Score
Following principled processes to attribute, mitigate, document, and communicate security, privacy, or safety incidents and vulnerabilities to relevant stakeholders in ways that limit harm and enable remediation.
High-level security properties (e.g., confidentiality, integrity) in the Software Development Life Cycle (SDLC) lack systematic refinement mechanisms, leading to semantic disconnects between these properties and concrete artifacts such as threats, defenses, and assets. Method: We propose the first SDLC-wide security property refinement taxonomy, implemented as a formal, refinable, verifiable, and traceable classification framework in Event-B. The framework integrates principles from security engineering and adaptive systems theory. Contribution: It bridges the semantic gap between high-level security objectives and mid-to-low-level security models, enabling co-evolution of security properties with threat and defense models. Rigorously verified in Event-B, the framework ensures logical consistency and correctness. It provides both theoretically sound foundations and practically actionable guidance for security requirements–driven system development.
This paper addresses the core challenge faced by statistical agencies in selecting and designing disclosure avoidance systems (DAS): the difficulty of distinguishing between inherent system properties and implementation-specific choices. We propose the first principled evaluation framework that explicitly decouples “system essential attributes” from “implementation decisions.” Methodologically, the framework integrates risk assessment theory, statistical disclosure control (SDC) paradigm analysis, multi-dimensional constraint modeling, and iterative systems engineering—enabling dynamic trade-offs among privacy protection strength, data utility, and system adaptability under concurrent constraints of legal compliance, scientific validity, resource limitations, and stakeholder requirements. Our primary contribution is filling a critical gap in standardized DAS evaluation by delivering a practical, actionable framework. It supports evidence-based system selection and customized deployment, thereby enhancing the usability and operational agility of official statistics while ensuring regulatory compliance.
This study addresses two core challenges in large-scale security vulnerability notifications: fragmented multi-stakeholder coordination and persistent conflation between vulnerability disclosure and notification practices. Through cross-case qualitative meta-analysis, operational log reconstruction, and comparative analysis of policy evolution, we systematically distinguish—along objective, procedural, and ethical dimensions—the fundamental nature of vulnerability disclosure (repair-oriented, collaboration-centric) versus vulnerability notification (reach-oriented, scalability-focused). Building on this distinction, we propose the first “end-to-end notification operations framework” tailored for large-scale stakeholder outreach, encompassing message initiation, multi-channel adaptation, and response assessment, accompanied by a dedicated ethical guideline. The framework has been formally integrated into a draft revision of the industry-wide Vulnerability Notification Operations Standard.
This study addresses the inadequacy of current IT compliance–oriented cybersecurity policies in safeguarding the physical safety of cyber-physical systems, as digital failures often precipitate real-world harm. By coding 292 critical infrastructure policies (2000–2025) and aligning them with the NIST SP 800-160 Vol. 2 resilience lifecycle, the research reveals a significant misalignment between prevailing policy approaches—overreliant on IT control catalogs during resistance and recovery phases—and actual physical risks. The work proposes a modernized “duty of reasonable care” standard centered on hazard-specific traceability, structured assurance cases, and cyber resilience engineering. It identifies three critical disconnects: misaligned delegation of standards, reduction of recovery mechanisms to mere incident reporting, and uneven sectoral adaptability. The study further outlines a viable pathway for federal policy that integrates engineering implementation with targeted incentives.
In process mining, real-world event logs are often inaccessible for sharing due to corporate privacy and confidentiality concerns—distinct from individual data privacy—posing a critical bottleneck for collaborative analysis. Method: This paper formally defines “confidentiality” for process data and introduces Privacy and Confidentiality Requirements Engineering (PCRE), a methodology integrating stakeholder co-modelling, structured expert interviews, and privacy-enhancing action design. PCRE systematically balances GDPR compliance, protection of business-sensitive information, and analytical utility. Contribution/Results: Empirical validation across two manufacturing enterprises demonstrates PCRE’s feasibility and reusability in high-sensitivity industrial settings. The framework delivers a practical, requirements-driven paradigm for conducting compliant and analytically viable process data analysis—bridging regulatory adherence with operational relevance in enterprise process intelligence.
