Get a true picture of how your current cyber security arrangements measure up against the requirements of the Network and Information Systems Regulations 2018 (NIS Regulations). Applicable to both RDSP and OES.
The NIS Regulations Gap Analysis is designed to help operators of essential services (OES) and relevant digital service providers (RDSPs) meet their requirements under the Network and Information Systems (NIS) Regulations 2018 by identifying where they may have gaps and providing a clear roadmap for achieving compliance.
The NIS Regulations require OES to implement a range of measures to ensure the security of their networks and information systems. The National Cyber Security Centre (NCSC) has defined these measures in the Cyber Assessment Framework (CAF). Meanwhile, RDSPs are required to comply with the EU’s Commission Implementing Regulation 2018/151, which is addressed in the European Union Agency for Cybersecurity’s (ENISA). Compliance for RDSPs in the UK is normally assessed by the Information Commissioner’s Office (ICO). If you would prefer an audit against the Regulations’ requirements, please refer to our NIS Regulations Mock Audit service.
For more information about this service, please contact us on +44 (0)333 800 7000.
Your IT Governance consultant will aim to:
A qualified consultant will work with you in person or remotely to undertake a detailed assessment to identify potential shortcomings in your current security routine. If your organisation is an OES, this will compare your security measures against the ‘indicators of good practice’ (IGPs) outlined by the NCSC’s CAF, and as interpreted by the competent authority for your industry. RSDPs will be assessed against the technical guidance provided by ENISA.
The consultant will also take into consideration any existing governance and security arrangements that may be in place and contribute to your security. Based on this assessment, the consultant will develop a prioritised action plan that your organisation can implement to meet your obligations and improve your security.
The consultant’s report will identify where your organisation is failing to meet the NIS Regulations’ requirements and explain how those areas can be addressed. This will be supported by the action plan.
The report will also include an executive summary that sets out what the findings mean in business terms, as well as a more detailed explanation for those who will be remediating any issues.
The report will be delivered within ten working days of completing the assessment.
Download the full service description >>
Following your gap analysis, we can offer support with remediating issues and closing gaps to ensure compliance with the NIS Regulations. Your IT Governance consultant will work through each gap and help your organisation make the necessary changes. For OES, this will ensure that all IGPs are in place; for RDSPs, the consultant will ensure your organisation aligns with ENISA’s technical guidance. This would include developing policies and, where applicable, standard operating procedures. These will be based on your organisation’s specific requirements in relation to the NIS Regulations.
This is an additional service not included in the gap analysis by default, and will be scoped according to the results of the gap analysis to ensure that your organisation only pays for the support it needs.