nis2

Art. 21(2)(g)

Full text: this article's wording is third-party regulatory text. See the official source for the authoritative provision.

Mapped SPARTA techniques (6)

Techniques referencing this article

  • IA-0007Compromise Ground SystemST0003
    addresses
    moderate
    direct

    Spear-phishing of operators and contractors is one of the named initial-access vectors; Art. 21(2)(g)'s basic cyber hygiene practices and cybersecurity training raise human resilience to that path.

  • IA-0011Auxiliary Device CompromiseST0003
    addresses
    moderate
    direct

    Removable-media discipline and peripheral hygiene are core elements of basic cyber hygiene practices under Art. 21(2)(g) — particularly during hurried I&T or contingency maintenance when auto-ingest workflows are most exploitable.

  • RD-0002Compromise InfrastructureST0002
    addresses
    moderate
    direct

    Spear-phishing of operators and vendors is one of the named initial-access routes; Art. 21(2)(g)'s basic cyber hygiene practices and cybersecurity training raise the floor of human resilience to that vector.

  • REC-0002.02OrganizationST0001
    addresses
    moderate
    direct

    Org-chart enumeration feeds spear-phishing, invoice-fraud, and credential-theft pretexts; basic cyber hygiene practices and cybersecurity training under Art. 21(2)(g) are the obligation that builds resistance in operators, finance, and engineering staff.

  • REC-0003.04Valid CredentialsST0001
    addresses
    moderate
    direct

    Spear-phishing, credential reuse, and exposure of secrets in scripts/CI runners are addressed by basic cyber hygiene practices and cybersecurity training under Art. 21(2)(g) that build human resilience to the most common credential-theft vectors.

  • REC-0008.04Business RelationshipsST0001
    addresses
    moderate
    direct

    Tailored phishing, invoice fraud, and credential reuse leveraged off business-relationship recon are countered by basic cyber hygiene practices and cybersecurity training under Art. 21(2)(g) covering operators, finance, and engineering staff.

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.