hh.sePublications
Change search
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf
CTEM: The Next Big Thing or Just a Buzzword?: A comparative study of CTEM and NIST CSF 2.0 in modern cyber risk management
Halmstad University, School of Information Technology.
Halmstad University, School of Information Technology.
2025 (English)Independent thesis Advanced level (degree of Master (One Year)), 10 credits / 15 HE creditsStudent thesis
Abstract [en]

The thesis "CTEM: The Next Big Thing or Just a Buzzword? - A comparative study of CTEM and NIST CSF 2.0 in modern cyber risk management" investigates Continuous Threat Exposure Management (CTEM) compared to the National Institute of Standards and Technology Cybersecurity Framework (NIST CSF) 2.0. Through a comparative analysis and interviews with cybersecurity professionals, the study aims to explore how CTEM can help organizations adopt a more continuous and adaptive approach to manage cybersecurity risks. 

The results show that CTEM offers a dynamic and proactive approach to threat management, focusing on continuous monitoring, while NIST CSF 2.0 relies more on traditional methods. It also identifies similarities and differences between the frameworks, recognizing that the continuous approach can complement the NIST CSF 2.0. That integration can strengthen the comprehensive cybersecurity strategy of organizations that addresses current and emerging threats. A combination of CTEM and NIST CSF 2.0 addresses challenges such as management support, which are discussed in the discussion. The combination can lead to sustained resilience to cyber threats and ensure a safer digital environment with economic benefits for organizations. 

Place, publisher, year, edition, pages
2025. , p. 40
Keywords [en]
Continuous Threat Exposure Management, CTEM, National Institute of Standards and Technology Cybersecurity Framework, NIST CSF 2.0, Cybersecurity, Framework
National Category
Other Computer and Information Science
Identifiers
URN: urn:nbn:se:hh:diva-56120OAI: oai:DiVA.org:hh-56120DiVA, id: diva2:1962315
External cooperation
Knowit Cybersecurity & Law
Subject / course
Digital Forensics
Educational program
Master's Programme in Network Forensics, 60 credits
Supervisors
Examiners
Available from: 2025-06-03 Created: 2025-05-29 Last updated: 2025-10-01Bibliographically approved

Open Access in DiVA

fulltext(560 kB)208 downloads
File information
File name FULLTEXT02.pdfFile size 560 kBChecksum SHA-512
ca2ea4b4be230df5c3046ef55712e220ed308c39a598460e7af313d2c6e742f1c18de2cf2905147704cbcf13b0e31f7df7e72975ecab3016acf69f0ad4f65fda
Type fulltextMimetype application/pdf

By organisation
School of Information Technology
Other Computer and Information Science

Search outside of DiVA

GoogleGoogle Scholar
Total: 208 downloads
The number of downloads is the sum of all downloads of full texts. It may include eg previous versions that are now no longer available

urn-nbn

Altmetric score

urn-nbn
Total: 657 hits
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf