Mapping AegiFlow evidence to NIS2 measures
Which Article 21 risk-management measures AegiFlow produces operational evidence for, and where each proof lives.
You can point an auditor to the concrete evidence behind each mapped measure.
The mapping
Incident handling maps to correlated cases with accountable timelines. Business continuity maps to signed static continuity bundles. Backup and disaster recovery map to recovery drills with retained receipts. Supply-chain security maps to the signed software inventory matched against public advisories. Effectiveness assessment maps to capability states with freshness.
Where the evidence lives
Cases and their timelines sit under Cases; drill receipts under Recovery; inventory and coverage under Threat Radar; capability freshness on every surface. Exports carry the same records your dashboard shows.
The honest boundary
AegiFlow provides operational evidence, not legal advice, and no tool makes an organization compliant by itself. The compliance determination remains with your organization and its advisors - what AegiFlow removes is the scramble to reconstruct proof.
Verification
- Each mapped measure links to a live surface of the dashboard
- Missing evidence is displayed as Unknown
- not omitted