4 ms·
NIS2: Europe’s Most Extensive Cybersecurity Directive to Date
- utsavchopra 4y agoThe NIS2 directive is the most comprehensive European cybersecurity directive yet.
- pjmlp 4y agoCurious if it also includes programming language requirements towards security processes.
- tirpen 4y agoIt does not. Other than mandating some details about cryptography and MFA, it's mostly about company processes, incident reporting, security training, risk assessments and such. And it only affects corporations and other entities in a few select sectors of critical importance to society.
- pjmlp 4y agoPity, it is not yet that we get labels in the box depending on how the sausage was produced.
- deafpiano 4y agoSo this isn't an official site from the EU, and is instead just a big add for a password management company https://uniqkey.eu/en_US/ https://uniqkey.eu/en_US/ As far as I can read in there as well the proposal hasn't been approved/ratified yet, so I don't know what fool is going to pay someone to prepare for a directive that isn't even official yet.
- skyeto 4y agoEspecially considering that OP posted a link to uniqkey a couple months ago on HN (not necessarily wrong, but considering that downloading the "whitepaper" also asks for a bunch of PI...)
- kramerger 4y agoNote that this page is operated by some Danish cybersecurity company. This is not the official EU page. The directive is here https://www.europarl.europa.eu/RegData/etudes/BRIE/2021/689333/EPRS_BRI(2021)689333_EN.pdf https://www.europarl.europa.eu/RegData/etudes/BRIE/2021/6893... The legal documents are here https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A52020PC0823&qid=1610720363291 https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A... For those of you already familiar with NIS, this update increases the scope to more industries (e.g. waste management) but also reduces the work needed in some cases.
- stehtisch123 4y agoThis practice of putting up official looking and sounding pages for things like this while just using it for marketing is borderline evil, another example would be this https://zanzibar.academy/ https://zanzibar.academy/
- eppp 4y agoFrom a sysadmin perspective, these things are so unbelievably frustrating. Just give me a list of things we need to do and we will do it. I don't want to hunt for the requirements and need a law degree to implement it. I looked for what we need to do and I can't find it.
- deleted 4y ago[deleted]
- hyperman1 4y agoIs there any practice-oriented list of actions to undertake? The article has some details, e.g the 10 minimum measures ( https://nis2directive.eu/nis2-requirements/ https://nis2directive.eu/nis2-requirements/ ) but I'm not too happy with them. On the good side, the main concrete thing I see in that list is MFA. But all the other things in there seem ways to keep some consultants busy writing vague documents, not real steps forward to a secure organizations.
- kramerger 4y agoNote that this for "critical sectors" of the society, E.g. water, food and medicine or running your country's Internet backbone. https://www.europarl.europa.eu/RegData/etudes/BRIE/2021/689333/EPRS_BRI(2021)689333_EN.pdf https://www.europarl.europa.eu/RegData/etudes/BRIE/2021/6893... Unlike GDPR, if you work on some random product or website this most likely does not apply to you.
- utsavchopra 4y agoThis is not the official site, but it has most of the information all together at one place. Also i the bottom you will find the big section where it disclaimer everything. So I don't see anything about fooling or fishy.