Digitala Vetenskapliga Arkivet

Change search
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf
Securing the digital lifeline: Third-party risks in the cyber supply chain
Stockholm University, Faculty of Social Sciences, Department of Computer and Systems Sciences.
2024 (English)Independent thesis Advanced level (degree of Master (Two Years)), 20 credits / 30 HE creditsStudent thesis
Abstract [en]

The increasing cyber-attacks on the cyber supply chains have put organizational integrity and data security at risk, as such, it is important to understand how to enhance Cyber Supply Chain Risk Management (CSCRM) frameworks. This study investigates the application, effectiveness, and challenges of three frameworks (ISO, NIST, and NIS2) in the context of mitigating third-party risks in the cyber supply chain. This study uses a qualitative research approach and data was gathered with semi-structured interviews of eight domain experts in the field of information security. Participants of this study gave the study valuable data and insights into the real-world application of their perceptions of these frameworks in CSCRM. This study used reflexive thematic analysis to understand and analyze the collected data. The findings showed that while there is consensus amongst the domain experts regarding the framework’s flexibility and adaptability, the frameworks do have some difficulties regarding their complexity and resource-intensive implementation process.

Furthermore, it was also found that the effectiveness of these frameworks in enhancing organizational data security and asset protection is dependent on the specific adoption and implementation practices within organizations. Overall, the findings of this study show that while the theoretical underpinnings of these frameworks are strong, in such a way that they are comprehensive and effective, applying them into an organizational context is challenging due to difficulties in the practical implementation. This study contributes to the field of CSCRM practices and strategies by providing valuable findings that organizations who are aiming to strengthen their cyber defense in their cyber supply chain may use. Furthermore, the findings may also provide valuable insights for policymakers to better understand challenges for future improvements.

Place, publisher, year, edition, pages
2024.
Keywords [en]
Cyber Supply Chain Risk Management (CSCRM), Third-party cyber risks, Cybersecurity frameworks, ISO, NIST, NIS2
National Category
Computer Sciences
Identifiers
URN: urn:nbn:se:su:diva-242807OAI: oai:DiVA.org:su-242807DiVA, id: diva2:1955740
Available from: 2025-04-30 Created: 2025-04-30

Open Access in DiVA

fulltext(1078 kB)18 downloads
File information
File name FULLTEXT01.pdfFile size 1078 kBChecksum SHA-512
3e93aa683740272e2ce86fef0458de8ebb5f9e0b7787aa3565ecbc28c78826c0cc9692b81ceaf0373d3cc78cde8f35be6283a8296a59e83d8e67804388966720
Type fulltextMimetype application/pdf

Search in DiVA

By author/editor
Ilter, Deniz
By organisation
Department of Computer and Systems Sciences
Computer Sciences

Search outside of DiVA

GoogleGoogle Scholar
Total: 18 downloads
The number of downloads is the sum of all downloads of full texts. It may include eg previous versions that are now no longer available

urn-nbn

Altmetric score

urn-nbn
Total: 42 hits
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf