A comprehensive analysis of the NIS2 implementation in international companies in Finland through the ISO/IEC 27001 framework
| dc.contributor.author | Abrar, Ehsanul | |
| dc.contributor.department | fi=Tietotekniikan laitos|en=Department of Computing| | |
| dc.contributor.faculty | fi=Teknillinen tiedekunta|en=Faculty of Technology| | |
| dc.contributor.studysubject | fi=Tietotekniikka|en=Information and Communication Technology| | |
| dc.date.accessioned | 2026-08-04T19:31:32Z | |
| dc.date.issued | 2026-07-31 | |
| dc.description.abstract | This MSc thesis investigates how international companies operating in Finland can implement the EU’s NIS2 Directive using the ISO/IEC 27001:2022 framework as their primary compliance instrument. Through a systematic, control-by-control mapping between NIS2 provisions-particularly risk management (Article 21), incident reporting (Article 23), and supply chain security (Article 21(2)(d))-and the 93 controls of ISO 27001, the study identifies direct alignments, partial overlaps, and complete gaps. The analysis reveals that approximately 63.6% of NIS2’s risk management requirements are fully addressed by existing ISO controls, while critical gaps remain in binding incident reporting timelines (24-hour, 72-hour, and one-month deadlines), multi-factor authentication prescriptiveness, individual supplier vulnerability assessment granularity, and management liability. To address these gaps, the thesis proposes six supplementary measures (S1-S6), including a dedicated NIS2 incident reporting procedure, mandatory MFA policy, per-supplier vulnerability assessment templates, and formalised management accountability. The outcome is an evidence-based, phased implementation model that enables organisations to extend their existing Information Security Management Systems (ISMS) for full NIS2 compliance without requiring re-certification. The findings provide actionable insights for practitioners navigating the evolving regulatory landscape in Finland, particularly in light of the national implementation proposal HE 57/2024, and contribute to the broader academic discourse on standard-regulation alignment in cybersecurity governance. | |
| dc.format.extent | 91 | |
| dc.identifier.uri | https://www.utupub.fi/handle/11111/62879 | |
| dc.identifier.urn | URN:NBN:fi-fe20260804115121 | |
| dc.language.iso | eng | |
| dc.rights | fi=Julkaisu on tekijänoikeussäännösten alainen. Teosta voi lukea ja tulostaa henkilökohtaista käyttöä varten. Käyttö kaupallisiin tarkoituksiin on kielletty.|en=This publication is copyrighted. You may download, display and print it for Your own personal use. Commercial use is prohibited.| | |
| dc.rights.accessrights | avoin | |
| dc.subject | NIS2 Directive | |
| dc.subject | ISO/IEC 27001 | |
| dc.subject | information security management systems (ISMS) | |
| dc.subject | cybersecurity regulation | |
| dc.subject | compliance implementation | |
| dc.subject | information security | |
| dc.subject | risk management | |
| dc.title | A comprehensive analysis of the NIS2 implementation in international companies in Finland through the ISO/IEC 27001 framework | |
| dc.type.ontasot | fi=Diplomityö|en=Master's thesis| |
Tiedostot
1 - 1 / 1