NISG 2026 course All courses

Lesson 4.2 · 7 min

Security policy, risk analysis and effectiveness

Open in the coursewith narrated slides, a checklist to tick off and a quiz

At a glance

In detail

The security policy

Point (a) requires policies on risk analysis and information system security § 32(4)(a) NISG 2026. Under the EU catalogue, which applies through the NISV 2026 § 2 NISV 2026, the policy must, among other things (Implementing Regulation (EU) 2024/2690, Annex point 1.1.1):

The management reviews it at least once a year and after significant incidents or major changes; the result is documented (point 1.1.2).

Roles

Responsibilities and authority for security are set and communicated to the management; at least one person reports directly to it; depending on size, this can be an extra task for an existing role; conflicting duties are separated where applicable (point 1.2). A business too small to separate them provides a compensating measure § 4 NISV 2026.

The risk analysis

The entity establishes a risk management framework and documents risk assessments; a risk treatment plan follows from them (point 2.1.1). In doing so it must (point 2.1.2):

  1. follow a methodology and set a risk tolerance threshold and risk criteria;
  2. identify risks on an all-hazards basis, in particular those involving third parties, including single points of failure;
  3. analyse them by threat, likelihood and impact and evaluate them against the criteria;
  4. decide on measures, each with an owner and a date, and monitor their implementation;
  5. explain in the treatment plan why residual risks are accepted.

At least the NISV's four categories must be covered: technological risks (such as cloud, virtualisation, artificial intelligence), human risks (mistakes, insiders, social engineering, stress), risks in the ICT supply chain (such as dependence on one provider) and site-related risks (flooding, fire, unauthorised entry) § 3 NISV 2026 (notes on the NISV 2026). The risk assessment and treatment plan are reviewed at least once a year (point 2.1.4).

Checking that it works

For a business with 60 staff, in practice: a security policy of a few pages, a risk register with a treatment plan, a handful of indicators (such as patch status, the share of accounts with MFA, successful restore tests) and a yearly meeting where the management goes through it all and signs it off.

Checklist

Quiz

How often must the risk assessment and treatment plan be reviewed at least, under the EU catalogue?

  1. Only when the Federal Office asks
  2. Only after an incident
  3. Every five years
  4. At least once a year, and on major changes or significant incidents
Show the answer

The answer is D: At least once a year, and on major changes or significant incidents. Implementing Regulation (EU) 2024/2690, Annex point 2.1.4, through § 2 NISV 2026: at planned intervals and at least once a year, and on major changes or significant incidents.

Sources

This lesson's statements rest on:

Not legal advice. What counts is the NISG 2026 and the NISV 2026 in the Federal Legal Information System and Implementing Regulation (EU) 2024/2690 (read on 6 October 2026). Not covered are the special rules for banks and financial entities (DORA), for critical entities under the RKE Act, for domain name registration services and for the public administration. Not an offer of the Federal Office for Cyber Security, a CERT or the Chamber of Commerce.