2026· International Conference on Security and Cryptography· pp. 1121-1126· 0 citations· 13 references
Computer Science
TL;DR
A compliance management platform that operationalizes regulatory requirements through structured, expert-guided control implementation, that combines NLP extraction with human-supervised annotation to convert regulatory texts into machine-readable frameworks, enabling multi-framework management, control mapping, evidence tracking, and role-based audit workflows is presented.
Abstract
: As cybersecurity regulations such as ISO/IEC 27001 and the NIS2 Directive continue to expand in scope and complexity, organizations face growing challenges in translating regulatory obligations into actionable security policies and audit-ready evidence. Conventional compliance approaches rely on manual interpretation of regulatory texts, fragmented documentation repositories, and ad hoc audit preparation, introducing operational bottlenecks and exposing organizations to non-compliance risks. This paper presents a compliance management platform that operationalizes regulatory requirements through structured, expert-guided control implementation. It combines NLP extraction with human-supervised annotation to convert regulatory texts into machine-readable frameworks, enabling multi-framework management (ISO/IEC 27001:2022 and NIS2), control mapping, evidence tracking, and role-based audit workflows. In a task-based usability study with twelve participants, the platform scored 83.3 on the System Usability Scale (SUS), rated “excellent,” indicating that embedded guidance can reduce expertise barriers in cybersecurity compliance management.
Organisations operating in regulated and critical-infrastructure sectors must satisfy multiple, heterogeneous cybersecurity and privacy instruments simultaneously, including but not limited to ISO/IEC~27001, the NIST Cybersecurity Framework~2.0, Cyber Essentials, and the GDPR. In practice, these obligations are managed through manual mappings, spreadsheet-based tracking, and periodic audits that are costly to maintain, inconsistent across standards, and weak in traceability. This paper presents \emph{AspisAI}, a bounded, standard-agnostic governance framework that translates selected requirements from several frameworks into a canonical, machine-interpretable control model, and evaluates submitted evidence against condition-based decision rules to produce explainable, traceable compliance determinations. Within a bounded scope of 26 representative requirements, the framework is evaluated in a controlled simulation against five governance-oriented criteria and, critically, against two external reference points that mitigate the circularity of single-author evaluation: its cross-standard mappings are validated against NIST's own published informative references, with 57\,\% exact agreement and divergences confined to same-family controls, and the framework is applied to real third-party evidence from the OpenSSF Scorecard, surfacing genuine governance gaps in a live open-source project. The controlled results, comprising full requirement encoding, 88.5\,\% mapping coverage, complete traceability, and correct detection of all introduced gaps, establish functional correctness, while the external validation provides evidence of applicability beyond the simulation. The contribution is therefore a demonstration that a canonical, provenance-preserving governance model can render multi-standard compliance both automatable and auditable.
Tsafac Nkombong Regine Cyrille, Hasan Dağ, R. Creutzburg et al.· 0 citations
The study concludes that universities require a layered, integrated governance model rather than separate compliance silos, and recommends multidisciplinary oversight, harmonised control catalogues, precise data classification, Zero Trust access, privacy and security by design, recurring impact assessments, supplier accountability, and measurable assurance.
Dominic Feboh, Ayokunle Olamide Ijagbemi, Stanley Nwakamma et al.· International Journal of Mul...· 0 citations
Environmental, Social, and Governance (ESG) compliance has shifted from voluntary best practice to enforceable legal obligation across major global jurisdictions. Frameworks such as the European Union's Corporate Sustainability Reporting Directive (CSRD), the Sustainable Finance Disclosure Regulation (SFDR), the United Kingdom's Sustainability Disclosure Requirements (SDR), and disclosure rules from the U.S. Securities and Exchange Commission (SEC), adopted in 2024 and now under proposed rescission, impose structured reporting duties on a growing range of organizations. Yet dominant compliance methods remain manual, fragmented, and difficult to verify. Static documentation, subjective interpretation, and scoring systems that cannot be traced back to specific legal provisions continue to define current practice.
