forked from intuitem/ciso-assistant-community
-
Notifications
You must be signed in to change notification settings - Fork 0
/
nis1-rules-fr.yaml
3202 lines (3200 loc) · 154 KB
/
nis1-rules-fr.yaml
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
350
351
352
353
354
355
356
357
358
359
360
361
362
363
364
365
366
367
368
369
370
371
372
373
374
375
376
377
378
379
380
381
382
383
384
385
386
387
388
389
390
391
392
393
394
395
396
397
398
399
400
401
402
403
404
405
406
407
408
409
410
411
412
413
414
415
416
417
418
419
420
421
422
423
424
425
426
427
428
429
430
431
432
433
434
435
436
437
438
439
440
441
442
443
444
445
446
447
448
449
450
451
452
453
454
455
456
457
458
459
460
461
462
463
464
465
466
467
468
469
470
471
472
473
474
475
476
477
478
479
480
481
482
483
484
485
486
487
488
489
490
491
492
493
494
495
496
497
498
499
500
501
502
503
504
505
506
507
508
509
510
511
512
513
514
515
516
517
518
519
520
521
522
523
524
525
526
527
528
529
530
531
532
533
534
535
536
537
538
539
540
541
542
543
544
545
546
547
548
549
550
551
552
553
554
555
556
557
558
559
560
561
562
563
564
565
566
567
568
569
570
571
572
573
574
575
576
577
578
579
580
581
582
583
584
585
586
587
588
589
590
591
592
593
594
595
596
597
598
599
600
601
602
603
604
605
606
607
608
609
610
611
612
613
614
615
616
617
618
619
620
621
622
623
624
625
626
627
628
629
630
631
632
633
634
635
636
637
638
639
640
641
642
643
644
645
646
647
648
649
650
651
652
653
654
655
656
657
658
659
660
661
662
663
664
665
666
667
668
669
670
671
672
673
674
675
676
677
678
679
680
681
682
683
684
685
686
687
688
689
690
691
692
693
694
695
696
697
698
699
700
701
702
703
704
705
706
707
708
709
710
711
712
713
714
715
716
717
718
719
720
721
722
723
724
725
726
727
728
729
730
731
732
733
734
735
736
737
738
739
740
741
742
743
744
745
746
747
748
749
750
751
752
753
754
755
756
757
758
759
760
761
762
763
764
765
766
767
768
769
770
771
772
773
774
775
776
777
778
779
780
781
782
783
784
785
786
787
788
789
790
791
792
793
794
795
796
797
798
799
800
801
802
803
804
805
806
807
808
809
810
811
812
813
814
815
816
817
818
819
820
821
822
823
824
825
826
827
828
829
830
831
832
833
834
835
836
837
838
839
840
841
842
843
844
845
846
847
848
849
850
851
852
853
854
855
856
857
858
859
860
861
862
863
864
865
866
867
868
869
870
871
872
873
874
875
876
877
878
879
880
881
882
883
884
885
886
887
888
889
890
891
892
893
894
895
896
897
898
899
900
901
902
903
904
905
906
907
908
909
910
911
912
913
914
915
916
917
918
919
920
921
922
923
924
925
926
927
928
929
930
931
932
933
934
935
936
937
938
939
940
941
942
943
944
945
946
947
948
949
950
951
952
953
954
955
956
957
958
959
960
961
962
963
964
965
966
967
968
969
970
971
972
973
974
975
976
977
978
979
980
981
982
983
984
985
986
987
988
989
990
991
992
993
994
995
996
997
998
999
1000
urn: urn:intuitem:risk:library:nis1-rules-fr
locale: fr
ref_id: NIS-1 FR
name: Loi NIS-1 FR
description: "Arr\xEAt\xE9 du 14 septembre 2018 fixant les r\xE8gles de s\xE9curit\xE9\
\ et les d\xE9lais mentionn\xE9s \xE0 l'article 10 du d\xE9cret n\xB0 2018-384 du\
\ 23 mai 2018 relatif \xE0 la s\xE9curit\xE9 des r\xE9seaux et syst\xE8mes d'information\
\ des op\xE9rateurs de services essentiels et des fournisseurs de service num\xE9\
rique\nhttps://www.legifrance.gouv.fr/loda/id/JORFTEXT000037444012/"
copyright: "Loi fran\xE7aise"
version: 1
provider: "Gouvernement fran\xE7ais"
packager: intuitem
translations:
en:
name: NIS-1 rules
description: 'Order of 14 September 2018 setting the security rules and deadlines
mentioned in Article 10 of Decree No. 2018-384 of 23 May 2018 on the security
of networks and information systems of operators of essential services and digital
service providers
https://www.legifrance.gouv.fr/loda/id/JORFTEXT000037444012/'
copyright: French law
provider: French government
dependencies:
- urn:intuitem:risk:library:doc-pol
- urn:intuitem:risk:library:mitre-attack-v14
objects:
framework:
urn: urn:intuitem:risk:framework:nis1-rules-fr
ref_id: NIS-1 FR
name: Loi NIS-1 FR
description: "Arr\xEAt\xE9 du 14 septembre 2018 fixant les r\xE8gles de s\xE9\
curit\xE9 et les d\xE9lais mentionn\xE9s \xE0 l'article 10 du d\xE9cret n\xB0\
\ 2018-384 du 23 mai 2018 relatif \xE0 la s\xE9curit\xE9 des r\xE9seaux et syst\xE8\
mes d'information des op\xE9rateurs de services essentiels et des fournisseurs\
\ de service num\xE9rique\nhttps://www.legifrance.gouv.fr/loda/id/JORFTEXT000037444012/"
translations:
en:
name: NIS-1 rules for FR
description: 'Order of 14 September 2018 setting the security rules and deadlines
mentioned in Article 10 of Decree No. 2018-384 of 23 May 2018 on the security
of networks and information systems of operators of essential services and
digital service providers
https://www.legifrance.gouv.fr/loda/id/JORFTEXT000037444012/'
requirement_nodes:
- urn: urn:intuitem:risk:req_node:nis1-rules-fr:node2
assessable: false
depth: 1
name: Chapitre I
description: "R\xE8gles relatives \xE0 la gouvernance de la s\xE9curit\xE9 des\
\ r\xE9seaux et syst\xE8mes d'information"
translations:
en:
name: Chapter I
description: Rules relating to the governance of the security of networks
and information systems
- urn: urn:intuitem:risk:req_node:nis1-rules-fr:1
assessable: false
depth: 2
parent_urn: urn:intuitem:risk:req_node:nis1-rules-fr:node2
ref_id: '1'
name: "R\xE8gle 1"
description: Analyse de risque
translations:
en:
name: Rule 1
description: Risk Analysis
- urn: urn:intuitem:risk:req_node:nis1-rules-fr:node4
assessable: true
depth: 3
parent_urn: urn:intuitem:risk:req_node:nis1-rules-fr:1
description: "L'op\xE9rateur de services essentiels effectue et tient \xE0 jour,\
\ dans le cadre de l'homologation de s\xE9curit\xE9 pr\xE9vue \xE0 la r\xE8\
gle 3, une analyse de risque de ses syst\xE8mes d'information essentiels (SIE)."
