{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,12,31]],"date-time":"2025-12-31T11:45:34Z","timestamp":1767181534626,"version":"3.48.0"},"reference-count":41,"publisher":"Riga Technical University","issue":"45","license":[{"start":{"date-parts":[[2025,12,31]],"date-time":"2025-12-31T00:00:00Z","timestamp":1767139200000},"content-version":"unspecified","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["J. Complex Syst. Inform. Model. Q."],"abstract":"<jats:p>The revised Network and Information Security Directive (NIS2) aims to achieve a high level of common cybersecurity across the European Union. Several stakeholders, including member states, supervisory authorities, and critical infrastructure service providers, are expected to support this effort by ensuring a high level of information security. Part of increasing security levels involves implementing risk management measures by service providers, but also an evaluation of the security situation and its changes is necessary from the perspective of each stakeholder. Previous research has described NIS2-related activities through user stories that encompass six types of stakeholders with their respective goals in relation to the security level evaluation of organizations. In this article, we examine the real-life implementation of these security evaluation user stories and demonstrate how the framework for security level evaluation (F4SLE) can be utilized to achieve NIS2 compliance within this narrowed scope of security level evaluation. The advantage of F4SLE is that the data can be collected once and then reused to satisfy different stakeholders without imposing an additional reporting burden on entities that must be NIS2-compliant.<\/jats:p>","DOI":"10.7250\/csimq.2025-45.07","type":"journal-article","created":{"date-parts":[[2025,12,31]],"date-time":"2025-12-31T11:40:32Z","timestamp":1767181232000},"page":"136-159","source":"Crossref","is-referenced-by-count":0,"title":["Toward NIS2 Compliance for Multiple Stakeholders with Security Level Evaluation Framework"],"prefix":"10.7250","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-9066-2467","authenticated-orcid":false,"given":"Mari","family":"Seeba","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3301-7020","authenticated-orcid":false,"given":"Tarmo","family":"Oja","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1599-8649","authenticated-orcid":false,"given":"Sten","family":"M\u00e4ses","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0006-4908-637X","authenticated-orcid":false,"given":"Maria Pibilota","family":"Murumaa","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1829-4794","authenticated-orcid":false,"given":"Raimundas","family":"Matulevi\u010dius","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"4297","published-online":{"date-parts":[[2025,12,31]]},"reference":[{"key":"3245","doi-asserted-by":"crossref","unstructured":"A. Lamba, S. Singh, B. Singh, N. Dutta, and S. S. R. Muni, \u201cAnalyzing and Fixing Cyber Security Threats for Supply Chain Management,\u201d International Journal for Technological Research in Engineering, vol. 4, no. 5, 2017. Available: https:\/\/doi.org\/10.2139\/ssrn.3492687","DOI":"10.2139\/ssrn.3492687"},{"key":"3246","unstructured":"European Parlament, \u201cDirective (EU) 2022\/2555 of the European Parliament and of the Council of 14 December 2022 on measures for a high common level of cybersecurity across the Union, amending Regulation (EU) No 910\/2014 and Directive (EU) 2018\/1972, and repealing Directive (EU) 2016\/1148 (NIS 2 Directive),\u201d 2022. Available: https:\/\/eur-lex.europa.eu\/legal-content\/en\/TXT\/?uri=CELEX%3A32022L2555"},{"key":"3247","doi-asserted-by":"crossref","unstructured":"M. Seeba, M. Valgre, and R. Matulevi\u010dius, \u201cEvaluating Organization Security: User Stories of European Union NIS2 Directive,\u201d in Advanced Information Systems Engineering, Springer, 2025, pp. 57\u201374. Available: https:\/\/doi.org\/10.1007\/978-3-031-94569-4_4","DOI":"10.1007\/978-3-031-94569-4_4"},{"key":"3248","doi-asserted-by":"crossref","unstructured":"N. T. Le and D. B. Hoang, \u201cCan Maturity Models Support Cyber Security?