SkarpSkarp

Chapter 1 of 5

Regulatory Foundations and the Cybersecurity Control Rationale

Why does this directly applicable EU Regulation combine legal thresholds with a detailed security-control framework? The opening chapter situates Commission Implementing Regulation (EU) 2024/2690, identifies its covered entities and follows the recitals from proportionality and standards through governance, technical safeguards, personnel and physical resilience.

27 min readen

1. The Regulation's Purpose, Scope, and Standards Basis

Purpose and covered entities

Recital (1) identifies the covered sectors and calls them the relevant entities. The Regulation links them to technical and methodological measures under Article 21(2) of Directive (EU) 2022/2555.

A dual function

The Regulation addresses cybersecurity risk-management measures and further specifies when incidents should be considered significant. For trust service providers, Recital (2) uses shall for the additional incident-significance specification.

Why standards matter

Recital (3) says the Annex requirements are based on ISO/IEC 27001, ISO/IEC 27002, ETSI EN 319401, and CEN/TS 18026:2024. Standards provide a recognised basis for detailed controls.

2. Proportionality, Feasibility, and Documented Reasoning

The proportionality factors

Recital (4) calls for account to be taken of criticality, exposure to risk, size and structure, incident likelihood and severity, and societal and economic impact. Size alone does not determine the outcome.

Compensating measures

Where an entity cannot implement some requirements due to its size, Recital (5) says it should be able to use suitable compensating measures. Management oversight or increased monitoring and logging may address limited segregation of duties.

Explain qualified non-application

Requirements may apply where appropriate, applicable, or feasible. If an entity considers one of these qualifications unmet, Recital (6) says it should document its reasoning in a comprehensible manner.

Knowledge Check: Proportionality

Choose the statement that most closely reflects Recitals (4) to (6).

A micro-sized relevant entity cannot fully segregate conflicting cybersecurity duties. According to the recitals, what is the best response?

  1. Ignore the control objective because small entities are exempt.
  2. Consider suitable compensating measures, such as targeted management oversight or increased monitoring and logging.
  3. Apply every requirement identically, regardless of whether it is appropriate, applicable, or feasible.
  4. Wait for a national competent authority to design all controls.
Show Answer

Answer: B) Consider suitable compensating measures, such as targeted management oversight or increased monitoring and logging.

Recital (5) says entities that cannot implement some requirements due to size should be able to take compensating measures suitable to achieve the purpose of those requirements. Recital (6) also requires comprehensible documentation where a qualified requirement is considered not appropriate, not applicable, or not feasible.

3. Guidance Supports Compliance, but Does Not Replace It

Guidance can help

Recital (7) says ENISA and national competent authorities can support risk identification, analysis, assessment, framework development, and risk treatment through guidance, assessments, tools, or templates.

But guidance does not displace obligations

Guidance is without prejudice to the entity's obligation to identify and document risks and to implement Annex requirements according to its needs and resources.

Network-security challenges

Recital (8) identifies challenges involving modern network protocols, interoperable email standards, DNS security, routing security, and routing hygiene. A multistakeholder forum should help identify best practices.

4. Governance: Policies, Users, and Risk Treatment

Highest-level policy

The network-and-information-systems security policy should set the overall approach and be approved by the management body. Topic-specific policies, including access-control policies, should be coherent with it.

Users are broadly defined

For the Annex requirements, a user should encompass every legal or natural person with access to the entity's network and information systems. The term is not limited to employees.

From assessment to treatment

A risk treatment plan should be established, implemented, and monitored. Options include avoiding, reducing, or, in exceptional cases, accepting risk; the choice should follow assessment results and the security policy.

5. Detect, Recover, Test, Patch, and Manage Suppliers

Monitor and evaluate

Relevant entities should monitor systems and evaluate events, near misses, and incidents. Detection should be capable of identifying anomalous traffic patterns and denial-of-service attacks in a timely manner.

Test controls, not assumptions

Security tests should be regular and governed by dedicated policy and procedures. They may range from penetration tests and vulnerability scans to configuration tests and security audits.

Resilience includes patching and suppliers

Patch procedures should align with change, vulnerability, and risk management. Supply-chain policies should govern direct suppliers and service providers, including adequate contractual security clauses.

6. Network Defences and Basic Cyber Hygiene

Reduce exposure by design

Typical network-security solutions include firewalls, restricted connections, VPNs for remote access, and time-limited service-provider access after authorisation. The focus is preventing unnecessary access paths.

Control software risk

Entities should prevent or detect unauthorised software and, where appropriate, use detection-and-response software. They should consider attack-surface reduction, endpoint execution control, and content filtering.

Cyber hygiene is broad

Basic cyber hygiene can include zero trust, updates, configuration, segmentation, identity and access management, and awareness. Training and anti-phishing practices connect user behaviour to technical resilience.

7. Worked Example: Access, Personnel, and Multi-Factor Authentication

Access policy in practice

A topic-specific access policy should address access by persons and by systems such as applications. In practice, remote engineers, privileged administrators, contractors, and applications can require different access conditions.

Personnel accountability

Entities should consider employee security measures and awareness. They should establish, communicate, and maintain a disciplinary process for violations of network-and-information-system security policies.

When to consider MFA

MFA should be considered in particular for remote access, sensitive information, privileged accounts, and system-administration accounts. Extra factors may respond to unusual location, device, or time patterns.

8. Assets, Accountability, and the All-Hazards Approach

Know and classify assets

Entities should manage tangible and intangible assets, create an inventory, assign classification levels, track assets, and protect them throughout their lifecycle. Asset management supports both risk analysis and continuity.

