data security

Designs, builds, and analyzes technical controls, processes, and policies that protect data confidentiality, integrity, and availability across storage, processing, and transmission; this includes access control, encryption, masking, secure backups, auditing/logging, and incident response. Evaluates risks, implements compliance and lifecycle controls, and tests systems for vulnerabilities, leakage, or unauthorized access to prevent or mitigate data breaches and loss.

datasecurity

Recent Skill Trend

Momentum and market value over time
Trending
Score
No comparison yet
-0.31
Oct 01, 2026Oct 01, 2026
Career
Value
No comparison yet
$199K/year
Oct 01, 2026Oct 01, 2026

Recommended Survey Paper

Quick overview of the field
View more

Must-Read Papers

Most classic and influential ideas
View more

This study addresses the escalating threat of unauthorized data access confronting enterprises and proposes an integrated defense framework that synergistically combines technological, human, and organizational dimensions. The framework establishes a robust security foundation through technical measures such as firewalls, intrusion detection systems, and encryption, while simultaneously reinforcing this infrastructure with employee security awareness training and rigorous enforcement of data access policies. By integrating these layers into a cohesive, defense-in-depth architecture, the approach not only substantially mitigates the risk of data breaches but also enhances organizational compliance and overall cyber resilience. This work thus offers a practical, holistic solution for effective data governance in complex enterprise environments.

data breach preventiondata securityregulatory compliance

Modeling and Simulation of Data Protection Systems for Business Continuity and Disaster Recovery

Dec 01, 2025
SN
Sašo Nikolovski
🏛️ AUE -FON University | University "St. Kliment Ohridski"

In cloud environments, selecting optimal data protection strategies for business continuity and disaster recovery remains challenging due to the lack of quantitative foundations for evaluating reliability and aligning with organizational Recovery Time Objectives (RTOs) and operational requirements. Method: This paper proposes an integrated assessment framework that synergistically combines system dynamics modeling and simulation-based optimization. It quantitatively evaluates key performance indicators—including recovery timeliness, data integrity, and system robustness—across public and hybrid cloud scenarios by simulating mainstream recovery mechanisms. Contribution/Results: The framework innovatively applies system dynamics to model time-varying dependencies during recovery processes and establishes interpretable, traceable mappings between policy parameters, technical metrics, and business objectives. Empirical validation demonstrates its reproducibility and practical utility, providing cloud-native organizations with a quantifiable, verifiable, and actionable decision-support methodology for data protection strategy selection.

Comparative analysis of cloud-based recovery solutions for reliabilityModeling and simulation of data protection systems for business continuityProposes a framework for selecting and maintaining organizational recovery solutions

Large organizations struggle to sustain information security and regulatory compliance in dynamic, evolving environments. Method: This study models enterprise information security governance as a multidimensional dynamical system and, for the first time, formalizes it as a feedback regulation problem within control-theoretic frameworks. Leveraging the UK BS standard, we construct an enterprise-scale digital twin with 1.2 million parameters and propose a quantification paradigm centered on an integral-type security state metric, enabling real-time security态势 characterization and closed-loop compliance verification. Contribution/Results: The work transcends traditional static audit paradigms by establishing a novel digital twin–enabled security governance approach—standards-driven, parameter-auditable, quantitatively evaluable, and response-controllable. The solution has been fully deployed across an operational enterprise and integrated with organization-wide capability alignment, yielding significant improvements in security resilience and regulatory response efficiency.

Access ControlInformation SecuritySecurity Measures Evaluation

Cyber-Physical Security Vulnerabilities Identification and Classification in Smart Manufacturing -- A Defense-in-Depth Driven Framework and Taxonomy

Dec 29, 2024
MH
Md Habibor Rahman
🏛️ University of Massachusetts Dartmouth | The University of Arizona

Traditional vulnerability identification methods in smart manufacturing overlook physical-layer weaknesses and cross-domain coordination flaws due to deep cyber-physical-human coupling. To address this, this paper proposes a纵深-defense-oriented vulnerability identification and classification framework. It formally defines the “vulnerability–defense” duality in manufacturing contexts and establishes the first cyber-physical-human co-vulnerability taxonomy and纵深-defense model tailored to intelligent manufacturing. The framework spans five dimensions—cyberspace, human behavior, process monitoring,出厂 inspection, and organizational policy—enabling cross-domain vulnerability mapping, threat modeling, and coordinated evaluation of multi-layered security mechanisms. Evaluated on a representative smart production line, the framework successfully identifies exploitable cross-domain gaps missed by conventional approaches, significantly improving domain-specific adaptability and actionable guidance for defense deployment.

Classifying vulnerabilities across cyber, human, and physical dimensionsDeveloping a defense-in-depth framework for manufacturing resilienceIdentifying cyber-physical vulnerabilities in smart manufacturing systems

Enhancing Energy Sector Resilience: Integrating Security by Design Principles

Feb 18, 2024
DS
Dov Shirtz
🏛️ Ben-Gurion University | Shamoon College of Engineering

Energy-sector industrial control systems (ICS) exhibit insufficient security resilience and overreliance on reactive, post-incident remediation. Method: This paper proposes a layered, implementable Security-by-Design (SbD) framework and a deployable set of security requirements tailored to critical infrastructure. Integrating systems engineering, ICS-specific security architecture, organizational behavior principles, and continuous monitoring, the approach spans the entire lifecycle—design, development, deployment, and operations—while ensuring alignment with IEC 62443 and NIST SP 800-82. Contribution/Results: It represents the first systematic, end-to-end operationalization of SbD in energy ICS contexts, enabling a paradigm shift from passive incident response to inherent, “native immunity.” The resulting scalable, auditable, and standards-coordinated SbD implementation guide supports the development of high-assurance, resilient, and sustainably evolvable cybersecurity ecosystems.

