Translating NIS2 Requirements into Actionable Tasks for SMEs Using STRNIS2

Open Access
Article
Conference Proceedings
Authors: Imants Breidaks, Henrijs Kaļķis, Anton Semenov, Valdis Pornieks
Abstract

Organisations must translate cybersecurity requirements into work that people can carry out and managers can check. This methods paper specifies STRNIS2, a six-stage method for assigning that work in small and medium-sized enterprises. Its Human-Centric Compliance Matrix (HCCM) records the requirement, task, responsibilities and evidence. The method develops our earlier NIS2 Compliance Starter Pack by specifying how information and effort are allocated across a handover. A purposive document analysis connects European and Latvian requirements with human-factors research and incident-response guidance. In a constructed reporting example, information may be deferred only if it is unnecessary for an immediate safe decision, a capable recipient accepts the remaining work, and recording and notification deadlines remain achievable. Comparison with an existing shared ticket examines when to change a procedure and when to retain it. A planned five-case study will assess method use through paired task-structuring sessions, Raw NASA-TLX, interviews and documentary review. The contribution is a task-design method and review procedure; effects on workload and cybersecurity remain to be tested.

Keywords: NIS2, human factors, SMEs, work-system design, compliance tasks, NASA-TLX

DOI: 10.54941/ahfe1008232

Cite this paper
Downloads
28
Visits
55
Download PDF

More from this volume

← Development digital skills for sustainable fashion design projects: a case study of Portuguese brandTrustworthy AI Literacy in Primary Education: A Human-Centred Learning and Measurement Design →
View all articles in Human Systems Engineering and Design (IHSED2026): Future Trends and Applications →