Case study: The decision-support framework and NIS2, CER, and DORA incident reporting obligations

The European Union is committed to enhancing cybersecurity across its Member States by introducing legislation that impacts organizations cybersecurity preparedness. These laws include the Network and Information Security 2 Directive (NIS2), the Critical Entities Resilience Directive (CER), and the...

Full description

Bibliographic Details
Main Author: Boddy, Sara Elizabeth
Other Authors: Faculty of Information Technology, Informaatioteknologian tiedekunta, Jyväskylän yliopisto, University of Jyväskylä
Format: Master's thesis
Language:eng
Published: 2024
Subjects:
Online Access: https://jyx.jyu.fi/handle/123456789/95795
_version_ 1826225731486613504
author Boddy, Sara Elizabeth
author2 Faculty of Information Technology Informaatioteknologian tiedekunta Jyväskylän yliopisto University of Jyväskylä
author_facet Boddy, Sara Elizabeth Faculty of Information Technology Informaatioteknologian tiedekunta Jyväskylän yliopisto University of Jyväskylä Boddy, Sara Elizabeth Faculty of Information Technology Informaatioteknologian tiedekunta Jyväskylän yliopisto University of Jyväskylä
author_sort Boddy, Sara Elizabeth
datasource_str_mv jyx
description The European Union is committed to enhancing cybersecurity across its Member States by introducing legislation that impacts organizations cybersecurity preparedness. These laws include the Network and Information Security 2 Directive (NIS2), the Critical Entities Resilience Directive (CER), and the Digital Operational Resilience Act (DORA). These legislations mandate that organizations report cyber incidents to authorities. Currently, there are few guidelines available to help organizations understand how to report incidents to authorities. With the new legislations, it becomes even more crucial for organizations to comprehend how to report cyber incidents effectively to authorities. This research aims to determine do organizations current practices align with the decision-support framework and does the new legislations warrant adaptions to the framework in question. This thesis was conducted as a case study, beginning with a comprehensive literature review on existing research on incident reporting and the legislations. Data was gathered through semi-structured interviews with cybersecurity professionals who have observed cybersecurity exercises simulating real-life cyber incidents. The data was analyzed using deductive coding. The results indicate that the decision-support framework partially corresponds to real-life operations; however, the specifics vary depending on the particular incident and the organization's processes. The key findings highlight that clear roles and responsibilities, established communication paths, a diverse team, and knowledgeable individuals in the core group related to the incident are essential. These team members must understand the legislative obligations and have experience in incident management, making sure that the organization can effectively handle the complexities of reporting under the new legislations.
first_indexed 2024-06-12T20:07:40Z
format Pro gradu
free_online_boolean 1
fullrecord [{"key": "dc.contributor.advisor", "value": "Paananen, Hanna Kaisa", "language": null, "element": "contributor", "qualifier": "advisor", "schema": "dc"}, {"key": "dc.contributor.author", "value": "Boddy, Sara Elizabeth", "language": null, "element": "contributor", "qualifier": "author", "schema": "dc"}, {"key": "dc.date.accessioned", "value": "2024-06-12T09:18:41Z", "language": null, "element": "date", "qualifier": "accessioned", "schema": "dc"}, {"key": "dc.date.available", "value": "2024-06-12T09:18:41Z", "language": null, "element": "date", "qualifier": "available", "schema": "dc"}, {"key": "dc.date.issued", "value": "2024", "language": null, "element": "date", "qualifier": "issued", "schema": "dc"}, {"key": "dc.identifier.uri", "value": "https://jyx.jyu.fi/handle/123456789/95795", "language": null, "element": "identifier", "qualifier": "uri", "schema": "dc"}, {"key": "dc.description.abstract", "value": "The European Union is committed to enhancing cybersecurity across its Member States by introducing legislation that impacts organizations cybersecurity preparedness. These laws include the Network and Information Security 2 Directive (NIS2), the Critical Entities Resilience Directive (CER), and the Digital Operational Resilience Act (DORA). These legislations mandate that organizations report cyber incidents to authorities. Currently, there are few guidelines available to help organizations understand how to report incidents to authorities. With the new legislations, it becomes even more crucial for organizations to comprehend how to report cyber incidents effectively to authorities. This research aims to determine do organizations current practices align with the decision-support framework and does the new legislations warrant adaptions to the framework in question. This thesis was conducted as a case study, beginning with a comprehensive literature review on existing research on incident reporting and the legislations. Data was gathered through semi-structured interviews with cybersecurity professionals who have observed cybersecurity exercises simulating real-life cyber incidents. The data was analyzed using deductive coding. The results indicate that the decision-support framework partially corresponds to real-life operations; however, the specifics vary depending on the particular incident and the organization's processes. The