NIS 2 och nya krav på cybersäkerhet i leverantörskedjor: En fallstudie av krav och kravuppfyllnad inom informationssäkerhet i ett infrastrukturprojekt
Information
Författare: Anton MämmiBeräknat färdigt: 2025-06
Handledare: Anonymt
Handledares företag/institution: Anonymt
Ämnesgranskare: Anders Arweström Jansson
Övrigt: -
Presentation
Presentatör: Anton MämmiPresentationstid: 2025-06-13 11:15
Opponent: Katariina Blom
Abstract
In 2022, the NIS 2 directive was adopted by the European Parliament. The directive imposes new and stricter cybersecurity requirements, than those found in the previous NIS directive, for actors operating in several different sectors deemed to be of societal importance. One of these new requirements is that the actor must guarantee the security of its supply chain. In this study, one of the projects commissioned by Trafikverket was studied based on the actors’ approach to maintain information security in their respective supply chains.
The study is based on data collected through interviews, a questionnaire and a documentation review. This data has then been analyzed using the STPA (System-Theoretic Process Analysis) method, which is based on the theoretical framework STAMP (System-Theoretic Accident Model and Processes). Within this framework, accidents and risks occur because of a lack of control. This control takes the form of control measures and feedback between different components of the studied system. The study also aimed to evaluate STAMP in the project organizational context, in which the study took place.
In accordance with the method, the data was analyzed through a hierarchical control structure. This analysis identified several deficient areas among the actors’ approach to maintain information security in the project. Trafikverket relies heavily on documents to convey information security requirements. These documents’ ability to act as control measures is unfortunately lacking due to several different reasons. Trafikverket also does not carry out sufficient supervision to ensure compliance with information security requirements within the project. The company in turn conveys requirements in an inadequate way to its foreign resources and is also lacking in supervision when it comes to information security.