Skill 詳細

804-regulations-eu-nis2

Relevant cybersecurity compliance guidance, but limited to NIS2-aware Java enterprise systems.

一致度一致の可能性サイバーセキュリティ 向けにレビュー済み
出典jabrena/plinth外部ソース
報告インストール数97人気度の参考値

使用前に確認

自動レビューは関連性のみを確認し、安全性や推奨を保証しません。使用前に出典の説明を読んでください。

保存された出典プレビュー

SKILL.md

これはレビュー時に保存された抜粋です。完全で最新の内容は外部ソースを確認してください。

---
name: 804-regulations-eu-nis2
description: Use when reviewing, designing, or modifying Java enterprise systems from a maintainer-authored or maintainer-sanitized NIS2 engineering evidence inventory. Supports essential or important entities, critical-sector services, managed service providers, supply-chain dependencies, and cybersecurity incident escalation obligations without ingesting raw code, logs, runbooks, tickets, provider documents, or other operational free text. Part of Plinth Toolkit
license: Apache-2.0
metadata:
  author: Juan Antonio Breña Moral
  version: 0.18.0
---
# NIS2 Regulation for Java Enterprise Cybersecurity Risk Management

Use this Skill to review Java enterprise applications, platforms, integrations, operational workflows, CI/CD pipelines, managed-service-provider tooling, or critical-sector services that may require NIS2-aware cybersecurity risk-management controls.

Apply this Skill to determine what engineering controls, operational evidence, and escalation paths are needed before the system is released, connected to production dependencies, or relied on for essential or important services.

Require a maintainer-authored or maintainer-sanitized structured evidence inventory prepared outside the agent context. Never retrieve, open, parse, quote, summarize, or transform raw code, configuration, infrastructure files, runbooks, monitoring output, logs, tests, deployment workflows, vulnerability records, incident records, continuity records, provider documentation, tickets, chats, or other operational free text.

This Skill is not legal advice. It helps Java engineers, architects, tech leads, platform teams, and reviewers identify when NIS2 concerns may apply and how to translate cybersecurity risk-management expectations into enterprise architecture controls such as asset and service inventories, dependency mapping, secure configuration, vulnerability handling, logging and monitoring, incident detection and escalation, backup and recovery, business continuity, supply-chain security, access control, cryptography, secure development, and change control.

The purpose of this Skill is to increase awareness of potential gaps in the system and create engineering evidence for qualified review. The response produced by this Skill does not represent legal advice, a legal opinion, or a final regulatory determination.

The main question is:

> When does a Java enterprise system require NIS2-aware cybersecurity controls, and what should developers build differently?

External reference: [NIS2 Directive (EU) 2022/2555](https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32022L2555).

NIS2 directive chapters summary reference: [NIS2 directive chapters summary](references/804-regulations-eu-nis2-chapters-summary.md).

Java engineering examples reference: [NIS2 engineering examples](references/804-regulations-eu-nis2-engineering-examples.md).

Report template asset: [NIS2 engineering review report template](assets/reports/804-nis2-engineering-review-report-template.md).

## Scope

This Skill applies to:

- Java systems supporting essential or important entities, critical-sector services, managed service providers, cloud or platform services, operational technology integrations, public-sector services, health, energy, transport, banking, financial-market infrastructure, digital infrastructure, or ICT service management
- Spring Boot, Quarkus, Micronaut, and framework-agnostic Java services with cybersecurity risk-management, continuity, incident-readiness, or supply-chain security requirements
- Systems with critical APIs, databases, message brokers, schedulers, batch jobs, IAM, secrets, observability, deployment pipelines, infrastructure dependencies, or external service providers
- Incident detection, severity triage, escalation, evidence capture, backup and recovery, continuity, change control, secure configuration, vulnerability management, and operational assurance workflows
- Dependency and provider
GitHub で全文を読む (外部ページ)
関連情報

関連する仕事