NIS2Art. 21(2)(f)voice-validated
NIS2 Art21f: Art. 21(2)(f)
Network and Information Security Directive 2 (EU 2022/2555)
AL
Founder at SQUR · last verified 2026-10-06
Regulation text
Essential and important entities must establish policies and procedures to assess the effectiveness of cybersecurity risk-management measures. This includes regular testing, auditing, and review of the security measures to ensure they remain effective against evolving threats.
ATT&CK techniques this article tests · 15
| Technique | Why it maps | Confidence |
|---|---|---|
| T1190 | 1. Ineffective security measures, not regularly tested as per NIS2 Art. 21(2)(f), allow attackers to exploit public-facing applications. 2. Regular testing identifies vulnerabilities before exploitation. | 90% |
| T1566 | 1. Ineffective security awareness training or email filtering, not reviewed under NIS2 Art. 21(2)(f), enables successful phishing. 2. Auditing and review ensure controls mitigate social engineering. | 85% |
| T1078 | 1. Compromised or misused valid accounts result from ineffective access controls, not regularly tested as per NIS2 Art. 21(2)(f). 2. Auditing user accounts and permissions prevents this. | 90% |
| T1547.001 | 1. Ineffective endpoint security or configuration management, not regularly reviewed under NIS2 Art. 21(2)(f), allows persistence via autostart execution. 2. Regular testing verifies system hardening. | 80% |
| T1068 | 1. Exploitation for privilege escalation occurs when vulnerability management and patching are ineffective, contrary to NIS2 Art. 21(2)(f). 2. Regular testing identifies and remediates such vulnerabilities. | 90% |
| T1055 | 1. Process injection succeeds due to ineffective endpoint protection or memory safeguards, not regularly reviewed under NIS2 Art. 21(2)(f). 2. Auditing and testing validate these protective measures. | 80% |
| T1027 | 1. Obfuscated files bypass detection when security measures are ineffective and not regularly tested, as required by NIS2 Art. 21(2)(f). 2. Testing ensures detection mechanisms are robust. | 85% |
| T1070.004 | 1. Indicator removal on host succeeds when logging and monitoring are ineffective, not regularly reviewed under NIS2 Art. 21(2)(f). 2. Auditing ensures forensic readiness and log integrity. | 80% |
| T1003 | 1. OS credential dumping occurs due to ineffective endpoint security or memory protection, not regularly tested as per NIS2 Art. 21(2)(f). 2. Regular security assessments verify credential protection. | 90% |
| T1087 | 1. Account discovery is facilitated by ineffective network segmentation or access controls, not regularly reviewed under NIS2 Art. 21(2)(f). 2. Auditing ensures proper account and network isolation. | 85% |
| T1046 | 1. Network share discovery indicates ineffective network monitoring or segmentation, not regularly tested as per NIS2 Art. 21(2)(f). 2. Regular reviews validate network access policies. | 80% |
| T1021.001 | 1. Remote Desktop Protocol misuse occurs when remote access controls are ineffective, not regularly managed and reviewed under NIS2 Art. 21(2)(f). 2. Auditing ensures secure remote access configurations. | 85% |
| T1005 | 1. Data from local systems is collected due to ineffective data loss prevention or endpoint monitoring, not regularly tested as per NIS2 Art. 21(2)(f). 2. Regular testing validates data protection controls. | 85% |
| T1071.001 | 1. Command and control via web protocols succeeds when network egress filtering and monitoring are ineffective, not regularly reviewed under NIS2 Art. 21(2)(f). 2. Auditing ensures robust network traffic controls. | 80% |
| T1041 | 1. Exfiltration over C2 channels occurs due to ineffective data exfiltration controls and monitoring, not regularly tested as per NIS2 Art. 21(2)(f). 2. Regular testing verifies data outflow prevention. | 85% |
Defending mitigations · 7
| Mitigation | What it does | Confidence |
|---|---|---|
| M1013 | 1. Application Developer Guidance ensures secure coding practices. 2. NIS2 Art. 21(2)(f) mandates regular review of such measures to reduce vulnerabilities found during testing. | 90% |
| M1015 | 1. Active Directory Configuration reduces attack surface for credential access. 2. NIS2 Art. 21(2)(f) requires auditing these configurations to verify their effectiveness against evolving threats. | 85% |
| M1017 | 1. User Account Management involves regular review of permissions. 2. This directly aligns with the NIS2 Art. 21(2)(f) requirement for regular review and auditing of security measures. | 90% |
| M1021 | 1. Audit directly corresponds to the 'auditing' requirement in NIS2 Art. 21(2)(f). 2. Audits assess the effectiveness of cybersecurity risk-management measures. | 100% |
| M1030 | 1. Network Segmentation limits lateral movement. 2. NIS2 Art. 21(2)(f) mandates regular testing of network segmentation effectiveness to ensure it remains robust. | 90% |
| M1035 | 1. Limiting Access to Resource Over Network is a core access control. 2. NIS2 Art. 21(2)(f) requires regular review and testing of these controls to prevent unauthorized access. | 85% |
| M1051 | 1. Software Configuration ensures secure system baselines. 2. NIS2 Art. 21(2)(f) mandates regular review and testing of these configurations to maintain security posture. | 85% |
Underlying weaknesses · 7
| CWE | Why it persists | Confidence |
|---|---|---|
| CWE-200 | 1. Exposure of Sensitive Information results from ineffective security measures. 2. NIS2 Art. 21(2)(f) requires regular testing and review to prevent such exposures. | 90% |
| CWE-287 | 1. Improper Authentication allows unauthorized access. 2. NIS2 Art. 21(2)(f) mandates regular auditing and testing of authentication mechanisms to ensure their effectiveness. | 85% |
| CWE-269 | 1. Improper Privilege Management leads to privilege escalation. 2. NIS2 Art. 21(2)(f) requires regular review of privilege controls to prevent this weakness. | 85% |
| CWE-798 | 1. Use of Hard-coded Credentials creates exploitable vulnerabilities. 2. NIS2 Art. 21(2)(f) requires regular testing and auditing to uncover and remediate such weaknesses. | 80% |
| CWE-732 | 1. Incorrect Permission Assignment for Critical Resource undermines access control. 2. NIS2 Art. 21(2)(f) mandates regular review and testing of permissions to ensure proper access. | 90% |
| CWE-22 | 1. Path Traversal vulnerabilities allow unauthorized file access. 2. NIS2 Art. 21(2)(f) requires regular testing of applications to identify and fix such flaws. | 80% |
| CWE-668 | 1. Exposure of Resource to Wrong Sphere indicates network segmentation or access control failures. 2. NIS2 Art. 21(2)(f) requires regular testing and review to prevent this exposure. | 85% |
What SQUR Covers
Web application + API pentesting for OWASP Top 10, business logic flaws, authentication bypass, injection attacks, and other application-layer vulnerabilities. €1,995 per scan, 24-hour turnaround, EU-only data.
What SQUR Does Not Cover
Internal network pentesting, endpoint security testing, physical security assessments, social engineering, or ICT third-party concentration risk reviews. Engage a complementary provider for those scope items.
Provenance
Mapped Q2.2026 using gemini-2.5-flash · €0.0200 compute · voice-rubric self-validated