Please use this identifier to cite or link to this item: http://hdl.handle.net/20.500.11960/5061
Full metadata record
DC FieldValueLanguage
dc.contributor.advisorMalta, Silvestre-
dc.contributor.advisorPinto, Pedro-
dc.contributor.authorSerra, Sérgio Tiago Gomes-
dc.date.accessioned2026-09-14T13:30:13Z-
dc.date.available2026-09-14T13:30:13Z-
dc.date.issued2026-09-07-
dc.identifier.urihttp://hdl.handle.net/20.500.11960/5061-
dc.descriptionMestrado em Cibersegurança na Escola Superior de Tecnologia e Gestão do Instituto Politécnico de Viana do Castelopt_PT
dc.description.abstractThe digital transformation and the increasing sophistication of cyber threats have driven organizations to rely on Managed Security Service Providers (MSSPs) for robust cyber defense capabilities, such as Security Operations Centers (SOCs), threat intelligence, and incident response. However, the delegation of security operations often leads to vendor lock-in due to the prevalence of proprietary technologies. This dependency limits organizations’ ability to independently verify security controls, ensure regulatory compliance (e.g., with Network and Information Security Directive 2 (NIS2) and General Data Protection Regulation (GDPR)), and maintain technological sovereignty over their cyber defense infrastructure. To address this gap, this dissertation proposes a comprehensive, open, and auditable MSSP framework designed to preserve technological sovereignty while delivering effective security services. Following a Design Science Research (DSR) methodology, informed by a Preferred Reporting Items for Systematic Reviews and Meta-Analyses (PRISMA)-based structured literature review, the study identifies the structural limitations of current MSSP architectures and derives verifiable design requirements. The main contribution is a five-layer reference architecture that orchestrates open-source security capabilities, ensuring multi-tenant isolation, continuous auditability, and the portability of operational artifacts. A functional prototype was developed to demonstrate the feasibility of the proposed framework, confirming that operational efficiency does not have to come at the expense of transparency. By shifting the service delivery model from opaque, proprietary ecosystems to inspectable workflows and replaceable components, this research advances the practical implementation of digital sovereignty in cybersecurity.pt_PT
dc.description.abstractA transformação digital e a crescente sofisticação das ameaças cibernéticas têm levado as organizações a recorrer a Managed Security Service Providers (MSSPs) para obter capacidades robustas de ciberdefesa, tais como Centros de Operações de Segurança (SOCs), inteligência de ameaças e resposta a incidentes. No entanto, a delegação das operações de segurança resulta frequentemente em dependência de fornecedores (vendor lock-in) devido à prevalência de tecnologias proprietárias. Esta dependência limita a capacidade das organizações de verificarem independentemente os controlos de segurança, garantirem a conformidade regulamentar (e.g., com a Diretiva de Segurança das Redes e da Informação 2 (NIS2) e o Regulamento Geral sobre a Proteção de Dados (RGPD)) e manterem a soberania tecnológica sobre a sua infraestrutura de ciberdefesa. Para colmatar esta lacuna, esta dissertação propõe uma framework de MSSP abrangente, aberta e auditável, concebida para preservar a soberania tecnológica sem comprometer a eficácia dos serviços de segurança. Adotando a metodologia de Design Science Research (DSR), informada por uma revisão estruturada da literatura baseada no método Preferred Reporting Items for Systematic Reviews and Meta-Analyses (PRISMA), o estudo identifica as limitações estruturais das atuais arquiteturas de MSSPs e deriva requisitos de design verificáveis. A principal contribuição é uma arquitetura de referência em cinco camadas que orquestra capacidades de segurança open-source, garantindo isolamento multi-tenant, auditabilidade contínua e a portabilidade de artefactos operacionais. Foi desenvolvido um protótipo funcional para demonstrar a viabilidade da framework proposta, confirmando que a eficiência operacional não tem de comprometer a transparência. Ao transitar de ecossistemas proprietários e opacos para workflows inspecionáveis e componentes substituíveis, esta investigação promove a implementação prática da soberania digital na cibersegurança.pt_PT
dc.language.isoengpt_PT
dc.rightsopenAccesspt_PT
dc.subjectManaged security servicespt_PT
dc.subjectTechnological sovereigntypt_PT
dc.subjectVendor lock-inpt_PT
dc.subjectAuditabilitypt_PT
dc.subjectOpen security architecturept_PT
dc.subjectDesign science researchpt_PT
dc.subjectServiços geridos de segurançapt_PT
dc.subjectSoberania tecnológicapt_PT
dc.subjectAuditabilidadept_PT
dc.subjectArquitetura aberta de segurançapt_PT
dc.titleAn open-source, auditable, and licensing-cost-efficient framework for managed security services : towards digital sovereigntypt_PT
dc.typemasterThesispt_PT
thesis.degree.nameMestrado em Cibersegurançapt_PT
thesis.degree.levelMestrept_PT
thesis.degree.disciplineCiência de Computadores e Telecomunicaçõespt_PT
dc.identifier.tid204359856pt_PT
Appears in Collections:ESTG - Dissertações de mestrado

Files in This Item:
File Description SizeFormat 
Sergio_Serra.pdf4.98 MBAdobe PDFView/Open


Items in DSpace are protected by copyright, with all rights reserved, unless otherwise indicated.