| Creators: |
Palinkas, Kevin and Buchwald, Arne |
| Title: |
Vom Modell zur Maßnahme: Orientierung für Unternehmen im Cybersecurity-Dschungel From Models to Measures : Hands-on Guidance for Companies in the Cybersecurity Jungle |
| Item Type: |
Article or issue of a publication series |
| Projects: |
IDI |
| Journal or Series Title: |
HMD Praxis der Wirtschaftsinformatik |
| Date: |
2026 |
| Divisions: |
Informationsmanagement |
| Abstract: |
Cybersecurity hat in den vergangenen Jahren erheblich an Bedeutung gewonnen. Heute stellt sich nicht mehr die Frage, ob ein Unternehmen Ziel eines Cyberangriffs wird, sondern lediglich wann. Entsprechend rückt die systematische Stärkung der organisatorischen Resilienz zunehmend in den Fokus. Zwar existieren zahlreiche Cybersecurity-Modelle mit unterschiedlichen Schwerpunkten und Maßnahmenempfehlungen, doch gerade diese Vielfalt erschwert es Unternehmen in der Praxis, ihr Sicherheitsniveau strukturiert zu erfassen und konkrete Verbesserungsansätze abzuleiten. Der vorliegende Beitrag verfolgt ein anwendungsnahes Ziel: Er bündelt zentrale Elemente aus etablierten Cybersecurity-Frameworks, darunter das 98 %-Schutzmodell von Microsoft, Maßnahmen aus der NIS-2-Richtlinie, dem Anhang A der ISO 27001, das Business Continuity Management nach dem Bundesamt für Sicherheit in der Informationstechnik (BSI) sowie das Krisenmanagement im Kontext der Feuerwehr-Dienstvorschriften (FwDV). Diese werden zu einem kompakten Maßnahmenkatalog zusammengeführt und entlang der vier Umsetzungsebenen des NIST Cybersecurity Frameworks (partiell, risiko-informiert, wiederholbar, anpassungsfähig) in ein Reifegradmodell überführt. Das Ergebnis bietet Unternehmen eine pragmatische Orientierungshilfe für die Selbsteinschätzung ihrer Cyber-Resilienz und liefert Impulse für die Weiterentwicklung ihrer Sicherheitsstrategie. |
| Abstract (ENG): |
Cybersecurity has gained significant importance in recent years. Today, the question is no longer if a company will become the target of a cyberattack, but when. Consequently, the systematic strengthening of organizational resilience has moved into the spotlight. Although numerous cybersecurity models exist, each with different focuses and recommended measures, their very diversity often makes it difficult for companies to systematically assess their security posture and derive concrete improvement actions. This paper pursues a practical and application-oriented goal: it consolidates key elements from established cybersecurity frameworks, including Microsoft’s 98% Protection Model, measures from the NIS2 Directive, Annex A of ISO 27001, Business Continuity Management according to the German Federal Office for Information Security (BSI), and crisis management principles based on the German Fire Service Regulation (FwDV). These components are integrated into a compact action catalogue and translated into a maturity model aligned with the four implementation tiers of the NIST Cybersecurity Framework (partial, risk-informed, repeatable, adaptive). The result provides organizations with a pragmatic tool for self-assessing their cyber resilience and offers actionable guidance for the ongoing development of their cybersecurity strategy. |
| Forthcoming: |
No |
| Language: |
German |
| Uncontrolled Keywords: |
Cybersecurity Management ; Business Continuity Management ;
NIS2 ; Krisenmanagement ; crisis management |
| Link eMedia: |
Download |
| Citation: |
Palinkas, Kevin and Buchwald, Arne
(2026)
Vom Modell zur Maßnahme: Orientierung für Unternehmen im Cybersecurity-Dschungel From Models to Measures : Hands-on Guidance for Companies in the Cybersecurity Jungle.
HMD Praxis der Wirtschaftsinformatik.
ISSN 2198-2775
|
 |
View Item in edit mode (academic staff only) |