Differences
This shows you the differences between two versions of the page.
| pub:trust_center:nis2_scope_determination [10.07.2026 10:59] – created Predrag Tasevski | pub:trust_center:nis2_scope_determination [15.07.2026 06:41] (current) – [5. Article 21(2) Minimum Measures — Voluntary Adoption & Gap Check] Predrag Tasevski | ||
|---|---|---|---|
| Line 55: | Line 55: | ||
| ^ # ^ Article 21(2) Measure ^ Status ^ Where evidenced ^ | ^ # ^ Article 21(2) Measure ^ Status ^ Where evidenced ^ | ||
| | a | Risk analysis & information system security policies | Covered | MVSP Business Controls; Unicis Cybersecurity Controls module | | | a | Risk analysis & information system security policies | Covered | MVSP Business Controls; Unicis Cybersecurity Controls module | | ||
| - | | b | Incident handling | Covered | IRIS incident | + | | b | Incident handling | Covered | Incident |
| | c | Business continuity, backup, disaster recovery, crisis management | Covered | Weekly encrypted backups, annual restore tests (MVSP Operational Controls) | | | c | Business continuity, backup, disaster recovery, crisis management | Covered | Weekly encrypted backups, annual restore tests (MVSP Operational Controls) | | ||
| | d | Supply chain security | Partial | Vendor Questionnaires + TPSRM cover outbound vendor risk; inbound (responding to customer NIS2 questionnaires) not yet formalised as a repeatable process | | | d | Supply chain security | Partial | Vendor Questionnaires + TPSRM cover outbound vendor risk; inbound (responding to customer NIS2 questionnaires) not yet formalised as a repeatable process | | ||