NIS2Art. 21(2)(i)voice-validated
NIS2 Art21i: Art. 21(2)(i)
Network and Information Security Directive 2 (EU 2022/2555)
AL
Founder at SQUR · last verified 2026-10-06
Regulation text
Essential and important entities must implement human resources security measures, access control policies, and asset management. This covers identity and access management, role-based access controls, principle of least privilege, secure onboarding and offboarding, asset inventory, and secure handling of corporate assets throughout their lifecycle.
ATT&CK techniques this article tests · 15
| Technique | Why it maps | Confidence |
|---|---|---|
| T1003 | 1. Weak identity and access management, as addressed by Art. 21(2)(i), enables adversaries to perform OS Credential Dumping. 2. Robust access control policies prevent unauthorized access to credential stores. | 90% |
| T1005 | 1. Inadequate access control policies and secure asset handling, as required by Art. 21(2)(i), allow unauthorized data collection from local systems. 2. Proper asset management restricts access to sensitive data. | 80% |
| T1015 | 1. Failures in access control policies and the principle of least privilege, mandated by Art. 21(2)(i), can allow adversaries to bypass User Account Control. 2. Strict privilege management limits such escalation. | 70% |
| T1016 | 1. A deficient asset inventory, contrary to Art. 21(2)(i), hinders the detection of unauthorized network configurations. 2. Comprehensive asset management provides visibility into system network settings. | 80% |
| T1018 | 1. Poor asset inventory and access control policies, as specified in Art. 21(2)(i), facilitate remote system discovery by adversaries. 2. Managed assets with enforced access controls limit network visibility for attackers. | 80% |
| T1021 | 1. Weak access control policies and identity and access management, as required by Art. 21(2)(i), enable adversaries to utilize remote services for lateral movement. 2. Role-based access controls restrict remote service access. | 90% |
| T1027 | 1. Inadequate asset management, as per Art. 21(2)(i), can allow obfuscated files or information to persist undetected on corporate assets. 2. Secure handling of assets includes monitoring for such evasion techniques. | 70% |
| T1033 | 1. Weak identity and access management, as per Art. 21(2)(i), allows adversaries to discover system owners and users. 2. Robust access controls and secure onboarding/offboarding limit this information exposure. | 80% |
| T1036 | 1. Deficiencies in identity and access management and secure onboarding/offboarding, as required by Art. 21(2)(i), can enable masquerading. 2. Strong HR security measures prevent unauthorized identity use. | 70% |
| T1037 | 1. Weak access control policies and insecure onboarding/offboarding, contrary to Art. 21(2)(i), allow adversaries to establish persistence via boot or logon autostart execution. 2. Strict asset configuration prevents unauthorized startup items. | 70% |
| T1039 | 1. Poor access control policies and secure handling of corporate assets, as specified in Art. 21(2)(i), facilitate data collection from network shared drives. 2. Principle of least privilege restricts access to shared resources. | 80% |
| T1040 | 1. Inadequate access control policies, as required by Art. 21(2)(i), can permit network sniffing. 2. Network segmentation and strict access rules limit an adversary's ability to monitor traffic. | 70% |
| T1041 | 1. Failures in secure handling of corporate assets and access control policies, as per Art. 21(2)(i), enable exfiltration over C2 channels. 2. Asset management includes monitoring for unauthorized data egress. | 80% |
| T1046 | 1. A deficient asset inventory and weak access control policies, contrary to Art. 21(2)(i), allow adversaries to discover network shares. 2. Comprehensive asset management and RBAC limit visibility of sensitive shares. | 80% |
| T1048 | 1. Poor access control policies and secure handling of corporate assets, as specified in Art. 21(2)(i), enable exfiltration over alternative protocols. 2. Asset management includes controlling network egress points. | 80% |
Defending mitigations · 7
| Mitigation | What it does | Confidence |
|---|---|---|
| M1030 | 1. User Account Management directly addresses identity and access management and secure onboarding/offboarding, as required by Art. 21(2)(i). 2. This mitigation ensures accounts are properly provisioned and deprovisioned. | 90% |
| M1026 | 1. Privileged Account Management enforces the principle of least privilege and robust access control policies, as mandated by Art. 21(2)(i). 2. This limits the impact of compromised high-privilege accounts. | 90% |
| M1040 | 1. Network Segmentation supports access control policies, as specified in Art. 21(2)(i), by limiting lateral movement and unauthorized access within the network. 2. This reduces the attack surface for corporate assets. | 80% |
| M1017 | 1. User Training is a core component of human resources security measures, as required by Art. 21(2)(i). 2. Educated personnel are less likely to fall victim to social engineering, protecting corporate assets. | 80% |
| M1039 | 1. Data Loss Prevention directly supports the secure handling of corporate assets throughout their lifecycle, as per Art. 21(2)(i). 2. This prevents unauthorized exfiltration of sensitive information. | 80% |
| M1047 | 1. Audit capabilities support asset management and access control policies, as required by Art. 21(2)(i), by monitoring for unauthorized activities. 2. This provides visibility into asset usage and access attempts. | 70% |
| M1028 | 1. Operating System Configuration contributes to the secure handling of corporate assets and access control policies, as per Art. 21(2)(i). 2. Secure configurations reduce vulnerabilities and enforce access restrictions. | 70% |
Underlying weaknesses · 7
| CWE | Why it persists | Confidence |
|---|---|---|
| CWE-284 | 1. Improper Access Control directly violates the requirement for robust access control policies in Art. 21(2)(i). 2. This weakness allows unauthorized actions on systems and data. | 90% |
| CWE-269 | 1. Improper Privilege Management undermines the principle of least privilege and role-based access controls, as mandated by Art. 21(2)(i). 2. This allows users or processes to gain excessive permissions. | 90% |
| CWE-287 | 1. Improper Authentication directly compromises identity and access management, as required by Art. 21(2)(i). 2. This weakness allows unauthorized users to gain access to systems or data. | 80% |
| CWE-200 | 1. Exposure of Sensitive Information to an Unauthorized Actor results from failures in secure handling of corporate assets and access control policies, as per Art. 21(2)(i). 2. This leads to data breaches and confidentiality loss. | 80% |
| CWE-732 | 1. Incorrect Permission Assignment for Critical Resource directly contradicts access control policies and the principle of least privilege, as specified in Art. 21(2)(i). 2. This allows unauthorized modification or access to critical assets. | 80% |
| CWE-220 | 1. Insufficient Management of Resources reflects a failure in asset management and asset inventory, as required by Art. 21(2)(i). 2. This leads to unmonitored or insecure corporate assets. | 70% |
| CWE-285 | 1. Improper Authorization directly impacts role-based access controls and the principle of least privilege, as mandated by Art. 21(2)(i). 2. This allows authenticated users to perform actions beyond their intended scope. | 80% |
What SQUR Covers
Web application + API pentesting for OWASP Top 10, business logic flaws, authentication bypass, injection attacks, and other application-layer vulnerabilities. €1,995 per scan, 24-hour turnaround, EU-only data.
What SQUR Does Not Cover
Internal network pentesting, endpoint security testing, physical security assessments, social engineering, or ICT third-party concentration risk reviews. Engage a complementary provider for those scope items.
Provenance
Mapped Q2.2026 using gemini-2.5-flash · €0.0204 compute · voice-rubric self-validated