develop security policies

Designs and documents an organization’s security governance artifacts — formal security policies, standards, procedures, role definitions, and enforcement mechanisms that specify acceptable use, access controls, risk-management requirements, incident‑response and reporting processes, and compliance obligations. Analyzes existing policies against threats, risks and regulations, revises policy content and scope, and produces implementation plans, controls and metrics to operationalize and measure policy compliance.

developsecuritypolicies

Recent Skill Trend

Momentum and market value over time
Trending
Score
No comparison yet
-0.53
Oct 01, 2026Oct 01, 2026
Career
Value
No comparison yet
$177K/year
Oct 01, 2026Oct 01, 2026

Must-Read Papers

Most classic and influential ideas
View more

To address the challenges of complex security control configuration, difficult policy enforcement, and delayed response in networked systems, this paper proposes a Security Capability Model (SCM). The SCM establishes, for the first time, a computable abstract framework integrating information and data models, formally specifying rule semantics, policy parsing mechanisms, and data representations for filtering- and channel-protection–based controls. Leveraging UML/SysML modeling, Model-Driven Engineering (MDE), and a multi-granularity security control description language, the approach enables automated policy refinement, cross-heterogeneous-device (e.g., firewalls, encrypted gateways) configuration generation, and event-driven response. Experimental evaluation demonstrates a threefold improvement in policy deployment timeliness and a 40% increase in configuration accuracy, thereby filling a critical gap in the formal foundations for automated security policy enforcement.

OptimizationSecurity ControlsThreat Response

This study addresses the challenge fintech firms face in effectively implementing ISO/IEC 27001:2022 requirements within high-intensity information environments due to the absence of actionable implementation pathways. By analyzing a real-world case in which an organization translated the standard’s clauses and Annex A controls into eight core operational procedures, this work proposes a multi-layered, procedural Information Security Management System (ISMS) framework. The framework integrates the CIA triad as a unified evaluation criterion, a twelve-step risk assessment methodology, and role-based accountability. Through structured process modeling, role-permission mapping, and root-cause analysis of non-conformities, it establishes a closed-loop governance mechanism that is executable, measurable, and clearly assigns responsibility. The findings indicate that a tightly integrated, hierarchically structured procedural system—equipped with quantifiable risk metrics and explicit accountability—is essential for effective ISMS implementation in fintech contexts.

Financial-Technology OrganisationInformation Security ManagementISMS Implementation

Enterprise-scale general-purpose agents lack built-in, reusable governance mechanisms for autonomous cross-tool operation, making it difficult to satisfy requirements for compliance, auditability, and behavioral controllability. This work proposes the CUGA policy system, which embeds runtime governance capabilities into five critical checkpoints of the agent execution pipeline—intent protection, playbook guidance, tool invocation control, human approval gating, and output formatting—through a modular “policy-as-code” architecture. Without requiring model fine-tuning, CUGA enables proactive, continuous, and structured behavior control. By integrating typed governance primitives, dynamic playbook injection, and human-in-the-loop approval, the system effectively blocks malicious requests, enforces structured tool sequences, and triggers manual review for high-risk operations in healthcare scenarios, significantly enhancing policy adherence, execution consistency, and deployment safety.

autonomous enterprise agentscompliance-aware behaviorgeneralist agents

This study addresses the challenges of assessing compliance between organizational cybersecurity policies and abstract security control frameworks such as NIST SP 800-53, which are often time-consuming, difficult to standardize, and lack traceability. To overcome these limitations, the authors propose PROPAGATE, a novel framework that leverages large language models (LLMs) to automate control-level compliance evaluation for the first time. By integrating both open-source and closed-source LLMs, the framework automatically retrieves relevant policy text, evaluates coverage across 1,007 security controls, and generates interpretable gap analyses with actionable improvement recommendations. Experimental results on two real-world organizational policy corpora demonstrate high effectiveness, achieving F1 scores of 88.54 and 82.31, respectively, thereby enabling traceable and explainable compliance enhancement.

