MARATTO

book chapter · Advances in computational intelligence and robotics book series

From Standards to Regulation Compliance

Abstract

The emergence of threats and their potential impact obliges organizations to be aligned with standards and frameworks to reduce and anticipate cyber risks. The ISO/IEC 27001 standard offers a set of measures to enhance an organization's cybersecurity posture by deploying an Information Security Management System (ISMS). To meet the conformity with the European Network and Information Systems (NIS2) Directive, entities already adhering to various international standards must map existing security controls with the new NIS2 mandates. To address these challenges, this study proposes a four-phase approach as a new mapping guide to reach compliance, ensuring harmonization of security across European member states, while fostering coordination and information sharing regarding cyber threats. Moreover, the chapter provides a comprehensive analysis of existing ISMS and the requirements outlined in the NIS2 Directive. Finally, the paper presents a side-by-side comparison of articles, recitals, clauses, and obligations, identifying key similarities and clarifying their meaning.

Research topics

  • Information and Cyber Security
  • Cybersecurity and Cyber Warfare Studies
  • Safety Systems Engineering in Autonomy

Read the original research

This page summarises published work. The authoritative version sits with the publisher.

DOI: 10.4018/979-8-2600-0888-1.ch009

Is something wrong with this record? Report it or request removal.

Discussion

Discuss this research

Have you built on this work, tried to replicate it, or seen it applied in practice? Share what you know. Verified researchers and MARATTO™ domain experts can open a discussion, and any member can reply. Contributions are reviewed before they appear.

No discussion yet. Open the first thread.