Case study: The decision-support framework and NIS2, CER, and DORA incident reporting obligations
Authors
Date
2024Copyright
© The Author(s)
The European Union is committed to enhancing cybersecurity across its Member States by introducing legislation that impacts organizations cybersecurity preparedness. These laws include the Network and Information Security 2 Directive (NIS2), the Critical Entities Resilience Directive (CER), and the Digital Operational Resilience Act (DORA). These legislations mandate that organizations report cyber incidents to authorities. Currently, there are few guidelines available to help organizations understand how to report incidents to authorities. With the new legislations, it becomes even more crucial for organizations to comprehend how to report cyber incidents effectively to authorities. This research aims to determine do organizations current practices align with the decision-support framework and does the new legislations warrant adaptions to the framework in question. This thesis was conducted as a case study, beginning with a comprehensive literature review on existing research on incident reporting and the legislations. Data was gathered through semi-structured interviews with cybersecurity professionals who have observed cybersecurity exercises simulating real-life cyber incidents. The data was analyzed using deductive coding. The results indicate that the decision-support framework partially corresponds to real-life operations; however, the specifics vary depending on the particular incident and the organization's processes. The key findings highlight that clear roles and responsibilities, established communication paths, a diverse team, and knowledgeable individuals in the core group related to the incident are essential. These team members must understand the legislative obligations and have experience in incident management, making sure that the organization can effectively handle the complexities of reporting under the new legislations.
...
Metadata
Show full item recordCollections
- Pro gradu -tutkielmat [29561]
License
Related items
Showing items with similar title or keywords.
-
Framework for governmental research institution’s sustainability report
Saarinen, Ronja (2021)Tämän tutkimuksen tavoitteena on luoda rakenne Suomen ympäristökeskuksen (SYKE) ensimmäiseen vastuullisuusraporttiin. SYKEn toiminta on yhteiskunnallisesti merkittävää, jatkuvaa ja kauas tulevaisuuteen tähtäävää, joten ... -
How modeling helps in developing self-sovereign identity governance framework : An experience report
Sroor, Maha; Hickman, Nicky; Kolehmainen, Taija; Laatikainen, Gabriella; Abrahamsson, Pekka (Elsevier, 2022)Digital Identity has become a topic that attracts the attention of researchers due to the enormous number of services that have been provided online recently. Researchers face many obstacles regarding the security, privacy, ... -
Modeling a first-stage sustainability reporting framework for Finnish SME sector knowledge organizations
Teittinen, Harri (2022)Tiivistelmä Vastuullisuutta ja siihen liittyvää raportointia koskevia velvoitteita yrityksiä kohtaan kiristetään sekä lainsäädännön että arvoketjujen odotusten vuoksi. Resurssien ja osaamisen erot näkyvät kestävien ... -
A whole-school intervention framework for enhancing social and emotional skills in secondary schools through arts-integrated practices : Research report from the REIMAGINED project
Yada, Takumi; Fenyvesi, Kristof (Jyväskylän yliopisto, Koulutuksen tutkimuslaitos, 2023)The 21st century demands a shift towards social and emotional education (SEE). The REIMAGINED project’s report provides an intervention framework that addresses training needs, assesses students’ needs, emphasizes interactive ... -
Creative Improvisations with Information and Communication Technology to Support Learning : A Conceptual and Developmental Framework
Vesisenaho, Mikko; Dillon, Patrick; Havu-Nuutinen, Sari; Nousiainen, Tuula; Valtonen, Teemu; Wang, RuoLan (Uludag University, 2017)This article is about facilitating collaborative, creative improvisations in learning with Information and Communication Technologies (ICT) and in so doing enhancing under-utilised creative possibilities in education and ...