Fragment
3.4.1 Relevant considerations and legal articles on risk-based approach from NIS2
The word 'risk' appears 146 times in NIS2 in both the considerations and the articles, with a total of twelve considerations and articles from NIS2 being the most relevant for this graduation research. In these twelve considerations and articles, 'risk' is related to a risk-based approach. In other considerations and articles from NIS2, 'risk' is, for example, related to the Cyber Security Incident Response Team (CSIRT) or the emphasis is placed on the measures (which arise from the risk-based approach). Art. 6(9) NIS2 defines the concept of 'risk' as 'the possibility of loss or disruption as a result of an incident, which is expressed as a combination of the magnitude of such loss or disruption and the likelihood of the incident occurring .' When determining an applicable risk-based approach, relevant considerations and legal articles from NIS2 must be analyzed. The twelve relevant considerations and articles from NIS2 are described in order below.
Firstly, show interdependencies, ex. ov. 37 NIS2, indicates that the EU is a dependent society. An incident at one entity can affect other entities in a Member State or abroad. Such a society is vulnerable to low-probability risks (such as Covid-19 pandemic or other major disaster or crisis). Because the purpose of NIS2 is to increase cyber resilience within the EU, it is necessary to also add these low-probability risks (and major economic and social consequences, ex. rec. 82 NIS2) to the risk-based approach.
gen.
×