How can ManageEngine support NIS2UmsG compliance?
With ManageEngine Log360, organizations can align with NIS2UmsG requirements through centralized log collection and correlation across the systems that support essential services, continuous auditing of who accessed which systems and when, real-time detection of significant security incidents with automated alerting and SOAR-driven containment to support the 24-hour, 72-hour, and one-month reporting timelines to the BSI, MITRE ATT&CK-mapped attack detection and UEBA for critical installations, file integrity monitoring over critical systems, and secure, tamper-evident log retention with audit-ready reporting. These capabilities help implement the risk management measures under § 30, satisfy the attack-detection duty under § 31, and produce the incident evidence and proof of compliance expected under §§ 32 and 39.
§ 30§ 30 Risk management measures for essential and important entities
| Clause | Functionality | Explanation |
|---|---|---|
| (2) Nr. 1 Policies on risk analysis and on the security of information technology. | Log360 - real-time security analytics, correlation engine, risk posture management, 1,000+ compliance report templates | Log360 supports the information-security-policy requirement by continuously analysing and correlating events, surfacing misconfigurations through risk posture management, and evidencing controls with prebuilt report templates. The risk-analysis methodology itself remains an organisational process the entity defines. |
| (2) Nr. 2 Handling of security incidents. | Log360 - correlation engine, ML-driven UEBA, SOAR incident-response workflows, Incident Workbench, threat intelligence | Log360 detects incidents through correlation and UEBA, then contains them with automated SOAR workflows that disable accounts, isolate endpoints, and block IP addresses, while the Incident Workbench guides investigation and recovery. This covers the prevent, detect, investigate, and recover cycle the clause requires. |
| (2) Nr. 4 Supply chain security, including security-related aspects of relationships with direct suppliers and service providers. | Log360 - multi-source log collection, cloud security monitoring, privileged-access auditing | Log360 preserves visibility over supplier-operated components by collecting and analysing logs from hosted, outsourced, and cloud environments and auditing third-party privileged access. Contractual supplier assurance is an organisational control outside Log360. |
| (2) Nr. 5 Security in the acquisition, development, and maintenance of systems, including vulnerability handling and disclosure. | Log360 - risk posture management, file integrity monitoring, vulnerability-related alerting | Log360 addresses the maintenance and vulnerability-handling portion by detecting misconfigurations and exposure points and monitoring critical files for unauthorised change. Secure development practices during acquisition and build are process controls Log360 does not perform. |
| (2) Nr. 6 Concepts and procedures to assess the effectiveness of risk management measures. | Log360 - audit-ready compliance reporting, real-time security analytics, dashboards | Log360 provides the monitoring evidence and metrics used to assess control effectiveness, with prebuilt reports and dashboards that measure detection outcomes over time for the security-monitoring domain. |
| (2) Nr. 7 Basic cyber hygiene and information security training. | Log360 - real-time logon auditing, privileged-user auditing | Log360 evidences account hygiene by auditing logon activity and privileged-account use across the monitored estate. The security-training element of the clause is a personnel measure Log360 does not provide. |
| (2) Nr. 9 Concepts for personnel security, access control, and the management of IT assets. | Log360 - privileged-user auditing, log-source and device discovery, change auditing | Log360 supports the access-control-oversight and asset-visibility portions by auditing privileged activity, auditing changes, and discovering log sources and devices across the estate. Formal IT-asset lifecycle management and HR processes fall outside Log360. |
§ 31§ 31 Special requirements for operators of critical installations
| Clause | Functionality | Explanation |
|---|---|---|
| (2) Use attack detection systems that continuously and automatically capture and evaluate parameters from live operation to identify and avoid threats. | Log360 - Vigil IQ TDIR with 2,000+ MITRE ATT&CK-mapped detections, correlation rules, ML-driven UEBA, threat intelligence, real-time alerting | Log360 provides the attack-detection systems the clause mandates for critical installations, continuously and automatically evaluating live telemetry against MITRE-mapped detections and behavioural baselines and alerting on identified threats. |
§ 32§ 32 Reporting obligations
| Clause | Functionality | Explanation |
|---|---|---|
| (1) Nr. 1 Early warning within 24 hours of becoming aware of a significant security incident, indicating suspected unlawful/malicious cause or cross-border effects. | Log360 - real-time alerting, anomaly detection, automated response workflows | Log360 flags significant incidents as they occur and can trigger notification and containment automatically, enabling the 24-hour early warning within the deadline. The regulatory submission to the BSI is performed by the entity. |
| (1) Nr. 2 Notification within 72 hours confirming or updating the early warning with an initial assessment of severity, impact, and indicators of compromise. | Log360 - Incident Workbench, AI-automated incident timelines, correlation-based severity scoring | Log360 consolidates severity, impact, and indicators of compromise and reconstructs incident timelines, producing the assessment needed for the 72-hour notification. |
| (1) Nr. 4 Final report within one month describing the incident, its severity and impact, its likely cause, and remediation. | Log360 - root-cause investigation with process-lineage visuals, audit-ready reporting | Log360 establishes likely cause through process-lineage investigation and generates the documented record of severity, impact, and remediation required for the one-month final report. |
§ 39§ 39 Proof of compliance for operators of critical installations
| Clause | Functionality | Explanation |
|---|---|---|
| (1) Demonstrate implementation of risk management measures to the BSI through security audits, tests, or certifications, and every three years thereafter. | Log360 - audit-ready compliance reporting, tamper-proof logs, searchable archive | Log360 produces the audit-ready reports, tamper-proof logs, and searchable evidence that support the periodic proof of implementation to the BSI. The audit, test, or certification itself is performed by an external assessor, not by Log360. |

