Score
Designs and implements maturity models and assessment frameworks by defining maturity levels, capability dimensions, metrics, scoring rubrics, and evaluation processes. Builds and conducts maturity assessments — including technical maturity assessments — producing measurement instruments, scoring procedures, and reports that analyze current state and guide capability improvement over time.
Systematic Literature Reviews (SLRs) in software engineering frequently suffer from validity threats due to omitted or inadequately executed steps, and lack an actionable, quality-improvement framework. Method: This paper introduces, for the first time, the Capability Maturity Model Integration (CMMI) maturity paradigm into SLR process modeling, proposing MM4SLR—a five-level, incremental maturity model grounded in 39 key practices, 9 goals, and 5 process areas. The model was designed via literature-driven identification, clustering analysis, and level mapping, and empirically validated across four published SLRs. Contribution/Results: MM4SLR enables effective diagnosis of SLR quality deficiencies, supports researchers in selecting context-appropriate practices, and facilitates continuous process improvement. It constitutes the first structured, assessable, and evolutionary maturity framework for enhancing the rigor, standardization, and credibility of SLRs in software engineering.
Current cybersecurity capability maturity models (CCMMs) suffer from structural rigidity, dimensional fragmentation—across technical, organizational, and human factors—overreliance on qualitative assessment, insufficient quantification, and poor contextual adaptability, resulting in fragmented evaluations and weak operational applicability. To address these limitations, this paper proposes an organization-centric cybersecurity capability maturity assessment framework. It introduces a novel dynamic modeling approach that integrates multi-dimensional capability domains, establishing a holistic, flexible, and quantitative evaluation system spanning technical, organizational, and human-factor dimensions. The framework incorporates hierarchical maturity scales, customizable scenario-adaptation mechanisms, and cross-domain consistency validation to significantly enhance assessment coverage and practical implementation. Evaluated across three representative organizational types, the framework achieves a 37% improvement in maturity identification accuracy and reduces assessment duration by 52%.
Traditional compliance assessments rely on point-in-time audits and self-attestation, which struggle to enable continuous, cross-organizational, and traceable verification of security controls in multi-vendor environments. This work proposes a permissioned blockchain-based Third-Party Risk Assessment (TPRA) framework that transforms static compliance into a dynamic, repeatable, and verifiable continuous governance mechanism through smart contract–automated evaluation workflows, multi-party governance protocols, and longitudinal state tracking. The study contributes an actionable TPRA architecture, along with complementary compliance maturity metrics and a qualitative model, enabling quantification and long-term validation of security control implementation maturity across organizational boundaries and time periods.
This study addresses the challenges of implementing technical quality control in agile R&D projects under conditions of high technological uncertainty and experimental pressure. Through a mixed-methods approach combining survey data, quantitative statistical analysis, and qualitative content analysis, it examines the adoption, perceived effectiveness, and key obstacles related to technical quality practices—such as automated testing, code reviews, and continuous integration—among Scrum teams in technology organizations based in Manaus, Brazil. As the first exploratory investigation focused on this regional innovation ecosystem, the research establishes a baseline for understanding technical quality management in agile R&D contexts. It reveals critical issues including inconsistent practice implementation, insufficient monitoring of technical quality metrics, and a lack of effective mechanisms to evaluate technical debt from a business-value perspective.
Current cryptographic agility lacks an interpretable, assessable maturity model. Method: This paper proposes the first hierarchical, quantitative cryptographic agility maturity framework, structured across four dimensions—policy, process, technology, and personnel—and defining five progressive maturity levels with corresponding evaluation metrics. It integrates CMMI-inspired modeling principles, Delphi expert consensus, and industry practice mapping analysis. Contribution/Results: The framework significantly enhances the measurability and improbability of organizational dynamic adaptability—including cryptographic algorithm replacement, protocol updates, and key management. Preliminary validation in financial and governmental sectors demonstrates its effectiveness in improving the scientific rigor and operational feasibility of cryptographic migration planning. Moreover, it serves as an interpretable, practitioner-friendly assessment tool for educational outreach, such as cultivating cryptographic literacy among secondary school students.
This work proposes a systematic approach to derive task effectiveness requirements in the absence of explicit user needs. The method deconstructs task intent into context, functionality, constraints, critical dimensions, performance attributes, and architectural solutions, and introduces a task complexity factor to quantify the impact of external challenges and technology maturity. By integrating Best-Worst Scaling, it prioritizes critical dimensions based on stakeholder judgments. Through task decomposition modeling and quantitative complexity analysis, the framework supports integration with UAF/SysML artifacts and establishes a traceable mechanism for generating Tier 1 and Tier 2 requirements. The approach is validated using a close air support mission case study, effectively addressing a critical gap in requirements engineering when clear initial inputs are unavailable.
This work addresses the absence of a unified, auditable framework for assessing the maturity of prompt assets in generative AI systems, which often struggle to balance operational objectives, safety constraints, and regulatory compliance. Inspired by Technology Readiness Levels (TRL), the paper introduces a nine-tier Prompt Readiness Levels (PRL) framework alongside a multidimensional Prompt Readiness Score (PRS) mechanism, marking the first application of engineering maturity principles to prompt engineering. Through structured design, stage-gate controls, and full lifecycle management, the proposed framework enables quantifiable and reproducible evaluation of prompt assets across dimensions including normative compliance, test coverage, traceability, security, and deployment readiness. This approach significantly enhances the reliability, regulatory compliance, and cross-team governance of generative AI systems.
This study addresses the underexplored tension between institutional expectations and lived experience among CMMC assessors operating in non-consultative roles. Drawing on role conflict theory, it employs interpretative phenomenological analysis (IPA) to conduct semi-structured interviews with CMMC-certified assessors, systematically uncovering their subjective experiences and logics of duty fulfillment in this mode. Findings reveal that assessors navigate role conflicts through strategies centered on technical competence, procedural discipline, and boundary management. These insights not only extend theoretical understandings of professional credibility construction in cybersecurity compliance contexts but also offer empirical grounding for establishing interactional norms and boundary-setting practices within CMMC implementation frameworks.