Skip to content
Open access

A Structured NIS2–ISO/IEC 27001:2022 Alignment Framework for Higher Education Institutions

Aug 2026 · Journal of Cybersecurity and Privacy · 0 citations · 35 references

TL;DR

A structured and reusable compliance design artefact for aligning NIS2 obligations with ISO/IEC 27001:2022 clauses and Annex A controls in the context of higher education institutions is proposed.

Abstract

Higher education institutions operate complex digital environments that combine administrative services, research infrastructures, learning platforms, identity systems, and heterogeneous departmental IT. In the European Union, the NIS2 Directive increases the need for structured cybersecurity governance, while ISO/IEC 27001:2022 provides a mature information security management system standard that can support implementation. This paper proposes a design science artefact for aligning NIS2 obligations with ISO/IEC 27001:2022 clauses and Annex A controls in the context of higher education institutions. The framework organizes cybersecurity governance, asset and service scoping, risk management, incident handling, business continuity, supplier and cloud dependencies, access control, awareness, monitoring, and continual improvement into a staged maturity model. The artefact is instantiated for a Romanian public university context and assessed through internal traceability analysis, including mappings between NIS2 Articles 20, 21, and 23, Romanian NIS2 transposition requirements, and ISO/IEC 27001:2022 control areas. The institutional illustration identifies candidate assessment domains and evidence requirements but does not assign maturity levels because the internal records required by the scoring protocol were unavailable; it therefore does not constitute an audit, verified institutional measurement, or empirical validation. The contribution is therefore a structured and reusable compliance design artefact, together with a transparent mapping method that can support future expert validation, institutional pilots, and audit-oriented refinement.

Read PDF

Similar papers

Open access Aug 2026

An Integrated University Digital Transformation Model Combining IT Governance, Interoperability, Cloud Security Assessment and Data Analytics: The UTMACH Case in Ecuador

The case indicates that university digital transformation is strengthened when technological implementation is integrated with formal governance, systematic assessment, evidence-based planning, and institutional accountability.

Jennifer Célleri-Pacheco, Fernanda Tusa Jumbo, Oswaldo Chuquirima Camacho et al. · 0 citations
2026

An Integrated Governance Model for University AI: Extending ISO/IEC 27001 for Higher Education

Generative Artificial Intelligence has become part of everyday practice in higher education. It supports learning and teaching, but it also enables new forms of academic misconduct, as students can use large language models to bypass assessment rules and to produce outputs that are difficult to attribute to individual...

Christoph Jungbauer, Eszter Geresics-Földi · 0 citations
#small language model Open access Sep 2026

Shipping Safer LLM Features in SMEs: A OnePage Checklist Mapped to NIST AI RMF and ISO/IEC 23894/42001

It is concluded that the distance between voluntary framework guidance and auditable management-system requirements can be closed for SMEs by a small, clause-mapped control set with explicit evidence requirements, and that the principal remaining barrier is threshold calibration rather than control selection.

Mohamed Riyaz M. Meera Rawuthar, Ahmad M. Al-Ali · 0 citations
Open access Aug 2026

A Conceptual Framework for OT/ICS Cybersecurity Governance in Malaysian Manufacturing Environments Under Industry 4.0

The convergence of Information Technology (IT) and Operational Technology (OT) in Malaysian manufacturing environments has created a cybersecurity governance problem that existing frameworks were not designed to solve. Malaysia's manufacturing sector contributes 24.5% of national GDP (EPU, 2022) and is overwhelmingly m...

Navenesh Kumar · 0 citations
Preprint Aug 2026

Operationalizing Regulations into Code: A Model to Enhance Governance and Compliance in LLM Selection for Software Engineering

The results provide preliminary evidence that regulatory disqualification logic, particularly K.O. criteria, can prevent the selection of technically competitive models that nonetheless pose unacceptable compliance risks, demonstrating the feasibility of governance-oriented LLM selection in software engineering project...

J. Quintino, H. Moura, Filipe Calegario · 0 citations
Review Open access Aug 2026

DIGITAL INFRASTRUCTURE GOVERNANCE IN U.S. HIGHER EDUCATION: A PRACTITIONER FRAMEWORK FOR SYSTEM SELECTION

The article proposes the Digital Infrastructure Governance and Selection (DIGS) framework, which combines seven decision domains with six stage gates spanning problem definition, mandatory assurance, comparative assessment, controlled piloting, contracting and implementation, and lifecycle review and is a transparent d...

Fatema Akter · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.