Lesson 4.5 · 7 min
Access, MFA, encryption, inventory
Open in the coursewith narrated slides, a checklist to tick off and a quiz
At a glance
- Only those who need it. Rights on a need-to-know and need-to-use basis, with separation of duties; a register of rights; changes when people leave; regular review.
- Separate accounts for administration. Administrator accounts only for administration, with strong authentication such as MFA and as few rights as possible.
- Several factors, where appropriate. Users are authenticated with several factors or continuously, where appropriate, depending on how much the system needs protecting.
- A policy for encryption. Which data is protected how strongly, which methods are approved, and how keys are created, stored, changed and destroyed.
- Know what you have. A current list of processes, services and systems, protection levels for all assets, rules for USB media and for devices when people leave.
In detail
Point (h) requires policies on cryptography and, where appropriate, encryption; point (i) human resources security, access control and asset management; point (j) multi-factor or continuous authentication, secured voice, video and text communications and, where appropriate, secured emergency communications § 32(4)(h) to (j) NISG 2026. The EU catalogue § 2 NISV 2026 spells this out (Implementing Regulation (EU) 2024/2690, Annex points 9 to 13):
Access control (point 11)
- a policy for logical and physical access, covering staff, visitors and service providers, and access only after appropriate authentication;
- rights on a need-to-know and need-to-use basis with separation of duties; adjusted when people leave or change roles; limited in scope and time for third parties; with a register of rights, reviewed regularly;
- privileged accounts with strong identification and authentication, for example MFA; separate accounts used only for administration; rights as narrow as possible; administration systems used only for administration;
- unique identities, each linked to one person; shared accounts only where necessary, approved and documented; identities no longer needed deactivated without delay;
- authentication matched to the protection needed: lock-out after a set number of failed attempts, ending idle sessions, changing credentials on suspicion, separate credentials for administrator accounts;
- multi-factor authentication or continuous authentication, where appropriate, in line with the system's protection level (point 11.7).
Human resources security (point 10)
All staff and, where needed, direct service providers know their security duties; administrators and the management know their roles; qualifications are checked when hiring; background checks, where feasible, for roles that require them; duties that continue after leaving, such as confidentiality, are in the contract; a disciplinary procedure for breaches is known.
Cryptography (point 9)
A policy sets which data, stored and in transit, gets what strength of cryptographic protection, which protocols and algorithms are approved, with crypto-agility where appropriate, and how keys are managed over their whole life: generated, distributed, stored, changed, revoked, recovered, backed up, destroyed. It is reviewed in line with the state of the art.
Assets (point 12) and physical security (point 13)
- protection levels for all assets, based on confidentiality, integrity, authenticity and availability;
- rules for their whole life cycle, down to secure deletion and destruction;
- removable media blocked technically unless there are organisational reasons; no autorun; scanning for malicious code;
- a complete, current inventory of processes and services and the systems that support them;
- return or deletion of devices and data when people leave, documented;
- secure areas with access control for rooms with systems, protection against environmental events such as fire and water.
Checklist
- Administrators work with separate administration accounts protected by MFA.
- Remote access, email and cloud services require MFA, or we have documented why not.
- We have a register of access rights and review it regularly; accounts are deactivated at once when people leave.
- We have an inventory of our services, systems and devices with protection levels.
- We have decided what is encrypted, and who manages the keys.
Quiz
What does the EU catalogue require for administrator accounts?
- One shared admin account for the whole IT team
- Nothing special, as long as the password is long
- That administrators may not read email
- Separate accounts used only for administration, with strong authentication such as MFA
Show the answer
The answer is D: Separate accounts used only for administration, with strong authentication such as MFA. Implementing Regulation (EU) 2024/2690, Annex point 11.3.2, through § 2 NISV 2026: strong identification and authentication (e.g. MFA) and specific accounts used only for system administration.
Sources
This lesson's statements rest on:
- Network and Information System Security Act 2026 (NISG 2026) § 32, Federal Legal Information System (RIS), in German, version of 6 October 2026
- Network and Information System Security Regulation (NISV 2026) § 2, RIS, in German, version of 6 October 2026
- Implementing Regulation (EU) 2024/2690, Art. 2 and Annex, EUR-Lex (also in English)
Not legal advice. What counts is the NISG 2026 and the NISV 2026 in the Federal Legal Information System and Implementing Regulation (EU) 2024/2690 (read on 6 October 2026). Not covered are the special rules for banks and financial entities (DORA), for critical entities under the RKE Act, for domain name registration services and for the public administration. Not an offer of the Federal Office for Cyber Security, a CERT or the Chamber of Commerce.