Användning av ISO 27001 för efterlevnad av NIS2: En jämförande kartläggning mellan ISO 27001 och NIS2
2025 (Swedish)Independent thesis Basic level (degree of Bachelor), 10 credits / 15 HE credits
Student thesisAlternative title
Using ISO 27001 for NIS2 Compliance : A Comparative Mapping Between ISO 27001 and NIS2 (English)
Abstract [sv]
Syftet med denna studie är att beskriva och förklara hur ISO 27001 kan användas för att uppfylla kraven i NIS2-direktivet som specificeras i artikel 21.2 och tydliggörs i Kommissionens Genomförandeförordning (KGF). För att uppnå detta har en kvalitativ metodologisk ansats tillämpats, där en triangulering genomförts genom en kombination av dokumentstudie och expertintervjuer. Dokumentstudien utgör studiens grund och består av en detaljerad kartläggning mellan specifikationerna i KGF och ISO 27001, där varje enskild specifikation har analyserats och mappats mot relevanta delar av standarden. Expertintervjuerna kompletterar den teoretiska analysen med praktiska erfarenheter och yrkesperspektiv. Resultatet visar att ISO 27001 till stor del uppfyller de tekniska specifikationerna i KGF: 66 % bedöms vara helt uppfyllda, 18 % delvis och 16 % inte alls. Kartläggningen visar att ISO 27001 i hög grad täcker områden som rör riskhantering, organisatorisk säkerhet samt personalrelaterade säkerhetsrutiner men är svagare inom operativa och teknikspecifika områden. Slutsatsen är att ISO 27001 erbjuder en systematisk och etablerad standard som stödjer implementeringen av NIS2, men att ytterligare anpassningar krävs för fullständig efterlevnad, något som även bekräftas av expertintervjuerna. Studien bygger på tolkningar av hur ISO 27001 motsvarar specifikationerna i KGF, vilket kan innebära viss subjektivitet. Trots detta bidrar studien till en fördjupad förståelse för sambandet mellan ISO 27001 och NIS2, vilket lägger en värdefull grund för vidare forskning.
Abstract [en]
The purpose of this study is to describe and explain how ISO 27001 can be used to meet the requirements in Article 21.2 of the NIS2 Directive, that is clarified in the Commission’s Implementing Regulation (CIR). To achieve this, a qualitative methodological approach has been applied, incorporating triangulation through a combination of document study and expert interviews. The document study forms the foundation of the research and consists of a detailed mapping between the specifications in the CIR and ISO 27001, in which each individual specification has been analyzed and mapped against relevant parts of the standard. The expert interviews complement the theoretical analysis with practical insights and professional perspectives. The results show that ISO 27001 largely meets the technical specifications in the CIR: 66% are assessed as fully met, 18% as partially met, and 16% as not met at all. The mapping indicates that ISO 27001 strongly covers areas related to risk management, organizational security, and personnel-related security procedures, but is weaker in operational and technically specific domains. The conclusion is that ISO 27001 offers a systematic and established framework that supports the implementation of NIS2, but additional adaptations are required to ensure full compliance, which is also confirmed by the expert interviews. The study is based on interpretations of how ISO 27001 corresponds to the specifications in the CIR, which may involve a degree of subjectivity. Nonetheless, the study contributes to a deeper understanding of the relationship between ISO 27001 and NIS2, providing a valuable foundation for further research.
Place, publisher, year, edition, pages
2025. , p. 54
Keywords [en]
Commission’s Implementing Regulation (CIR), Compliance, Information Security, ISO 27001, Mapping, NIS Directive, NIS2 Directive.
Keywords [sv]
Efterlevnad, Informationssäkerhet, ISO 27001, Kartläggning, Kommissionens genomförandeförordning (KGF), NIS-direktivet, NIS2-direktivet.
National Category
Information Systems Information Systems, Social aspects
Identifiers
URN: urn:nbn:se:hj:diva-68554OAI: oai:DiVA.org:hj-68554DiVA, id: diva2:1969948
Subject / course
JTH, Informatics
Supervisors
Examiners
2025-06-172025-06-162025-10-13Bibliographically approved