Cross-reference between ISO/IEC 27001:2022, the Spanish ENS, NIS2 and DORA, anchored on the 93 controls of ISO/IEC 27002:2022.
Equivalencias entre ISO/IEC 27001:2022, el ENS, NIS2 y DORA, tomando como eje los 93 controles de ISO/IEC 27002:2022.
mr7security· security tooling· herramientas de seguridadNIS2 and DORA are not control catalogues. NIS2 states ten obligations in Article 21(2) and details them, for some sectors, in Implementing Regulation (EU) 2024/2690; DORA is a regulation with articles and technical standards. So each row says how far an ISO control takes you towards the obligation — full, partial or none — rather than pretending there is a one-to-one equivalent.
NIS2 y DORA no son catalogos de controles. NIS2 enuncia diez obligaciones en el articulo 21.2 y las detalla, para algunos sectores, en el Reglamento de Ejecucion (UE) 2024/2690; DORA es un reglamento con articulos y normas tecnicas. Por eso cada fila dice hasta donde le lleva un control ISO respecto de la obligacion — total, parcial o ninguna — en lugar de fingir que existe un equivalente uno a uno.
Voluntary standard, certifiableNorma voluntaria, certificable
Any organisationCualquier organizacion
93 controlscontroles
Spanish law, certifiableNorma espanola, certificable
Spanish public sector and its suppliersSector publico espanol y sus proveedores
62 fulltotal · 27 partialparcial · 4 noneninguna
EU directive, transposed nationallyDirectiva europea, de transposicion nacional
Essential and important entities in the listed sectorsEntidades esenciales e importantes de los sectores listados
52 fulltotal · 38 partialparcial · 3 noneninguna
EU regulation, directly applicableReglamento europeo, de aplicacion directa
Financial entities and their critical ICT providersEntidades financieras y sus proveedores TIC esenciales
29 fulltotal · 55 partialparcial · 9 noneninguna
controls showncontroles mostrados
Requirements of the other regimes that no ISO 27002 control corresponds to. These are the ones a certified organisation still has to build from scratch. Requisitos de los otros regimenes a los que no corresponde ningun control de ISO 27002. Son los que una organizacion certificada todavia tiene que construir desde cero.