Recital 79
Directive on the security of network and information systems · UE 2022/2555
| (79) | As threats to the security of network and information systems can have different origins, cybersecurity risk-management measures should be based on an all-hazards approach, which aims to protect network and information systems and the physical environment of those systems from events such as theft, fire, flood, telecommunication or power failures, or unauthorised physical access and damage to, and interference with, an essential or important entity’s information and information processing facilities, which could compromise the availability, authenticity, integrity or confidentiality of stored, transmitted or processed data or of the services offered by, or accessible via, network and information systems. The cybersecurity risk-management measures should therefore also address the physical and environmental security of network and information systems by including measures to protect such systems from system failures, human error, malicious acts or natural phenomena, in line with European and international standards, such as those included in the ISO/IEC 27000 series. In that regard, essential and important entities should, as part of their cybersecurity risk-management measures, also address human resources security and have in place appropriate access control policies. Those measures should be consistent with Directive (EU) 2022/2557. |
In Luxembourg, the law of 28 July 2023 on cybersecurity (amended by the law of 28 July 2025) entrusts the ILR with the control of the all-hazards approach. The ILR expects an explicit articulation with the law of 23 July 2016 on critical entities (CER transposition) for entities concerned by both regimes, particularly in energy, transport and health, where hosting at eBRC, LuxConnect or POST implies coordinated physical and cyber audits.
Luxgap practice: we map your ISO/IEC 27002 A.7 and A.6 controls onto the ILR inspection grid and align your physical resilience plan with your NIS 2 plan in a single enforceable file.