NIS2Art. 21(2)(e)voice-validated
NIS2 Art21e: Art. 21(2)(e)
Network and Information Security Directive 2 (EU 2022/2555)
AL
Founder at SQUR · last verified 2026-10-06
Regulation text
Essential and important entities must implement security in the acquisition, development, and maintenance of network and information systems, including vulnerability handling and disclosure. This covers secure development lifecycle, secure configuration management, change control, and vulnerability management throughout the system lifecycle.
ATT&CK techniques this article tests · 15
| Technique | Why it maps | Confidence |
|---|---|---|
| T1190 | Adversaries exploit public-facing applications due to vulnerabilities arising from insecure development practices or inadequate vulnerability management, directly addressed by Art. 21(2)(e)'s focus on secure development lifecycle and vulnerability handling. | 90% |
| T1078 | Valid Accounts are compromised when systems lack secure configuration management, including default credentials or weak access controls, a core component of Art. 21(2)(e). | 85% |
| T1068 | Exploitation for Privilege Escalation frequently targets software vulnerabilities or misconfigurations, which secure development and configuration management, as mandated by Art. 21(2)(e), aim to prevent. | 90% |
| T1053 | Scheduled Task/Job creation for persistence often exploits insecure system configurations or weak change control processes, both covered by Art. 21(2)(e). | 80% |
| T1070.004 | File Deletion for defense evasion can be mitigated by robust change control and secure configuration management, ensuring proper logging and system integrity, as per Art. 21(2)(e). | 75% |
| T1003 | OS Credential Dumping exploits system weaknesses, often stemming from insecure development or configuration, which Art. 21(2)(e) seeks to prevent through secure lifecycle management. | 85% |
| T1087 | Account Discovery is facilitated by poor access control configurations or lack of secure development practices, which Art. 21(2)(e) addresses through secure configuration management. | 70% |
| T1049 | System Network Connections Discovery can reveal network architecture weaknesses, which secure development and configuration management, as per Art. 21(2)(e), aim to minimize. | 70% |
| T1021 | Remote Services are often exploited for lateral movement due to insecure configurations or unpatched vulnerabilities, directly targeted by Art. 21(2)(e)'s secure configuration and vulnerability management. | 80% |
| T1041 | Exfiltration Over C2 Channel can be limited by secure development practices that enforce data segregation and minimize accessible sensitive information, aligning with Art. 21(2)(e). | 70% |
| T1490 | Inhibit System Recovery techniques exploit weaknesses in backup and recovery configurations, which fall under the 'maintenance' and 'secure configuration management' aspects of Art. 21(2)(e). | 80% |
| T1592 | Gather Victim Host Information during reconnaissance often identifies vulnerabilities or misconfigurations that Art. 21(2)(e)'s vulnerability management aims to address proactively. | 75% |
| T1595.002 | Vulnerability Scanning by adversaries directly exploits the absence or ineffectiveness of an entity's vulnerability handling and disclosure processes, as mandated by Art. 21(2)(e). | 80% |
| T1588.006 | Obtain Capabilities: Vulnerabilities indicates adversaries acquiring exploits for known weaknesses. Robust vulnerability management and secure development, as per Art. 21(2)(e), reduce the attack surface. | 70% |
| T1059 | Command and Scripting Interpreter execution often leverages insecure system configurations or lack of proper controls, which secure configuration management under Art. 21(2)(e) aims to prevent. | 75% |
Defending mitigations · 6
| Mitigation | What it does | Confidence |
|---|---|---|
| M1051 | Software Configuration directly implements 'secure configuration management' for network and information systems, as specified in Art. 21(2)(e). | 95% |
| M1050 | Vulnerability Management directly addresses 'vulnerability handling and disclosure' and 'vulnerability management throughout the system lifecycle' as required by Art. 21(2)(e). | 95% |
| M1038 | User Account Management contributes to secure configuration and access control, preventing unauthorized access and aligning with Art. 21(2)(e)'s secure system maintenance. | 90% |
| M1030 | Network Segmentation is a key aspect of secure architecture and development, limiting the impact of breaches and supporting the 'secure development lifecycle' in Art. 21(2)(e). | 85% |
| M1047 | Audit mechanisms support 'change control' and 'vulnerability management' by providing visibility into system modifications and potential security events, as per Art. 21(2)(e). | 85% |
| M1026 | Privileged Account Management is a critical component of secure configuration and access control, directly supporting the secure maintenance of systems outlined in Art. 21(2)(e). | 90% |
Underlying weaknesses · 7
| CWE | Why it persists | Confidence |
|---|---|---|
| CWE-20 | Improper Input Validation is a fundamental secure development lifecycle weakness, leading to numerous vulnerabilities that Art. 21(2)(e) aims to prevent. | 90% |
| CWE-276 | Incorrect Default Permissions represent a failure in 'secure configuration management' and 'secure development lifecycle', directly addressed by Art. 21(2)(e). | 90% |
| CWE-119 | Improper Restriction of Operations within the Bounds of a Memory Buffer is a common vulnerability arising from insecure development, which Art. 21(2)(e)'s secure development lifecycle aims to mitigate. | 85% |
| CWE-787 | Out-of-bounds Write is a critical memory safety issue stemming from insecure development, directly targeted by the 'secure development lifecycle' requirement in Art. 21(2)(e). | 85% |
| CWE-502 | Deserialization of Untrusted Data is a common application vulnerability resulting from insecure development practices, which Art. 21(2)(e) mandates addressing. | 80% |
| CWE-79 | Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) is a pervasive web application vulnerability, preventable through secure development lifecycle practices as per Art. 21(2)(e). | 80% |
| CWE-287 | Improper Authentication weaknesses undermine system security and are a direct result of failures in secure development and configuration management, as covered by Art. 21(2)(e). | 85% |
What SQUR Covers
Web application + API pentesting for OWASP Top 10, business logic flaws, authentication bypass, injection attacks, and other application-layer vulnerabilities. €1,995 per scan, 24-hour turnaround, EU-only data.
What SQUR Does Not Cover
Internal network pentesting, endpoint security testing, physical security assessments, social engineering, or ICT third-party concentration risk reviews. Engage a complementary provider for those scope items.
Provenance
Mapped Q2.2026 using gemini-2.5-flash · €0.0192 compute · voice-rubric self-validated · 1 hallucination(s) dropped at validation