{"id":118368,"date":"2024-10-09T04:59:34","date_gmt":"2024-10-09T02:59:34","guid":{"rendered":"https:\/\/ceadigilaw.org\/paralelismo-y-complementariedad-entre-nis2-iso-iec-27001-y-nist-csf-2-0\/"},"modified":"2026-07-17T21:34:23","modified_gmt":"2026-07-17T19:34:23","slug":"paralelismo-y-complementariedad-entre-nis2-iso-iec-27001-y-nist-csf-2-0","status":"publish","type":"post","link":"https:\/\/ceadigilaw.org\/en\/blog\/paralelismo-y-complementariedad-entre-nis2-iso-iec-27001-y-nist-csf-2-0\/","title":{"rendered":"Parallelism and Complementarity between NIS2, ISO\/IEC 27001 and NIST CSF 2.0"},"content":{"rendered":"<p><span style=\"color: #000000\"><strong><a style=\"color: #000000\" href=\"\/staff\/antonio-tejeda-encinas-2\/\" target=\"_blank\" rel=\"noopener\">Antonio Tejeda Encinas<\/a><\/strong>\u00a0CEO META Channel corp. President of the Euro-American Committee on Digital Law \u2013<strong><a style=\"color: #000000\" href=\"\/en\/\" target=\"_blank\" rel=\"noopener\">EA Digital Law<\/a><\/strong>.<\/span><\/p>\n<p><span style=\"color: #000000\">Let&#8217;s not trust!<\/span><\/p>\n<p><span style=\"color: #000000\">Parallelism and Complementarity between NIS2, ISO\/IEC 27001 and NIST CSF 2.0: A Comprehensive Framework for Cybersecurity in Europe\u00a0<\/span><\/p>\n<p><span style=\"color: #000000\">With the growing importance of cybersecurity in Europe, it is essential to understand the differences and complementarities between these three frameworks:<\/span><\/p>\n<p><span style=\"color: #000000\">\u00a0<strong><br \/>\nNIS2 (European Network and Information Systems Security Directive)<\/strong><\/span><\/p>\n<p><span style=\"color: #000000\">\u2013\u00a0<strong>Nature:<\/strong>\u00a0European Union legal and regulatory directive.<\/span><\/p>\n<p><span style=\"color: #000000\">\u00a0\u2013\u00a0<strong>Objective:<\/strong>\u00a0Ensure a minimum level of cybersecurity in critical infrastructure and essential sectors (energy, health, transport, etc.).<\/span><\/p>\n<p><span style=\"color: #000000\">\u00a0<\/span><br \/>\n<span style=\"color: #000000\">\u2013\u00a0<strong>Mandatory:<\/strong>\u00a0Mandatory compliance for all member states and companies in critical sectors.<\/span><\/p>\n<p><span style=\"color: #000000\">\u2013\u00a0<strong>Scope:<\/strong>\u00a0Protection of the security of essential infrastructure and digital services.<\/span><\/p>\n<p><span style=\"color: #000000\">\u2013\u00a0<strong>Applicable:<\/strong>\u00a0From October 2024.<\/span><\/p>\n<p><span style=\"color: #000000\"><strong><br \/>\nISO\/IEC 27001 (Information Security Management System)<\/strong><\/span><\/p>\n<p><span style=\"color: #000000\">\u00a0<\/span><br \/>\n<span style=\"color: #000000\">\u2013\u00a0<strong>Nature:<\/strong>\u00a0International VOLUNTARY Standard.<\/span><\/p>\n<p><span style=\"color: #000000\">\u2013\u00a0<strong>Objective:<\/strong>\u00a0Create a security management system that ensures the confidentiality, integrity and availability of information.<\/span><\/p>\n<p><span style=\"color: #000000\">\u2013\u00a0\u00a0<strong>Mandatory:<\/strong>\u00a0Volunteer, based on certification.<\/span><\/p>\n<p><span style=\"color: #000000\">\u2013\u00a0<strong>Scope:<\/strong>\u00a0Applicable to any type of organization that wants to structure its security according to its specific risks.<\/span><\/p>\n<p><span style=\"color: #000000\">\u2013\u00a0<strong>Applicable<\/strong> Last updated October 2022.