Cyber Risk Maturity Assessment Model Based on SeMS for Aircraft Operations: A Systematic Literature Review
Abstract
Aviation cybersecurity governance rests on a three-document RTCA/EUROCAE airworthiness security family; DO-355A/ED-204A provides operational-phase compliance guidance, but no validated, scored maturity layer aligned with Security Management System (SeMS) principles exists above it. This study mapped evidence on cyber risk maturity frameworks in aviation operations, identified methodologies for developing a Cyber Risk Maturity Assessment Model (CRMAM), and characterized certification- and operational-phase gaps. A literature review followed Kitchenham’s methodology and PRISMA 2020 standards, searching Google Scholar, IEEE Xplore, collections, and grey literature, with quality assessed with a modified Design Science Research Methodology rubric. From 889 records, 164 studies included after deduplication and screening. Across five questions, no aviation-specific, SeMS-integrated maturity model was identified; DO-326A governed certification only; no Security Performance Indicators library existed for aircraft operators; 97% of cross-regulatory studies addressed one regulatory body; and combined Delphi-AHP validation had aviation precedent but lacked application to cybersecurity maturity assessment. Findings indicate that aviation cybersecurity governance research has matured technically but not institutionally, confirming a multi-dimensional governance gap and supporting the proposed CRMAM design.