conduct security assessments

Designs and executes systematic assessments and review processes to evaluate the security posture, controls effectiveness, and compliance of systems, services, and programs, including cloud environments. Builds and applies security assessment and evaluation frameworks, accreditation workflows, and security-metrics frameworks to analyze risk, measure controls, and produce program- and compliance-oriented assessment artifacts.

conductsecurityassessments

Recent Skill Trend

Momentum and market value over time
Trending
Score
No comparison yet
1.48
Oct 01, 2026Oct 01, 2026
Career
Value
No comparison yet
$202K/year
Oct 01, 2026Oct 01, 2026

Must-Read Papers

Most classic and influential ideas
View more

Traditional compliance assessments rely on point-in-time audits and self-attestation, which struggle to enable continuous, cross-organizational, and traceable verification of security controls in multi-vendor environments. This work proposes a permissioned blockchain-based Third-Party Risk Assessment (TPRA) framework that transforms static compliance into a dynamic, repeatable, and verifiable continuous governance mechanism through smart contract–automated evaluation workflows, multi-party governance protocols, and longitudinal state tracking. The study contributes an actionable TPRA architecture, along with complementary compliance maturity metrics and a qualitative model, enabling quantification and long-term validation of security control implementation maturity across organizational boundaries and time periods.

blockchaincompliance assessmentframework implementation

This study addresses the poor reproducibility, lack of auditability, and reliance on manual narratives in AI safety assessments by proposing a deterministic, auditable framework. The framework standardizes heterogeneous engineering evidence into control identifiers mapped to technical-level risks, generates executable assessment functions by compiling MITRE ATLAS rules, supports repeated evaluations via versioned policy objects, and incorporates formal verification to ensure logical consistency and semantic correctness. Experiments across five open-source projects demonstrate that the framework effectively quantifies risk variations before and after hardening interventions. Results confirm that strengthened controls reduce attack feasibility while precisely revealing residual risks arising from missing core safeguards.

AI security risk assessmentauditabilitydeterministic evaluation

Towards a Robust Quality Assurance Framework for Cloud Computing Environments

Feb 19, 2025
MA
Mohammed Alharbi
🏛️ King Abdul-Aziz University

Existing cloud-native QA frameworks lack standardization, automation, and adaptability, resulting in inconsistent service delivery, poor scalability, and insufficient reliability. This paper proposes a lightweight, intelligent quality assurance framework tailored for cloud-native environments. It introduces, for the first time, an extensible QA policy architecture that integrates policy modeling, an intelligent rule engine, and an adaptive configuration mechanism—enabling dynamic policy generation and environment-aware adjustment. Validated through descriptive statistical analysis and industry practice surveys, the framework significantly enhances cloud service functional completeness, system reliability, and architectural evolvability. Empirical evaluation demonstrates strong acceptance among frontline developers. The work bridges a critical gap in both research and practice by delivering the first generalized, lightweight, cloud-native QA framework.

Address automation and flexibility in QA systemsDevelop robust QA framework for cloud computingEnhance service reliability and scalability in clouds

This study addresses widespread compliance issues in GitHub Actions workflows, such as excessive permissions and weak secret management. It proposes the first documentation-driven compliance checking framework, which derives a 30-item checklist from official documentation and implements a hybrid auditing pipeline combining large language models (LLMs) with expert oversight. The authors automatically evaluate 95 real-world Java workflows using four open-source LLMs, employ GPT-5 as a conflict arbitrator, and integrate manual review into a multi-tiered validation system. Experimental results reveal an overall compliance rate of only 28%, with permission control as low as 4%. The proposed approach reduces manual verification effort by 81% while achieving 87% agreement with expert judgments, significantly enhancing audit efficiency and reproducibility.

best practicesCI/CD securitycompliance

ESASCF: Expertise Extraction, Generalization and Reply Framework for Optimized Automation of Network Security Compliance

Jul 20, 2023
MG
M. Ghanem
🏛️ London Metropolitan University | University of Liverpool | City, University of London | Technology Innovation Institute

To address high manual dependency, lengthy processes, elevated false-positive rates, and poor knowledge reuse in enterprise cybersecurity compliance, this paper proposes an expert system–driven security compliance automation framework. The framework innovatively models domain expertise as persistent, transferable, and inferable knowledge units, integrating rule-based reasoning, knowledge graphs, VA/PT toolchain orchestration, automated workflow scheduling, and feedback-driven incremental learning. It overcomes the limitations of siloed security tools by enabling cross-scenario, cross-cycle adaptive auditing and continuous capability evolution. Experimental evaluation in representative enterprise networks demonstrates a 50% reduction in initial assessment time and a 20% reduction in re-assessment time, alongside significant decreases in false negatives, improved compliance coverage and result consistency, and markedly reduced reliance on human experts.

