nis2

Art. 21(2)(f)

Full text: this article's wording is third-party regulatory text. See the official source for the authoritative provision.

Mapped SPARTA techniques (2)

Techniques referencing this article

  • DE-0003.12Poison AI/ML Training for EvasionST0006
    addresses
    moderate
    direct

    Validating that anomaly detectors actually detect — including against adversarial-input campaigns — is exactly how the entity assesses the effectiveness of its cybersecurity risk-management measures under Art. 21(2)(f).

  • REC-0006.02Security Testing ToolsST0001
    addresses
    moderate
    direct

    Coverage thresholds, mutation testing, and the gating logic between testing and release are how the entity assesses the effectiveness of its cybersecurity risk-management measures under Art. 21(2)(f).

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.