reference_controls:
- urn:intuitem:risk:function:doc-pol:DOC.RISK_REGISTER
translations:
en:
name: null
description: The operator of essential services shall carry out and maintain,
as part of the security approval provided for in Rule 3, a risk analysis
of its critical information systems (EIS).
- urn: urn:intuitem:risk:req_node:nis1-rules-fr:node5
assessable: true
depth: 3
parent_urn: urn:intuitem:risk:req_node:nis1-rules-fr:1
description: "Cette analyse de risque prend notamment en compte l'analyse que\
\ l'op\xE9rateur a men\xE9e pour identifier ses syst\xE8mes d'information\
\ en tant que SIE."
translations:
en:
name: null
description: This risk analysis takes into account the analysis that the
operator has carried out to identify its information systems as EIS.
- urn: urn:intuitem:risk:req_node:nis1-rules-fr:2
assessable: false
depth: 2
parent_urn: urn:intuitem:risk:req_node:nis1-rules-fr:node2
ref_id: '2'
name: "R\xE8gle 2"
description: "Politique de s\xE9curit\xE9"
translations:
en:
name: Rule 2
description: Security Policy
- urn: urn:intuitem:risk:req_node:nis1-rules-fr:2.1
assessable: true
depth: 3
parent_urn: urn:intuitem:risk:req_node:nis1-rules-fr:2
ref_id: '2.1'
description: "L'op\xE9rateur de services essentiels \xE9labore, tient \xE0 jour\
\ et met en \u0153uvre une politique de s\xE9curit\xE9 des r\xE9seaux et syst\xE8\
mes d'information (PSSI)."
reference_controls:
- urn:intuitem:risk:function:doc-pol:POL.RISK
translations:
en:
name: null
description: The operator of essential services shall develop, maintain
and implement a network and information systems security policy (ISSP).
- urn: urn:intuitem:risk:req_node:nis1-rules-fr:2.2
assessable: true
depth: 3
parent_urn: urn:intuitem:risk:req_node:nis1-rules-fr:2
ref_id: '2.2'
description: "La PSSI d\xE9crit l'ensemble des proc\xE9dures et des moyens organisationnels\
\ et techniques mis en \u0153uvre par l'op\xE9rateur afin d'assurer la s\xE9\
curit\xE9 de ses syst\xE8mes d'information essentiels (SIE)."
translations:
en:
name: null
description: The ISSP describes all the procedures and organisational and
technical means implemented by the operator in order to ensure the security
of its essential information systems (EIS).
- urn: urn:intuitem:risk:req_node:nis1-rules-fr:2.3
assessable: false
depth: 3
parent_urn: urn:intuitem:risk:req_node:nis1-rules-fr:2
ref_id: '2.3'
description: "Dans le domaine de la gouvernance de la s\xE9curit\xE9, la PSSI\
\ d\xE9finit :"
translations:
en:
name: null
description: 'In the area of security governance, the ISSP defines:'
- urn: urn:intuitem:risk:req_node:nis1-rules-fr:node10
assessable: true
depth: 4
parent_urn: urn:intuitem:risk:req_node:nis1-rules-fr:2.3
description: "- les objectifs et les orientations strat\xE9giques en mati\xE8\
re de s\xE9curit\xE9 des SIE ;"
translations:
en:
name: null
description: '- EIS security objectives and strategic directions;'
- urn: urn:intuitem:risk:req_node:nis1-rules-fr:node11
assessable: true
depth: 4
parent_urn: urn:intuitem:risk:req_node:nis1-rules-fr:2.3
description: "- l'organisation de la gouvernance de la s\xE9curit\xE9 et notamment\
\ les r\xF4les et les responsabilit\xE9s du personnel interne et du personnel\
\ externe (prestataires, fournisseurs, etc.) \xE0 l'\xE9gard de la s\xE9curit\xE9\
\ des SIE ;"
translations:
en:
name: null
description: '- the organization of security governance and in particular
the roles and responsibilities of internal staff and external personnel
(contractors, suppliers, etc.) with regard to the security of EIS;'
- urn: urn:intuitem:risk:req_node:nis1-rules-fr:node12
assessable: true
depth: 4
parent_urn: urn:intuitem:risk:req_node:nis1-rules-fr:2.3
description: "- les plans de sensibilisation \xE0 la s\xE9curit\xE9 des SIE\
\ au profit de l'ensemble du personnel ainsi que des plans de formation \xE0\
\ la s\xE9curit\xE9 des SIE au profit des personnes ayant des responsabilit\xE9\
s particuli\xE8res, notamment les personnes en charge de l'administration\
\ et de la s\xE9curit\xE9 des SIE et les utilisateurs disposant de droits\
\ d'acc\xE8s privil\xE9gi\xE9s aux SIE ;"
translations:
en:
name: null
description: '- EIS security awareness plans for all staff as well as EIS
security training plans for persons with specific responsibilities, including
those in charge of the administration and security of EIS and users with
privileged access rights to EIS;'
- urn: urn:intuitem:risk:req_node:nis1-rules-fr:node13
assessable: true
depth: 4
parent_urn: urn:intuitem:risk:req_node:nis1-rules-fr:2.3
description: "- la proc\xE9dure d'homologation de s\xE9curit\xE9 des SIE ;"
translations:
en:
name: null
description: '- the security approval procedure for EIS;'
- urn: urn:intuitem:risk:req_node:nis1-rules-fr:node14
assessable: true
depth: 4
parent_urn: urn:intuitem:risk:req_node:nis1-rules-fr:2.3
description: "- les proc\xE9dures de contr\xF4le et d'audit de la s\xE9curit\xE9\
\ des SIE, notamment celles mises en \u0153uvre dans le cadre de l'homologation\
\ de s\xE9curit\xE9."
