{"id":38567,"date":"2024-10-09T02:52:56","date_gmt":"2024-10-09T02:52:56","guid":{"rendered":"https:\/\/metachannelcorp.com\/nis2-iso-27001-parallelism-complementarity\/"},"modified":"2026-08-03T11:35:52","modified_gmt":"2026-08-03T11:35:52","slug":"nis2-iso-27001-parallelism-complementarity","status":"publish","type":"post","link":"https:\/\/metachannelcorp.com\/en\/perspectives\/nis2-iso-27001-parallelism-complementarity\/","title":{"rendered":"Parallelism and Complementarity between NIS2, ISO\/IEC 27001 and NIST CSF 2.0"},"content":{"rendered":"<p><span style=\"color: #000000;\"><strong><a href=\"https:\/\/ceadigilaw.org\/staff\/antonio-tejeda-encinas-2\/\" target=\"_blank\" rel=\"noopener\"><span style=\"color: #000000;\">Antonio Tejeda Encinas<\/span><\/a><\/strong> CEO META Channel corp. President of the Comit\u00e9 Euro Americano de Derecho Digital &#8211;<strong><a style=\"color: #000000;\" href=\"https:\/\/ceadigilaw.org\" target=\"_blank\" rel=\"noopener\">CEA Digital Law<\/a><\/strong>.<\/span><\/p>\n<p><span style=\"color: #000000;\"><br \/>\nLET&#8217;S NOT CONFUSE!<\/span><br \/>\n<span style=\"color: #000000;\"><br \/>\nParallelism and Complementarity between NIS2, ISO\/IEC 27001 and NIST CSF 2.0: A Comprehensive Framework for Cybersecurity in Europe\u00a0<\/span><\/p>\n<p><span style=\"color: #000000;\"><br \/>\nWith the growing importance of cybersecurity in Europe, it is essential to understand the differences and complementarities between these three frameworks:<\/span><\/p>\n<p><span style=\"color: #000000;\">\u00a0 <strong><br \/>\nNIS2 (European Network and Information Systems Security Directive)<\/strong><\/span><\/p>\n<p><span style=\"color: #000000;\"><br \/>\n&#8211; <strong>Nature:<\/strong> Legal and regulatory directive of the European Union.<\/span><\/p>\n<p><span style=\"color: #000000;\"><br \/>\n\u00a0&#8211; <strong>Aim:<\/strong> Guarantee a minimum level of cybersecurity in critical infrastructures and essential sectors (energy, health, transportation, etc.).<\/span><\/p>\n<p><span style=\"color: #000000;\">\u00a0<br \/>\n&#8211; <strong>Mandatory:<\/strong> Mandatory compliance for all member states and companies in critical sectors.<\/span><\/p>\n<p><span style=\"color: #000000;\"><br \/>\n&#8211; <strong>Coverage:<\/strong> Protecting the security of essential infrastructure and digital services.<\/span><\/p>\n<p><span style=\"color: #000000;\"><br \/>\n&#8211; <strong>Applicable:<\/strong> Starting in October 2024.<\/span><\/p>\n<p><span style=\"color: #000000;\"><strong><br \/>\nISO\/IEC 27001 (Information Security Management System)<\/strong><\/span><\/p>\n<p><span style=\"color: #000000;\">\u00a0<br \/>\n&#8211; <strong>Nature:<\/strong> VOLUNTARY international standard.<\/span><\/p>\n<p><span style=\"color: #000000;\"><br \/>\n&#8211; <strong>Aim:<\/strong> Create a security management system that guarantees the confidentiality, integrity and availability of information.<\/span><\/p>\n<p><span style=\"color: #000000;\"><br \/>\n&#8211;\u00a0 <strong>Mandatory:<\/strong> Voluntary, based on certification.<\/span><\/p>\n<p><span style=\"color: #000000;\"><br \/>\n&#8211; <strong>Coverage:<\/strong> Applicable to any type of organization that wants to structure its security based on its specific risks.<\/span><\/p>\n<p><span style=\"color: #000000;\"><br \/>\n&#8211; <strong>Applicable<\/strong>: Last update in October 2022.<\/span><\/p>\n<p><strong><span style=\"color: #000000;\"><br \/>\nNIST CSF 2.0 (National Institute of Standards and Technology Cybersecurity Framework)<\/span><\/strong><\/p>\n<p><span style=\"color: #000000;\"><br \/>\n&#8211; <strong>Nature:<\/strong> Cybersecurity management framework developed in the US.<\/span><\/p>\n<p><span style=\"color: #000000;\"><br \/>\n&#8211; <strong>Aim:<\/strong> Provide good practices to manage risks and improve the security posture in organizations.<\/span><\/p>\n<p><span style=\"color: #000000;\"><br \/>\n&#8211; <strong>Mandatory:<\/strong> Voluntary, adopted by many companies as a reference standard.<\/span><\/p>\n<p><span style=\"color: #000000;\"><strong><br \/>\n&#8211; Coverage:<\/strong> Adaptable approach for all types of organizations, from small businesses to large corporations.<\/span><\/p>\n<p><span style=\"color: #000000;\"><br \/>\n&#8211; <strong>Applicable<\/strong>: Draft version 2.0 presented in October 2024.<\/span><\/p>\n<p><span style=\"color: #000000;\"><strong><br \/>\nWhy is it important?<\/strong> \ud83d\udd0d\ud83d\udc47<\/span><br \/>\n<span style=\"color: #000000;\"><br \/>\nAlthough they all address cybersecurity, NIS2 establishes a mandatory legal framework to protect critical infrastructure in Europe. While ISO 27001 and NIST CSF 2.0 are voluntary guidelines that allow companies to structure their security according to their own risks and objectives.<\/span><\/p>\n<p><span style=\"color: #000000;\"><br \/>\n\ud83d\udca1 Together, these frameworks do not replace each other, but rather complement each other to build a comprehensive cybersecurity environment in the region.<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Antonio Tejeda Encinas CEO META Channel corp. President of the Comit\u00e9 Euro Americano de Derecho Digital &#8211;CEA Digital Law. LET&#8217;S&#8230;<\/p>\n","protected":false},"author":12,"featured_media":32803,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"wds_primary_category":0,"footnotes":""},"categories":[1838],"tags":[],"class_list":["post-38567","post","type-post","status-publish","format-standard","has-post-thumbnail","category-cybersecurity-and-digital-resilience"],"menu_order":0,"_links":{"self":[{"href":"https:\/\/metachannelcorp.com\/en\/wp-json\/wp\/v2\/posts\/38567","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/metachannelcorp.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/metachannelcorp.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/metachannelcorp.com\/en\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/metachannelcorp.com\/en\/wp-json\/wp\/v2\/comments?post=38567"}],"version-history":[{"count":1,"href":"https:\/\/metachannelcorp.com\/en\/wp-json\/wp\/v2\/posts\/38567\/revisions"}],"predecessor-version":[{"id":39020,"href":"https:\/\/metachannelcorp.com\/en\/wp-json\/wp\/v2\/posts\/38567\/revisions\/39020"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/metachannelcorp.com\/en\/wp-json\/wp\/v2\/media\/32803"}],"wp:attachment":[{"href":"https:\/\/metachannelcorp.com\/en\/wp-json\/wp\/v2\/media?parent=38567"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/metachannelcorp.com\/en\/wp-json\/wp\/v2\/categories?post=38567"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/metachannelcorp.com\/en\/wp-json\/wp\/v2\/tags?post=38567"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}