The sources focus primarily on cybersecurity and do not provide explicit details regarding physical security requirements for network and information systems.
However, they offer some insights that indirectly concern physical security:
The importance of a multi-risk approach
- Consider the physical environment: The NIS2 Directive promotes a multi-risk approach to cybersecurity, which takes into account risks that go beyond digital threats. This approach highlights the importance of physical security:
- Article 21, paragraph 2: Defines the measures for cyber risk management.
- Commission Communication: Specifies that these measures “must protect not only the entity’s networks and information systems, but also the physical environment of such systems from events such as sabotage, theft, fire, flood, telecommunication or power failures, or any unauthorized physical access that could compromise the availability, authenticity, integrity, or confidentiality of data stored, transmitted, or processed, or of the services offered by or accessible via the networks and information systems.”
Specific requirements and considerations
- Secure locations for CSIRTs: The Directive requires that Computer Security Incident Response Teams (CSIRTs) be located in secure facilities:
- Article 11, paragraph 1(b): Establishes that “the premises and information systems supporting the CSIRTs shall be located in secure sites.” This suggests that physical security is fundamental to ensuring cybersecurity. To learn more about the obligations related to CSIRTs, see also the obligation to designate a CSIRT contact person for NIS entities.
- Data center security: Although it does not directly address physical security, the inclusion of data center providers among essential or important entities implies the need to adopt robust security measures, which likely also include physical safeguards.
- General principles of confidentiality and risk management: The sources emphasize the importance of protecting the confidentiality of information and adopting a risk-based approach to security. These principles also extend to physical security, implying the need to protect physical assets and facilities that, if compromised, could compromise information systems or data.
Inferences and best practices
Although not expressly required, organizations subject to the NIS2 Directive should consider implementing physical security measures in line with the broader principles of the Directive. Those evaluating their level of compliance may find the NIS2 compliance path offered by ISGroup useful, which also includes the verification of physical environment protection measures. Examples of such measures include:
- Facility access control: Implement access control systems to restrict physical entry into sensitive areas where network equipment or data are present.
- Environmental controls: Protect against environmental threats, such as fire, flood, and power outages, through measures such as fire suppression systems, raised flooring in data centers, and backup power generators.
- Physical security personnel: Employ security personnel to deter unauthorized access, monitor surveillance systems, and respond to security incidents.
- Secure disposal of ICT assets: Implement procedures to ensure the secure disposal or destruction of ICT equipment, avoiding the potential exposure of sensitive data.
Important note: It is essential to remember that these inferences and examples are based on the interpretation of the principles and general requirements of the NIS2 Directive. Organizations should conduct their own risk assessments and consult with cybersecurity experts to determine the most appropriate physical security measures based on their specific needs. The official text of the NIS2 Directive remains the primary regulatory reference for any verification.
Protect your organisation with NIS2 compliance.
Choose ISGroup for a practical, tailored engagement:
- A focused assessment of your environment and requirements
- Clear findings with a prioritised, actionable roadmap
- Direct support from experienced specialists through remediation and implementation
