Available 24 - 7
Call us at +45 7565 0094
info@jashipping.com

CYBER SECURITY



ISO 27001 can be used as a framework to support NIS2 compliance. J.A. Shipping A/S is already ISO 9001 certified - and is thus well along in the process of documenting the requirements of ISO 27001. Organizations that are ISO 27001 certified often already have processes and controls in place that cover many of the NIS2 requirements. However, this does not mean that ISO 27001 alone is enough – there may be additional requirements in NIS2 that need to be addressed separately.
The connection between ISO/IEC 27001 and the NIS2 Directive lies in their common goal of strengthening information security, but they differ in their nature and scope:
🔒 ISO/IEC 27001:
Type: International standard (voluntary).
Purpose: Establishes requirements for an information security management system (ISMS).
Focus: Protection of information (confidentiality, integrity, availability).
Relevance: Can be used by all organizations regardless of industry or size.
Certifiable: Organizations can be certified according to ISO 27001.
🛡️ NIS2 (EU Directive 2022/2555):
Type: EU legislation (mandatory for designated organizations).
Purpose: To increase the level of cybersecurity in critical and important sectors in the EU.
Focus: Security and resilience of network and information systems.
Relevance: Applies to specific sectors (e.g. energy, transport, health, digital infrastructure).
Not certifiable: But the requirements must be complied with and documented.
🧩 ISO 27001 NIS2 Coherence
Purpose:
ISMS and information security / Regulation and supervision of cybersecurity
ISO 27001 can be used to meet NIS2 requirements.
Application
ISO 27001 is Voluntary / NIS2 is Mandatory for designated actors/
ISO 27001 helps to document compliance with NIS2
Requirements for risk assessment
Both ISO 27001 and NIS2 are Risk-based approach.
Management anchoring
Both iSO 27001 and NIS2 have the Requirements for Management anchring
Security measures
ISO 27001 has Security measures includen in its Annex A (controls)
Security Management for NIAS is included in its Article 21 (minimum measures)
Overlap in requirements for e.g. access control, incident management, backup.
Our goal is ISO 27001 certification latest by October this year.



