Mapping of OES security requirements to specific sectors
According to the Directive (EU) 2016/1148 issued by the European Parliament and the Council, hereafter referred to as 'Network and Information Security (NIS) Directive', specific types of entities which provide essential services to the European internal market, shall be identified by the Member States. The business sectors for these entities are depicted in Annex II of the NIS Directive. One of the main objectives of the NIS Directive is to enact security measures for operators of essential services (OES) across the European Union, in order to achieve a high common level of Security of Network and Information Systems. The current report provides a substantial and comprehensive mapping of the security requirements for OES, as they have been agreed in the NISD Cooperation Group, to sector specific information security standards. Initially, ENISA conducted desktop research on international security standards, guidelines and good practices per sector. Finally, the security requirements for OES were mapped to international standards used by operators covering all business sectors under scope. This report is a living document that we will augment on a regular basis to keep it up to date with the latest developments.