A NIS Directive compliant Cybersecurity Maturity Model
George Drivas, Argyro Chatzopoulou, Leandros A. Maglaras, Costas Lambrinoudakis, Allan Cook, Helge Janicke · DMU Open Research Archive (De Montfort University) · 2020
The EU NIS Directive introduces obligations related to the security of the network and information systems for Operators of Essential Services and for Digital Service Providers. Moreover, National Competent Authorities for cybersecurity are required to assess compliance with these obligations. This paper describes a novel Cybersecurity Maturity Assessment Framework (CMAF) that is tailored to the NIS Directive requirements. CMAF can be used either as a self-assessment tool from Operators of Essential Services and Digital Service Providers or as an audit tool from the National Competent Authorities for cybersecurity.