Framework overlap

Does NIS2 Directive cover ISO 27043?

You hold NIS2 Directive and have been told to do ISO 27043. Here is how much overlaps, control by control.

35% of ISO 27043 you already have

NIS2 Directive already covers about 35% of ISO 27043, leaving 34 of 52 controls as genuinely new work.

Already covered 7 Likely covered 11 New work 34

What is genuinely new work

Nothing in NIS2 Directive reaches these. This is the list to scope.

ISO27043-01
Information security policy framework
ISO27043-02
Management direction and commitment
ISO27043-03
Policy review and update procedures
ISO27043-05
Contact with authorities and special interest groups
ISO27043-07
Acceptable use of assets
ISO27043-09
Asset handling procedures
ISO27043-10.1
Storage and Retention of Evidence
ISO27043-10.2
Evidence Disposal
ISO27043-11.1
Investigator Competence and Training
ISO27043-11.2
Tool Validation
ISO27043-11.3
Quality Assurance for Investigations
ISO27043-12.1
Continuous Improvement of Investigation Process
ISO27043-16
Cryptographic policy and key management
ISO27043-21
Operational procedures and responsibilities
ISO27043-26
Audit considerations
ISO27043-28
Network service security
ISO27043-29
Segregation in networks
ISO27043-30
Information transfer policies
ISO27043-31
Secure messaging
ISO27043-5.1
Forensic Readiness Policy
ISO27043-5.2
Roles and Responsibilities for Investigations
ISO27043-5.3
Forensic Capability Assessment
ISO27043-6.1
Pre-incident Readiness Processes
ISO27043-6.2
Identification of Potential Digital Evidence
ISO27043-7.1
Incident Detection Trigger
ISO27043-7.2
First Response Procedures
ISO27043-8.1
Planning the Investigation
ISO27043-8.2
Evidence Identification and Collection
ISO27043-8.3
Chain of Custody
ISO27043-8.4
Evidence Preservation
ISO27043-8.5
Evidence Analysis
ISO27043-8.6
Investigation Documentation
ISO27043-9.1
Presentation of Findings
ISO27043-9.2
Closure of Investigation
Show the 18 you already have
ISO27043-08
Information classification and labeling
ISO27043-11
Access control policy and enforcement
ISO27043-14
Privileged access management
ISO27043-15
Access review and recertification
ISO27043-22
Protection from malware
ISO27043-23
Backup and recovery procedures
ISO27043-27
Network security management
ISO27043-04
Roles and responsibilities definition
ISO27043-06
Asset inventory and ownership
ISO27043-10
Media management and disposal
ISO27043-12
User access management and provisioning
ISO27043-13
Authentication and password management
ISO27043-17
Encryption of data at rest
ISO27043-18
Encryption of data in transit
ISO27043-19
Certificate management
ISO27043-20
Key lifecycle management
ISO27043-24
Logging and monitoring
ISO27043-25
Technical vulnerability management

How this is calculated

Already covered means a mapping runs from a control in NIS2 Directive to that control. Likely covered means no direct mapping exists but both frameworks map to the same control in a third standard. New work means neither. We keep those separate rather than adding them into one friendlier number, because blending them would present a two-hop inference as a verified fact.

Coverage is not symmetric. Run it the other way and you will get a different number; both are correct.

From 332,959 cross-framework control mappings across 723 frameworks, 531 of them verified against their source documents. It does not tell you that you are compliant: a mapped control means the two standards ask for the same thing, not that you have done it.

Try another pair ยท Today's edition