科研速览 · Science Skim继续刷下去 · Keep skimming →
◆ International Journal of Scientific Research in Science Engineering and Technology2026-07-31· Capability Maturity Model

Enterprise Cybersecurity Operational Resilience Maturity Assessment Using Artificial Intelligence and Integrated Governance Risk and Compliance Analytics

Ikenna Chizaram Mbuko, Onuh Matthew Ijiga, Lawrence Anebi Enyejo, Otugene Victor Bamigwojo

原始摘要(英文原文)· Original abstract
Enterprise cybersecurity programmes are increasingly judged not only by whether they satisfy compliance controls, but by whether they can preserve essential services during disruptive cyber events. Existing maturity assessments remain useful for organizing governance and control evidence, yet many rely on ordinal self-assessment, checklist scoring, and retrospective audit observations that are weakly connected to real-time telemetry, residual risk, and recovery performance. This paper develops a mathematically rooted Enterprise Cybersecurity Operational Resilience Maturity Index (ECORMI) that integrates artificial intelligence, governance, risk, and compliance analytics into a single risk-adjusted maturity assessment framework. The proposed approach models maturity as a latent enterprise capability estimated from normalized indicators across four construct blocks: AI-derived cyber intelligence, GRC evidence, residual cyber-risk exposure, and operational resilience performance. The methodology formalizes feature normalization, incident-disruption probability estimation, residual-risk computation, service-degradation resilience, maturity aggregation, construct reliability, and sensitivity testing. A simulated enterprise benchmark is used to illustrate how ECORMI-AI-GRC can outperform checklist maturity scoring, C2M2/CSF-style ordinal assessment, risk-matrix GRC scoring, and an ML-only SIEM baseline in predictive accuracy, F1-score, balanced accuracy, maturity-ranking stability, and decision interpretability. The results suggest that compliance evidence alone can overstate resilience when unresolved exposure, weak control ownership, and recovery degradation remain high. By penalizing residual risk and rewarding measured recovery capability, ECORMI produces a more defensible maturity classification for board reporting, audit planning, cyber-investment prioritization, and operational resilience improvement. The paper contributes a reproducible mathematical assessment structure that can be calibrated to sector-specific risk appetite, validated against incident outcomes, and deployed through integrated SIEM, SOAR, GRC, and business-continuity data pipelines.
读原文 · Read the paper ↗

AI 追问PRO

登录后使用 AI 追问

讨论区

登录后参与讨论

相关论文 · Related

Enterprise Cybersecurity Operational Resilience Maturity Assessment Using Artificial Intelligence and Integrated Governance Risk and Compliance Analytics — 科研速览 Science Skim