Score
Designs, implements, and evaluates technical and organizational measures to protect information assets' confidentiality, integrity, and availability; this includes creating security architectures, access control and authentication systems, cryptographic protections and key management, secure network and system configurations, monitoring and intrusion-detection capabilities, vulnerability assessments, incident response procedures, and risk assessments.
This study addresses the challenge fintech firms face in effectively implementing ISO/IEC 27001:2022 requirements within high-intensity information environments due to the absence of actionable implementation pathways. By analyzing a real-world case in which an organization translated the standard’s clauses and Annex A controls into eight core operational procedures, this work proposes a multi-layered, procedural Information Security Management System (ISMS) framework. The framework integrates the CIA triad as a unified evaluation criterion, a twelve-step risk assessment methodology, and role-based accountability. Through structured process modeling, role-permission mapping, and root-cause analysis of non-conformities, it establishes a closed-loop governance mechanism that is executable, measurable, and clearly assigns responsibility. The findings indicate that a tightly integrated, hierarchically structured procedural system—equipped with quantifiable risk metrics and explicit accountability—is essential for effective ISMS implementation in fintech contexts.
Scientific research cyberinfrastructure (CI) faces unique challenges—including high collaboration requirements, component heterogeneity, and the absence of adaptable security assessment frameworks. To address these, we propose a mission-centric security posture assessment method: first, top-down identification of critical assets and unacceptable losses; second, construction of a security knowledge graph integrating system components, dependencies, and threat behaviors; and third, integration with directed attack graphs to quantify multi-hop attack paths from entry points to critical assets—enabling visualization of attacker-defender relationships and identification of security blind spots. Unlike conventional generic standards, our approach is the first to deeply couple mission-driven assessment, knowledge graphs, and attack graphs. It supports risk prioritization and generation of actionable defensive strategies, significantly enhancing the precision and effectiveness of CI security defense.
Large organizations struggle to sustain information security and regulatory compliance in dynamic, evolving environments. Method: This study models enterprise information security governance as a multidimensional dynamical system and, for the first time, formalizes it as a feedback regulation problem within control-theoretic frameworks. Leveraging the UK BS standard, we construct an enterprise-scale digital twin with 1.2 million parameters and propose a quantification paradigm centered on an integral-type security state metric, enabling real-time security态势 characterization and closed-loop compliance verification. Contribution/Results: The work transcends traditional static audit paradigms by establishing a novel digital twin–enabled security governance approach—standards-driven, parameter-auditable, quantitatively evaluable, and response-controllable. The solution has been fully deployed across an operational enterprise and integrated with organization-wide capability alignment, yielding significant improvements in security resilience and regulatory response efficiency.
Energy-sector industrial control systems (ICS) exhibit insufficient security resilience and overreliance on reactive, post-incident remediation. Method: This paper proposes a layered, implementable Security-by-Design (SbD) framework and a deployable set of security requirements tailored to critical infrastructure. Integrating systems engineering, ICS-specific security architecture, organizational behavior principles, and continuous monitoring, the approach spans the entire lifecycle—design, development, deployment, and operations—while ensuring alignment with IEC 62443 and NIST SP 800-82. Contribution/Results: It represents the first systematic, end-to-end operationalization of SbD in energy ICS contexts, enabling a paradigm shift from passive incident response to inherent, “native immunity.” The resulting scalable, auditable, and standards-coordinated SbD implementation guide supports the development of high-assurance, resilient, and sustainably evolvable cybersecurity ecosystems.
This study addresses the multi-target deployment optimization problem for surface-to-air missile (SAM) batteries within integrated air defense systems (IADS), aiming to minimize interceptor expenditure, maximize interception probability against incoming threats, and optimize protection utility for geographically distributed high-value assets. We propose the first IADS-oriented framework of seven serializable network defense strategies. A novel network deployment algorithm is designed to jointly account for asset-weighted protection and offensive-defensive coordination, integrating probabilistic interception modeling, coverage optimization under resource constraints, and a shortest-path variant—yielding polynomial-time near-optimal solutions. Simulation results demonstrate a 23–37% improvement in interception efficiency, a 19% reduction in interceptor consumption, and significantly enhanced joint protection capability across multiple operational domains.
