nis2-impl

Annex 8.1.1

Full text: this article's wording is third-party regulatory text. See the official source for the authoritative provision.

Mapped SPARTA techniques (3)

Techniques referencing this article

  • Cyber-hygiene awareness across collaborator organizations limits the social-engineering footprint of cross-org repositories and shared portals where collaborator accounts are most often the entry point.

  • REC-0002.02OrganizationST0001
    addresses
    high
    direct

    Mapping the human and institutional terrain to enable phishing, credential theft and invoice fraud is precisely the threat surface the cyber-hygiene awareness obligation addresses; the implementing regulation requires the entity to ensure employees understand the risks they expose through public profiles and routine communication.

  • REC-0008.04Business RelationshipsST0001
    addresses
    moderate
    derived

    Cyber-hygiene awareness is the human-side defence against social engineering against the well-connected nodes a relationship-recon adversary identifies as weakest.

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.