translations:
en:
name: null
description: '- procedures for monitoring and auditing the security of EIS,
including those implemented in the context of security accreditation.'
- urn: urn:intuitem:risk:req_node:nis1-rules-fr:2.4
assessable: false
depth: 3
parent_urn: urn:intuitem:risk:req_node:nis1-rules-fr:2
ref_id: '2.4'
description: "Dans le domaine de la protection, la PSSI d\xE9finit :"
translations:
en:
name: null
description: 'In the area of protection, the ISSP defines:'
- urn: urn:intuitem:risk:req_node:nis1-rules-fr:node16
assessable: true
depth: 4
parent_urn: urn:intuitem:risk:req_node:nis1-rules-fr:2.4
description: "- les mesures de s\xE9curit\xE9 g\xE9n\xE9rales, notamment en\
\ mati\xE8re de gestion et de s\xE9curit\xE9 des ressources mat\xE9rielles\
\ et logicielles des SIE, de contr\xF4le d'acc\xE8s aux SIE, d'exploitation\
\ et d'administration des SIE et de s\xE9curit\xE9 des r\xE9seaux, des postes\
\ de travail et des donn\xE9es ;"
translations:
en:
name: null
description: '- general security measures, including the management and
security of EIS hardware and software resources, access control to EIS,
operation and administration of EIS, and network, workstation and data
security;'
- urn: urn:intuitem:risk:req_node:nis1-rules-fr:node17
assessable: true
depth: 4
parent_urn: urn:intuitem:risk:req_node:nis1-rules-fr:2.4
description: "- les proc\xE9dures et les mesures de s\xE9curit\xE9 physique\
\ et environnementale applicables aux SIE ;"
translations:
en:
name: null
description: '- physical and environmental security procedures and measures
applicable to EFAs;'
- urn: urn:intuitem:risk:req_node:nis1-rules-fr:node18
assessable: true
depth: 4
parent_urn: urn:intuitem:risk:req_node:nis1-rules-fr:2.4
description: "- la proc\xE9dure de maintien en conditions de s\xE9curit\xE9\
\ des ressources des SIE."
translations:
en:
name: null
description: '- the procedure for maintaining the security of EIS resources.'
- urn: urn:intuitem:risk:req_node:nis1-rules-fr:2.5
assessable: false
depth: 3
parent_urn: urn:intuitem:risk:req_node:nis1-rules-fr:2
ref_id: '2.5'
description: "Dans le domaine de la d\xE9fense, la PSSI d\xE9finit :"
translations:
en:
name: null
description: 'In the field of defence, the ISSP defines:'
- urn: urn:intuitem:risk:req_node:nis1-rules-fr:node20
assessable: true
depth: 4
parent_urn: urn:intuitem:risk:req_node:nis1-rules-fr:2.5
description: "- la proc\xE9dure de d\xE9tection des incidents de s\xE9curit\xE9\
\ ;"
translations:
en:
name: null
description: '- the procedure for detecting security incidents;'
- urn: urn:intuitem:risk:req_node:nis1-rules-fr:node21
assessable: true
depth: 4
parent_urn: urn:intuitem:risk:req_node:nis1-rules-fr:2.5
description: "- la proc\xE9dure de traitement des incidents de s\xE9curit\xE9\
."
translations:
en:
name: null
description: '- the procedure for handling security incidents.'
- urn: urn:intuitem:risk:req_node:nis1-rules-fr:2.6
assessable: false
depth: 3
parent_urn: urn:intuitem:risk:req_node:nis1-rules-fr:2
ref_id: '2.6'
description: "Dans le domaine de la r\xE9silience des activit\xE9s, la PSSI\
\ d\xE9finit\_:"
translations:
en:
name: null
description: 'In the area of business resilience, the ISSP defines:'
- urn: urn:intuitem:risk:req_node:nis1-rules-fr:node23
assessable: true
depth: 4
parent_urn: urn:intuitem:risk:req_node:nis1-rules-fr:2.6
description: "- la proc\xE9dure de gestion de crises en cas d'incidents de s\xE9\
curit\xE9 ayant un impact majeur sur les services essentiels de l'op\xE9rateur\
\ ;"
translations:
en:
name: null
description: '- the crisis management procedure in the event of security
incidents having a major impact on the operator''s essential services;'
- urn: urn:intuitem:risk:req_node:nis1-rules-fr:node24
assessable: true
depth: 4
parent_urn: urn:intuitem:risk:req_node:nis1-rules-fr:2.6
description: "- les proc\xE9dures de continuit\xE9 et de reprise d'activit\xE9\
."
translations:
en:
name: null
description: '- Business continuity and disaster recovery procedures.'
