Framework
Full specification

NIS2 Romania

Oh no! No description found. But not to worry. Read from Tasks below how to advance this topic.

OUG 155/2024 is a Romanian law implementing the NIS2 Directive, designed to bolster cybersecurity across essential and important entities by establishing a framework for network and information system security.

Ordonanța de Urgență a Guvernului nr. 155/2024 (OUG 155/2024) is a Romanian law that transposes the NIS2 Directive into national legislation. It establishes a legal and institutional framework for the cybersecurity of networks and information systems in the national civil cyberspace.

OUG 155/2024 aims to enhance Romania's resilience against cyber threats by implementing the NIS2 Directive, ensuring improved protection of critical infrastructure sectors. The ordinance applies to both public and private entities considered essential or important for national infrastructure, and it enforces measures for risk management, incident reporting, and security audits. It also mandates professional training for management bodies and outlines penalties for non-compliance.

Tasks
40
Scope
Romania
Here's what
NIS2 Romania
requires and how to comply.

Below you'll find all of the requirements of this framework. In Cyberday, we map all requirement to global tasks, making multi-compliance management easy. Do it once, and see the progress across all frameworks!

Requirements
11.1: Gestionarea riscurilor de securitate
11.4: Abordare cuprinzătoare a securității cibernetice
11.5: Auditului de securitate
11.7: Listei de active și riscuri
11.8: Definirea și monitorizarea măsurilor necesare de securitate a lanțului de aprovizionare
12.3: Aplicarea măsurilor corective în caz de nerespectare
12.4: Transmiterea autoevaluării anuale a maturității cibernetice
12.5: Planul de măsuri pentru remedierea deficiențelor
13.1.a: Gestionarea riscurilor și securitatea sistemelor informatice
13.1.b: Evaluarea eficacității măsurilor de securitate
13.1.c: Criptarea
13.1.d: Securitatea lanțului de aprovizionare
13.1.e: Achiziționarea și dezvoltarea de sisteme sigure
13.1.f (activ): Gestionarea activelor
13.1.f (acces): Controlul accesului
13.1.f (resurse umane): Securitatea resurselor umane
NIS2 Romania
learning hub

Explore our comprehensive resources and improve your security with the themes of this framework.

How Cyberday helps with
NIS2 Romania

Discover specific ways our platform streamlines your ISO 27001 compliance process, from automated controls to audit preparation.

Explore use case
Free
NIS2 Romania
assessment

Take our comprehensive assessment to identify gaps in your current implementation and get personalized recommendations.

Start assessment
Read more about
NIS2 Romania

Dive deeper with our articles, case studies, and expert insights on framework implementation.

Read article
Guide to compliance

Get a concise overview of all requirements, controls, and implementation steps in our quick guide.

Get the guide
Framework comparison

See how the overlap and differences with any other framework to optimize your compliance strategy.

Compare framework
Join a live
NIS2 Romania
webinar

Participate in expert-led sessions covering implementation strategies, common pitfalls, and best practices for compliance.

Register for webinar
Join our live webinars

Participate in expert-led sessions covering implementation strategies, common pitfalls, and best practices for compliance.

Register for webinar
What are frameworks?

Understand the basics of cyber security frameworks with our comprehensive guide.

Read the article

The ISMS component hierachy

When building an ISMS, it's important to understand the different levels of information hierarchy. Here's how Cyberday is structured.

Framework

Sets the overall compliance standard or regulation your organization needs to follow.

Requirements

Break down the framework into specific obligations that must be met.

Tasks

Concrete actions and activities your team carries out to satisfy each requirement.

Policies

Documented rules and practices that are created and maintained as a result of completing tasks.

Never duplicate effort. Do it once - improve compliance across frameworks.

Reach multi-framework compliance in the simplest possible way
Security frameworks tend to share the same core requirements - like risk management, backup, malware, personnel awareness or access management.
Cyberday maps all frameworks’ requirements into shared tasks - one single plan that improves all frameworks’ compliance.
Do it once - we automatically apply it to all current and future frameworks.