This paper introduces ESG-as-Code, a deterministic rule-based framework designed to address these limitations by converting ESG regulatory obligations into structured rule logic formally specified for machine implementation. Drawing on established principles from Policy-as-Code, Infrastructure-as-Code, and computational law, the framework provides a structured methodology for encoding jurisdictional ESG rules as conditional logic that can be evaluated systematically against organizational data and disclosures.
Central to the framework is a deliberate separation between probabilistic systems used for document interpretation and deterministic engines used for compliance decision-making. This separation preserves full auditability, allowing every compliance outcome to be traced directly to a specific regulatory provision rather than a statistical inference. Determinism in this sense guarantees reproducibility and rule-level traceability, properties that probabilistic scoring systems cannot offer by design. It does not by itself guarantee that a given outcome is legally correct; that additionally depends on the accuracy of the underlying rule encoding, the currency of the regulatory source, and the governance processes surrounding the rule library. The paper argues that reproducibility and traceability are necessary but not sufficient conditions for regulatory defensibility and proposes deterministic rule-based architecture as the foundation on which the remaining conditions can be built.
This review synthesizes peer-reviewed literature on governance structures, auditing methods, and resulting outcomes across key sectors including financial services, capital markets, healthcare, and critical infrastructure to reveal consistent emphasis on integrated governance approaches alongside persistent implementation tensions.
William Asare Yirenkyi, Apaflo Godson Teye, Matilda Konotey et al.· Magna Scientia Advanced Rese...· 0 citations
Digital financial reporting depends on identity services, enterprise systems, cloud platforms, automated controls and system-generated evidence. Cybersecurity weaknesses therefore enter external audit when a governance condition or control deficiency affects a material reporting process, an assertion, a disclosure, an estimate or the reliability of audit evidence. This article develops a non-deterministic control-to-assertion framework through a structured integrative review. The search, completed on 16 July 2026, covered English-language journal work published from 2000 to 15 July 2026 through Google Scholar and publisher search services. The final analytic set contains 32 peer-reviewed journal articles, four institutional sources and two public company filings used for worked application. The revision separates organisation-level cybersecurity governance deficiencies from process-level cyber control deficiencies. It also locates the model against COSO, COBIT 2019, NIST CSF 2.0, IT general control methods and relevant International Standards on Auditing. Existing sources provide taxonomies for governance, internal control, security outcomes and audit procedures. The new framework supplies the missing translation route between those taxonomies: governance condition, control state, financial reporting dependency, assertion-level misstatement risk, audit-evidence reliability, audit response and reassessment. Compensating, detective and corrective controls might interrupt or reduce the route, so no governance deficiency automatically produces a control failure or a material misstatement. Two worked documentary applications, The Clorox Company and MGM Resorts International, show how public incident facts enter account, assertion, evidence and procedure analysis. The framework does not estimate incident probability, expected loss or a cyber risk score. It provides a file-ready reasoning structure for entity-specific risk assessment under the auditing standards. Its main contribution lies in the separate treatment of misstatement risk and evidence reliability, followed by a traceable link to accounts, assertions, evidence sources, specialist input and audit procedures.
Alessio Faccia, S. Tangjitsitcharoen· Journal of Cybersecurity and...· 0 citations
The NERC CIP standards have been mandatory for more than fifteen years and are widely regarded as a baseline for securing the bulk power system, yet little is known about how the people who implement, audit, and write them experience the regulatory lifecycle in practice. Drawing on interviews with twenty two auditors, utility implementers, and standard drafters, this article synthesizes firsthand accounts of where compliance succeeds and where it creates friction. We find that prescriptiveness can hinder flexibility and encourage a check the box mentality, that the burden of proving compliance increasingly competes with substantive security work, and that workforce shortages and a persistent gap between information technology auditors and operational technology environments compound these difficulties across the lifecycle. Because the ultimate purpose of the standards is to prevent cyber events from producing physical harm, we connect these findings to the power engineering literature on cyber-physical risk in substations and argue for a shift from compliance-driven practice toward engineering-based methods that use system modeling, risk quantification, and analysis of cascading effects. We close with a roadmap for modernization built on risk-based auditing, flexible standards, specialized auditor training, and automation, with the goal of moving beyond mere compliance toward measurable operational resilience.
Sena Şahin, Burak Sahin, Robin Berthier et al.· IEEE Power and Energy Magazi...· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.