compliance assessmentcybersecurity policyNIST SP 800-53

Latest Papers

What's happening recently
View more

This work addresses the inadequacy of existing large language model (LLM) lifecycle frameworks, which predominantly emphasize operational efficiency while lacking explicit support for security-critical activities—such as data provenance, component signing, and access control—and failing to align governance requirements with specific lifecycle phases. The paper proposes the first security-oriented LLM system lifecycle model, structured not by workflow but by security boundaries, organizing 32 phases into four layered pipelines: data, model, distribution, and application, while integrating LLMOps and governance pillars. It uniquely identifies 13 distinct security-critical phases and exposes a structural imbalance wherein regulatory evidence is concentrated at deployment despite pivotal decisions occurring during development. By mapping key standards—including NIST AI RMF, the EU AI Act, and ISO/IEC 42001—the study establishes a phase-to-governance correspondence mechanism, yielding a comprehensive, lifecycle-spanning security analysis framework that offers structured guidance for compliance and secure design.

governance frameworklarge language modelsLLM systems

Current AI incident governance frameworks lack consistency in defining, categorizing, monitoring, and reporting incidents, which constrains the depth and accuracy of post-deployment failure analysis. This study addresses this gap through a systematic literature review and comparative analysis across multiple governance frameworks, thereby identifying and synthesizing key inconsistencies that span existing mechanisms. The work reveals systemic deficiencies in data collection practices, classification logics, and analytical rigor, and elucidates critical misalignments among core governance components. By clarifying these structural disconnects, the research establishes a theoretical foundation and proposes a coordinated pathway toward a unified, standardized framework for AI incident governance.

AI incident governanceclassificationdefinitions

This study addresses the challenge faced by small and medium-sized organizations in leveraging large language models (LLMs) for automated gap analysis between their security policy documents and compliance standards such as ISO/IEC 27002:2022, primarily due to limited access to high-compute resources. To bridge this gap, the work presents the first end-to-end benchmarking framework tailored for low-resource environments, integrating document parsing, control alignment, and semantic retrieval techniques to evaluate lightweight LLMs that operate without GPU acceleration or substantial memory. Experimental results demonstrate that these resource-efficient models maintain high accuracy and consistency across multiple real-world compliance assessment tasks comparing organizational policies against ISO/IEC 27002:2022, thereby facilitating the practical deployment of lightweight AI solutions in cybersecurity governance.

automated compliance checkingcybersecurity complianceinformation security governance

This study addresses critical challenges in the management of cybersecurity risk documentation for medical devices, which is typically authored in semi-structured natural language and suffers from poor consistency, low review efficiency, limited reusability, and a lack of unified modeling of safety and cybersecurity risks. To overcome these limitations, the authors propose SECUMAN, an ontology integrated with SHACL constraints, extending the safety-oriented RISKMAN methodology to the cybersecurity domain for the first time. The framework introduces key concepts such as threat scenarios, protection objectives, and attacker profiles, aligning with both the VDE Spec 90025 standard and the RISKMAN ontology. This approach enables semantic structuring of risk documentation, automated completeness validation, and cross-domain interoperability, thereby significantly enhancing document consistency, review efficiency, and the integrated governance of safety and cybersecurity risks.

consistency checkingcybersecurity risk managementmedical devices

Hot Scholars

NA

Nikolaos Avouris

Professor, University of Patras
Human-Computer InteractionSoftware EngineeringLearning TechnologyCultural Heritage
AM

Amy McGovern

University of Oklahoma
Artificial IntelligenceMachine LearningSevere Weather
IR

Iyad Rahwan

Center for Humans & Machines, Max Planck Institute for Human Development
Computational Social ScienceAIMachine BehaviorPsychology of Technology
RB

Ruta Binkyte

CISPA Helmholtz Center for Information Security
FairnessCausalityLLMMulti-Agent Fairness
ME

Maksim E. Eren

Los Alamos National Laboratory
Machine LearningCybersecurityTensor Decompositions