\u201d in 2016 IEEE 35th International Performance Computing and Communications Conference (IPCCC), 2016, pp. 1\u20137. Available: https:\/\/doi.org\/10.1109\/PCCC.2016.7820663","DOI":"10.1109\/PCCC.2016.7820663"},{"key":"3249","doi-asserted-by":"crossref","unstructured":"A. M. Rea-Guaman, I. D. S\u00e1nchez-Garc\u00eda, T. S. Feliu, and J. A. Calvo-Manzano, \u201cMaturity models in cybersecurity: A systematic review,\u201d in 2017 12th Iberian Conference on Information Systems and Technologies (CISTI), 2017, pp. 1\u20136. Available: https:\/\/doi.org\/10.23919\/cisti.2017.7975865","DOI":"10.23919\/CISTI.2017.7975865"},{"key":"3250","unstructured":"University of Tartu, NCSC-EE, \u201cOrganisation\u2019s information security maturity level evaluation,\u201d 2025. Available: https:\/\/mass.cloud.ut.ee\/test-massui\/. Accessed on June 01, 2025."},{"key":"3251","doi-asserted-by":"crossref","unstructured":"M. Seeba, S. M\u00e4ses, and R. Matulevi\u010dius, \u201cMethod for evaluating information security level in organisations,\u201d in Research Challenges in Information Science, Lecture Notes in Business Information Processing, Springer, vol. 446, 2022, pp. 644\u2013652. Available: https:\/\/doi.org\/10.1007\/978-3-031-05760-1_39","DOI":"10.1007\/978-3-031-05760-1_39"},{"key":"3252","doi-asserted-by":"crossref","unstructured":"M. Seeba, T. Oja, M. P. Murumaa, and V. Stupka, \u201cSecurity Level Evaluation with F4SLE,\u201d in Proceedings of the 18th International Conference on Availability, Reliability and Security, Association for Computing Machinery, pp. 1\u20138, 2023. Available: https:\/\/doi.org\/10.1145\/3600160.3605045","DOI":"10.1145\/3600160.3605045"},{"key":"3253","unstructured":"M. P. Murumaa, \u201cDesigning a Security Sensitive Self-Assessment Framework,\u201d Master\u2019s Thesis, Faculty of Science and Technology, University of Tartu, Estonia, 2023. Available: https:\/\/thesis.cs.ut.ee\/92895428-9fc4-4248-bc78-4a00b3e90101"},{"key":"3254","doi-asserted-by":"crossref","unstructured":"A. Brezav\u0161\u010dek and A. Baggia, \u201cRecent trends in information and cyber security maturity assessment: A systematic literature review,\u201d Systems, vol. 13, no. 1, 2025. Available: https:\/\/doi.org\/10.3390\/systems13010052","DOI":"10.3390\/systems13010052"},{"key":"3255","doi-asserted-by":"crossref","unstructured":"A. Rabii, S. Assoul, K. Ouazzani Touhami, and O. Roudies, \u201cInformation and cyber security maturity models: a systematic literature review,\u201d Information and Computer Security, vol. 28, no. 4, pp. 627\u2013644, 2020. Available: https:\/\/doi.org\/10.1108\/ICS-03-2019-0039","DOI":"10.1108\/ICS-03-2019-0039"},{"key":"3256","doi-asserted-by":"crossref","unstructured":"K. Peffers, T. Tuunanen, M. A. Rothenberger, and S. Chatterjee, \u201cA design science research methodology for information systems research,\u201d Journal of Management Information Systems, vol. 24, no. 3, pp. 45\u201377, 2007. Available: https:\/\/doi.org\/10.2753\/MIS0742-1222240302","DOI":"10.2753\/MIS0742-1222240302"},{"key":"3257","unstructured":"\u201cISO\/IEC 27001:2022(en) Information security, cybersecurity and privacy protection \u2013 Information security management systems \u2013 Requirements,\u201d International Organization for Standardization, Standard, 2022."