Views: 2
Complete Control Mapping for Belgian Organizations
This comprehensive mapping shows how ISO 27001:2022 controls align with NIS2 Directive requirements, helping organizations leverage existing ISMS implementations for NIS2 compliance.
Risk Management Measures
1. Policies on Risk Analysis and Information System Security
| NIS2 Requirement | ISO 27001:2022 Control | ISO 27002:2022 Reference | Implementation Notes | Gap Analysis |
|---|---|---|---|---|
| Risk analysis policies | 5.7 Threat intelligence 5.8 Information security in project management | 5.7, 5.8 | ISO 27001 provides comprehensive risk assessment methodology | ✅ ALIGNED – No significant gap |
| Information system security policies | 5.1 Policies for information security 5.10 Acceptable use of information | 5.1, 5.10 | Document all security policies with management approval | ✅ ALIGNED – Ensure regular review |
| Risk management framework | Clause 6.1.2 Information security risk assessment Clause 6.1.3 Information security risk treatment | N/A (ISO 27001 main body) | Risk assessment must be documented and regular | ⚠️ MINOR GAP – NIS2 requires sector-specific risk scenarios |
2. Incident Handling
| NIS2 Requirement | ISO 27001:2022 Control | ISO 27002:2022 Reference | Implementation Notes | Gap Analysis |
|---|---|---|---|---|
| Incident detection | 5.24 Information security incident management planning and preparation 5.25 Assessment and decision on information security events | 5.24, 5.25 | Deploy SIEM/logging for continuous monitoring | ⚠️ SIGNIFICANT GAP – NIS2 requires 24-hour detection capability |
| Incident response | 5.26 Response to information security incidents | 5.26 | Document response procedures with clear escalation | ✅ ALIGNED – Enhance with NIS2 reporting templates |
| Incident reporting | 5.27 Learning from information security incidents | 5.27 | CRITICAL: Add NIS2-specific 24/72-hour reporting to CCB | 🔴 MAJOR GAP – ISO doesn’t specify external reporting timelines |
| Post-incident review | 5.28 Collection of evidence | 5.28 | Forensic capabilities and evidence preservation | ✅ ALIGNED – Ensure compliance with Belgian legal requirements |
3. Business Continuity and Disaster Recovery
| NIS2 Requirement | ISO 27001:2022 Control | ISO 27002:2022 Reference | Implementation Notes | Gap Analysis |
|---|---|---|---|---|
| Business continuity planning | 5.29 Information security during disruption 5.30 ICT readiness for business continuity | 5.29, 5.30 | Document BCP with RTO/RPO for critical services | ✅ ALIGNED – Include NIS2 service criticality assessment |
| Backup management | 8.13 Information backup | 8.13 | Regular backups with tested restoration procedures | ✅ ALIGNED – Ensure offline/immutable backups |
| Disaster recovery | 5.30 ICT readiness for business continuity | 5.30 | Test DR plans at least annually | ✅ ALIGNED – Document test results for CCB audits |
| Crisis management | 5.29 Information security during disruption | 5.29 | Crisis communication plans including stakeholder notification | ⚠️ MINOR GAP – Add NIS2 stakeholder notification requirements |
4. Supply Chain Security
| NIS2 Requirement | ISO 27001:2022 Control | ISO 27002:2022 Reference | Implementation Notes | Gap Analysis |
|---|---|---|---|---|
| Supplier security assessment | 5.19 Information security in supplier relationships 5.20 Addressing information security within supplier agreements | 5.19, 5.20, 5.21, 5.22 | Conduct security due diligence on critical suppliers | ⚠️ SIGNIFICANT GAP – NIS2 requires detailed supplier risk assessment |
| Third-party risk management | 5.21 Managing information security in ICT supply chain 5.22 Monitoring, review and change management of supplier services | 5.21, 5.22 | Continuous monitoring of supplier security posture | 🔴 MAJOR GAP – More extensive than ISO requirements |
| Contractual security requirements | 5.20 Addressing information security within supplier agreements | 5.20 | Include security SLAs, audit rights, incident notification | ⚠️ MINOR GAP – Add NIS2-specific breach notification clauses |