- urn: urn:intuitem:risk:req_node:nis1-rules-fr:2.7
assessable: true
depth: 3
parent_urn: urn:intuitem:risk:req_node:nis1-rules-fr:2
ref_id: '2.7'
description: "La PSSI et ses documents d'application sont approuv\xE9s formellement\
\ par la direction de l'op\xE9rateur."
translations:
en:
name: null
description: The ISSP and its application documents are formally approved
by the operator's management.
- urn: urn:intuitem:risk:req_node:nis1-rules-fr:node26
assessable: true
depth: 4
parent_urn: urn:intuitem:risk:req_node:nis1-rules-fr:2.7
description: "L'op\xE9rateur \xE9labore au profit de sa direction, au moins\
\ annuellement, un rapport sur la mise en \u0153uvre de la PSSI et de ses\
\ documents d'application."
translations:
en:
name: null
description: The operator shall prepare a report for the benefit of its
management, at least annually, on the implementation of the ISSP and its
application documents.
- urn: urn:intuitem:risk:req_node:nis1-rules-fr:node27
assessable: true
depth: 4
parent_urn: urn:intuitem:risk:req_node:nis1-rules-fr:2.7
description: "Ce rapport pr\xE9cise notamment l'\xE9tat des lieux des risques,\
\ le niveau de s\xE9curit\xE9 des SIE et les actions de s\xE9curisation men\xE9\
es et pr\xE9vues."
translations:
en:
name: null
description: This report specifies in particular the state of the risks,
the level of security of the EFAs and the security actions carried out
and planned.
- urn: urn:intuitem:risk:req_node:nis1-rules-fr:2.8
assessable: true
depth: 3
parent_urn: urn:intuitem:risk:req_node:nis1-rules-fr:2
ref_id: '2.8'
description: "L'op\xE9rateur tient \xE0 la disposition de l'Agence nationale\
\ de la s\xE9curit\xE9 des syst\xE8mes d'information la PSSI, ses documents\
\ d'application et les rapports sur leur mise en \u0153uvre."
translations:
en:
name: null
description: The operator shall make available to the National Agency for
the Security of Information Systems the PSSI, its application documents
and the reports on their implementation.
- urn: urn:intuitem:risk:req_node:nis1-rules-fr:3
assessable: false
depth: 2
parent_urn: urn:intuitem:risk:req_node:nis1-rules-fr:node2
ref_id: '3'
name: "R\xE8gle 3"
description: "Homologation de s\xE9curit\xE9"
translations:
en:
name: Rule 3
description: Security Approval
- urn: urn:intuitem:risk:req_node:nis1-rules-fr:3.1
assessable: true
depth: 3
parent_urn: urn:intuitem:risk:req_node:nis1-rules-fr:3
ref_id: '3.1'
description: "L'op\xE9rateur de services essentiels proc\xE8de \xE0 l'homologation\
\ de s\xE9curit\xE9 de chaque syst\xE8me d'information essentiel (SIE), en\
\ mettant en \u0153uvre la proc\xE9dure d'homologation pr\xE9vue par sa politique\
\ de s\xE9curit\xE9 des r\xE9seaux et syst\xE8mes d'information."
translations:
en:
name: null
description: The operator of essential services carries out the security
approval of each essential information system (EIS), by implementing the
approval procedure provided for in its network and information systems
security policy.
- urn: urn:intuitem:risk:req_node:nis1-rules-fr:3.2
assessable: true
depth: 3
parent_urn: urn:intuitem:risk:req_node:nis1-rules-fr:3
ref_id: '3.2'
description: "L'homologation d'un syst\xE8me est une d\xE9cision formelle prise\
\ par l'op\xE9rateur qui atteste que les risques pesant sur la s\xE9curit\xE9\
\ de ce syst\xE8me ont \xE9t\xE9 identifi\xE9s et que les mesures n\xE9cessaires\
\ pour le prot\xE9ger sont mises en \u0153uvre. Elle atteste \xE9galement\
\ que les \xE9ventuels risques r\xE9siduels ont \xE9t\xE9 identifi\xE9s et\
\ accept\xE9s par l'op\xE9rateur."
translations:
en:
name: null
description: The approval of a system is a formal decision taken by the
operator that the risks to the safety of the system have been identified
and that the necessary measures to protect it are implemented. It also
certifies that any residual risks have been identified and accepted by
the operator.
- urn: urn:intuitem:risk:req_node:nis1-rules-fr:3.3
assessable: true
depth: 3
parent_urn: urn:intuitem:risk:req_node:nis1-rules-fr:3
ref_id: '3.3'
description: "Dans le cadre de l'homologation, un audit de la s\xE9curit\xE9\
\ du SIE doit \xEAtre r\xE9alis\xE9 conform\xE9ment \xE0 la r\xE8gle 5."
translations:
en:
name: null
description: As part of the approval, a safety audit of the EIS shall be
carried out in accordance with Regulation 5.
- urn: urn:intuitem:risk:req_node:nis1-rules-fr:3.4
assessable: true
depth: 3
parent_urn: urn:intuitem:risk:req_node:nis1-rules-fr:3
ref_id: '3.4'
description: "L'op\xE9rateur prend la d\xE9cision d'homologuer un SIE sur la\
\ base du dossier d'homologation comportant notamment :"
translations:
en:
name: null
description: 'The operator makes the decision to approve an EIS on the basis
of the approval file, which includes, in particular:'
- urn: urn:intuitem:risk:req_node:nis1-rules-fr:node34
assessable: true
depth: 4
parent_urn: urn:intuitem:risk:req_node:nis1-rules-fr:3.4
description: "- l'analyse de risques et les objectifs de s\xE9curit\xE9 du SIE\
\ ;"
translations:
en:
name: null
description: '- the risk analysis and security objectives of the EIS;'
- urn: urn:intuitem:risk:req_node:nis1-rules-fr:node35
assessable: true
depth: 4
parent_urn: urn:intuitem:risk:req_node:nis1-rules-fr:3.4
description: "- les proc\xE9dures et les mesures de s\xE9curit\xE9 appliqu\xE9\
es au SIE ;"
translations:
en:
name: null
description: '- the procedures and security measures applied to the EIS;'
- urn: urn:intuitem:risk:req_node:nis1-rules-fr:node36
assessable: true
depth: 4
parent_urn: urn:intuitem:risk:req_node:nis1-rules-fr:3.4
description: "- les rapports d'audit de la s\xE9curit\xE9 du SIE ;"
translations:
en:
name: null
description: '- EIS security audit reports;'
- urn: urn:intuitem:risk:req_node:nis1-rules-fr:node37
assessable: true
depth: 4
parent_urn: urn:intuitem:risk:req_node:nis1-rules-fr:3.4
description: "- les risques r\xE9siduels et les raisons justifiant leur acceptation."