},{"key":"3258","doi-asserted-by":"crossref","unstructured":"C. Boggini, \u201cReporting cybersecurity to stakeholders: A review of CSRD and the EU cyber legal framework,\u201d Computer Law & Security Review, vol. 53, article 105987, 2024. Available: https:\/\/doi.org\/10.1016\/j.clsr.2024.105987","DOI":"10.1016\/j.clsr.2024.105987"},{"key":"3259","doi-asserted-by":"crossref","unstructured":"M. Seeba, A. O. Affia, S. M\u00e4ses, and R. Matulevi\u010dius, \u201cCreate your own MUSE: A method for updating security level evaluation instruments,\u201d Computer Standards & Interfaces, vol. 87, article 103776, 2024. Available: https:\/\/doi.org\/10.1016\/j.csi.2023.103776","DOI":"10.1016\/j.csi.2023.103776"},{"key":"3260","unstructured":"J. P\u00f6ppelbu\u00df and M. R\u00f6glinger, \u201cWhat makes a useful maturity model? A framework of general design principles for maturity models and its demonstration in business process management,\u201d in ECIS 2011 Proceedings, 2011. Available: https:\/\/aisel.aisnet.org\/ecis2011\/28"},{"key":"3261","doi-asserted-by":"crossref","unstructured":"L. Sweeney, \u201ck-anonymity: A model for protecting privacy,\u201d International Journal of Uncertainty, Fuzziness and Knowledge-Based Systems, vol. 10, no. 05, pp. 557\u2013570, 2002. Available: https:\/\/doi.org\/10.1142\/S0218488502001648","DOI":"10.1142\/S0218488502001648"},{"key":"3262","unstructured":"\u201cISO 9241-11:2018 Ergonomics of human-system interaction \u2013 Part 11: Usability: Definitions and concepts,\u201d International Organization for Standardization, Geneva, Switzerland, Standard, 2018. Available: https:\/\/www.iso.org\/standard\/63500.html"},{"key":"3263","doi-asserted-by":"crossref","unstructured":"N. Bevan, J. Carter, J. Earthy, T. Geis, and S. Harker, \u201cNew ISO Standards for Usability, Usability Reports and Usability Measures,\u201d in Human-Computer Interaction. Theory, Design, Development and Practice, HCI 2016. Lecture Notes in Computer Science, vol. 9731, Springer, 2016, pp. 268\u2013278. Available: https:\/\/doi.org\/10.1007\/978-3-319-39510-4_25","DOI":"10.1007\/978-3-319-39510-4_25"},{"key":"3264","doi-asserted-by":"crossref","unstructured":"E. Rehnstam, W. Winquist, and S. Hacks, \u201cNIS2 Directive in Sweden: A Report on the Readiness of Swedish Critical Infrastructure,\u201d in Secure IT Systems, NordSec 2024. Lecture Notes in Computer Science, vol. 15396, Springer, 2025, pp. 176\u2013195. Available: https:\/\/doi.org\/10.1007\/978-3-031-79007-2_10","DOI":"10.1007\/978-3-031-79007-2_10"},{"key":"3265","unstructured":"S. \u00d6rri, \u201cNIS2 directive readiness in the Nordics,\u201d Haaga-Helia University of Applied Sciences, Finland, 2025."},{"key":"3266","unstructured":"NCSC-BE, \u201cCyberfundamentals conformity selfassessment tool,\u201d 2024. Available: https:\/\/atwork.safeonweb.be\/tools-resources\/cyberfundamentals-framework. Accessed on Jan. 21, 2025."},{"key":"3267","unstructured":"NCC-AT, \u201cWKO Online Ratgeber,\u201d 2025. Available: https:\/\/ratgeber.wko.at\/itsafe\/. Accessed on Jan. 21, 2025."},{"key":"3268","unstructured":"NCSC-IE, \u201cCyber Security Baseline Standards Self-Assessment Form,\u201d 2025. Available: https:\/\/www.ncsc.gov.ie\/guidance\/. Accessed on Jan. 21, 2025."},{"key":"3269","unstructured":"NC3-LU, \u201cFit 4 Cybersecurity Assessment Tool,\u201d 2025. Available: https:\/\/nc3.lu\/assessment-testing-and-training\/fit4cybersecurity. Accessed on Jan. 21, 2025."},{"key":"3270","unstructured":"CNCS Portugal, \u201cCiberCheckUp,\u201d 2025. Available: https:\/\/www.cncs.gov.pt\/pt\/quadro-nacional\/#cibercheckup. Accessed on Jan. 21, 2025."},{"key":"3271","unstructured":"Finnish Transport and Communication Agency National Cyber Security Centre, \u201cCybermeter,\u201d 2024. Available: https:\/\/www.kyberturvallisuuskeskus.fi\/fi\/palvelumme\/tilannekuva-ja-verkostojohtaminen\/kybermittari. Accessed on May 13, 2024."},{"key":"3272","unstructured":"Hellenic Ministry of Digital Governance Government department, \u201cCybersecurity Self Assessment Tool,\u201d 2021. Available: https:\/\/mindigital.gr\/wp-content\/uploads\/2022\/03\/cybersecurity-self-assessment.xlsm. Accessed on Jan. 21, 2025."