Lesson 4.2 · 7 min
Security policy, risk analysis and effectiveness
Open in the coursewith narrated slides, a checklist to tick off and a quiz
At a glance
- A security policy approved by the management. It sets out the approach, objectives, roles, resources and the records to keep, and is reviewed at least once a year.
- One person reports directly. At least one person is directly responsible to the management for security. Conflicting duties are separated where possible.
- Identify, analyse, evaluate, treat. With a method, a risk tolerance and criteria. Every measure has an owner and a date, every residual risk a reason.
- Risk assessment and treatment plan. Reviewed and updated at least once a year, and after significant incidents or major changes.
- Measure whether it works. What is measured, how, when and by whom, and who evaluates the results? Plus an independent review at regular intervals.
In detail
The security policy
Point (a) requires policies on risk analysis and information system security § 32(4)(a) NISG 2026. Under the EU catalogue, which applies through the NISV 2026 § 2 NISV 2026, the policy must, among other things (Implementing Regulation (EU) 2024/2690, Annex point 1.1.1):
- set out the approach to managing security and the security objectives, in line with the business strategy;
- commit to continual improvement and to the resources needed, staff and money included;
- be communicated to and acknowledged by staff and relevant outside parties;
- list roles and responsibilities, the records to keep and for how long, and the topic-specific policies;
- set indicators for monitoring its implementation;
- carry the date of its formal approval by the management.
The management reviews it at least once a year and after significant incidents or major changes; the result is documented (point 1.1.2).
Roles
Responsibilities and authority for security are set and communicated to the management; at least one person reports directly to it; depending on size, this can be an extra task for an existing role; conflicting duties are separated where applicable (point 1.2). A business too small to separate them provides a compensating measure § 4 NISV 2026.
The risk analysis
The entity establishes a risk management framework and documents risk assessments; a risk treatment plan follows from them (point 2.1.1). In doing so it must (point 2.1.2):
- follow a methodology and set a risk tolerance threshold and risk criteria;
- identify risks on an all-hazards basis, in particular those involving third parties, including single points of failure;
- analyse them by threat, likelihood and impact and evaluate them against the criteria;
- decide on measures, each with an owner and a date, and monitor their implementation;
- explain in the treatment plan why residual risks are accepted.
At least the NISV's four categories must be covered: technological risks (such as cloud, virtualisation, artificial intelligence), human risks (mistakes, insiders, social engineering, stress), risks in the ICT supply chain (such as dependence on one provider) and site-related risks (flooding, fire, unauthorised entry) § 3 NISV 2026 (notes on the NISV 2026). The risk assessment and treatment plan are reviewed at least once a year (point 2.1.4).
Checking that it works
- Compliance: check regularly that your own policies are followed, and report to the management (point 2.2).
- Independent review: by people with audit competence who don't report to the area being reviewed; if size makes that impossible, other ways to ensure impartiality, such as an outside review (point 2.3).
- Effectiveness (point (f)): decide which measures are measured, how, when and by whom, and who evaluates the results when (point 7).
For a business with 60 staff, in practice: a security policy of a few pages, a risk register with a treatment plan, a handful of indicators (such as patch status, the share of accounts with MFA, successful restore tests) and a yearly meeting where the management goes through it all and signs it off.
Checklist
- We have a security policy with the date of its approval by the management.
- One person is directly responsible to the management for security.
- We have a risk register: every risk assessed, every measure with an owner and a date.
- Residual risks have reasons and have been accepted by the management.
- A yearly date for the review, the indicators and an independent check is in the calendar.
Quiz
How often must the risk assessment and treatment plan be reviewed at least, under the EU catalogue?
- Only when the Federal Office asks
- Only after an incident
- Every five years
- At least once a year, and on major changes or significant incidents
Show the answer
The answer is D: At least once a year, and on major changes or significant incidents. Implementing Regulation (EU) 2024/2690, Annex point 2.1.4, through § 2 NISV 2026: at planned intervals and at least once a year, and on major changes or significant incidents.
Sources
This lesson's statements rest on:
- Network and Information System Security Act 2026 (NISG 2026) § 32, Federal Legal Information System (RIS), in German, version of 6 October 2026
- Network and Information System Security Regulation (NISV 2026) § 2, RIS, in German, version of 6 October 2026
- Network and Information System Security Regulation (NISV 2026) § 3, RIS, in German, version of 6 October 2026
- Network and Information System Security Regulation (NISV 2026) § 4, RIS, in German, version of 6 October 2026
- Implementing Regulation (EU) 2024/2690, Art. 2 and Annex, EUR-Lex (also in English)
- Explanatory notes to the NISV 2026, PDF, in German
Not legal advice. What counts is the NISG 2026 and the NISV 2026 in the Federal Legal Information System and Implementing Regulation (EU) 2024/2690 (read on 6 October 2026). Not covered are the special rules for banks and financial entities (DORA), for critical entities under the RKE Act, for domain name registration services and for the public administration. Not an offer of the Federal Office for Cyber Security, a CERT or the Chamber of Commerce.