This study addresses the challenge of privacy communication in human–robot collaboration systems within Industry 5.0, where sensitive data monitoring raises significant privacy concerns that are often obscured by technical complexity, leading to mistrust and resistance among non-technical stakeholders. To bridge this gap, the authors propose a novel conceptual framework that integrates Privacy by Design principles with large language models (LLMs), leveraging LLMs for the first time in the requirements engineering process to automatically generate natural-language privacy reports tailored for non-technical audiences from representative human–robot monitoring scenarios. Evaluation across two industrial use cases demonstrates that the approach substantially enhances the comprehensibility of privacy information and supports informed decision-making, thereby addressing a critical accessibility gap in existing privacy communication mechanisms.
This study uncovers an inherent tension among cybersecurity governance, data protection, and corporate reputation in digital transformation: despite high compliance readiness—75% of surveyed firms experienced at least one cyberattack within the past year—security incidents persist, with reputational damage and erosion of customer trust being the predominant consequences. Method: Drawing on an online diagnostic survey across multiple industries in Poland, the study applies the ISO/IEC 27001/27032 frameworks and a structured questionnaire, employing descriptive statistics and attributional analysis. Contribution/Results: It provides the first empirical identification of the “compliance–security paradox.” The study proposes a novel paradigm that integrates cybersecurity governance deeply into corporate communication and reputation management systems. It positions data protection as the cornerstone of digital trust and organizational resilience, reframing cybersecurity from a regulatory cost center to a strategic investment.
This work addresses the limitations of existing large language models, which are typically confined to isolated tasks and struggle to integrate into industrial-scale, multi-stage security workflows. To bridge this gap, the authors propose the first role-based multi-agent framework tailored to the entire vulnerability lifecycle, incorporating specialized agents—Planner, Analyzer, Fixer, and Verifier—augmented with CodeQL static analysis for enhanced precision. By introducing a role-oriented multi-agent architecture into end-to-end vulnerability management, this approach effectively aligns the capabilities of large models with real-world security engineering demands. Evaluated on 25 real-world C/C++ vulnerabilities, the system achieves a detection accuracy of 44%—comparable to GPT-5.5—and a repair accuracy of 19%, offering a practical and collaborative paradigm for intelligent security operations.
This study addresses the pervasive delay in patching critical vulnerabilities (CVSS ≥ 9.0) following disclosure, which significantly exacerbates organizational cybersecurity risks. Analyzing 12.8% of critical vulnerabilities among 245,456 CVEs reported between 2009 and 2024, this work presents the first integrated approach combining large-scale quantitative analysis with in-depth case studies. It reveals that remediation lags are systematically constrained by organizational processes, resource endowments, and system complexity, with pronounced disparities across industry sectors. Beyond elucidating the systemic mechanisms underlying vulnerability management delays, the research offers actionable recommendations for optimizing incident response. These findings provide empirical grounding and practical guidance to enhance the effectiveness of critical vulnerability governance.
This study addresses the challenge fintech firms face in effectively implementing ISO/IEC 27001:2022 requirements within high-intensity information environments due to the absence of actionable implementation pathways. By analyzing a real-world case in which an organization translated the standard’s clauses and Annex A controls into eight core operational procedures, this work proposes a multi-layered, procedural Information Security Management System (ISMS) framework. The framework integrates the CIA triad as a unified evaluation criterion, a twelve-step risk assessment methodology, and role-based accountability. Through structured process modeling, role-permission mapping, and root-cause analysis of non-conformities, it establishes a closed-loop governance mechanism that is executable, measurable, and clearly assigns responsibility. The findings indicate that a tightly integrated, hierarchically structured procedural system—equipped with quantifiable risk metrics and explicit accountability—is essential for effective ISMS implementation in fintech contexts.
Traditional CVSS scores often fail to effectively prioritize vulnerability remediation in real-world attack scenarios. This work proposes a composite Key Risk Indicator (KRI) based on expected loss decomposition, which, for the first time, decouples threat, exposure, and business impact into distinct modeling components to enable risk-informed remediation decisions. The KRI model integrates the Known Exploited Vulnerabilities (KEV) catalog, over 280,000 CVE records, and metrics including EPSS, CVSS, and attack surface exposure. Empirical evaluation demonstrates that KRI achieves a ROC-AUC of 0.927 and an AUPRC of 0.223, significantly outperforming CVSS. Moreover, when prioritizing the top 500 vulnerabilities for remediation, KRI captures 92.3% of impact-weighted value and identifies 1.75 times more critically exploited vulnerabilities than EPSS.