImplementation NotesGap Analysis
24-hour early warning5.26 Response to information security incidents5.26CRITICAL: Procedures for rapid detection and initial reporting to CCB🔴 MAJOR GAP – Requires 24/7 monitoring capability
72-hour detailed report5.26 Response to information security incidents5.26Template and process for comprehensive incident reporting🔴 MAJOR GAP – Specific NIS2 reporting format required
Final report (1 month)5.27 Learning from information security incidents5.27Root cause analysis and remediation documentation⚠️ MINOR GAP – Add post-mortem report template

Summary: Gap Analysis Categories

ALIGNED (65-70% of requirements)

ISO 27001 controls directly support NIS2 compliance with minimal enhancements needed.

Actions:

  • Document existing controls
  • Map to NIS2 requirements
  • Ensure evidence is audit-ready

⚠️ MINOR GAP (20-25% of requirements)

ISO 27001 provides foundation but requires specific NIS2 additions or enhancements.

Actions:

  • Enhance existing controls
  • Add NIS2-specific procedures
  • Update documentation
  • Provide additional training

🔴 MAJOR GAP (10-15% of requirements)

New requirements not covered by ISO 27001 that need significant additional work.

Priority Focus Areas:

  1. Incident Reporting: 24/72-hour reporting to CCB
  2. Management Accountability: Board-level training and explicit liability
  3. Supply Chain Security: Comprehensive supplier risk assessment and monitoring
  4. Multi-Factor Authentication: Broader deployment beyond current scope

Implementation Priority Matrix

Priority 1 – Critical (Implement First)

Timeline: Weeks 1-8

  1. ✅ Incident detection and 24-hour reporting capability
  2. ✅ Management/board training and accountability documentation
  3. ✅ Multi-factor authentication deployment
  4. ✅ Supply chain inventory and initial risk assessment
  5. ✅ Incident response procedures with CCB reporting templates

Priority 2 – High (Implement Second)

Timeline: Weeks 9-16

  1. ✅ Comprehensive supply chain security assessments
  2. ✅ Enhanced vulnerability management program
  3. ✅ Business continuity and disaster recovery testing
  4. ✅ Network segmentation and security monitoring
  5. ✅ Security metrics and effectiveness measurement

Priority 3 – Medium (Implement Third)

Timeline: Weeks 17-24

  1. ✅ Advanced cryptographic controls
  2. ✅ Enhanced security awareness program
  3. ✅ Privileged access management solution
  4. ✅ Automated compliance monitoring
  5. ✅ Third-party security audits

Using This Mapping Table

For Organizations Starting from Scratch:

  1. Use ISO 27001 as your compliance framework foundation
  2. Implement controls systematically following ISO structure
  3. Add NIS2-specific requirements as you build
  4. Pursue ISO 27001 certification (demonstrates compliance rigor)

For ISO 27001 Certified Organizations:

  1. Conduct gap analysis using this mapping
  2. Focus resources on 🔴 MAJOR GAP areas first
  3. Enhance ⚠️ MINOR GAP controls with NIS2 specifics
  4. Document ✅ ALIGNED controls for NIS2 audit evidence
  5. Leverage existing ISMS documentation

For Organizations Pursuing Dual Compliance:

  1. Build integrated compliance program
  2. Single set of policies covering both frameworks
  3. Unified audit and review processes
  4. Shared security metrics dashboard
  5. Combined training programs

Belgian Context Considerations

Centre for Cybersecurity Belgium (CCB) Expectations:

  • Documented risk assessment aligned with sector-specific threats
  • Demonstrated management accountability and oversight
  • Operational incident response capability with proven reporting process
  • Evidence of supply chain security program
  • Regular testing and validation of security measures

Audit Preparation:

  • Maintain comprehensive evidence repository
  • Document all security decisions and risk acceptances
  • Keep records of management reviews and training
  • Track incident response activities and reporting
  • Maintain supplier security assessments and contracts

Need Implementation Support?

TekGenX Consulting offers:

  • ✅ NIS2 Gap Analysis using this mapping framework
  • ✅ ISO 27001 implementation integrated with NIS2
  • ✅ Dual compliance program development
  • ✅ Incident response planning for 24/72-hour reporting
  • ✅ Management training and accountability frameworks

Contact: [email protected] | www.tekgenx.com