Score
Designs and executes systematic assessments and review processes to evaluate the security posture, controls effectiveness, and compliance of systems, services, and programs, including cloud environments. Builds and applies security assessment and evaluation frameworks, accreditation workflows, and security-metrics frameworks to analyze risk, measure controls, and produce program- and compliance-oriented assessment artifacts.
Traditional compliance assessments rely on point-in-time audits and self-attestation, which struggle to enable continuous, cross-organizational, and traceable verification of security controls in multi-vendor environments. This work proposes a permissioned blockchain-based Third-Party Risk Assessment (TPRA) framework that transforms static compliance into a dynamic, repeatable, and verifiable continuous governance mechanism through smart contract–automated evaluation workflows, multi-party governance protocols, and longitudinal state tracking. The study contributes an actionable TPRA architecture, along with complementary compliance maturity metrics and a qualitative model, enabling quantification and long-term validation of security control implementation maturity across organizational boundaries and time periods.
This study addresses the poor reproducibility, lack of auditability, and reliance on manual narratives in AI safety assessments by proposing a deterministic, auditable framework. The framework standardizes heterogeneous engineering evidence into control identifiers mapped to technical-level risks, generates executable assessment functions by compiling MITRE ATLAS rules, supports repeated evaluations via versioned policy objects, and incorporates formal verification to ensure logical consistency and semantic correctness. Experiments across five open-source projects demonstrate that the framework effectively quantifies risk variations before and after hardening interventions. Results confirm that strengthened controls reduce attack feasibility while precisely revealing residual risks arising from missing core safeguards.
Existing cloud-native QA frameworks lack standardization, automation, and adaptability, resulting in inconsistent service delivery, poor scalability, and insufficient reliability. This paper proposes a lightweight, intelligent quality assurance framework tailored for cloud-native environments. It introduces, for the first time, an extensible QA policy architecture that integrates policy modeling, an intelligent rule engine, and an adaptive configuration mechanism—enabling dynamic policy generation and environment-aware adjustment. Validated through descriptive statistical analysis and industry practice surveys, the framework significantly enhances cloud service functional completeness, system reliability, and architectural evolvability. Empirical evaluation demonstrates strong acceptance among frontline developers. The work bridges a critical gap in both research and practice by delivering the first generalized, lightweight, cloud-native QA framework.
This study addresses widespread compliance issues in GitHub Actions workflows, such as excessive permissions and weak secret management. It proposes the first documentation-driven compliance checking framework, which derives a 30-item checklist from official documentation and implements a hybrid auditing pipeline combining large language models (LLMs) with expert oversight. The authors automatically evaluate 95 real-world Java workflows using four open-source LLMs, employ GPT-5 as a conflict arbitrator, and integrate manual review into a multi-tiered validation system. Experimental results reveal an overall compliance rate of only 28%, with permission control as low as 4%. The proposed approach reduces manual verification effort by 81% while achieving 87% agreement with expert judgments, significantly enhancing audit efficiency and reproducibility.
To address high manual dependency, lengthy processes, elevated false-positive rates, and poor knowledge reuse in enterprise cybersecurity compliance, this paper proposes an expert system–driven security compliance automation framework. The framework innovatively models domain expertise as persistent, transferable, and inferable knowledge units, integrating rule-based reasoning, knowledge graphs, VA/PT toolchain orchestration, automated workflow scheduling, and feedback-driven incremental learning. It overcomes the limitations of siloed security tools by enabling cross-scenario, cross-cycle adaptive auditing and continuous capability evolution. Experimental evaluation in representative enterprise networks demonstrates a 50% reduction in initial assessment time and a 20% reduction in re-assessment time, alongside significant decreases in false negatives, improved compliance coverage and result consistency, and markedly reduced reliance on human experts.
This study addresses the challenge small and medium-sized enterprises face in translating EU AI Act compliance requirements into engineering practice by presenting the first systematic empirical evaluation of twelve mainstream compliance-checking tools. Employing multi-dimensional feature characterization, legal alignment analysis, and structured report assessment, this work comprehensively examines the tools’ legal coverage and result actionability. The findings reveal significant quality disparities among existing tools, indicating their suitability is largely confined to early-stage compliance orientation while posing risks of false compliance. By establishing a critical benchmark in this domain, this research exposes current tool limitations and proposes design principles for reliable compliance instruments, thereby charting a clear direction for future optimization efforts.
This study addresses the complex assurance challenges confronting AI-enabled Cyber-Physical Systems (AI-CPS) across perception, computation, control, human factors, and governance dimensions, noting that mere compliance with ISO/IEC 42001 fails to reveal architectural impacts or practical maturity. The authors propose CEDAR-42001, a two-stage method that uniquely maps compliance audit evidence onto a seven-layer AI-CPS architecture and governance hierarchy. By integrating a five-dimensional maturity profile, constraint identification, and rule-driven reasoning, the approach generates a traceable, architecture-aware assurance posture. Applied to an autonomous vehicle fleet case, it revealed that while 89.9% of audit items were compliant, only 34.3% met a high-assurance baseline. The method successfully reconstructed the 2023 Cruise incident, precisely identifying cross-layer deficiencies and recommending targeted mitigations to inform decision-making from strategic to operational levels.
This study addresses recurring failure modes and post-certification security degradations in Common Criteria (CC) evaluations. By systematically integrating the ISO/IEC 15408 standard with the Common Evaluation Methodology (CEM), this work pioneers an evaluator-centric, cross-vendor taxonomy of lifecycle failures alongside a comprehensive root cause analysis. Furthermore, it proposes an evaluability-by-design framework and associated guidelines tailored for CC assessments, while systematically identifying unresolved challenges in critical domains such as cloud computing and artificial intelligence. The primary contribution of this research lies in bridging the existing gap in the classification of CC evaluation failure modes. Ultimately, it provides both theoretical foundations and practical guidance for enhancing the security evaluability and certification effectiveness of complex systems.
This study addresses the failure of continuous assurance in CI pipelines caused by the non-determinism of LLM-based security auditors. We propose a Policy-Evidence-Execution separation architecture that, through the TAIP engine and CCPA framework, pioneers the decoupling of policy definition from stable execution while binding admission evidence to versioned posture trees. This design achieves unified control assurance across models and environments, enabling evidence reuse and logical consistency. Evaluation on the RepoAudit benchmark demonstrates that, for Python null-pointer detection tasks, the maximum latency across 1,000 independent full-context recomputations is merely 1.62 seconds—well within the 5-second budget—thereby effectively guaranteeing the real-time performance and reliability of CI pipelines.
This study addresses the inefficiencies in SaaS onboarding within regulated enterprises, where siloed security and compliance controls—spanning third-party risk management, cybersecurity, identity and access management, and disaster recovery—often result in process delays, redundant assessments, and ambiguous accountability. To overcome these challenges, this work proposes an end-to-end, control-driven SaaS onboarding framework that integrates multi-domain controls into a unified lifecycle model encompassing requirement intake, architectural validation, identity design, resilience assessment, and post-deployment governance. By leveraging cross-domain control mapping, phased process modeling, and governance checklists, the framework codifies key design patterns such as secure connectivity, federated identity, least-privilege access, and shared-responsibility disaster recovery. Empirical implementation demonstrates that the approach significantly reduces onboarding friction, enhances audit traceability, and strengthens both the security posture and operational resilience of SaaS platforms.