Automated CybersecurityRule-based SystemsThreat Mitigation

Latest Papers

What's happening recently
View more

This study addresses the challenge small and medium-sized enterprises face in translating EU AI Act compliance requirements into engineering practice by presenting the first systematic empirical evaluation of twelve mainstream compliance-checking tools. Employing multi-dimensional feature characterization, legal alignment analysis, and structured report assessment, this work comprehensively examines the tools’ legal coverage and result actionability. The findings reveal significant quality disparities among existing tools, indicating their suitability is largely confined to early-stage compliance orientation while posing risks of false compliance. By establishing a critical benchmark in this domain, this research exposes current tool limitations and proposes design principles for reliable compliance instruments, thereby charting a clear direction for future optimization efforts.

AI governancecompliance checkersempirical study

This study addresses the complex assurance challenges confronting AI-enabled Cyber-Physical Systems (AI-CPS) across perception, computation, control, human factors, and governance dimensions, noting that mere compliance with ISO/IEC 42001 fails to reveal architectural impacts or practical maturity. The authors propose CEDAR-42001, a two-stage method that uniquely maps compliance audit evidence onto a seven-layer AI-CPS architecture and governance hierarchy. By integrating a five-dimensional maturity profile, constraint identification, and rule-driven reasoning, the approach generates a traceable, architecture-aware assurance posture. Applied to an autonomous vehicle fleet case, it revealed that while 89.9% of audit items were compliant, only 34.3% met a high-assurance baseline. The method successfully reconstructed the 2023 Cruise incident, precisely identifying cross-layer deficiencies and recommending targeted mitigations to inform decision-making from strategic to operational levels.

AI-CPSarchitectural layersassurance posture

This study addresses recurring failure modes and post-certification security degradations in Common Criteria (CC) evaluations. By systematically integrating the ISO/IEC 15408 standard with the Common Evaluation Methodology (CEM), this work pioneers an evaluator-centric, cross-vendor taxonomy of lifecycle failures alongside a comprehensive root cause analysis. Furthermore, it proposes an evaluability-by-design framework and associated guidelines tailored for CC assessments, while systematically identifying unresolved challenges in critical domains such as cloud computing and artificial intelligence. The primary contribution of this research lies in bridging the existing gap in the classification of CC evaluation failure modes. Ultimately, it provides both theoretical foundations and practical guidance for enhancing the security evaluability and certification effectiveness of complex systems.

Common CriteriaFailure ModesProduct Evaluation

This study addresses the failure of continuous assurance in CI pipelines caused by the non-determinism of LLM-based security auditors. We propose a Policy-Evidence-Execution separation architecture that, through the TAIP engine and CCPA framework, pioneers the decoupling of policy definition from stable execution while binding admission evidence to versioned posture trees. This design achieves unified control assurance across models and environments, enabling evidence reuse and logical consistency. Evaluation on the RepoAudit benchmark demonstrates that, for Python null-pointer detection tasks, the maximum latency across 1,000 independent full-context recomputations is merely 1.62 seconds—well within the 5-second budget—thereby effectively guaranteeing the real-time performance and reliability of CI pipelines.

Agentic Security AuditorsContinuous AssuranceLarge Language Models

This study addresses the inefficiencies in SaaS onboarding within regulated enterprises, where siloed security and compliance controls—spanning third-party risk management, cybersecurity, identity and access management, and disaster recovery—often result in process delays, redundant assessments, and ambiguous accountability. To overcome these challenges, this work proposes an end-to-end, control-driven SaaS onboarding framework that integrates multi-domain controls into a unified lifecycle model encompassing requirement intake, architectural validation, identity design, resilience assessment, and post-deployment governance. By leveraging cross-domain control mapping, phased process modeling, and governance checklists, the framework codifies key design patterns such as secure connectivity, federated identity, least-privilege access, and shared-responsibility disaster recovery. Empirical implementation demonstrates that the approach significantly reduces onboarding friction, enhances audit traceability, and strengthens both the security posture and operational resilience of SaaS platforms.

disaster recoveryIdentity and Access Managementregulated enterprises

Hot Scholars

AO

Alina Oprea

Northeastern University
Computer SecurityAdversarial Machine LearningAI Security
CN

Cristina Nita-Rotaru

Professor, Khoury College of Computer Science, Northeastern University
network securitydistributed systemsbyzantine-resiliencetrustworthy AI
RS

Riccardo Scandariato

Head of the Institute of Software Security, Hamburg University of Technology (TUHH)
SecurityPrivacySoftware Engineering
ZW

Zhun Wang

Graduate Student, UC Berkeley
DS

Dawn Song

Professor of Computer Science, UC Berkeley
Computer Security and Privacy