Skip to content

GLBANIS2 crosswalk

A control-by-control mapping between GLBA Safeguards Rule (16 CFR Part 314) and NIS2 Directive (EU 2022/2555). 5 mappings.

GLBANIS2RelationshipNotes
§314.4(a)
Designate a qualified individual
Art. 21(2)(a)
Risk analysis and information system security policies
RelatedCurated
Governance & security policy
§314.4(c)(1)
Access controls
Art. 21(2)(i)
Access control and asset management
PartialCurated
Access control & identity
§314.4(c)(3)
Encryption of customer information
Art. 21(2)(h)
Cryptography and encryption
EquivalentCurated
Cryptography & data protection
§314.4(h)
Incident response plan
Art. 21(2)(b)
Incident handling
PartialCurated
Incident response & breach notification
§314.4(h)
Incident response plan
Art. 23
Reporting obligations
PartialCurated
Incident response & breach notification

Mappings marked “Official” derive from standards-body informative references; “Curated” mappings are authored by Cyber Compliance and provided for guidance only.