Αξιολόγηση κινδύνων ασφάλειας πληροφοριών και οργανωτικής ετοιμότητας κρίσιμων υποδομών πληροφορικής
Information security risk and organizational readiness assessment of critical IT infrastructures

View/ Open
Keywords
Ασφάλεια πληροφοριών ; Αξιολόγηση κινδύνων ; Οργανωτική ετοιμότητα ; Ταξινομίες απειλών ; Υποδομές υψηλής κρισιμότητας ; ISO/IEC 27001 ; NIS2 ; MONARC ; CUSTODES ; ENISA ; Information security ; Risk assessment ; Organizational readiness ; Threat taxonomies ; High-criticality infrastructuresAbstract
This MSc thesis develops and applies a systematic, repeatable method for assessing information security risks and organizational readiness in a synthetic, anonymized public-sector ERP archetype (govERP), without using real operational or sensitive data. The method has two complementary strands: risk assessment with MONARC, grounded in ISO/IEC 27001:2022, ISO/IEC 27002:2022 and ENISA’s Interoperable EU Risk Management Toolbox; and an assessment of documentation readiness for conformity assessment and certification using CUSTODES. The NIS2 Directive, Greek Law 5160/2024 and Joint Ministerial Decision 1689/2025 are used as regulatory references, without implying legal applicability to the archetype. The application produces a traceable risk register, a gap analysis, an organizational-readiness assessment and a draft Security Target for the e-invoicing interface. The highest priorities concern identity, access, human practices and documentation. Risk assessment and certification readiness are complementary, but no risk score is converted into an assurance level. The process was executable, reproducible and traceable on the stated archetype; external validity was not tested. In the specific platform version and sessions examined, the coexistence of different threat catalogues made some relevant security objectives harder to retrieve.


