8
Personnel, access and assets
2026-08-10
Cbw art. 21, third paragraph, opening (i) · NIS-2 art. 21(2)(i) · Cbb art. 14, 15 and 16
Who has access to what, and why? This family covers personnel, access and the assets you're responsible for.
What this means in practice
You designate who holds which security task, set trustworthiness requirements for staff with access to sensitive systems, run an access policy for logical and physical access, periodically review accounts and rights, and keep an asset policy with classification and a current inventory.
Why this is in the law
Without a current inventory and periodic review of rights, old access piles up — a well-known entry point for attackers.
Measures in this family
- MC-33 — Designating who holds which security task
- MC-34 — Trustworthiness requirements for staff with access
- MC-35 — Access policy for logical and physical access
- MC-36 — Periodic review of accounts and rights
- MC-37 — Asset policy, classification and a current inventory
Sources
Also worth reading
Not sure yet whether this applies to you? Take the free scope check.
Take the free scope check