
doi: 10.32091/riid0268
handle: 11382/587192
Il panorama digitale odierno richiede un approccio strategico alla sicurezza informatica. Questo studio presenta un modello operativo e pragmatico progettato per semplificare la complessa conformità normativa in un sistema di gestione aziendale facilmente applicabile. Il Modello si basa su un allineamento multilivello tra le misure di sicurezza operative e i due pilastri normativi internazionali: ISO/IEC 27001:2022 e NIST Cybersecurity Framework (CSF) 2.0. La metodologia utilizzata ha permesso di generare una mappatura innovativa che associa le misure operative ai controlli ISO e alle categorie NIST. L’utilità pratica del Modello è dimostrata come strumento di adattamento cruciale per le organizzazioni (note come “entità NIS”) soggette agli obblighi della direttiva NIS2. Ciò consente l’implementazione operativa degli elementi essenziali di gestione del rischio richiesti dalla normativa. Il Modello è progettato per essere scalabile a qualsiasi quadro normativo, riducendo i costi di conformità e massimizzando l’efficacia operativa. In prospettiva, lo stesso mira ad evolversi in un sistema quantitativo di misurazione della sicurezza IT, fornendo alle organizzazioni un mezzo tangibile per dimostrare il proprio livello di sicurezza informatica
Today’s digital landscape requires a strategic approach to cybersecurity. This study presents a model (hereinafter also “Smartlex Model”), an operational and pragmatic model designed to simplify complex regulatory compliance into an easily applicable business management system. The Model is based on a multi-level alignment between operational security measures and the two international regulatory pillars: ISO/IEC 27001:2022 and the NIST Cybersecurity Framework (CSF) 2.0. The methodology generates an innovative mapping that associates operational measures with ISO controls and NIST categories. The practical usefulness of the Model is demonstrated as a crucial adaptation tool for organisations (known as “NIS entities”) subject to the obligations of the NIS2 Directive. This allows for the operational implementation of the essential risk management elements required by the regulation. The Model is designed to be scalable to any regulatory framework, reducing compliance costs and maximising operational effectiveness. Looking ahead, the Smartlex Model aims to evolve into a quantitative IT security measurement system, providing organizations with a tangible means of demonstrating their cybersecurity posture.
| selected citations These citations are derived from selected sources. This is an alternative to the "Influence" indicator, which also reflects the overall/total impact of an article in the research community at large, based on the underlying citation network (diachronically). | 0 | |
| popularity This indicator reflects the "current" impact/attention (the "hype") of an article in the research community at large, based on the underlying citation network. | Average | |
| influence This indicator reflects the overall/total impact of an article in the research community at large, based on the underlying citation network (diachronically). | Average | |
| impulse This indicator reflects the initial momentum of an article directly after its publication, based on the underlying citation network. | Average |
