security governance

Designs, builds, and analyzes organizational security governance artifacts — frameworks, models, policies, roles, processes, metrics, control mappings, and implementation plans — that embed security objectives, accountability, and compliance into decision‑making and oversight. Develops and assesses secure governance models and governance frameworks and implements mechanisms for enforcement, monitoring, and continuous improvement.

securitygovernance

Recent Skill Trend

Momentum and market value over time
Trending
Score
No comparison yet
2.14
Oct 01, 2026Oct 01, 2026
Career
Value
No comparison yet
$220K/year
Oct 01, 2026Oct 01, 2026

Must-Read Papers

Most classic and influential ideas
View more

This work addresses the inadequacy of existing large language model (LLM) lifecycle frameworks, which predominantly emphasize operational efficiency while lacking explicit support for security-critical activities—such as data provenance, component signing, and access control—and failing to align governance requirements with specific lifecycle phases. The paper proposes the first security-oriented LLM system lifecycle model, structured not by workflow but by security boundaries, organizing 32 phases into four layered pipelines: data, model, distribution, and application, while integrating LLMOps and governance pillars. It uniquely identifies 13 distinct security-critical phases and exposes a structural imbalance wherein regulatory evidence is concentrated at deployment despite pivotal decisions occurring during development. By mapping key standards—including NIST AI RMF, the EU AI Act, and ISO/IEC 42001—the study establishes a phase-to-governance correspondence mechanism, yielding a comprehensive, lifecycle-spanning security analysis framework that offers structured guidance for compliance and secure design.

governance frameworklarge language modelsLLM systems

Enterprise-scale general-purpose agents lack built-in, reusable governance mechanisms for autonomous cross-tool operation, making it difficult to satisfy requirements for compliance, auditability, and behavioral controllability. This work proposes the CUGA policy system, which embeds runtime governance capabilities into five critical checkpoints of the agent execution pipeline—intent protection, playbook guidance, tool invocation control, human approval gating, and output formatting—through a modular “policy-as-code” architecture. Without requiring model fine-tuning, CUGA enables proactive, continuous, and structured behavior control. By integrating typed governance primitives, dynamic playbook injection, and human-in-the-loop approval, the system effectively blocks malicious requests, enforces structured tool sequences, and triggers manual review for high-risk operations in healthcare scenarios, significantly enhancing policy adherence, execution consistency, and deployment safety.

autonomous enterprise agentscompliance-aware behaviorgeneralist agents

To address the challenges of complex security control configuration, difficult policy enforcement, and delayed response in networked systems, this paper proposes a Security Capability Model (SCM). The SCM establishes, for the first time, a computable abstract framework integrating information and data models, formally specifying rule semantics, policy parsing mechanisms, and data representations for filtering- and channel-protection–based controls. Leveraging UML/SysML modeling, Model-Driven Engineering (MDE), and a multi-granularity security control description language, the approach enables automated policy refinement, cross-heterogeneous-device (e.g., firewalls, encrypted gateways) configuration generation, and event-driven response. Experimental evaluation demonstrates a threefold improvement in policy deployment timeliness and a 40% increase in configuration accuracy, thereby filling a critical gap in the formal foundations for automated security policy enforcement.

OptimizationSecurity ControlsThreat Response

This study addresses the challenge fintech firms face in effectively implementing ISO/IEC 27001:2022 requirements within high-intensity information environments due to the absence of actionable implementation pathways. By analyzing a real-world case in which an organization translated the standard’s clauses and Annex A controls into eight core operational procedures, this work proposes a multi-layered, procedural Information Security Management System (ISMS) framework. The framework integrates the CIA triad as a unified evaluation criterion, a twelve-step risk assessment methodology, and role-based accountability. Through structured process modeling, role-permission mapping, and root-cause analysis of non-conformities, it establishes a closed-loop governance mechanism that is executable, measurable, and clearly assigns responsibility. The findings indicate that a tightly integrated, hierarchically structured procedural system—equipped with quantifiable risk metrics and explicit accountability—is essential for effective ISMS implementation in fintech contexts.