This study addresses the escalating threat of unauthorized data access confronting enterprises and proposes an integrated defense framework that synergistically combines technological, human, and organizational dimensions. The framework establishes a robust security foundation through technical measures such as firewalls, intrusion detection systems, and encryption, while simultaneously reinforcing this infrastructure with employee security awareness training and rigorous enforcement of data access policies. By integrating these layers into a cohesive, defense-in-depth architecture, the approach not only substantially mitigates the risk of data breaches but also enhances organizational compliance and overall cyber resilience. This work thus offers a practical, holistic solution for effective data governance in complex enterprise environments.
This study uncovers an inherent tension among cybersecurity governance, data protection, and corporate reputation in digital transformation: despite high compliance readiness—75% of surveyed firms experienced at least one cyberattack within the past year—security incidents persist, with reputational damage and erosion of customer trust being the predominant consequences. Method: Drawing on an online diagnostic survey across multiple industries in Poland, the study applies the ISO/IEC 27001/27032 frameworks and a structured questionnaire, employing descriptive statistics and attributional analysis. Contribution/Results: It provides the first empirical identification of the “compliance–security paradox.” The study proposes a novel paradigm that integrates cybersecurity governance deeply into corporate communication and reputation management systems. It positions data protection as the cornerstone of digital trust and organizational resilience, reframing cybersecurity from a regulatory cost center to a strategic investment.
In cloud environments, selecting optimal data protection strategies for business continuity and disaster recovery remains challenging due to the lack of quantitative foundations for evaluating reliability and aligning with organizational Recovery Time Objectives (RTOs) and operational requirements. Method: This paper proposes an integrated assessment framework that synergistically combines system dynamics modeling and simulation-based optimization. It quantitatively evaluates key performance indicators—including recovery timeliness, data integrity, and system robustness—across public and hybrid cloud scenarios by simulating mainstream recovery mechanisms. Contribution/Results: The framework innovatively applies system dynamics to model time-varying dependencies during recovery processes and establishes interpretable, traceable mappings between policy parameters, technical metrics, and business objectives. Empirical validation demonstrates its reproducibility and practical utility, providing cloud-native organizations with a quantifiable, verifiable, and actionable decision-support methodology for data protection strategy selection.
This study addresses the challenges of dynamically managing compliance risks under Ukraine’s cybersecurity regulations and the complexity and error-proneness of manually constructing security profiles. To overcome these issues, the authors propose a novel approach that integrates Retrieval-Augmented Generation (RAG) with large language models (LLMs), harmonizing the ISO/IEC 27001 and NIST cybersecurity frameworks to automatically generate jurisdiction-specific target security profiles. By incorporating a vector database linked to a knowledge base of Ukrainian legal requirements and organizational policies, the method enables precise alignment between regulatory mandates and technical controls. This framework significantly reduces the need for manual intervention and associated error rates, offering a structured, AI-assisted workflow that effectively supports risk-driven cybersecurity compliance management.
To address the acute cybersecurity risks confronting European microenterprises—exacerbated by severe resource constraints—this study develops a lightweight, implementable governance framework. Methodologically, it integrates ENISA guidelines, ISO/IEC 27005 risk assessment principles, and NIS2 Directive requirements, informed by the Squad 2025 initiative, to propose an innovative seven-dimensional preventive model centered on security awareness as a primary lever; the model emphasizes capability appropriateness, policy transferability, and embedded maturity assessment. Contributions include: (1) the first systematic integration of regulatory compliance, organizational capacity limitations, and behavioral change pathways; (2) a generalizable security framework enabling microenterprises’ transition from security awareness to operational practice; and (3) empirically grounded insights and an actionable implementation paradigm to support EU cybersecurity policymaking and standardization.