key findings highlight that clear roles and responsibilities, established communication paths, a diverse team, and knowledgeable individuals in the core group related to the incident are essential. These team members must understand the legislative obligations and have experience in incident management, making sure that the organization can effectively handle the complexities of reporting under the new legislations.", "language": "en", "element": "description", "qualifier": "abstract", "schema": "dc"}, {"key": "dc.description.provenance", "value": "Submitted by jyx lomake-julkaisija (jyx-julkaisija.group@korppi.jyu.fi) on 2024-06-12T09:18:41Z\nNo. of bitstreams: 0", "language": "en", "element": "description", "qualifier": "provenance", "schema": "dc"}, {"key": "dc.description.provenance", "value": "Made available in DSpace on 2024-06-12T09:18:41Z (GMT). No. of bitstreams: 0", "language": "en", "element": "description", "qualifier": "provenance", "schema": "dc"}, {"key": "dc.format.extent", "value": "69", "language": null, "element": "format", "qualifier": "extent", "schema": "dc"}, {"key": "dc.format.mimetype", "value": "application/pdf", "language": null, "element": "format", "qualifier": "mimetype", "schema": "dc"}, {"key": "dc.language.iso", "value": "eng", "language": null, "element": "language", "qualifier": "iso", "schema": "dc"}, {"key": "dc.rights", "value": "CC BY 4.0", "language": "en", "element": "rights", "qualifier": null, "schema": "dc"}, {"key": "dc.title", "value": "Case study: The decision-support framework and NIS2, CER, and DORA incident reporting obligations", "language": null, "element": "title", "qualifier": null, "schema": "dc"}, {"key": "dc.type", "value": "master thesis", "language": null, "element": "type", "qualifier": null, "schema": "dc"}, {"key": "dc.identifier.urn", "value": "URN:NBN:fi:jyu-202406124562", "language": null, "element": "identifier", "qualifier": "urn", "schema": "dc"}, {"key": "dc.contributor.faculty", "value": "Faculty of Information Technology", "language": "en", "element": "contributor", "qualifier": "faculty", "schema": "dc"}, {"key": "dc.contributor.faculty", "value": "Informaatioteknologian tiedekunta", "language": "fi", "element": "contributor", "qualifier": "faculty", "schema": "dc"}, {"key": "dc.contributor.organization", "value": "Jyv\u00e4skyl\u00e4n yliopisto", "language": "fi", "element": "contributor", "qualifier": "organization", "schema": "dc"}, {"key": "dc.contributor.organization", "value": "University of Jyv\u00e4skyl\u00e4", "language": "en", "element": "contributor", "qualifier": "organization", "schema": "dc"}, {"key": "dc.subject.discipline", "value": "Cyber Security", "language": "en", "element": "subject", "qualifier": "discipline", "schema": "dc"}, {"key": "dc.subject.discipline", "value": "Kyberturvallisuus", "language": "fi", "element": "subject", "qualifier": "discipline", "schema": "dc"}, {"key": "dc.type.coar", "value": "http://purl.org/coar/resource_type/c_bdcc", "language": null, "element": "type", "qualifier": "coar", "schema": "dc"}, {"key": "dc.rights.copyright", "value": "\u00a9 The Author(s)", "language": null, "element": "rights", "qualifier": "copyright", "schema": "dc"}, {"key": "dc.rights.accesslevel", "value": "openAccess", "language": null, "element": "rights", "qualifier": "accesslevel", "schema": "dc"}, {"key": "dc.type.publication", "value": "masterThesis", "language": null, "element": "type", "qualifier": "publication", "schema": "dc"}, {"key": "dc.format.content", "value": "fulltext", "language": null, "element": "format", "qualifier": "content", "schema": "dc"}, {"key": "dc.rights.url", "value": "https://creativecommons.org/licenses/by/4.0/", "language": null, "element": "rights", "qualifier": "url", "schema": "dc"}]
id jyx.123456789_95795
language eng
last_indexed 2025-02-18T10:54:59Z
main_date 2024-01-01T00:00:00Z
main_date_str 2024
online_boolean 1
online_urls_str_mv {"url":"https:\/\/jyx.jyu.fi\/bitstreams\/5ed12901-092a-42f7-8857-84c43303eba0\/download","text":"URN:NBN:fi:jyu-202406124562.pdf","source":"jyx","mediaType":"application\/pdf"}
publishDate 2024
record_format qdc
source_str_mv jyx
spellingShingle Boddy, Sara Elizabeth Case study: The decision-support framework and NIS2, CER, and DORA incident reporting obligations Cyber Security Kyberturvallisuus
title Case study: The decision-support framework and NIS2, CER, and DORA incident reporting obligations
title_full Case study: The decision-support framework and NIS2, CER, and DORA incident reporting obligations
title_fullStr Case study: The decision-support framework and NIS2, CER, and DORA incident reporting obligations Case study: The decision-support framework and NIS2, CER, and DORA incident reporting obligations
title_full_unstemmed Case study: The decision-support framework and NIS2, CER, and DORA incident reporting obligations Case study: The decision-support framework and NIS2, CER, and DORA incident reporting obligations
title_short Case study: The decision-support framework and NIS2, CER, and DORA incident reporting obligations
title_sort case study the decision support framework and nis2 cer and dora incident reporting obligations
title_txtP Case study: The decision-support framework and NIS2, CER, and DORA incident reporting obligations
topic Cyber Security Kyberturvallisuus
topic_facet Cyber Security Kyberturvallisuus
url https://jyx.jyu.fi/handle/123456789/95795 http://www.urn.fi/URN:NBN:fi:jyu-202406124562
work_keys_str_mv AT boddysaraelizabeth casestudythedecisionsupportframeworkandnis2ceranddoraincidentreportingobligat