Συνδυάζοντας τα ρυθμιστικά και τα εθελοντικά πλαίσια κυβερνοασφάλειας – Μια συγκριτική μελέτη μεταξύ των προτύπων EU NIS2 και US SOC2
View/ Open
Keywords
EU NIS2 ; US SOC2 ; Κυβερνοασφάλεια ; Κανονιστική συμμόρφωση ; Διαχείριση κινδύνων ; GRC ; Trust services criteria ; ΚυβερνοανθεκτικότηταAbstract
The continuous increase in cyber threats and the growing dependence of organizations and businesses on digital infrastructures have made cybersecurity and regulatory compliance critical factors for ensuring business continuity and information protection. In this context, the present dissertation comparatively examines two significant cybersecurity and compliance frameworks: the NIS2 Directive of the European Union and the SOC 2 framework of the American Institute of Certified Public Accountants (AICPA).
Initially, the modern cyber threat landscape and the importance of regulatory compliance for organizations are presented. Subsequently, the key characteristics of NIS2 are analyzed, including risk management requirements, incident reporting obligations, governance mechanisms, and penalties for non-compliance. At the same time, the SOC 2 framework, the Trust Services Criteria, and the compliance assessment and auditing process are examined.
The study proceeds with a detailed comparison of the two frameworks regarding their purpose, scope of application, security requirements, compliance processes, and enforcement mechanisms. Furthermore, technological tools and solutions that support the implementation of cybersecurity and regulatory compliance requirements are presented, such as GRC platforms, risk management tools, and security incident monitoring systems.
The research findings indicate that, despite their differences, NIS2 and SOC 2 converge in terms of the need to implement effective risk management mechanisms, internal controls, and organizational governance. In addition, it is highlighted that compliance constitutes not only a regulatory obligation but also a strategic tool for strengthening cyber resilience, reliability, and stakeholder trust.
Finally, the dissertation examines future trends in the field of cybersecurity, emphasizing new European initiatives such as DORA and CSRD, as well as the role of artificial intelligence and automation in regulatory compliance and cyber risk management.