translations:
en:
name: null
description: '- the residual risks and the reasons for their acceptance.'
- urn: urn:intuitem:risk:req_node:nis1-rules-fr:3.5
assessable: true
depth: 3
parent_urn: urn:intuitem:risk:req_node:nis1-rules-fr:3
ref_id: '3.5'
description: "La validit\xE9 de l'homologation est r\xE9examin\xE9e par l'op\xE9\
rateur au moins tous les trois ans et lors de chaque \xE9v\xE9nement ou \xE9\
volution de nature \xE0 modifier le contexte d\xE9crit dans le dossier d'homologation."
translations:
en:
name: null
description: The validity of the approval shall be reviewed by the operator
at least every three years and at the time of each event or development
likely to change the context described in the approval dossier.
- urn: urn:intuitem:risk:req_node:nis1-rules-fr:node39
assessable: true
depth: 4
parent_urn: urn:intuitem:risk:req_node:nis1-rules-fr:3.5
description: "Chaque r\xE9examen de l'homologation est consign\xE9 dans le dossier\
\ d'homologation."
translations:
en:
name: null
description: Each re-examination of the registration is recorded in the
registration file.
- urn: urn:intuitem:risk:req_node:nis1-rules-fr:node40
assessable: true
depth: 4
parent_urn: urn:intuitem:risk:req_node:nis1-rules-fr:3.5
description: "L'op\xE9rateur proc\xE8de au renouvellement de l'homologation\
\ d\xE8s qu'elle n'est plus valide."
translations:
en:
name: null
description: The operator shall renew the approval as soon as it is no longer
valid.
- urn: urn:intuitem:risk:req_node:nis1-rules-fr:3.6
assessable: true
depth: 3
parent_urn: urn:intuitem:risk:req_node:nis1-rules-fr:3
ref_id: '3.6'
description: "L'op\xE9rateur tient \xE0 la disposition de l'Agence nationale\
\ de la s\xE9curit\xE9 des syst\xE8mes d'information les d\xE9cisions et dossiers\
\ d'homologation."
translations:
en:
name: null
description: The operator shall make decisions and approval files available
to the National Agency for the Security of Information Systems.
- urn: urn:intuitem:risk:req_node:nis1-rules-fr:4
assessable: false
depth: 2
parent_urn: urn:intuitem:risk:req_node:nis1-rules-fr:node2
ref_id: '4'
name: "R\xE8gle 4"
description: Indicateurs
translations:
en:
name: Rule 4
description: Indicators
- urn: urn:intuitem:risk:req_node:nis1-rules-fr:4.1
assessable: true
depth: 3
parent_urn: urn:intuitem:risk:req_node:nis1-rules-fr:4
ref_id: '4.1'
description: "L'op\xE9rateur de services essentiels \xE9value et tient \xE0\
\ jour, pour chaque syst\xE8me d'information essentiel (SIE), les indicateurs\
\ suivants :"
translations:
en:
name: null
description: 'The operator of essential services shall assess and maintain
the following indicators for each critical information system (EIS):'
- urn: urn:intuitem:risk:req_node:nis1-rules-fr:node44
assessable: true
depth: 4
parent_urn: urn:intuitem:risk:req_node:nis1-rules-fr:4.1
description: " des indicateurs relatifs au maintien en conditions de s\xE9curit\xE9\
\ des ressources :"
translations:
en:
name: null
description: ' Indicators relating to the maintenance of resources in a
safe condition:'
- urn: urn:intuitem:risk:req_node:nis1-rules-fr:node45
assessable: true
depth: 4
parent_urn: urn:intuitem:risk:req_node:nis1-rules-fr:4.1
description: " le pourcentage de postes utilisateurs dont les ressources syst\xE8\
mes ne sont pas install\xE9es dans une version support\xE9e par le fournisseur\
\ ou le fabricant ;"
translations:
en:
name: null
description: ' The percentage of user workstations whose system resources
are not installed in a version supported by the vendor or manufacturer.'
- urn: urn:intuitem:risk:req_node:nis1-rules-fr:node46
assessable: true
depth: 4
parent_urn: urn:intuitem:risk:req_node:nis1-rules-fr:4.1
description: " le pourcentage de serveurs dont les ressources syst\xE8mes ne\
\ sont pas install\xE9es dans une version support\xE9e par le fournisseur\
\ ou le fabricant ;"
translations:
en:
name: null
description: ' The percentage of servers whose system resources are not
installed in a version supported by the vendor or manufacturer.'
- urn: urn:intuitem:risk:req_node:nis1-rules-fr:node47
assessable: true
depth: 4
parent_urn: urn:intuitem:risk:req_node:nis1-rules-fr:4.1
description: " des indicateurs relatifs aux droits d'acc\xE8s des utilisateurs\
\ et \xE0 l'authentification des acc\xE8s aux ressources :"
translations:
en:
name: null
description: ' Indicators relating to user access rights and authentication
of access to resources:'
- urn: urn:intuitem:risk:req_node:nis1-rules-fr:node48
assessable: true
depth: 4
parent_urn: urn:intuitem:risk:req_node:nis1-rules-fr:4.1
description: " le pourcentage d'utilisateurs acc\xE9dant au SIE au moyen de\
\ comptes privil\xE9gi\xE9s ;"
translations:
en:
name: null
description: ' the percentage of users accessing the EIS through privileged
accounts;'
- urn: urn:intuitem:risk:req_node:nis1-rules-fr:node49
assessable: true
depth: 4
parent_urn: urn:intuitem:risk:req_node:nis1-rules-fr:4.1
description: " le pourcentage de ressources dont les \xE9l\xE9ments secrets\
\ d'authentification ne peuvent pas \xEAtre modifi\xE9s par l'op\xE9rateur\
\ ;"
translations:
en:
name: null
description: ' The percentage of resources whose authentication secrets
cannot be changed by the operator.'
- urn: urn:intuitem:risk:req_node:nis1-rules-fr:node50
assessable: true
depth: 4
parent_urn: urn:intuitem:risk:req_node:nis1-rules-fr:4.1
description: " des indicateurs relatifs \xE0 l'administration des ressources\
\ :"
translations:
en:
name: null
description: ' Indicators related to the administration of resources:'
- urn: urn:intuitem:risk:req_node:nis1-rules-fr:node51
assessable: true
depth: 4
parent_urn: urn:intuitem:risk:req_node:nis1-rules-fr:4.1
description: " le pourcentage de ressources administr\xE9es dont l'administration\
\ est effectu\xE9e \xE0 partir d'un compte non sp\xE9cifique d'administration\
\ ;"
translations:
en:
name: null
description: ' The percentage of administered resources that are administered
from a non-specific administrative account.'
- urn: urn:intuitem:risk:req_node:nis1-rules-fr:node52
assessable: true
depth: 4
parent_urn: urn:intuitem:risk:req_node:nis1-rules-fr:4.1
description: " le pourcentage de ressources administr\xE9es dont l'administration\
\ ne peut pas \xEAtre effectu\xE9e au travers d'une liaison r\xE9seau physique\
\ ou d'une interface d'administration physique."
translations:
en:
name: null
description: ' The percentage of managed resources that cannot be administered
through a physical network link or physical administration interface.'
- urn: urn:intuitem:risk:req_node:nis1-rules-fr:4.2
assessable: true
depth: 3
parent_urn: urn:intuitem:risk:req_node:nis1-rules-fr:4
ref_id: '4.2'
description: "L'op\xE9rateur pr\xE9cise pour chaque indicateur la m\xE9thode\
\ d'\xE9valuation employ\xE9e et, le cas \xE9ch\xE9ant, la marge d'incertitude\
\ de son \xE9valuation."
translations:
en:
name: null
description: The operator shall specify for each indicator the method of
assessment used and, where appropriate, the margin of uncertainty in its
assessment.
- urn: urn:intuitem:risk:req_node:nis1-rules-fr:node54
assessable: true
depth: 4
parent_urn: urn:intuitem:risk:req_node:nis1-rules-fr:4.2
description: "Lorsqu'un indicateur \xE9volue de fa\xE7on significative par rapport\
\ \xE0 l'\xE9valuation pr\xE9c\xE9dente, l'op\xE9rateur en pr\xE9cise les\
\ raisons."
translations:
en:
name: null
description: When an indicator changes significantly compared to the previous
assessment, the operator specifies the reasons for this.
- urn: urn:intuitem:risk:req_node:nis1-rules-fr:4.3
assessable: true
depth: 3
parent_urn: urn:intuitem:risk:req_node:nis1-rules-fr:4
ref_id: '4.3'
description: "L'op\xE9rateur communique \xE0 l'Agence nationale de la s\xE9\
curit\xE9 des syst\xE8mes d'information, \xE0 sa demande, les indicateurs\
\ mis \xE0 jour sur un support \xE9lectronique."
translations:
en:
name: null
description: The operator shall provide the National Agency for the Security
of Information Systems, at its request, with the updated indicators on
an electronic medium.
- urn: urn:intuitem:risk:req_node:nis1-rules-fr:5
assessable: false
depth: 2
parent_urn: urn:intuitem:risk:req_node:nis1-rules-fr:node2
ref_id: '5'
name: "R\xE8gle 5"
description: "Audits de la s\xE9curit\xE9"
translations:
en:
name: Rule 5
description: Security Audits
- urn: urn:intuitem:risk:req_node:nis1-rules-fr:5.1
assessable: true
depth: 3
parent_urn: urn:intuitem:risk:req_node:nis1-rules-fr:5
ref_id: '5.1'
description: "L'op\xE9rateur de services essentiels r\xE9alise, dans le cadre\
\ de l'homologation de s\xE9curit\xE9 pr\xE9vue \xE0 la r\xE8gle 3, un audit\
\ de la s\xE9curit\xE9 de chaque syst\xE8me d'information essentiel (SIE)"
translations:
en:
name: null
description: The operator of essential services shall, as part of the security
approval provided for in Regulation 3, carry out a security audit of each
critical information system (EIS)
- urn: urn:intuitem:risk:req_node:nis1-rules-fr:node58
assessable: true
depth: 4
parent_urn: urn:intuitem:risk:req_node:nis1-rules-fr:5.1
description: "L'audit doit aussi \xEAtre r\xE9alis\xE9 lors de chaque renouvellement\
\ de l'homologation en prenant notamment en compte les r\xE9sultats de la\
\ mise \xE0 jour de l'analyse de risque du SIE."
translations:
en:
name: null
description: The audit must also be carried out at the time of each renewal
of the accreditation, taking into account in particular the results of
the update of the EIS risk analysis.
