NIS2Art. 21(2)(e)voice-validated

NIS2 Art21e: Art. 21(2)(e)

Network and Information Security Directive 2 (EU 2022/2555)

AL
Adam Lundqvist
Founder at SQUR · last verified 2026-10-06

Regulation text

Essential and important entities must implement security in the acquisition, development, and maintenance of network and information systems, including vulnerability handling and disclosure. This covers secure development lifecycle, secure configuration management, change control, and vulnerability management throughout the system lifecycle.

ATT&CK techniques this article tests · 15

TechniqueWhy it mapsConfidence
T1190Adversaries exploit public-facing applications due to vulnerabilities arising from insecure development practices or inadequate vulnerability management, directly addressed by Art. 21(2)(e)'s focus on secure development lifecycle and vulnerability handling.
90%
T1078Valid Accounts are compromised when systems lack secure configuration management, including default credentials or weak access controls, a core component of Art. 21(2)(e).
85%
T1068Exploitation for Privilege Escalation frequently targets software vulnerabilities or misconfigurations, which secure development and configuration management, as mandated by Art. 21(2)(e), aim to prevent.
90%
T1053Scheduled Task/Job creation for persistence often exploits insecure system configurations or weak change control processes, both covered by Art. 21(2)(e).
80%
T1070.004File Deletion for defense evasion can be mitigated by robust change control and secure configuration management, ensuring proper logging and system integrity, as per Art. 21(2)(e).
75%
T1003OS Credential Dumping exploits system weaknesses, often stemming from insecure development or configuration, which Art. 21(2)(e) seeks to prevent through secure lifecycle management.
85%
T1087Account Discovery is facilitated by poor access control configurations or lack of secure development practices, which Art. 21(2)(e) addresses through secure configuration management.
70%
T1049System Network Connections Discovery can reveal network architecture weaknesses, which secure development and configuration management, as per Art. 21(2)(e), aim to minimize.
70%
T1021Remote Services are often exploited for lateral movement due to insecure configurations or unpatched vulnerabilities, directly targeted by Art. 21(2)(e)'s secure configuration and vulnerability management.
80%
T1041Exfiltration Over C2 Channel can be limited by secure development practices that enforce data segregation and minimize accessible sensitive information, aligning with Art. 21(2)(e).
70%
T1490Inhibit System Recovery techniques exploit weaknesses in backup and recovery configurations, which fall under the 'maintenance' and 'secure configuration management' aspects of Art. 21(2)(e).
80%
T1592Gather Victim Host Information during reconnaissance often identifies vulnerabilities or misconfigurations that Art. 21(2)(e)'s vulnerability management aims to address proactively.
75%
T1595.002Vulnerability Scanning by adversaries directly exploits the absence or ineffectiveness of an entity's vulnerability handling and disclosure processes, as mandated by Art. 21(2)(e).
80%
T1588.006Obtain Capabilities: Vulnerabilities indicates adversaries acquiring exploits for known weaknesses. Robust vulnerability management and secure development, as per Art. 21(2)(e), reduce the attack surface.
70%
T1059Command and Scripting Interpreter execution often leverages insecure system configurations or lack of proper controls, which secure configuration management under Art. 21(2)(e) aims to prevent.
75%

Defending mitigations · 6

MitigationWhat it doesConfidence
M1051Software Configuration directly implements 'secure configuration management' for network and information systems, as specified in Art. 21(2)(e).
95%
M1050Vulnerability Management directly addresses 'vulnerability handling and disclosure' and 'vulnerability management throughout the system lifecycle' as required by Art. 21(2)(e).
95%
M1038User Account Management contributes to secure configuration and access control, preventing unauthorized access and aligning with Art. 21(2)(e)'s secure system maintenance.
90%
M1030Network Segmentation is a key aspect of secure architecture and development, limiting the impact of breaches and supporting the 'secure development lifecycle' in Art. 21(2)(e).
85%
M1047Audit mechanisms support 'change control' and 'vulnerability management' by providing visibility into system modifications and potential security events, as per Art. 21(2)(e).
85%
M1026Privileged Account Management is a critical component of secure configuration and access control, directly supporting the secure maintenance of systems outlined in Art. 21(2)(e).
90%

Underlying weaknesses · 7

CWEWhy it persistsConfidence
CWE-20Improper Input Validation is a fundamental secure development lifecycle weakness, leading to numerous vulnerabilities that Art. 21(2)(e) aims to prevent.
90%
CWE-276Incorrect Default Permissions represent a failure in 'secure configuration management' and 'secure development lifecycle', directly addressed by Art. 21(2)(e).
90%
CWE-119Improper Restriction of Operations within the Bounds of a Memory Buffer is a common vulnerability arising from insecure development, which Art. 21(2)(e)'s secure development lifecycle aims to mitigate.
85%
CWE-787Out-of-bounds Write is a critical memory safety issue stemming from insecure development, directly targeted by the 'secure development lifecycle' requirement in Art. 21(2)(e).
85%
CWE-502Deserialization of Untrusted Data is a common application vulnerability resulting from insecure development practices, which Art. 21(2)(e) mandates addressing.
80%
CWE-79Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) is a pervasive web application vulnerability, preventable through secure development lifecycle practices as per Art. 21(2)(e).
80%
CWE-287Improper Authentication weaknesses undermine system security and are a direct result of failures in secure development and configuration management, as covered by Art. 21(2)(e).
85%

What SQUR Covers

Web application + API pentesting for OWASP Top 10, business logic flaws, authentication bypass, injection attacks, and other application-layer vulnerabilities. €1,995 per scan, 24-hour turnaround, EU-only data.

What SQUR Does Not Cover

Internal network pentesting, endpoint security testing, physical security assessments, social engineering, or ICT third-party concentration risk reviews. Engage a complementary provider for those scope items.

Provenance

Mapped Q2.2026 using gemini-2.5-flash · €0.0192 compute · voice-rubric self-validated · 1 hallucination(s) dropped at validation