Assign accountable owners

A comprehensive inventory could record identifiers, owners, location, information classification, patch date, risk classification, and end of life. Asset ownership should identify who is responsible for protection.

All hazards means more than cyberattacks

The all-hazards approach covers threats to systems and their physical environment, including fire, flood, theft, power failures, human error, malicious acts, and natural phenomena.

Flashcards: Core Regulatory Logic

Flip each card, then explain the connection between the term and the Regulation's control rationale.

Relevant entities
The covered DNS, TLD registry, cloud, data-centre, CDN, managed-service, managed-security-service, online platform, search-engine, social-networking-platform, and trust-service entities identified in Recital (1).
Proportionality
Recital (4) says account should be taken of criticality, risk exposure, size and structure, and incident likelihood, severity, and societal and economic impact.
Compensating measures
Where requirements cannot be implemented due to size, Recital (5) says entities should be able to use suitable alternatives that achieve the purpose of the requirements.
Risk treatment plan
A plan that entities should establish, implement, and monitor as part of their risk management framework; it may identify and prioritise treatment options and measures.
Asset inventory
A record of tangible and intangible assets that supports classification, tracking, lifecycle protection, risk analysis, and business continuity.
All-hazards approach
An approach protecting network and information systems and their physical environment from cyber, physical, environmental, utility, human, and natural threats.

Knowledge Check: Risk Treatment and Assets

Test whether you can distinguish the Regulation's stated treatment options from its asset-management expectations.

Which option is described in Recital (11) as a risk treatment option only "in exceptional cases"?

  1. Avoiding the risk
  2. Reducing the risk
  3. Accepting the risk
  4. Documenting the asset inventory
Show Answer

Answer: C) Accepting the risk

Recital (11) says options include avoiding, reducing, or, in exceptional cases, accepting the risk. It also says the choice should take account of the entity's risk assessment and comply with its network-and-information-systems security policy.

9. Thought Exercise: Build a Control Rationale

Your task

A data centre service provider has a small security team, remote administrators, third-party maintenance suppliers, servers nearing end of life, and a facility in an area exposed to flooding.

Write a short control rationale using the recitals covered in this module. Include:

  1. One proportionality decision under Recitals (4) to (6), including what must be documented if a qualified requirement is not applied.
  2. One governance measure under Recitals (9) to (11), including the management body's role in the highest-level security policy.
  3. One access or personnel measure under Recitals (21) to (23), explaining why remote privileged access makes MFA relevant.
  4. One asset-management measure under Recitals (24) to (26), including ownership, classification, and lifecycle information.
  5. One physical-resilience measure under Recitals (28) and (29), such as early flood detection, environmental monitoring, fire protection, or emergency power.

Check your wording carefully: where a recital says should, retain should. Where it says may, do not describe the action as mandatory.

Which recital most directly supports installing early flooding detection in areas where network and information systems are located?

  1. Recital (11)
  2. Recital (18)
  3. Recital (29)
  4. Recital (10)
Show Answer

Answer: C) Recital (29)

Recital (29) gives early flood-detection systems as an example of physical and environmental protection measures that relevant entities should consider.

Final Check: Reading Mandatory and Non-Mandatory Language Precisely

The Regulation's recitals use carefully qualified language. Select the answer that preserves it accurately.

Which statement is the most accurate reading of the recitals on security testing, patching, and physical resilience?

  1. Relevant entities should regularly carry out security tests based on dedicated policy and procedures; they should set out and apply appropriate patch-management procedures; and they should design and implement protection measures against physical and environmental threats.
  2. Relevant entities may conduct all security testing only after a breach, and physical protection is optional because cybersecurity concerns software only.
  3. Relevant entities must use penetration testing as their only security-test method and must notify all customers before every patch.
  4. Relevant entities should accept every identified risk if a patch might cause planned service inaccessibility.
Show Answer

Answer: A) Relevant entities should regularly carry out security tests based on dedicated policy and procedures; they should set out and apply appropriate patch-management procedures; and they should design and implement protection measures against physical and environmental threats.

Recital (15) says entities should regularly carry out security tests based on dedicated policy and procedures, while listing several tests that may be used. Recital (16) says entities should set out and apply appropriate patch-management procedures, and they are encouraged to inform customers in advance where planned patching causes service inaccessibility. Recitals (28) and (29) address physical and environmental security.

Key Terms

user
For the technical and methodological requirements, all legal and natural persons with access to the entity's network and information systems.
asset inventory
An inventory of tangible and intangible assets that supports classification, handling, tracking, lifecycle protection, risk analysis, and business continuity.
relevant entities
The covered categories listed in Recital (1), including DNS service providers, TLD name registries, cloud computing service providers, data centre service providers, content delivery network providers, managed service providers, managed security service providers, specified online platforms, and trust service providers.
risk treatment plan
A plan that should be established, implemented, and monitored as part of the risk management framework to identify and prioritise risk treatment options and measures.
all-hazards approach
An approach that protects network and information systems and their physical environment from cyber, physical, environmental, utility, human, and natural threats.
compensating measures
Alternative measures that relevant entities should be able to take where they cannot implement some requirements due to size, provided the alternatives are suitable to achieve the requirements' purpose.
business impact analysis
An analysis that entities are encouraged to make comprehensive, establishing as appropriate maximum tolerable downtime, recovery time objectives, recovery point objectives, and service delivery objectives.
risk management framework
The appropriate framework that relevant entities should establish and maintain to identify, assess, document, and address risks to network and information systems.
multi-factor authentication
Authentication using more than one factor; it should be considered in particular for remote access, sensitive information, privileged accounts, and system-administration accounts.

Finished reading?

Test your understanding with a custom practice exam on this chapter.

Test yourself