FAST–NIS2–CRA Compliance Artefact: Structured Requirements, Criteria, and Framework Mapping
收藏资源简介:
This dataset supports the research article “From Theory to Compliance: Operationalising Industrial Security under NIS2 and the Cyber Resilience Act,” and provides a regulatory mapping of cybersecurity obligations from the NIS2 Directive (Directive (EU) 2022/2555) and the Cyber Resilience Act (Regulation (EU) 2024/2847) to the FAST framework. The artefacts apply a structured methodology based on Breaux & Antón (2008), involving five analytical steps: role identification, obligation extraction, requirement elicitation, formulation of acceptance criteria, and mapping to FAST framework elements. The dataset enables traceability from legal obligations to implementation artefacts, supporting compliance efforts for manufacturers and system designers in industrial automation contexts. Each artefact includes: Legal traceability and classification of obligations Elicited compliance requirements with acceptance criteria Mappings to FAST framework components: Functions, Assets, Security Threats, and Treatments Justifications and coverage evaluations to assess completeness These datasets were validated with legal and technical experts to ensure traceability, legal alignment, and practical relevance for compliance planning. Contents NIS2 Requirements using Breaux and Anton(2008) method.xlsx CRA Requirements using Breaux and Anton(2008) method.xlsx README_NIS2_Requirements.rtf README_CRA_Requirements.rtf Each file is self-contained, with a recommended tab-by-tab reading order and column descriptions.



