Högskolan i Skövde

his.sePublications
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • apa-cv
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf
Aligning EU Cybersecurity Regulations with ICS Security Standards: A Systematic Literature Review
University of Skövde, School of Informatics.
2025 (English)Independent thesis Advanced level (degree of Master (Two Years)), 20 credits / 30 HE creditsStudent thesis
Abstract [en]

Industrial Control Systems (ICS) form the backbone of critical infrastructure but face increasing cybersecurity risks as connectivity expands. To address these challenges, the European Union has introduced new legislation, including the Cyber Resilience Act (CRA), the NIS2 Directive, and the Machinery Regulation, which establish mandatory cybersecurity obligations. At the same time, technical standards such as IEC 62443 and ISO/IEC 27001 continue to provide structured frameworks for securing industrial systems.The aim of this thesis is to analyse how the EU’s emerging cybersecurity regulations relate to existing ICS security standards and to identify regulatory requirements that are not yet addressed by them. The study was conducted as a Systematic Literature Review (SLR), covering the period 2015–2025, drawing on four major academic databases together with grey literature, including EU legislative texts and industry guidelines. The findings show broad alignment between regulations and standards in areas such as lifecycle security, secure development, and incident reporting. However, gaps remain concerning post-market surveillance, vulnerability disclosure, and long-term update obligations, which are not comprehensively covered by current standards. These results highlight the need for closer harmonization to ensure that secure-by-design principles can be effectively implemented in ICS environments. The thesis contributes by clarifying the relationship between regulations and standards and by providing practical insights for industry and policymakers.

Place, publisher, year, edition, pages
2025. , p. 47
Keywords [en]
Industrial Control Systems (ICS), Cyber Resilience Act (CRA), Machinery Regulation, IEC 62443, Security-by-Design
National Category
Computer Sciences
Identifiers
URN: urn:nbn:se:his:diva-25899OAI: oai:DiVA.org:his-25899DiVA, id: diva2:2004003
Subject / course
Informationsteknologi
Educational program
Privacy, Information and Cyber Security - Master's Programme 120 ECTS
Supervisors
Examiners
Available from: 2025-10-06 Created: 2025-10-06 Last updated: 2025-10-06Bibliographically approved

Open Access in DiVA

fulltext(1353 kB)56 downloads
File information
File name FULLTEXT01.pdfFile size 1353 kBChecksum SHA-512
f769b31c0f003106fc9c0dcba73c197459155ad959010d8a44d3d13a1f31c0a5192d42c5eae60b578efdb281a8fd4dd440ba3e9222ccc6ba4828687202127eac
Type fulltextMimetype application/pdf

By organisation
School of Informatics
Computer Sciences

Search outside of DiVA

GoogleGoogle Scholar
The number of downloads is the sum of all downloads of full texts. It may include eg previous versions that are now no longer available

urn-nbn

Altmetric score

urn-nbn
Total: 1120 hits
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • apa-cv
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf