Skip to content

Commit

Permalink
Fix menu layout and add NIS2 overview page (#723)
Browse files Browse the repository at this point in the history
* Adds links to Elastisys' four service offerings

* Adds NIS2 overview page

* More descriptive text in navigation
  • Loading branch information
llarsson authored Oct 30, 2023
1 parent 410913f commit 9036602
Show file tree
Hide file tree
Showing 2 changed files with 57 additions and 2 deletions.
52 changes: 52 additions & 0 deletions docs/ciso-guide/nis2.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,52 @@
---
title: NIS2 Overview
description: Overview of what the Network and Information Security Directive 2 (NIS2) is and how it relates to Compliant Kubernetes
---

# Network and Information Security Directive 2 (NIS2)

{%
include-markdown './controls/_common.include'
start='<!--legal-disclaimer-start-->'
end='<!--legal-disclaimer-end-->'
%}

The [NIS2 Directive](https://digital-strategy.ec.europa.eu/en/policies/nis2-directive){:target="_blank"} stands as a comprehensive EU-wide cybersecurity legislation, aimed at elevating the overall state of cybersecurity across the European Union.
Imposing legal measures, it serves to fortify the digital landscape in the region.

Initiated in 2016, the EU's cybersecurity regulations underwent a substantial transformation with the enactment of the NIS2 Directive in 2023.
This update was imperative to adapt to the expanding realm of digitization and the continuously evolving cybersecurity threats.
The directive's enhancements extend the applicability of cybersecurity regulations to novel sectors and entities, thereby enhancing the resilience and response capabilities of public and private bodies, competent authorities, and the entire EU.

The NIS2 Directive, officially titled the Directive on measures for a high common level of cybersecurity across the Union, imposes legal requisites to augment cybersecurity throughout the EU.
Its key provisions encompass ensuring the preparedness of Member States, mandating the establishment of essential capabilities like a Computer Security Incident Response Team (CSIRT) and a competent national network and information systems (NIS) authority.
Furthermore, it promotes cooperation among Member States through the establishment of a Cooperation Group, fostering strategic collaboration and information exchange.

The directive seeks to instill a culture of security across critical sectors vital for the economy and society, heavily reliant on information and communication technologies (ICTs).
These sectors include energy, transport, water, banking, financial market infrastructures, healthcare, and digital infrastructure.

To uphold the directive's objectives, businesses identified by Member States as operators of essential services in the specified sectors must implement suitable security measures and promptly report significant incidents to relevant national authorities.
Similarly, key digital service providers, such as search engines, cloud computing services, and online marketplaces, are obligated to adhere to the security and notification requirements outlined in the directive.

## Which sectors are covered by the NIS2 Directive?

A lot more sectors than in the previous iteration.
Society has become more digital, and as a result, more vulnerable to cyberattacks.
It is clear that many use-cases where Compliant Kubernetes has been successfully used in the past are in scope for NIS2, including sectors of high criticality, healthcare, banking and the financial market, and general public administration.

The [official FAQ](https://digital-strategy.ec.europa.eu/en/faqs/directive-measures-high-common-level-cybersecurity-across-union-nis2-directive-faqs){:target="_blank"} lists the sectors in scope as follows:

> Sectors of high criticality: energy (electricity, district heating and cooling, oil, gas and hydrogen); transport (air, rail, water and road); banking; financial market infrastructures; health including manufacture of pharmaceutical products including vaccines; drinking water; waste water; digital infrastructure (internet exchange points; DNS service providers; TLD name registries; cloud computing service providers; data centre service providers; content delivery networks; trust service providers; providers of public electronic communications networks and publicly available electronic communications services); ICT service management (managed service providers and managed security service providers), public administration and space.
>
> Other critical sectors: postal and courier services; waste management; chemicals; food; manufacturing of medical devices, computers and electronics, machinery and equipment, motor vehicles, trailers and semi-trailers and other transport equipment; digital providers (online market places, online search engines, and social networking service platforms) and research organisations.
## How does the NIS2 Directive relate to Compliant Kubernetes?

The NIS2 Directive shares a strong connection with two additional initiatives: the Critical Entities Resilience (CER) Directive and the Regulation for Digital Operational Resilience in the Financial Sector, commonly known as the Digital Operational Resilience Act (DORA).

The directives and regulations affect how Compliant Kubernetes is composed on an architectural level and configured for specific use-cases, depending on industry needs.
Please see the following pages, also linked in the side bar, for specific implementations made to meet these demands:

- [KRITIS](controls/kritis.md) (Germany)
- [BSI IT Grundschutz](controls/bsi-it-grundschutz.md) (Germany)
- [MSBFS 2018:8](controls/msbfs-20188.md) (Sweden)
7 changes: 5 additions & 2 deletions mkdocs.yml
Original file line number Diff line number Diff line change
Expand Up @@ -200,6 +200,7 @@ nav:
- 'Public sector':
- 'MSBFS 2020:7 (SE)': 'ciso-guide/controls/msbfs-20207.md'
- 'NIS2':
- 'Overview': 'ciso-guide/nis2.md'
- 'KRITIS (DE)': 'ciso-guide/controls/kritis.md'
- 'BSI IT-Grundschutz (DE)': 'ciso-guide/controls/bsi-it-grundschutz.md'
- 'MSBFS 2018:8 (SE)': 'ciso-guide/controls/msbfs-20188.md'
Expand Down Expand Up @@ -230,7 +231,9 @@ nav:
- 'CK8S Argo CD': 'release-notes/argocd.md'
- 'Glossary': 'glossary.md'
- 'Roadmap': 'roadmap.md'
- 'Support': 'https://elastisys.com/'
- 'Training': 'https://elastisys.com/training/'
- 'Fully Managed Compliant Kubernetes': 'https://elastisys.com/managed-services/'
- 'Support for Self-Managed Compliant Kubernetes': 'https://elastisys.com/self-managed/'
- 'Consulting': 'https://elastisys.com/consulting/'
- 'Official Training': 'https://elastisys.com/training/'
- 'Blog': 'https://elastisys.com/blog/'
- 'Privacy Policy': 'https://elastisys.com/legal/privacy-policy/'

0 comments on commit 9036602

Please sign in to comment.