Score
Designs, builds, and analyzes organizational security governance artifacts — frameworks, models, policies, roles, processes, metrics, control mappings, and implementation plans — that embed security objectives, accountability, and compliance into decision‑making and oversight. Develops and assesses secure governance models and governance frameworks and implements mechanisms for enforcement, monitoring, and continuous improvement.
This work addresses the inadequacy of existing large language model (LLM) lifecycle frameworks, which predominantly emphasize operational efficiency while lacking explicit support for security-critical activities—such as data provenance, component signing, and access control—and failing to align governance requirements with specific lifecycle phases. The paper proposes the first security-oriented LLM system lifecycle model, structured not by workflow but by security boundaries, organizing 32 phases into four layered pipelines: data, model, distribution, and application, while integrating LLMOps and governance pillars. It uniquely identifies 13 distinct security-critical phases and exposes a structural imbalance wherein regulatory evidence is concentrated at deployment despite pivotal decisions occurring during development. By mapping key standards—including NIST AI RMF, the EU AI Act, and ISO/IEC 42001—the study establishes a phase-to-governance correspondence mechanism, yielding a comprehensive, lifecycle-spanning security analysis framework that offers structured guidance for compliance and secure design.
Enterprise-scale general-purpose agents lack built-in, reusable governance mechanisms for autonomous cross-tool operation, making it difficult to satisfy requirements for compliance, auditability, and behavioral controllability. This work proposes the CUGA policy system, which embeds runtime governance capabilities into five critical checkpoints of the agent execution pipeline—intent protection, playbook guidance, tool invocation control, human approval gating, and output formatting—through a modular “policy-as-code” architecture. Without requiring model fine-tuning, CUGA enables proactive, continuous, and structured behavior control. By integrating typed governance primitives, dynamic playbook injection, and human-in-the-loop approval, the system effectively blocks malicious requests, enforces structured tool sequences, and triggers manual review for high-risk operations in healthcare scenarios, significantly enhancing policy adherence, execution consistency, and deployment safety.
To address the challenges of complex security control configuration, difficult policy enforcement, and delayed response in networked systems, this paper proposes a Security Capability Model (SCM). The SCM establishes, for the first time, a computable abstract framework integrating information and data models, formally specifying rule semantics, policy parsing mechanisms, and data representations for filtering- and channel-protection–based controls. Leveraging UML/SysML modeling, Model-Driven Engineering (MDE), and a multi-granularity security control description language, the approach enables automated policy refinement, cross-heterogeneous-device (e.g., firewalls, encrypted gateways) configuration generation, and event-driven response. Experimental evaluation demonstrates a threefold improvement in policy deployment timeliness and a 40% increase in configuration accuracy, thereby filling a critical gap in the formal foundations for automated security policy enforcement.
本文提出AspisAI框架,通过将多种标准要求转化为机器可解释的模型并评估证据,解决多标准合规监测成本高、一致性差的问题。
This study addresses the challenge fintech firms face in effectively implementing ISO/IEC 27001:2022 requirements within high-intensity information environments due to the absence of actionable implementation pathways. By analyzing a real-world case in which an organization translated the standard’s clauses and Annex A controls into eight core operational procedures, this work proposes a multi-layered, procedural Information Security Management System (ISMS) framework. The framework integrates the CIA triad as a unified evaluation criterion, a twelve-step risk assessment methodology, and role-based accountability. Through structured process modeling, role-permission mapping, and root-cause analysis of non-conformities, it establishes a closed-loop governance mechanism that is executable, measurable, and clearly assigns responsibility. The findings indicate that a tightly integrated, hierarchically structured procedural system—equipped with quantifiable risk metrics and explicit accountability—is essential for effective ISMS implementation in fintech contexts.
This work addresses the absence of standardized, composable oversight infrastructure in current AI deployments, which leads teams to repeatedly build fragmented auditing and monitoring mechanisms. The authors propose a five-layer, six-dimension framework for AI oversight, with a particular focus on formally defining— for the first time—the “normative layer.” This layer translates human intent into executable, traceable, and upgradable machine-checkable norms through six design principles, including elicitable, adversarially aware, and governable specifications. Integrating formal methods, policy languages (e.g., Cedar, OPA), and constitutional AI concepts, the study introduces CARMA, a norm-driven runtime oversight prototype that demonstrates how a single norm can uniformly drive execution, evaluation, and upgrading. The system validates the feasibility of reusing composable oversight components across teams.
Traditional compliance assessments rely on point-in-time audits and self-attestation, which struggle to enable continuous, cross-organizational, and traceable verification of security controls in multi-vendor environments. This work proposes a permissioned blockchain-based Third-Party Risk Assessment (TPRA) framework that transforms static compliance into a dynamic, repeatable, and verifiable continuous governance mechanism through smart contract–automated evaluation workflows, multi-party governance protocols, and longitudinal state tracking. The study contributes an actionable TPRA architecture, along with complementary compliance maturity metrics and a qualitative model, enabling quantification and long-term validation of security control implementation maturity across organizational boundaries and time periods.
This study addresses the inefficiency of manual auditing in corporate governance and the challenges in validating automated alternatives by proposing a task replacement system within a Digital Governance Framework (DGF). Methodologically, it introduces a residual workload threshold as the criterion for task substitution, establishing an information sufficiency gating mechanism. Architecturally, the framework integrates intelligent agents, rule engines, and evidence services, automating auditing workflows through forward deployment engineering and constructing the DGF-Bench benchmark for multi-model evaluation. Experimental results demonstrate that models such as Gemini achieve success rates up to 94.98% under strict gating conditions, confirming the technical feasibility of automating specific governance tasks and offering an effective paradigm for enterprise digital governance.
This study addresses the governance failures in cybersecurity arising from AI deployment in the public sector, a domain underexplored in existing literature due to insufficient integration of institutional constraints and governance instruments. The authors develop a seven-dimensional typological framework to identify ten root causes of AI-driven governance failure, introducing “velocity asymmetry” as a novel structural mechanism. They critically evaluate five major frameworks—including NIST CSF 2.0 and ISO/IEC 27001—through institutional analysis, typology construction, and coverage matrix assessment, revealing significant gaps in addressing shadow AI, velocity asymmetry, and governance vacuums. Building on these insights, the study proposes an interactive tripartite model linking accountability, operational resilience, and compliance failures, culminating in a design specification for an AI-enabled cybersecurity maturity model tailored to government agencies that explicitly maps current governance frameworks’ coverage gaps in the public sector.
This work addresses the security and compliance risks arising when large language model (LLM) agents directly trigger state-changing actions within workflows. To mitigate these risks, the authors propose decoupling action generation from execution and introduce, for the first time, an Organizational Control Layer (OCL) architecture—a model-agnostic, non-intrusive governance infrastructure that enforces policy checks, enables action interception, and supports human escalation prior to execution. The approach requires no modification to the underlying LLM and is compatible with diverse backend systems. Evaluated on an adversarial negotiation task, the method reduces unsafe execution rates from 88% to near zero while increasing effective success rates from 12% to 96%, demonstrating the efficacy and practicality of the proposed governance mechanism.