| Supply chain mapping | 5.21 Managing information security in ICT supply chain | 5.21 | Maintain inventory of critical suppliers and dependencies | 🔴 MAJOR GAP – ISO doesn’t require comprehensive supply chain mapping |
5. Security in Network and Information Systems Acquisition, Development, and Maintenance
| NIS2 Requirement | ISO 27001:2022 Control | ISO 27002:2022 Reference | Implementation Notes | Gap Analysis |
|---|---|---|---|---|
| Secure development lifecycle | 8.25 Secure development life cycle 8.26 Application security requirements | 8.25, 8.26 | Implement security in SDLC (DevSecOps) | ✅ ALIGNED – Document practices for audit |
| Secure procurement | 5.19 Information security in supplier relationships | 5.19 | Security requirements in RFPs and procurement | ⚠️ MINOR GAP – Add NIS2 compliance verification |
| Change management | 8.32 Change management | 8.32 | Documented change control with security review | ✅ ALIGNED – Ensure emergency change procedures |
| System hardening | 8.8 Management of technical vulnerabilities | 8.8 | Configuration baselines and hardening standards | ✅ ALIGNED – Use CIS Benchmarks or similar |
| Secure deployment | 8.31 Separation of development, test and production environments | 8.31 | Isolated environments with controlled promotion | ✅ ALIGNED – Document deployment procedures |
6. Policies and Procedures to Assess Effectiveness
| NIS2 Requirement | ISO 27001:2022 Control | ISO 27002:2022 Reference | Implementation Notes | Gap Analysis |
|---|---|---|---|---|
| Security metrics and KPIs | Clause 9.1 Monitoring, measurement, analysis and evaluation | N/A (ISO 27001 main body) | Define security metrics aligned with business objectives | ✅ ALIGNED – Ensure metrics cover NIS2 requirements |
| Internal audits | Clause 9.2 Internal audit | N/A (ISO 27001 main body) | Annual internal audits of ISMS effectiveness | ✅ ALIGNED – Include NIS2-specific controls |
| Management review | Clause 9.3 Management review | N/A (ISO 27001 main body) | Regular management review of security program | ⚠️ MINOR GAP – Document board-level accountability |
| Security testing | 8.8 Management of technical vulnerabilities | 8.8 | Regular vulnerability assessments and penetration testing | ⚠️ MINOR GAP – NIS2 may require more frequent testing |
| Continuous improvement | Clause 10 Improvement | N/A (ISO 27001 main body) | Implement corrective actions from audits and incidents | ✅ ALIGNED – Track improvements for CCB |
7. Cybersecurity Hygiene Practices and Training
| NIS2 Requirement | ISO 27001:2022 Control | ISO 27002:2022 Reference | Implementation Notes | Gap Analysis |
|---|---|---|---|---|
| Security awareness training | 6.3 Information security awareness, education and training | 6.3 | Annual security awareness for all staff | ✅ ALIGNED – Include NIS2-specific topics |
| Management training | 6.3 Information security awareness, education and training | 6.3 | CRITICAL: Board/management cybersecurity training | 🔴 MAJOR GAP – ISO doesn’t mandate management training |
| Phishing awareness | 6.3 Information security awareness, education and training | 6.3 | Regular phishing simulations and training | ✅ ALIGNED – Document training completion rates |
| Security hygiene practices | 5.16 Identity management 5.17 Authentication information 8.5 Secure authentication | 5.16, 5.17, 8.5 | Password policies, clean desk, device security | ✅ ALIGNED – Ensure regular reminders |
8. Cryptography and Encryption Policies
| NIS2 Requirement | ISO 27001:2022 Control | ISO 27002:2022 Reference | Implementation Notes | Gap Analysis |
|---|---|---|---|---|
| Cryptographic controls | 8.24 Use of cryptography | 8.24 | Define encryption requirements for data at rest and in transit | ✅ ALIGNED – Use current standards (TLS 1.3, AES-256) |
| Key management | 8.24 Use of cryptography | 8.24 | Secure key generation, distribution, storage, and destruction | ✅ ALIGNED – Consider HSM for critical keys |
