A comprehensive analysis of the NIS2 implementation in international companies in Finland through the ISO/IEC 27001 framework

dc.contributor.authorAbrar, Ehsanul
dc.contributor.departmentfi=Tietotekniikan laitos|en=Department of Computing|
dc.contributor.facultyfi=Teknillinen tiedekunta|en=Faculty of Technology|
dc.contributor.studysubjectfi=Tietotekniikka|en=Information and Communication Technology|
dc.date.accessioned2026-08-04T19:31:32Z
dc.date.issued2026-07-31
dc.description.abstractThis MSc thesis investigates how international companies operating in Finland can implement the EU’s NIS2 Directive using the ISO/IEC 27001:2022 framework as their primary compliance instrument. Through a systematic, control-by-control mapping between NIS2 provisions-particularly risk management (Article 21), incident reporting (Article 23), and supply chain security (Article 21(2)(d))-and the 93 controls of ISO 27001, the study identifies direct alignments, partial overlaps, and complete gaps. The analysis reveals that approximately 63.6% of NIS2’s risk management requirements are fully addressed by existing ISO controls, while critical gaps remain in binding incident reporting timelines (24-hour, 72-hour, and one-month deadlines), multi-factor authentication prescriptiveness, individual supplier vulnerability assessment granularity, and management liability. To address these gaps, the thesis proposes six supplementary measures (S1-S6), including a dedicated NIS2 incident reporting procedure, mandatory MFA policy, per-supplier vulnerability assessment templates, and formalised management accountability. The outcome is an evidence-based, phased implementation model that enables organisations to extend their existing Information Security Management Systems (ISMS) for full NIS2 compliance without requiring re-certification. The findings provide actionable insights for practitioners navigating the evolving regulatory landscape in Finland, particularly in light of the national implementation proposal HE 57/2024, and contribute to the broader academic discourse on standard-regulation alignment in cybersecurity governance.
dc.format.extent91
dc.identifier.urihttps://www.utupub.fi/handle/11111/62879
dc.identifier.urnURN:NBN:fi-fe20260804115121
dc.language.isoeng
dc.rightsfi=Julkaisu on tekijänoikeussäännösten alainen. Teosta voi lukea ja tulostaa henkilökohtaista käyttöä varten. Käyttö kaupallisiin tarkoituksiin on kielletty.|en=This publication is copyrighted. You may download, display and print it for Your own personal use. Commercial use is prohibited.|
dc.rights.accessrightsavoin
dc.subjectNIS2 Directive
dc.subjectISO/IEC 27001
dc.subjectinformation security management systems (ISMS)
dc.subjectcybersecurity regulation
dc.subjectcompliance implementation
dc.subjectinformation security
dc.subjectrisk management
dc.titleA comprehensive analysis of the NIS2 implementation in international companies in Finland through the ISO/IEC 27001 framework
dc.type.ontasotfi=Diplomityö|en=Master's thesis|

Tiedostot

Näytetään 1 - 1 / 1
Ladataan...
Name:
Thesis-Abrar-Ehsanul.pdf
Size:
1.56 MB
Format:
Adobe Portable Document Format