Enhancing energy sector resilience through Security by Design (SbD) principlesEstablishing an SbD-driven ecosystem to combat cyber threats effectivelyIntegrating SbD in industrial control systems lifecycle for robust security

Latest Papers

What's happening recently
View more

This study addresses the challenges posed by divergent and conflicting data protection regulations across jurisdictions, which hinder the early identification of compliance requirements in software development and often lead to costly rework and legal risks. Drawing on interviews with 70 legal experts from G20 and other countries, the research employs systematic content analysis and deductive qualitative methods to distill, for the first time from a legal expert perspective, both commonalities—such as consent—and key divergences—such as the right to be forgotten—across global data protection laws. These insights are innovatively operationalized into a comprehensive set of Data Protection Officer (DPO) user stories mapped to each phase of the software development lifecycle and enterprise architecture layers, significantly enhancing the actionable integration of compliance requirements into early-stage software engineering practices.

data protection regulationsprivacy complianceregulatory data protection requirements

This study addresses the challenges of assessing compliance between organizational cybersecurity policies and abstract security control frameworks such as NIST SP 800-53, which are often time-consuming, difficult to standardize, and lack traceability. To overcome these limitations, the authors propose PROPAGATE, a novel framework that leverages large language models (LLMs) to automate control-level compliance evaluation for the first time. By integrating both open-source and closed-source LLMs, the framework automatically retrieves relevant policy text, evaluates coverage across 1,007 security controls, and generates interpretable gap analyses with actionable improvement recommendations. Experimental results on two real-world organizational policy corpora demonstrate high effectiveness, achieving F1 scores of 88.54 and 82.31, respectively, thereby enabling traceable and explainable compliance enhancement.

compliance assessmentcybersecurity policyNIST SP 800-53

Traditional enterprise security models, reliant on static perimeters, struggle to address the dynamic risks introduced by production-grade AI agents operating within authorized workflows. This work proposes the first five-plane reference architecture for runtime governance of AI agents—spanning inference, network, identity, endpoint, and data—and introduces core primitives including arbitrary-point interception, composite subjects with capability decay, and structured audit evidence. By extending policy enforcement from atomic subjects to decay-aware composite subjects, the framework defines six interruption primitives and four correctness invariants. Evaluated across five real-world workflows, it successfully mitigates seven threat classes, achieves microsecond-scale policy decisions, and validates correctness of capability decay, audit reconstructability, and tamper resistance, thereby filling a critical gap in dynamic governance for agent-driven workflows.

AI agentscapability attenuationcomposite principals

This work addresses the inadequacy of existing large language model (LLM) lifecycle frameworks, which predominantly emphasize operational efficiency while lacking explicit support for security-critical activities—such as data provenance, component signing, and access control—and failing to align governance requirements with specific lifecycle phases. The paper proposes the first security-oriented LLM system lifecycle model, structured not by workflow but by security boundaries, organizing 32 phases into four layered pipelines: data, model, distribution, and application, while integrating LLMOps and governance pillars. It uniquely identifies 13 distinct security-critical phases and exposes a structural imbalance wherein regulatory evidence is concentrated at deployment despite pivotal decisions occurring during development. By mapping key standards—including NIST AI RMF, the EU AI Act, and ISO/IEC 42001—the study establishes a phase-to-governance correspondence mechanism, yielding a comprehensive, lifecycle-spanning security analysis framework that offers structured guidance for compliance and secure design.

governance frameworklarge language modelsLLM systems

This work addresses the critical gap that while AI-generated SQL queries may be semantically correct, they often violate data privacy and security policies, and current database systems lack fine-grained data flow control. The paper proposes Data Flow Control (DFC), a framework that embeds tuple-level security policies directly into the database infrastructure for the first time. DFC employs a declarative policy language to specify constraints and formalizes the security of aggregate predicates using provenance monomials. Through the Passant query rewriting layer, DFC enables optimizer-agnostic, cross-DBMS-compatible policy enforcement with zero runtime overhead, without materializing provenance data. Experiments demonstrate that Passant incurs near 0% performance overhead across DuckDB, Umbra, PostgreSQL, DataFusion, and SQL Server, outperforming existing approaches by several orders of magnitude, thereby shifting data security from prompt engineering to native infrastructure guarantees.

AI AgentsData Flow ControlData Safety

Hot Scholars

RD

Ronnie de Souza Santos

Assistant Professor, University of Calgary
Human Aspects of Software EngineeringSoftware TestingSoftware FairnessSoftware Development
AA

Abdulrhman Aljouie

Assistant Professor of Computer Science, KSAU-HS. Associate Research Scientist, KAIMRC
Machine LearningMedical AIBioinformatics
QH

Qiwei Han

Nova School of Business and Economics
Information SystemsBusiness AnalyticsApplied Data Science
JL

Jeffrey L. Rogers

IBM Research
Digital HealthDynamicsControl and OptimizationMicrosystems
CO

Cengiz Ozel

Researcher, University of Rochester
Computer ScienceArtificial IntelligenceHuman-Computer Interaction