| Encryption implementation | 8.24 Use of cryptography | 8.24 | Encrypt sensitive data, communications, and backups | ✅ ALIGNED – Document encryption inventory |
9. Human Resources Security, Access Control, and Asset Management
| NIS2 Requirement | ISO 27001:2022 Control | ISO 27002:2022 Reference | Implementation Notes | Gap Analysis |
|---|---|---|---|---|
| Human resources security | 6.1 Screening 6.2 Terms and conditions of employment 6.4 Disciplinary process 6.5 Responsibilities after termination | 6.1-6.8 | Background checks, NDAs, offboarding procedures | ✅ ALIGNED – Ensure Belgian labor law compliance |
| Access control policy | 5.15 Access control 5.16 Identity management 5.18 Access rights | 5.15-5.18, 8.2-8.6 | Implement least privilege and need-to-know | ✅ ALIGNED – Regular access reviews required |
| Privileged access management | 5.18 Access rights 8.2 Privileged access rights | 5.18, 8.2 | Control and monitor privileged accounts | ✅ ALIGNED – Implement PAM solution |
| Asset inventory | 5.9 Inventory of information and other associated assets 5.10 Acceptable use of information and other associated assets | 5.9, 5.10 | Comprehensive inventory of hardware, software, data | ✅ ALIGNED – Include criticality ratings |
| Asset classification | 5.12 Classification of information 5.13 Labelling of information | 5.12, 5.13 | Define classification scheme and handling requirements | ✅ ALIGNED – Align with NIS2 service criticality |
10. Multi-Factor Authentication and Secure Communications
| NIS2 Requirement | ISO 27001:2022 Control | ISO 27002:2022 Reference | Implementation Notes | Gap Analysis |
|---|---|---|---|---|
| Multi-factor authentication | 5.17 Authentication information 5.18 Access rights | 5.17, 5.18 | MFA for remote access and privileged accounts (minimum) | ⚠️ MINOR GAP – NIS2 strongly recommends MFA for all users |
| Secure communications | 5.14 Information transfer 8.24 Use of cryptography | 5.14, 8.24 | Encrypted email, VPN, secure messaging | ✅ ALIGNED – Document approved communication channels |
| Network security | 8.20 Networks security 8.21 Security of network services 8.22 Segregation of networks | 8.20-8.23 | Firewalls, network segmentation, intrusion detection | ✅ ALIGNED – Regular security reviews |
Management and Governance Requirements
Management Accountability
| NIS2 Requirement | ISO 27001:2022 Control | ISO 27002:2022 Reference | Implementation Notes | Gap Analysis |
|---|---|---|---|---|
| Board oversight | Clause 5.1 Leadership and commitment | N/A (ISO 27001 main body) | Management must approve security measures | 🔴 MAJOR GAP – NIS2 requires explicit board accountability |
| Management training | 6.3 Information security awareness, education and training | 6.3 | MANDATORY: Board cybersecurity training with evidence | 🔴 MAJOR GAP – Must document management training completion |
| Security budget | Clause 7.1 Resources | N/A (ISO 27001 main body) | Adequate resources allocated to security | ⚠️ MINOR GAP – Document budget decisions for audit |
| Management liability | N/A | N/A | NEW: Personal liability for management non-compliance | 🔴 MAJOR GAP – Legal/insurance considerations needed |
Incident Reporting Compliance
| NIS2 Requirement | ISO 27001:2022 Control | ISO 27002:2022 Reference | Implementation Notes | Gap Analysis |
|---|---|---|---|---|
| 24-hour early warning | 5.26 Response to information security incidents | 5.26 | CRITICAL: Procedures for rapid detection and initial reporting to CCB | 🔴 MAJOR GAP – Requires 24/7 monitoring capability |
| 72-hour detailed report | 5.26 Response to information security incidents | 5.26 | Template and process for comprehensive incident reporting | 🔴 MAJOR GAP – Specific NIS2 reporting format required |
| Final report (1 month) | 5.27 Learning from information security incidents | 5.27 | Root cause analysis and remediation documentation | ⚠️ MINOR GAP – Add post-mortem report template |
Summary: Gap Analysis Categories
✅ ALIGNED (65-70% of requirements)
ISO 27001 controls directly support NIS2 compliance with minimal enhancements needed.