Financial-Technology OrganisationInformation Security ManagementISMS Implementation

Latest Papers

What's happening recently
View more

This work addresses the absence of standardized, composable oversight infrastructure in current AI deployments, which leads teams to repeatedly build fragmented auditing and monitoring mechanisms. The authors propose a five-layer, six-dimension framework for AI oversight, with a particular focus on formally defining— for the first time—the “normative layer.” This layer translates human intent into executable, traceable, and upgradable machine-checkable norms through six design principles, including elicitable, adversarially aware, and governable specifications. Integrating formal methods, policy languages (e.g., Cedar, OPA), and constitutional AI concepts, the study introduces CARMA, a norm-driven runtime oversight prototype that demonstrates how a single norm can uniformly drive execution, evaluation, and upgrading. The system validates the feasibility of reusing composable oversight components across teams.

AI OversightComposabilityCoordination Gap

Traditional compliance assessments rely on point-in-time audits and self-attestation, which struggle to enable continuous, cross-organizational, and traceable verification of security controls in multi-vendor environments. This work proposes a permissioned blockchain-based Third-Party Risk Assessment (TPRA) framework that transforms static compliance into a dynamic, repeatable, and verifiable continuous governance mechanism through smart contract–automated evaluation workflows, multi-party governance protocols, and longitudinal state tracking. The study contributes an actionable TPRA architecture, along with complementary compliance maturity metrics and a qualitative model, enabling quantification and long-term validation of security control implementation maturity across organizational boundaries and time periods.

blockchaincompliance assessmentframework implementation

This study addresses the inefficiency of manual auditing in corporate governance and the challenges in validating automated alternatives by proposing a task replacement system within a Digital Governance Framework (DGF). Methodologically, it introduces a residual workload threshold as the criterion for task substitution, establishing an information sufficiency gating mechanism. Architecturally, the framework integrates intelligent agents, rule engines, and evidence services, automating auditing workflows through forward deployment engineering and constructing the DGF-Bench benchmark for multi-model evaluation. Experimental results demonstrate that models such as Gemini achieve success rates up to 94.98% under strict gating conditions, confirming the technical feasibility of automating specific governance tasks and offering an effective paradigm for enterprise digital governance.

Digital Governance FrameworksForward Deployed EngineeringGovernance Automation

This study addresses the governance failures in cybersecurity arising from AI deployment in the public sector, a domain underexplored in existing literature due to insufficient integration of institutional constraints and governance instruments. The authors develop a seven-dimensional typological framework to identify ten root causes of AI-driven governance failure, introducing “velocity asymmetry” as a novel structural mechanism. They critically evaluate five major frameworks—including NIST CSF 2.0 and ISO/IEC 27001—through institutional analysis, typology construction, and coverage matrix assessment, revealing significant gaps in addressing shadow AI, velocity asymmetry, and governance vacuums. Building on these insights, the study proposes an interactive tripartite model linking accountability, operational resilience, and compliance failures, culminating in a design specification for an AI-enabled cybersecurity maturity model tailored to government agencies that explicitly maps current governance frameworks’ coverage gaps in the public sector.

AI deploymentcybersecurity governancegovernance failure

This work addresses the security and compliance risks arising when large language model (LLM) agents directly trigger state-changing actions within workflows. To mitigate these risks, the authors propose decoupling action generation from execution and introduce, for the first time, an Organizational Control Layer (OCL) architecture—a model-agnostic, non-intrusive governance infrastructure that enforces policy checks, enables action interception, and supports human escalation prior to execution. The approach requires no modification to the underlying LLM and is compatible with diverse backend systems. Evaluated on an adversarial negotiation task, the method reduces unsafe execution rates from 88% to near zero while increasing effective success rates from 12% to 96%, demonstrating the efficacy and practicality of the proposed governance mechanism.

action safetyexecution-boundary problemgovernance infrastructure

Hot Scholars

YH

Yongming Huang

Professor of Information and Communications Engineering, Southeast University, China
Wireless CommunicationsSignal Processing
NB

Nick Bostrom

Professor, Director of the Future of Humanity Institute, Oxford University
PhilosophyArtificial IntelligenceEthicsTechnology
DG

David Garcia

Professor for Social and Behavioral Data Science, University of Konstanz. Also CSH Vienna and ETHZ
Computational social sciencecollective emotionspolarizationprivacy