Please use this identifier to cite or link to this item: http://hdl.handle.net/20.500.11960/4394
Title: Crafting good practises aligned with NIST CSF 2.0 and CMMI
Authors: Coutinho, Pedro
Oliveira, Luís Filipe Mesquita
Keywords: Information security
Cybersecurity
Risk management
Cybersecurity maturity
CMMI
NIST CSF 2.0
ISO/IEC 27001:2022
CIS Controls
C2M2
CMMC
CIA
Cybersecurity resilience
Segurança da informação
Cibersegurança
Gestão de risco
Maturidade em cibersegurança
Resiliência em cibersegurança
Issue Date: 7-Mar-2025
Abstract: In today’s digital landscape, organizations face increasingly sophisticated cybersecurity threats, often compounded by the absence of standardized and adaptive methodologies for assessing and improving cybersecurity maturity. This thesis introduces a novel framework that integrates the National Institute of Standards and Technology Cybersecurity Framework 2.0 (NIST CSF 2.0) with the Capability Maturity Model Integration (CMMI). The proposed framework aligns best practices across the three core dimensions of CMMI—People, Processes, and Technology—spanning maturity levels 1 to 5, while mapping these practices to the subcategories of NIST CSF 2.0. This thesis undertakes a comprehensive analysis of existing frameworks/standards and maturity models to identify their strengths and limitations. The development and validation of the framework followed a systematic approach, with expert feedback playing a crucial role. The results demonstrate that the framework supports organizations in systematically advancing through maturity levels, offering scalable and tailored practices that address diverse cybersecurity challenges. Furthermore, the validation highlights the framework’s usability, adaptability, and potential to strengthen organizational resilience and security postures. By providing a systematic and adaptable approach for assessing and improving cybersecurity maturity, this thesis contributes to bridging critical gaps in current methodologies.
No atual panorama digital, as organizações enfrentam ameaças cibernéticas cada vez mais sofisticadas, muitas vezes agravadas pela ausência de metodologias padronizadas e adaptativas para avaliar e melhorar a maturidade em cibersegurança. Esta tese apresenta uma framework inovadora que integra o NIST CSF 2.0 com o CMMI. A framework proposta alinha as melhores práticas nas três dimensões do CMMI— Pessoas, Processos e Tecnologia — abrangendo os níveis de maturidade de 1 a 5, enquanto mapeia estas práticas para as subcategorias do NIST CSF 2.0. Esta tese realiza uma análise abrangente dos frameworks/standards e modelos de maturidade existentes para identificar os seus pontos fortes e limitações. O desenvolvimento e a validação da framework seguiram uma abordagem sistemática, com o feedback de especialistas a desempenhar um papel crucial. Os resultados demonstram que a framework apoia as organizações na progressão sistemática pelos níveis de maturidade, oferecendo práticas escaláveis e personalizadas que respondem aos diversos desafios da cibersegurança. Além disso, a validação destaca a usabilidade, adaptabilidade e o potencial da framework para reforçar a resiliência organizacional e as posturas de segurança. Ao fornecer uma abordagem sistemática e adaptável para avaliar e melhorar a maturidade em cibersegurança, esta tese contribui para colmatar lacunas críticas nas metodologias atuais.
Description: Mestrado em Cibersegurança na Escola Superior de Tecnologia e Gestão do Instituto Politécnico de Viana do Castelo
URI: http://hdl.handle.net/20.500.11960/4394
Appears in Collections:ESTG - Dissertações de mestrado

Files in This Item:
File Description SizeFormat 
Luis_Oliveira.pdf
  Until 2035-03-07
3.03 MBAdobe PDFView/Open Request a copy


Items in DSpace are protected by copyright, with all rights reserved, unless otherwise indicated.