Please use this identifier to cite or link to this item:
http://hdl.handle.net/20.500.11960/5061Full metadata record
| DC Field | Value | Language |
|---|---|---|
| dc.contributor.advisor | Malta, Silvestre | - |
| dc.contributor.advisor | Pinto, Pedro | - |
| dc.contributor.author | Serra, Sérgio Tiago Gomes | - |
| dc.date.accessioned | 2026-09-14T13:30:13Z | - |
| dc.date.available | 2026-09-14T13:30:13Z | - |
| dc.date.issued | 2026-09-07 | - |
| dc.identifier.uri | http://hdl.handle.net/20.500.11960/5061 | - |
| dc.description | Mestrado em Cibersegurança na Escola Superior de Tecnologia e Gestão do Instituto Politécnico de Viana do Castelo | pt_PT |
| dc.description.abstract | The digital transformation and the increasing sophistication of cyber threats have driven organizations to rely on Managed Security Service Providers (MSSPs) for robust cyber defense capabilities, such as Security Operations Centers (SOCs), threat intelligence, and incident response. However, the delegation of security operations often leads to vendor lock-in due to the prevalence of proprietary technologies. This dependency limits organizations’ ability to independently verify security controls, ensure regulatory compliance (e.g., with Network and Information Security Directive 2 (NIS2) and General Data Protection Regulation (GDPR)), and maintain technological sovereignty over their cyber defense infrastructure. To address this gap, this dissertation proposes a comprehensive, open, and auditable MSSP framework designed to preserve technological sovereignty while delivering effective security services. Following a Design Science Research (DSR) methodology, informed by a Preferred Reporting Items for Systematic Reviews and Meta-Analyses (PRISMA)-based structured literature review, the study identifies the structural limitations of current MSSP architectures and derives verifiable design requirements. The main contribution is a five-layer reference architecture that orchestrates open-source security capabilities, ensuring multi-tenant isolation, continuous auditability, and the portability of operational artifacts. A functional prototype was developed to demonstrate the feasibility of the proposed framework, confirming that operational efficiency does not have to come at the expense of transparency. By shifting the service delivery model from opaque, proprietary ecosystems to inspectable workflows and replaceable components, this research advances the practical implementation of digital sovereignty in cybersecurity. | pt_PT |
| dc.description.abstract | A transformação digital e a crescente sofisticação das ameaças cibernéticas têm levado as organizações a recorrer a Managed Security Service Providers (MSSPs) para obter capacidades robustas de ciberdefesa, tais como Centros de Operações de Segurança (SOCs), inteligência de ameaças e resposta a incidentes. No entanto, a delegação das operações de segurança resulta frequentemente em dependência de fornecedores (vendor lock-in) devido à prevalência de tecnologias proprietárias. Esta dependência limita a capacidade das organizações de verificarem independentemente os controlos de segurança, garantirem a conformidade regulamentar (e.g., com a Diretiva de Segurança das Redes e da Informação 2 (NIS2) e o Regulamento Geral sobre a Proteção de Dados (RGPD)) e manterem a soberania tecnológica sobre a sua infraestrutura de ciberdefesa. Para colmatar esta lacuna, esta dissertação propõe uma framework de MSSP abrangente, aberta e auditável, concebida para preservar a soberania tecnológica sem comprometer a eficácia dos serviços de segurança. Adotando a metodologia de Design Science Research (DSR), informada por uma revisão estruturada da literatura baseada no método Preferred Reporting Items for Systematic Reviews and Meta-Analyses (PRISMA), o estudo identifica as limitações estruturais das atuais arquiteturas de MSSPs e deriva requisitos de design verificáveis. A principal contribuição é uma arquitetura de referência em cinco camadas que orquestra capacidades de segurança open-source, garantindo isolamento multi-tenant, auditabilidade contínua e a portabilidade de artefactos operacionais. Foi desenvolvido um protótipo funcional para demonstrar a viabilidade da framework proposta, confirmando que a eficiência operacional não tem de comprometer a transparência. Ao transitar de ecossistemas proprietários e opacos para workflows inspecionáveis e componentes substituíveis, esta investigação promove a implementação prática da soberania digital na cibersegurança. | pt_PT |
| dc.language.iso | eng | pt_PT |
| dc.rights | openAccess | pt_PT |
| dc.subject | Managed security services | pt_PT |
| dc.subject | Technological sovereignty | pt_PT |
| dc.subject | Vendor lock-in | pt_PT |
| dc.subject | Auditability | pt_PT |
| dc.subject | Open security architecture | pt_PT |
| dc.subject | Design science research | pt_PT |
| dc.subject | Serviços geridos de segurança | pt_PT |
| dc.subject | Soberania tecnológica | pt_PT |
| dc.subject | Auditabilidade | pt_PT |
| dc.subject | Arquitetura aberta de segurança | pt_PT |
| dc.title | An open-source, auditable, and licensing-cost-efficient framework for managed security services : towards digital sovereignty | pt_PT |
| dc.type | masterThesis | pt_PT |
| thesis.degree.name | Mestrado em Cibersegurança | pt_PT |
| thesis.degree.level | Mestre | pt_PT |
| thesis.degree.discipline | Ciência de Computadores e Telecomunicações | pt_PT |
| dc.identifier.tid | 204359856 | pt_PT |
| Appears in Collections: | ESTG - Dissertações de mestrado | |
Files in This Item:
| File | Description | Size | Format | |
|---|---|---|---|---|
| Sergio_Serra.pdf | 4.98 MB | Adobe PDF | View/Open |
Items in DSpace are protected by copyright, with all rights reserved, unless otherwise indicated.

