Telecommunications networks now underpin the delivery of financial, healthcare, government, and
emergency services, which makes service continuity in this sector a matter of public as well as commercial
consequence. Operators face disruption from two directions that they typically govern separately: physical and
technical failure addressed through engineering maintenance, and adversarial activity addressed through information
security. This article examines whether that separation is defensible and what an integrated alternative would involve.
Using a structured narrative literature review of thirty peer reviewed sources, six core standards and guidance
documents, and selected primary United States legal and regulatory materials, it synthesises four literatures that have
developed largely in parallel, covering critical infrastructure resilience, maintenance optimisation, incident response,
and cybersecurity governance. The review finds that resilience measurement weights heavily toward outcome
indicators, that maintenance optimisation remains largely cyber agnostic, that incident response research centres on
enterprise security operations rather than multi vendor field restoration, and that governance research is normative
rather than operational. Drawing on management system logic, the governance function of the NIST Cybersecurity
Framework 2.0, cyber resiliency engineering objectives, and organisational learning theory, the article proposes a
thirteen stage integrated governance framework organised into phases of direction, prevention, response, and learning,
together with nine performance indicators combining leading and outcome measures. Its central proposition is that
preventive maintenance and security monitoring should share a governance cycle because both depend on asset
inventory and behavioural baselining. The framework is proposed rather than empirically validated
Josephat Deogratius Katundabwile, David Mbui Kamau· International Journal of Eng...· 0 citations
An IT audit finding does not reduce risk. Risk falls only when an organisation understands the finding,
connects it to a critical system or business service, determines its risk level, assigns an accountable owner, implements
a treatment, verifies that the treatment worked, formally addresses whatever risk remains, and reports progress to those
charged with oversight. Evidence from the auditing and information systems literatures indicates that this chain breaks
routinely, and that findings accumulate as open items rather than closing as reduced exposure. This article asks how
organisations can convert audit findings into prioritised, accountable, measurable, and verified remediation, with
particular attention to critical digital infrastructure, where an unremediated weakness affects service continuity for
dependent sectors rather than the audited organisation alone. Using a structured narrative literature review of thirty
peer-reviewed sources and seven authoritative frameworks, the review identifies four recurring failure modes: findings
disconnected from business impact, ownership that is nominal rather than accountable, verification treated as
administrative closure, and residual risk accepted informally. Drawing on enterprise risk management integration
guidance, governance accountability models, and exploit-based prioritization research, the article proposes an eleven-
stage risk-based remediation framework running from finding validation through continuous monitoring, together with
eight measures spanning timeliness, ownership, verification quality, and business linkage. The framework is proposed
rather than empirically validated, and no claim is made that it has produced measured improvement in any organisation
Josephat Deogratius Katundabwile, David Mbui Kamau· International journal of res...· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.