r/ISO27001 17h ago

🛠 Implementation Help How do you handle the overlap between NIS2, GDPR and ISO 27001?

6 Upvotes

Many Swedish organisations currently need to work with several sets of requirements at the same time. It's easy to end up creating a separate project, a separate checklist and new governance documents for each regulation.

At the same time, many areas overlap, for example risk management, incident management, supplier governance, accountability and documentation.

One alternative is to first establish a common control structure, and then map each requirement to existing processes, controls and responsibilities.

How do you work with this? Do you have a shared governance model, or do you handle each regulation separately? Which parts have been hardest to align?