Skip to content
Open access

Systematization of human-centered continuous audit for IoT security compliance

2026 · Journal of Cybersecurity · Vol 12 · 0 citations · 154 references
Computer Science

TL;DR

This study seeks to understand why auditors struggle to use automated auditing tools and identifying the conditions under which adoption succeeds, and introduces a human-centered auditing framework that maps the research landscape to the three core stages of human auditor workflow: planning, verification, and reporting.

Abstract

The promise of automated compliance is falling short of its real-world potential. Although extensive research has proposed many automated compliance solutions, real-world adoption shows that only 18% of organizations have implemented them. This implementation gap is especially critical in Internet of Things (IoT) environments, where even small and medium-sized business networks can see hundreds of distinct IoT devices over short period of time, rendering traditional manual auditing methods quickly overwhelmed. This study seeks to understand this implementation gap by clarifying why auditors struggle to use automated auditing tools and identifying the conditions under which adoption succeeds. In doing so, it contributes to the field of auditing by helping shift automation approaches from prototypes into used instruments that enhance security assurance in increasingly complex environments such as IoT. We propose a systematic mapping of literature relevant to technologies used for computer-assisted audit tools, from rule-based checking to artificial intelligence-powered approach. From this mapping, we introduce a human-centered auditing framework that maps the research landscape to the three core stages of human auditor workflow: planning, verification, and reporting. We use this framework to assess the state-of-the-art in IoT security compliance audit, revealing critical misalignments between technological capabilities and auditor requirements. In each workflow stage, we categorize and systematize key technologies which researchers are uniquely positioned to advance. Finally, we present a research roadmap that enables security researchers to build on strong academic foundations and meet the practical need of continuous IoT security auditing.

Read PDF

Similar papers

Review Open access 2026

Review of Security-aware Software Engineering Frameworks for Internet of Things

—Internet of Things (IoT) environments are rapidly growing, which in turn has accelerated security threats that are often mitigated by re-activistic deployment-stage controls rather than actively embedded throughout the software development process. Although many other works suggest technical security solutions, little...

Nada Mohammed Hassan Moter · 0 citations
Review Open access Aug 2026

Intelligent Cybersecurity for the Internet of Things: An AI-Based Adaptive Model and Landscape Analysis — A Systematic Literature Review

A conceptual model of an AI-based adaptive cybersecurity system for IoTs, designed to utilise edge intelligence, federated learning, and continuous feedback mechanisms to detect and respond dynamically to potential threats is proposed.

Hareshwar Prasad · 0 citations
Review Open access Aug 2026

Cybersecurity in the IoT Era: Protecting the Expanding Internet of Things

It is argued that securing the IoT ecosystem requires sustained, coordinated effort from manufacturers, regulators and end-users, and where current technological and regulatory responses fall short of that goal is identified.

K. Curran, J. Kyle, Lovepreet Singh · 0 citations
Conference Open access 2026

Smart Contract-Based Automated Response System for IoT Attacks in Web3 Ecosystems

Experimental evaluation demonstrates up to 95% detection accuracy, a 50% reduction in response latency, and scalability to over 100,000 IoT devices without performance degradation, highlighting the suitability of SC-ARS for deployment in smart cities, industrial IoT, and decentralized critical infrastructures where tru...

S. Bassey, B. Stephen, Emediong Bassey Obot et al. · 0 citations
Open access Aug 2026

Security-by-Design and Risk-Based Certification for AI-Enabled Smart Home

A Security-by-Design and risk-based certification framework that combines a six-layer IoT-AI reference architecture with STRIDE-based threat analysis augmented to capture AI-specific threats, including prompt injection and data poisoning is proposed.

Iván Ortiz-Garcés, Roberto O. Andrade · 0 citations
Open access Aug 2026

CRITICAL ROLE OF SECURE CYBER FORENSIC SYSTEMS IN MAINTAINING DATA INTEGRITY AND SECURITY WITHIN IOT-DRIVEN BYOD SETTINGS

The swift expansion of the Internet of Things (IoT) and Bring Your Own Device (BYOD) regulations has revolutionized organizational functions while concurrently presenting substantial security vulnerabilities and data integrity issues. This study rigorously analyzes the function of safe cyber forensic systems in allevia...

Kiran Basavaraja Malagi, Javed Wasim · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.