Actions:
- Document existing controls
- Map to NIS2 requirements
- Ensure evidence is audit-ready
⚠️ MINOR GAP (20-25% of requirements)
ISO 27001 provides foundation but requires specific NIS2 additions or enhancements.
Actions:
- Enhance existing controls
- Add NIS2-specific procedures
- Update documentation
- Provide additional training
🔴 MAJOR GAP (10-15% of requirements)
New requirements not covered by ISO 27001 that need significant additional work.
Priority Focus Areas:
- Incident Reporting: 24/72-hour reporting to CCB
- Management Accountability: Board-level training and explicit liability
- Supply Chain Security: Comprehensive supplier risk assessment and monitoring
- Multi-Factor Authentication: Broader deployment beyond current scope
Implementation Priority Matrix
Priority 1 – Critical (Implement First)
Timeline: Weeks 1-8
- ✅ Incident detection and 24-hour reporting capability
- ✅ Management/board training and accountability documentation
- ✅ Multi-factor authentication deployment
- ✅ Supply chain inventory and initial risk assessment
- ✅ Incident response procedures with CCB reporting templates
Priority 2 – High (Implement Second)
Timeline: Weeks 9-16
- ✅ Comprehensive supply chain security assessments
- ✅ Enhanced vulnerability management program
- ✅ Business continuity and disaster recovery testing
- ✅ Network segmentation and security monitoring
- ✅ Security metrics and effectiveness measurement
Priority 3 – Medium (Implement Third)
Timeline: Weeks 17-24
- ✅ Advanced cryptographic controls
- ✅ Enhanced security awareness program
- ✅ Privileged access management solution
- ✅ Automated compliance monitoring
- ✅ Third-party security audits
Using This Mapping Table
For Organizations Starting from Scratch:
- Use ISO 27001 as your compliance framework foundation
- Implement controls systematically following ISO structure
- Add NIS2-specific requirements as you build
- Pursue ISO 27001 certification (demonstrates compliance rigor)
For ISO 27001 Certified Organizations:
- Conduct gap analysis using this mapping
- Focus resources on 🔴 MAJOR GAP areas first
- Enhance ⚠️ MINOR GAP controls with NIS2 specifics
- Document ✅ ALIGNED controls for NIS2 audit evidence
- Leverage existing ISMS documentation
For Organizations Pursuing Dual Compliance:
- Build integrated compliance program
- Single set of policies covering both frameworks
- Unified audit and review processes
- Shared security metrics dashboard
- Combined training programs
Belgian Context Considerations
Centre for Cybersecurity Belgium (CCB) Expectations:
- Documented risk assessment aligned with sector-specific threats
- Demonstrated management accountability and oversight
- Operational incident response capability with proven reporting process
- Evidence of supply chain security program
- Regular testing and validation of security measures
Audit Preparation:
- Maintain comprehensive evidence repository
- Document all security decisions and risk acceptances
- Keep records of management reviews and training
- Track incident response activities and reporting
- Maintain supplier security assessments and contracts
Need Implementation Support?
TekGenX Consulting offers:
- ✅ NIS2 Gap Analysis using this mapping framework
- ✅ ISO 27001 implementation integrated with NIS2
- ✅ Dual compliance program development
- ✅ Incident response planning for 24/72-hour reporting
- ✅ Management training and accountability frameworks
Contact: [email protected] | www.tekgenx.com