<\/span><\/p>\n<p><span style=\"color: #000000\"><strong><br \/>\nNIST CSF 2.0 (National Institute of Standards and Technology Cybersecurity Framework)<\/strong><\/span><\/p>\n<p><span style=\"color: #000000\">\u2013\u00a0<strong>Nature:<\/strong>\u00a0Cybersecurity management framework developed in the US<\/span><\/p>\n<p><span style=\"color: #000000\">\u2013\u00a0<strong>Objective:<\/strong>\u00a0Provide good practices to manage risks and improve safety posture in organizations.<\/span><\/p>\n<p><span style=\"color: #000000\">\u2013\u00a0<strong>Mandatory:<\/strong>\u00a0Volunteer, adopted by many companies as reference standard.<\/span><\/p>\n<p><span style=\"color: #000000\"><strong><br \/>\n\u2013 Coverage:<\/strong>\u00a0Adaptable approach for all types of organizations, from small businesses to large corporations.<\/span><\/p>\n<p><span style=\"color: #000000\">\u2013\u00a0<strong>Applicable<\/strong>: Draft version 2.0 presented in October 2024.<\/span><\/p>\n<p><span style=\"color: #000000\"><strong><br \/>\nWhy is it important?<\/strong>\u00a0\ud83d\udd0d\ud83d\udc47<\/span><\/p>\n<p><span style=\"color: #000000\">Although they all address cybersecurity, NIS2 establishes a mandatory legal framework to protect critical infrastructures in Europe. While ISO 27001 and NIST CSF 2.0 are voluntary guides that allow companies to structure their security according to their own risks and objectives.<\/span><\/p>\n<p><span style=\"color: #000000\">Together, these frameworks are not replaced, but complement each other to build a comprehensive cybersecurity environment in the region.<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Antonio Tejeda Encinas\u00a0CEO META Channel corp. President of the Euro-American Committee on Digital Law \u2013EA Digital Law. Let&#8217;s not trust! Parallelism and Complementarity between NIS2, ISO\/IEC 27001 and NIST CSF 2.0: A Comprehensive Framework for Cybersecurity in Europe\u00a0 With the growing importance of cybersecurity in Europe, it is essential to understand the differences and complementarities [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":112331,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"wds_primary_category":0,"wds_primary_cea_women":0,"footnotes":""},"categories":[1110],"tags":[],"cea_women":[],"class_list":["post-118368","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity"],"acf":[],"_links":{"self":[{"href":"https:\/\/ceadigilaw.org\/en\/wp-json\/wp\/v2\/posts\/118368","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ceadigilaw.org\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ceadigilaw.org\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ceadigilaw.org\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/ceadigilaw.org\/en\/wp-json\/wp\/v2\/comments?post=118368"}],"version-history":[{"count":1,"href":"https:\/\/ceadigilaw.org\/en\/wp-json\/wp\/v2\/posts\/118368\/revisions"}],"predecessor-version":[{"id":119450,"href":"https:\/\/ceadigilaw.org\/en\/wp-json\/wp\/v2\/posts\/118368\/revisions\/119450"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ceadigilaw.org\/en\/wp-json\/wp\/v2\/media\/112331"}],"wp:attachment":[{"href":"https:\/\/ceadigilaw.org\/en\/wp-json\/wp\/v2\/media?parent=118368"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ceadigilaw.org\/en\/wp-json\/wp\/v2\/categories?post=118368"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ceadigilaw.org\/en\/wp-json\/wp\/v2\/tags?post=118368"},{"taxonomy":"cea_women","embeddable":true,"href":"https:\/\/ceadigilaw.org\/en\/wp-json\/wp\/v2\/cea_women?post=118368"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}