https://www.mdu.se/

mdu.sePublications
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf
Study of Cybersecurity Risk Analysis Under NIS2 Within a Municipality
Mälardalen University, Faculty of Engineering and Health Sciences, Department of Computer Science & Engineering.
Mälardalen University, Faculty of Engineering and Health Sciences, Department of Computer Science & Engineering.
2026 (English)Independent thesis Basic level (degree of Bachelor), 10 credits / 15 HE creditsStudent thesis
Abstract [en]

This report is a qualitative case study that investigates the compliance of NIS2 Article 21(2)(a) within a large Swedish municipality outside the three major metropolitan regions. NIS2 represents a major shift in the Swedish legal landscape regarding cybersecurity since it has increased the number of sectors that are covered by mandated actions. Since NIS2 has recently been implemented in Sweden there are few other studies regarding its implementation. This study aims to investigate its implementation and analyze potential gaps by using a qualitative methodology based on the municipality’s policies and as well as a survey that was used to confirm and close identified gaps. The empirical findings are mapped within an analytical framework created during this study that encompasses three levels spanning through the governance layer, the process layer, and the technical layer. This analytical framework was developed by considering relevant standardization frameworks, such as ISO/IEC 27000 series and CIS Controls. Gaps were identified in all layers while the technical layer contained the most identified gaps. Recommendations for closing the gaps are given based on our analysis. This study enhances the available knowledge of NIS2 implementation in Sweden and gives insight into how NIS2(2)(a) can be implemented into an organization, as well as how potential gaps in the implementation can be identified and corrected.

Place, publisher, year, edition, pages
2026. , p. 84
National Category
Computer Sciences
Identifiers
URN: urn:nbn:se:mdh:diva-78403OAI: oai:DiVA.org:mdh-78403DiVA, id: diva2:2081580
External cooperation
Anonym svensk storstadskommun
Subject / course
Computer Science
Available from: 2026-08-05 Created: 2026-06-29 Last updated: 2026-08-05Bibliographically approved

Open Access in DiVA

fulltext(3077 kB)32 downloads
File information
File name FULLTEXT01.pdfFile size 3077 kBChecksum SHA-512
6ae5393774e0331c89a5a3ad8c6cb88a5fa229e8d71516a680f07c268605e190dbe17559065e70c24b5b1ba0e517cba8ee26299d0e49be88f8fe9927a2695829
Type fulltextMimetype application/pdf

Search in DiVA

By author/editor
Högström, IdaLindhult, Therése
By organisation
Department of Computer Science & Engineering
Computer Sciences

Search outside of DiVA

GoogleGoogle Scholar
The number of downloads is the sum of all downloads of full texts. It may include eg previous versions that are now no longer available

urn-nbn

Altmetric score

urn-nbn
Total: 1729 hits
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf