CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf
Lösenordsfri autentisering inom den offentliga sektorn: En analys av säkerhet och organisatoriska utmaningar under NIS2 och cybersäkerhetslagen
Jönköping University, School of Engineering, JTH, Department of Computer Science and Informatics.
Jönköping University, School of Engineering, JTH, Department of Computer Science and Informatics.
Jönköping University, School of Engineering, JTH, Department of Computer Science and Informatics.
2026 (Swedish)Independent thesis Basic level (degree of Bachelor), 10 credits / 15 HE creditsStudent thesisAlternative title
Passwordless authentication in the public sector : An analysis of security and organizational challenges under NIS2 and the cybersecurity act (English)
Abstract [sv]

Den snabba tekniska utvecklingen och ökade cyberhot mot den offentliga sektorn ställer högre krav på robusta autentiseringsmetoder. Syftet med detta examensarbete är att undersöka förutsättningarna samt organisatoriska utmaningar vid ett införande av lösenordsfri autentisering (LFA) inom svenska offentliga verksamheter, särskilt fokus på hur regelverk som NIS2-direktivet och cybersäkerhetslagen påverkar styrningen. Studiens frågeställningar besvaras genom en kvalitativ forskningsansats baserad på en dokumentanalys av gällande lagstiftning i kombination med semistrukturerade intervjuer med IT-ansvariga inom offentliga verksamheter. Den insamlade datan analyserades tematiskt för att identifiera tekniska, ekonomiska och regulatoriska faktorer som styr myndigheters strategiska IT-prioriteringar.

Studiens resultat visar att offentliga verksamheter har en positiv inställning till lösenordsfri autentisering som en del av en multifaktorsautentisering (MFA), men att det ofta rör sig om organisatoriska och ekonomiska hinder som stoppar en fullskalig lösenordsfri autentiseringslösning. Det framkommer att lagkraven är för ospecifika för att driva större arbete inom lösenordsfri autentisering utöver de krav som finns på multifaktorsautentisering.

För att underlätta övergången till LFA rekommenderas att skiftet förankras strategiskt i organisationens ledningssystem för informationssäkerhet (LIS) och att biometrisk teknik integreras i ordinarie hårdvaruupphandlingar.

Slutligen bör resultaten tolkas utifrån studiens specifika avgränsning. Undersökningen har avsiktligt begränsats till offentliga verksamhetsutövare, och analysen har strikt koncentrerats kring effekterna av NIS2-direktivet och cybersäkerhetslagen.

Abstract [en]

The rapid pace of technological development and increasing cyber threats against the public sector place stricter demands on robust authentication methods. The purpose of this bachelor thesis was to investigate the conditions and organizational challenges surrounding the implementation of passwordless authentication within Swedish public organizations, with a specific focus on how regulations such as the NIS2 Directive and the Cybersecurity Act influence governance. A qualitative research approach was applied, based on a document analysis of current legislation combined with semi-structured interviews with IT managers within public organizations. The collected data was analyzed thematically. 

The results show that public organizations have a positive attitude toward passwordless authentication as part of multi-factor authentication (MFA), however, organizational and economic barriers often prevent full-scale implementations. Furthermore, legal requirements are too non-specific to drive major efforts beyond existing requirements . 

To facilitate the transition, it is recommended that the shift be strategically integrated into the information security management system (ISMS) and that biometric technology be incorporated into regular hardware procurement processes .

Finally, the findings should be interpreted within the study's specific limitations. The study was intentionally restricted to public sector entities, and the analysis concentrated strictly on the effects of the NIS2 Directive and the Cybersecurity Act. 

Place, publisher, year, edition, pages
2026. , p. 43
Keywords [en]
Cybersecurity act, MFA, NIS2-directive, passwordless authentication, public sector
Keywords [sv]
cybersäkerhetslagen, LFA, lösenordsfri autentisering, MFA, NIS2-direktivet, offentlig sektor
National Category
Computer and Information Sciences
Identifiers
URN: urn:nbn:se:hj:diva-73562OAI: oai:DiVA.org:hj-73562DiVA, id: diva2:2092567
Subject / course
JTH, Informatics
Supervisors
Examiners
Available from: 2026-08-18 Created: 2026-08-17 Last updated: 2026-08-18Bibliographically approved

Open Access in DiVA

fulltext(1017 kB)26 downloads
File information
File name FULLTEXT01.pdfFile size 1017 kBChecksum SHA-512
455d19684351ae647bc41c92aa48d5d3c4409a34999d9127fe41a65588d7bb66ce5a05b721d1b432d63e59df4e87a84f857fb03a6d431cea1d0119f24ad319c6
Type fulltextMimetype application/pdf

By organisation
JTH, Department of Computer Science and Informatics
Computer and Information Sciences

Search outside of DiVA

GoogleGoogle Scholar
The number of downloads is the sum of all downloads of full texts. It may include eg previous versions that are now no longer available

urn-nbn

Altmetric score

urn-nbn
Total: 1776 hits
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf