Näytä suppeat kuvailutiedot

Legislation within cybersecurity: preparing for NIS2 – a detailed framework in the healthcare sector in the Netherlands

van Welie, Alwin (2024-07-29)

dc.contributor.authorvan Welie, Alwin
dc.date.accessioned2024-08-19T21:04:50Z
dc.date.available2024-08-19T21:04:50Z
dc.date.issued2024-07-29
dc.identifier.urihttps://www.utupub.fi/handle/10024/178884
dc.description.abstractCybersecurity is becoming increasingly important for organizations, particularly in the healthcare sector. In 2023, the healthcare sector was the third most attacked sector of all sectors. Preventing and preparing for cybersecurity incidents is critical in the current digital landscape. The NIS2 Directive is the EU9s answer to a more cyber resilient Europe. Preparing to become compliant is not only difficult since the directive has not officially been published yet, but also because compliance is mandatory with the set deadline of the 17th of October, 2024. Non-compliance means big fines which can reach heights as big as 2% of the annual revenue of organizations, or €10 million alternatively. Preventing and preparing for cybersecurity risks is key for the continuation of daily operations. Healthcare organizations do not know how to properly prepare for the NIS2 Directive, nor is there a detailed framework or overview available which specifically addresses the gaps between currently taken measures and yet to be taken measures. This asks for an in-depth gap review of the currently available information regarding the NIS2 Directive to come up with specific controls to prepare for compliance for the healthcare sector, which is what this thesis aimed to do. By using the Design Science approach, a framework for the Dutch healthcare sector was developed. The framework is created based on a gap analysis. Six gaps were found: incident management, standardized reporting, contact with the CSIRT, standardized impact assessment, mandatory cybersecurity education for management and supply chain cybersecurity assessment. The framework is created based on three iterations, where IT audit, cybersecurity and healthcare experts were interviewed. A NIS2 research involving a thorough understanding of the NIS2 Directive was done to understand the NIS2 Directive9s context. A literature review and analysis of frameworks which are often used in IT auditing was then conducted. These frameworks provide the baseline for the created controls for the gaps which were found in a gap analysis between the Dutch healthcare cybersecurity standard NEN 7510 and the NIS2 Directive. The developed framework is verified by ten expert interviews and later validated with two interviews. Required controls in the framework are based on maturity levels to reflect the current level of cybersecurity measures combined with different risk levels within different healthcare organizations.
dc.format.extent158
dc.language.isoeng
dc.rightsfi=Julkaisu on tekijänoikeussäännösten alainen. Teosta voi lukea ja tulostaa henkilökohtaista käyttöä varten. Käyttö kaupallisiin tarkoituksiin on kielletty.|en=This publication is copyrighted. You may download, display and print it for Your own personal use. Commercial use is prohibited.|
dc.subjectNIS2 Directive, cybersecurity, maturity, controls, framework, healthcare, Cyberbeveiligingswet (Cbw), legislation,
dc.titleLegislation within cybersecurity: preparing for NIS2 – a detailed framework in the healthcare sector in the Netherlands
dc.type.ontasotfi=Pro gradu -tutkielma|en=Master's thesis|
dc.rights.accessrightsavoin
dc.identifier.urnURN:NBN:fi-fe2024081965472
dc.contributor.facultyfi=Turun kauppakorkeakoulu|en=Turku School of Economics|
dc.contributor.studysubjectfi=Tietojärjestelmätiede|en=Information Systems Science|
dc.contributor.departmentfi=Johtamisen ja yrittäjyyden laitos|en=Department of Management and Entrepreneurship|


Aineistoon kuuluvat tiedostot

Thumbnail

Aineisto kuuluu seuraaviin kokoelmiin

Näytä suppeat kuvailutiedot