Skip to content

1 paper indexed here

We haven’t gathered this author’s papers yet. Follow them and we’ll fetch their work.

Not the right person? Other researchers publish under this name.

Open access Aug 2026

A Structured NIS2–ISO/IEC 27001:2022 Alignment Framework for Higher Education Institutions

Higher education institutions operate complex digital environments that combine administrative services, research infrastructures, learning platforms, identity systems, and heterogeneous departmental IT. In the European Union, the NIS2 Directive increases the need for structured cybersecurity governance, while ISO/IEC 27001:2022 provides a mature information security management system standard that can support implementation. This paper proposes a design science artefact for aligning NIS2 obligations with ISO/IEC 27001:2022 clauses and Annex A controls in the context of higher education institutions. The framework organizes cybersecurity governance, asset and service scoping, risk management, incident handling, business continuity, supplier and cloud dependencies, access control, awareness, monitoring, and continual improvement into a staged maturity model. The artefact is instantiated for a Romanian public university context and assessed through internal traceability analysis, including mappings between NIS2 Articles 20, 21, and 23, Romanian NIS2 transposition requirements, and ISO/IEC 27001:2022 control areas. The institutional illustration identifies candidate assessment domains and evidence requirements but does not assign maturity levels because the internal records required by the scoring protocol were unavailable; it therefore does not constitute an audit, verified institutional measurement, or empirical validation. The contribution is therefore a structured and reusable compliance design artefact, together with a transparent mapping method that can support future expert validation, institutional pilots, and audit-oriented refinement.

Alexandru Iovanovici, L. Prodan · 0 citations