Maturity Model with Emphasis on Information Security ‎Management and Cyberattack Preparedness

سال انتشار: 1405
نوع سند: مقاله کنفرانسی
زبان: فارسی
مشاهده: 21

فایل این مقاله در 18 صفحه با فرمت PDF و WORD قابل دریافت می باشد

استخراج به نرم افزارهای پژوهشی:

لینک ثابت به این مقاله:

شناسه ملی سند علمی:

ICMHSR24_160

تاریخ نمایه سازی: 23 شهریور 1405

چکیده مقاله:

The rapid digital transformation of organizations and their increasing dependence on ‎interconnected information systems have significantly expanded the potential impact of cyber ‎threats on organizational operations. Contemporary cyberattacks are increasingly sophisticated, ‎persistent, and capable of disrupting critical services, compromising sensitive information, and ‎generating substantial financial, operational, and reputational consequences. In this environment, ‎traditional cybersecurity approaches that primarily emphasize prevention and protection are no ‎longer sufficient. Organizations must also develop the ability to anticipate threats, withstand ‎cyber incidents, detect malicious activities, respond effectively, maintain critical operations, ‎recover from disruptions, and learn from previous incidents. This broader capability is referred to ‎as cyber resilience.‎ The purpose of this study is to design and validate an organizational cyber ‎resilience maturity model with particular emphasis on information security management and ‎preparedness for cyberattacks. The study adopts an applied research approach and a descriptive-‎survey methodology. Through a review of theoretical literature, international standards, ‎cybersecurity frameworks, and previous research, seven major dimensions of cyber resilience are ‎identified: information security governance and management, cyber risk identification and ‎assessment, security protection and controls, threat detection and monitoring, incident ‎preparedness and response, business continuity and recovery, and organizational learning and ‎continuous improvement. Based on these dimensions, a five-level maturity structure is proposed, ‎ranging from the Initial level to the Optimized level. The model is designed to enable ‎organizations to evaluate their current cyber resilience capabilities, identify capability gaps, ‎prioritize improvement initiatives, and establish a systematic roadmap for resilience ‎enhancement. The proposed framework emphasizes that cyber resilience should be considered an ‎integrated organizational capability rather than a purely technical cybersecurity function.‎

نویسندگان

Mohammad reza Jahan khah

Shiraz Municipality