Please use this identifier to cite or link to this item: http://hdl.handle.net/20.500.11960/4394
Full metadata record
DC FieldValueLanguage
dc.contributor.advisorCoutinho, Pedro-
dc.contributor.authorOliveira, Luís Filipe Mesquita-
dc.date.accessioned2025-03-24T12:03:06Z-
dc.date.available2025-03-24T12:03:06Z-
dc.date.issued2025-03-07-
dc.identifier.urihttp://hdl.handle.net/20.500.11960/4394-
dc.descriptionMestrado em Cibersegurança na Escola Superior de Tecnologia e Gestão do Instituto Politécnico de Viana do Castelopt_PT
dc.description.abstractIn today’s digital landscape, organizations face increasingly sophisticated cybersecurity threats, often compounded by the absence of standardized and adaptive methodologies for assessing and improving cybersecurity maturity. This thesis introduces a novel framework that integrates the National Institute of Standards and Technology Cybersecurity Framework 2.0 (NIST CSF 2.0) with the Capability Maturity Model Integration (CMMI). The proposed framework aligns best practices across the three core dimensions of CMMI—People, Processes, and Technology—spanning maturity levels 1 to 5, while mapping these practices to the subcategories of NIST CSF 2.0. This thesis undertakes a comprehensive analysis of existing frameworks/standards and maturity models to identify their strengths and limitations. The development and validation of the framework followed a systematic approach, with expert feedback playing a crucial role. The results demonstrate that the framework supports organizations in systematically advancing through maturity levels, offering scalable and tailored practices that address diverse cybersecurity challenges. Furthermore, the validation highlights the framework’s usability, adaptability, and potential to strengthen organizational resilience and security postures. By providing a systematic and adaptable approach for assessing and improving cybersecurity maturity, this thesis contributes to bridging critical gaps in current methodologies.pt_PT
dc.description.abstractNo atual panorama digital, as organizações enfrentam ameaças cibernéticas cada vez mais sofisticadas, muitas vezes agravadas pela ausência de metodologias padronizadas e adaptativas para avaliar e melhorar a maturidade em cibersegurança. Esta tese apresenta uma framework inovadora que integra o NIST CSF 2.0 com o CMMI. A framework proposta alinha as melhores práticas nas três dimensões do CMMI— Pessoas, Processos e Tecnologia — abrangendo os níveis de maturidade de 1 a 5, enquanto mapeia estas práticas para as subcategorias do NIST CSF 2.0. Esta tese realiza uma análise abrangente dos frameworks/standards e modelos de maturidade existentes para identificar os seus pontos fortes e limitações. O desenvolvimento e a validação da framework seguiram uma abordagem sistemática, com o feedback de especialistas a desempenhar um papel crucial. Os resultados demonstram que a framework apoia as organizações na progressão sistemática pelos níveis de maturidade, oferecendo práticas escaláveis e personalizadas que respondem aos diversos desafios da cibersegurança. Além disso, a validação destaca a usabilidade, adaptabilidade e o potencial da framework para reforçar a resiliência organizacional e as posturas de segurança. Ao fornecer uma abordagem sistemática e adaptável para avaliar e melhorar a maturidade em cibersegurança, esta tese contribui para colmatar lacunas críticas nas metodologias atuais.pt_PT
dc.language.isoengpt_PT
dc.rightsembargoedAccesspt_PT
dc.subjectInformation securitypt_PT
dc.subjectCybersecuritypt_PT
dc.subjectRisk managementpt_PT
dc.subjectCybersecurity maturitypt_PT
dc.subjectCMMIpt_PT
dc.subjectNIST CSF 2.0pt_PT
dc.subjectISO/IEC 27001:2022pt_PT
dc.subjectCIS Controlspt_PT
dc.subjectC2M2pt_PT
dc.subjectCMMCpt_PT
dc.subjectCIApt_PT
dc.subjectCybersecurity resiliencept_PT
dc.subjectSegurança da informaçãopt_PT
dc.subjectCibersegurançapt_PT
dc.subjectGestão de riscopt_PT
dc.subjectMaturidade em cibersegurançapt_PT
dc.subjectResiliência em cibersegurançapt_PT
dc.titleCrafting good practises aligned with NIST CSF 2.0 and CMMIpt_PT
dc.typemasterThesispt_PT
thesis.degree.nameMestrado em Cibersegurançapt_PT
thesis.degree.levelMestrept_PT
thesis.degree.disciplineCiência de Computadores e Telecomunicaçõespt_PT
dc.date.embargo2035-03-07-
dc.identifier.tid203924517pt_PT
Appears in Collections:ESTG - Dissertações de mestrado

Files in This Item:
File Description SizeFormat 
Luis_Oliveira.pdf
  Until 2035-03-07
3.03 MBAdobe PDFView/Open Request a copy


Items in DSpace are protected by copyright, with all rights reserved, unless otherwise indicated.