},{"key":"3273","doi-asserted-by":"crossref","unstructured":"G. Drivas, A. Chatzopoulou, L. Maglaras, C. Lambrinoudakis, A. Cook, and H. Janicke, \u201cA NIS Directive Compliant Cybersecurity Maturity Assessment Framework,\u201d in 2020 IEEE 44th Annual Computers, Software, and Applications Conference (COMPSAC), 2020, pp. 1641\u20131646. Available: https:\/\/doi.org\/10.1109\/COMPSAC48688.2020.00-20","DOI":"10.1109\/COMPSAC48688.2020.00-20"},{"key":"3274","doi-asserted-by":"crossref","unstructured":"J. Ralyt\u00e9, G. Koutsopoulos, and J. Stirna, \u201cVerification, validation, and evaluation of modeling methods: experiences and recommendations,\u201d Software and Systems Modeling, 2025. Available: https:\/\/doi.org\/10.1007\/s10270-025-01304-2","DOI":"10.1007\/s10270-025-01304-2"},{"key":"3275","doi-asserted-by":"crossref","unstructured":"M. Seeba, \u201cFramework for Security Level Evaluation (F4SLE) E-ITS based ver 2024,\u201d 2025. Available: https:\/\/doi.org\/10.23673\/re-562","DOI":"10.1145\/3600160.3605045"},{"key":"3276","unstructured":"RIA (Estonian Information System Authority), \u201cE-ITS. Portal of Estonian Information Security Standard,\u201d 2022. Available: https:\/\/eits.ria.ee\/"},{"key":"3277","unstructured":"\u201cISO\/IEC 27002:2022 Information security, cybersecurity and privacy protection \u2013 Information security controls,\u201d International Organization for Standardization, Standard, 2022."},{"key":"3278","unstructured":"The MITRE Corporation, \u201cMITRE ATT&CK,\u201d 2025. Available: https:\/\/attack.mitre.org\/. Accessed on Jan. 12, 2025."},{"key":"3279","unstructured":"ENISA, \u201cENISA NIS360 2024. ENISA Cybersecurity Maturity & Criticality Assessment of NIS2 Sectors,\u201d 2025."},{"key":"3280","unstructured":"ENISA, \u201c2024 Report on the State of Cybersecurity in the Union,\u201d 2024-12."},{"key":"3281","unstructured":"ENISA, \u201cEU Cybersecurity Index. Framework and methodological note,\u201d 2024. Available: https:\/\/www.enisa.europa.eu\/sites\/default\/files\/2024-12\/eu_csi_methodological_note_v1-0.pdf"},{"key":"3282","doi-asserted-by":"crossref","unstructured":"A. Shaked and N. Messe, \u201cBridgeSec: Facilitating effective communication between security engineering and systems engineering,\u201d Journal of Information Security and Applications, vol. 89, article 103954, 2025. Available: https:\/\/www.sciencedirect.com\/science\/article\/pii\/S2214212624002564","DOI":"10.1016\/j.jisa.2024.103954"},{"key":"3283","doi-asserted-by":"crossref","unstructured":"F. Angermeir, J. Fischbach, F. Moy\u00f3n, and D. Mendez, \u201cTowards automated continuous security compliance,\u201d in Proceedings of the 18th ACM\/IEEE International Symposium on Empirical Software Engineering and Measurement, Association for Computing Machinery, 2024, p. 440\u2013446. Available: https:\/\/doi.org\/10.1145\/3674805.3690748","DOI":"10.1145\/3674805.3690748"},{"key":"3284","doi-asserted-by":"crossref","unstructured":"J. Sweller, \u201cElement interactivity and intrinsic, extraneous, and germane cognitive load,\u201d Educational Psychology Review, vol. 22, pp. 123\u2013138, 2010. Available: https:\/\/doi.org\/10.1007\/s10648-010-9128-5","DOI":"10.1007\/s10648-010-9128-5"},{"key":"3285","doi-asserted-by":"crossref","unstructured":"D. Thaw, \u201cThe Efficacy of Cybersecurity Regulation,\u201d Georgia State University Law Review, vol. 30, p. 287, 2013\u20132014.","DOI":"10.2139\/ssrn.2241838"}],"container-title":["Complex Systems Informatics and Modeling Quarterly"],"original-title":[],"link":[{"URL":"https:\/\/csimq-journals.rtu.lv\/csimq\/article\/download\/csimq.2025-45.07\/295","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/csimq-journals.rtu.lv\/csimq\/article\/download\/csimq.2025-45.07\/295","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,12,31]],"date-time":"2025-12-31T11:40:36Z","timestamp":1767181236000},"score":1,"resource":{"primary":{"URL":"https:\/\/csimq-journals.rtu.lv\/csimq\/article\/view\/csimq.2025-45.07"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,12,31]]},"references-count":41,"journal-issue":{"issue":"45","published-online":{"date-parts":[[2025,12,31]]}},"URL":"https:\/\/doi.org\/10.7250\/csimq.2025-45.07","relation":{},"ISSN":["2255-9922"],"issn-type":[{"value":"2255-9922","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,12,31]]}}}