- urn: urn:intuitem:risk:req_node:nis1-rules-fr:5.2
assessable: true
depth: 3
parent_urn: urn:intuitem:risk:req_node:nis1-rules-fr:5
ref_id: '5.2'
description: "Cet audit vise \xE0 v\xE9rifier l'application et l'efficacit\xE9\
\ des mesures de s\xE9curit\xE9 du SIE et notamment le respect des pr\xE9\
sentes r\xE8gles de s\xE9curit\xE9."
translations:
en:
name: null
description: The purpose of this audit is to verify the application and
effectiveness of the EIS security measures and in particular compliance
with these safety rules.
- urn: urn:intuitem:risk:req_node:nis1-rules-fr:node60
assessable: true
depth: 4
parent_urn: urn:intuitem:risk:req_node:nis1-rules-fr:5.2
description: "Il doit permettre d'\xE9valuer le niveau de s\xE9curit\xE9 du\
\ SIE au regard des menaces et des vuln\xE9rabilit\xE9s connues et comporte\
\ notamment la r\xE9alisation d'un audit d'architecture, d'un audit de configuration\
\ et d'un audit organisationnel et physique."
reference_controls:
- urn:intuitem:risk:function:doc-pol:POL.AUDIT
translations:
en:
name: null
description: It must make it possible to assess the security level of the
EIS with regard to known threats and vulnerabilities and includes in particular
the performance of an architecture audit, a configuration audit and an
organizational and physical audit.
- urn: urn:intuitem:risk:req_node:nis1-rules-fr:5.3
assessable: true
depth: 3
parent_urn: urn:intuitem:risk:req_node:nis1-rules-fr:5
ref_id: '5.3'
description: "L'op\xE9rateur ou le prestataire mandat\xE9 \xE0 cet effet r\xE9\
alise cet audit en s'appuyant sur les exigences du r\xE9f\xE9rentiel en mati\xE8\
re d'audit de s\xE9curit\xE9 des syst\xE8mes d'information pris en application\
\ de l'article 10 du d\xE9cret n\xB0 2015-350 du 27 mars 2015 modifi\xE9 relatif\
\ \xE0 la qualification des produits de s\xE9curit\xE9 et des prestataires\
\ de service de confiance pour les besoins de la s\xE9curit\xE9 des syst\xE8\
mes d'information."
reference_controls:
- urn:intuitem:risk:function:doc-pol:POL.AUDIT
translations:
en:
name: null
description: The operator or service provider mandated for this purpose
carries out this audit based on the requirements of the reference framework
for information systems security audits adopted pursuant to Article 10
of Decree No. 2015-350 of 27 March 2015, as amended, relating to the
qualification of security products and trust service providers for the
purposes of information system security.
- urn: urn:intuitem:risk:req_node:nis1-rules-fr:5.4
assessable: true
depth: 3
parent_urn: urn:intuitem:risk:req_node:nis1-rules-fr:5
ref_id: '5.4'
description: "A l'issue de l'audit, l'op\xE9rateur ou, le cas \xE9ch\xE9ant,\
\ le prestataire \xE9labore un rapport d'audit qui expose les constatations\
\ sur les mesures appliqu\xE9es et sur le respect des pr\xE9sentes r\xE8gles\
\ de s\xE9curit\xE9."
translations:
en:
name: null
description: At the end of the audit, the operator or, where applicable,
the service provider shall draw up an audit report setting out the findings
on the measures applied and on compliance with these safety rules.
- urn: urn:intuitem:risk:req_node:nis1-rules-fr:node63
assessable: true
depth: 4
parent_urn: urn:intuitem:risk:req_node:nis1-rules-fr:5.4
description: "Le rapport pr\xE9cise si le niveau de s\xE9curit\xE9 atteint est\
\ conforme aux objectifs de s\xE9curit\xE9, compte tenu des menaces et des\
\ vuln\xE9rabilit\xE9s connues."
translations:
en:
name: null
description: The report specifies whether the level of security achieved
is consistent with the security objectives, taking into account known
threats and vulnerabilities.
- urn: urn:intuitem:risk:req_node:nis1-rules-fr:node64
assessable: true
depth: 4
parent_urn: urn:intuitem:risk:req_node:nis1-rules-fr:5.4
description: "Il formule des recommandations pour rem\xE9dier aux \xE9ventuelles\
\ non-conformit\xE9s et vuln\xE9rabilit\xE9s d\xE9couvertes."
translations:
en:
name: null
description: It makes recommendations to address any non-conformities and
vulnerabilities discovered.
