This work presents an identity-centric threat governance framework for public universities operating under the NIS2 Directive and its Italian transposition (D.Lgs. 138/2024). It formalizes an identity-based threat model for Microsoft 365 environments, performs a regulatory gap analysis against AgID baseline controls, and proposes a locally deployed RAG-based governance prototype designed for resource-constrained public sector institutions.
Fulvio D'Onofrio (Mon,) studied this question.