Skip to content
Back to the knowledge base

8

Personnel, access and assets

2026-08-10

Cbw art. 21, third paragraph, opening (i) · NIS-2 art. 21(2)(i) · Cbb art. 14, 15 and 16

Who has access to what, and why? This family covers personnel, access and the assets you're responsible for.

What this means in practice

You designate who holds which security task, set trustworthiness requirements for staff with access to sensitive systems, run an access policy for logical and physical access, periodically review accounts and rights, and keep an asset policy with classification and a current inventory.

Why this is in the law

Without a current inventory and periodic review of rights, old access piles up — a well-known entry point for attackers.

Measures in this family

  • MC-33 — Designating who holds which security task
  • MC-34 — Trustworthiness requirements for staff with access
  • MC-35 — Access policy for logical and physical access
  • MC-36 — Periodic review of accounts and rights
  • MC-37 — Asset policy, classification and a current inventory

Sources

Also worth reading

Not sure yet whether this applies to you? Take the free scope check.

Take the free scope check