Control 1
Policies for risk analysis and information security
A. Legal requirement
“Member States shall ensure that essential and important entities take appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of network and information systems... including (a) policies on risk analysis and information system security.”
Directive text: Medlemsstaterne sikrer, at væsentlige og vigtige enheder træffer passende og forholdsmæssige tekniske, operationelle og organisatoriske foranstaltninger for at håndtere risici for sikkerheden af netværks- og informationssystemer... herunder (a) politikker for risikoanalyse og informationssystemsikkerhed.
B. What it means in practice
You need written policies that document how you identify, assess, and handle cyber risks. It's not enough to say *"we take security seriously"*, you need concrete documents that are updated regularly and approved by leadership.
C. Microsoft 365 features
- Microsoft Purview Compliance Manager(primary)
- Microsoft Secure Score(primary)
- Purview Risk Management(supplementary)
D. Licence requirement
Minimum licence: Business Prem
E. Configuration
- •Go to Microsoft 365 Defender → Secure Score and baseline your current score
- •Open Purview Compliance Manager and start a NIS2 assessment (or use IT-grundbeskyttelse as a proxy)
- •Export the Compliance Manager report monthly as documentation
- •Document your own policies (in SharePoint or an external tool)
F. Audit evidence
- •Exported Secure Score history (at least 12 months)
- •Compliance Manager assessment report, dated within the last 3 months
- •Written information security policy approved by leadership, version-stamped
- •Meeting minutes from leadership reviews of the policy (quarterly recommended)