- urn: urn:intuitem:risk:req_node:nis1-rules-fr:6
assessable: false
depth: 2
parent_urn: urn:intuitem:risk:req_node:nis1-rules-fr:node2
ref_id: '6'
name: "R\xE8gle 6"
description: Cartographie
translations:
en:
name: Rule 6
description: Cartography
- urn: urn:intuitem:risk:req_node:nis1-rules-fr:6.1
assessable: true
depth: 3
parent_urn: urn:intuitem:risk:req_node:nis1-rules-fr:6
ref_id: '6.1'
description: "L'op\xE9rateur de services essentiels \xE9labore et tient \xE0\
\ jour, pour chaque syst\xE8me d'information essentiel (SIE), les \xE9l\xE9\
ments de cartographie suivants :"
translations:
en:
name: null
description: 'The operator of essential services shall develop and maintain
the following mapping elements for each essential information system (EIS):'
- urn: urn:intuitem:risk:req_node:nis1-rules-fr:node67
assessable: true
depth: 4
parent_urn: urn:intuitem:risk:req_node:nis1-rules-fr:6.1
description: " les noms et les fonctions des applications, supportant les activit\xE9\
s de l'op\xE9rateur, install\xE9es sur le SIE ;"
translations:
en:
name: null
description: ' the names and functions of the applications, supporting the
operator''s activities, installed on the EIS;'
- urn: urn:intuitem:risk:req_node:nis1-rules-fr:node68
assessable: true
depth: 4
parent_urn: urn:intuitem:risk:req_node:nis1-rules-fr:6.1
description: " le cas \xE9ch\xE9ant, les plages d'adresses IP de sortie du SIE\
\ vers internet ou un r\xE9seau tiers, ou accessibles depuis ces r\xE9seaux\
\ ;"
translations:
en:
name: null
description: ' if applicable, IP address ranges from the SIE to or accessible
from the Internet or a third-party network;'
- urn: urn:intuitem:risk:req_node:nis1-rules-fr:node69
assessable: true
depth: 4
parent_urn: urn:intuitem:risk:req_node:nis1-rules-fr:6.1
description: " le cas \xE9ch\xE9ant, les plages d'adresses IP associ\xE9es aux\
\ diff\xE9rents sous-r\xE9seaux composant le SIE ;"
translations:
en:
name: null
description: ' if applicable, the IP address ranges associated with the
different subnets that make up the EIS;'
- urn: urn:intuitem:risk:req_node:nis1-rules-fr:node70
assessable: true
depth: 4
parent_urn: urn:intuitem:risk:req_node:nis1-rules-fr:6.1
description: " la description fonctionnelle et les lieux d'installation du SIE\
\ et de ses diff\xE9rents sous-r\xE9seaux ;"
translations:
en:
name: null
description: ' the functional description and installation locations of
the EIS and its various sub-networks;'
- urn: urn:intuitem:risk:req_node:nis1-rules-fr:node71
assessable: true
depth: 4
parent_urn: urn:intuitem:risk:req_node:nis1-rules-fr:6.1
description: " la description fonctionnelle des points d'interconnexion du SIE\
\ et de ses diff\xE9rents sous-r\xE9seaux avec des r\xE9seaux tiers, notamment\
\ la description des \xE9quipements et des fonctions de filtrage et de protection\
\ mis en \u0153uvre au niveau de ces interconnexions ;"
translations:
en:
name: null
description: ' the functional description of the points of interconnection
of the EIS and its various subnetworks with third-party networks, including
a description of the equipment and the filtering and protection functions
implemented at the level of those interconnections;'
- urn: urn:intuitem:risk:req_node:nis1-rules-fr:node72
assessable: true
depth: 4
parent_urn: urn:intuitem:risk:req_node:nis1-rules-fr:6.1
description: " l'inventaire et l'architecture des dispositifs d'administration\
\ du SIE permettant de r\xE9aliser notamment les op\xE9rations d'installation\
\ \xE0 distance, de mise \xE0 jour, de supervision, de gestion des configurations,\
\ d'authentification ainsi que de gestion des comptes et des droits d'acc\xE8\
s ;"
translations:
en:
name: null
description: ' the inventory and architecture of the EIS management devices
to carry out remote installation, update, supervision, configuration management,
authentication as well as account and access rights management;'
- urn: urn:intuitem:risk:req_node:nis1-rules-fr:node73
assessable: true
depth: 4
parent_urn: urn:intuitem:risk:req_node:nis1-rules-fr:6.1
description: " la liste des comptes disposant de droits d'acc\xE8s privil\xE9\
gi\xE9s au SIE (appel\xE9s \xAB comptes privil\xE9gi\xE9s \xBB). Cette liste\
\ pr\xE9cise pour chaque compte le niveau et le p\xE9rim\xE8tre des droits\
\ d'acc\xE8s associ\xE9s, notamment les comptes sur lesquels portent ces droits\
\ (comptes d'utilisateurs, comptes de messagerie, comptes de processus, etc.)\
\ ;"
translations:
en:
name: null
description: ' the list of accounts with privileged access rights to the
EIS (referred to as "privileged accounts"). This list specifies for each
account the level and scope of the associated access rights, including
the accounts to which these rights relate (user accounts, email accounts,
process accounts, etc.);'
- urn: urn:intuitem:risk:req_node:nis1-rules-fr:node74
assessable: true
depth: 4
parent_urn: urn:intuitem:risk:req_node:nis1-rules-fr:6.1
description: " l'inventaire, l'architecture et le positionnement des services\
\ de r\xE9solution de noms d'h\xF4te, de messagerie, de relais internet et\
\ d'acc\xE8s distant mis en \u0153uvre par le SIE."
translations:
en:
name: null
description: ' the inventory, architecture, and positioning of hostname
resolution, messaging, Internet relay, and remote access services implemented
by the EIS.'
- urn: urn:intuitem:risk:req_node:nis1-rules-fr:6.2
assessable: true
depth: 3
parent_urn: urn:intuitem:risk:req_node:nis1-rules-fr:6
ref_id: '6.2'
description: "L'op\xE9rateur communique \xE0 l'Agence nationale de la s\xE9\
curit\xE9 des syst\xE8mes d'information, \xE0 sa demande, les \xE9l\xE9ments\
\ de cartographie mis \xE0 jour sur un support \xE9lectronique."
translations:
en:
name: null
description: The operator shall provide the National Agency for the Security
of Information Systems, at its request, with the updated mapping elements
on an electronic medium.
- urn: urn:intuitem:risk:req_node:nis1-rules-fr:node76
assessable: false
depth: 1
name: Chapitre II
description: "R\xE8gles relatives \xE0 la protection des r\xE9seaux et syst\xE8\
mes d'information"
reference_controls:
- urn:intuitem:risk:function:mitre-attack:M1026
translations:
en:
name: Chapter II
description: Rules relating to the protection of networks and information
systems
- urn: urn:intuitem:risk:req_node:nis1-rules-fr:node77
assessable: false
depth: 2
parent_urn: urn:intuitem:risk:req_node:nis1-rules-fr:node76
name: Section II.1
description: "S\xE9curit\xE9 de l'architecture"
translations:
en:
name: Section II.1
description: Architecture Security
- urn: urn:intuitem:risk:req_node:nis1-rules-fr:7
assessable: false
depth: 3
parent_urn: urn:intuitem:risk:req_node:nis1-rules-fr:node77
ref_id: '7'
name: "R\xE8gle 7"
description: Configuration