A comprehensive analysis of the NIS2 implementation in international companies in Finland through the ISO/IEC 27001 framework

avoin
Julkaisu on tekijänoikeussäännösten alainen. Teosta voi lukea ja tulostaa henkilökohtaista käyttöä varten. Käyttö kaupallisiin tarkoituksiin on kielletty.
Lataukset6

Verkkojulkaisu

DOI

Tiivistelmä

This MSc thesis investigates how international companies operating in Finland can implement the EU’s NIS2 Directive using the ISO/IEC 27001:2022 framework as their primary compliance instrument. Through a systematic, control-by-control mapping between NIS2 provisions-particularly risk management (Article 21), incident reporting (Article 23), and supply chain security (Article 21(2)(d))-and the 93 controls of ISO 27001, the study identifies direct alignments, partial overlaps, and complete gaps. The analysis reveals that approximately 63.6% of NIS2’s risk management requirements are fully addressed by existing ISO controls, while critical gaps remain in binding incident reporting timelines (24-hour, 72-hour, and one-month deadlines), multi-factor authentication prescriptiveness, individual supplier vulnerability assessment granularity, and management liability. To address these gaps, the thesis proposes six supplementary measures (S1-S6), including a dedicated NIS2 incident reporting procedure, mandatory MFA policy, per-supplier vulnerability assessment templates, and formalised management accountability. The outcome is an evidence-based, phased implementation model that enables organisations to extend their existing Information Security Management Systems (ISMS) for full NIS2 compliance without requiring re-certification. The findings provide actionable insights for practitioners navigating the evolving regulatory landscape in Finland, particularly in light of the national implementation proposal HE 57/2024, and contribute to the broader academic discourse on standard-regulation alignment in cybersecurity governance.

item.page.okmtext