Maturity Model with Emphasis on Information Security Management and Cyberattack Preparedness
سال انتشار: 1405
نوع سند: مقاله کنفرانسی
زبان: فارسی
مشاهده: 21
- صدور گواهی نمایه سازی
- من نویسنده این مقاله هستم
استخراج به نرم افزارهای پژوهشی:
شناسه ملی سند علمی:
ICMHSR24_160
تاریخ نمایه سازی: 23 شهریور 1405
چکیده مقاله:
The rapid digital transformation of organizations and their increasing dependence on interconnected information systems have significantly expanded the potential impact of cyber threats on organizational operations. Contemporary cyberattacks are increasingly sophisticated, persistent, and capable of disrupting critical services, compromising sensitive information, and generating substantial financial, operational, and reputational consequences. In this environment, traditional cybersecurity approaches that primarily emphasize prevention and protection are no longer sufficient. Organizations must also develop the ability to anticipate threats, withstand cyber incidents, detect malicious activities, respond effectively, maintain critical operations, recover from disruptions, and learn from previous incidents. This broader capability is referred to as cyber resilience. The purpose of this study is to design and validate an organizational cyber resilience maturity model with particular emphasis on information security management and preparedness for cyberattacks. The study adopts an applied research approach and a descriptive-survey methodology. Through a review of theoretical literature, international standards, cybersecurity frameworks, and previous research, seven major dimensions of cyber resilience are identified: information security governance and management, cyber risk identification and assessment, security protection and controls, threat detection and monitoring, incident preparedness and response, business continuity and recovery, and organizational learning and continuous improvement. Based on these dimensions, a five-level maturity structure is proposed, ranging from the Initial level to the Optimized level. The model is designed to enable organizations to evaluate their current cyber resilience capabilities, identify capability gaps, prioritize improvement initiatives, and establish a systematic roadmap for resilience enhancement. The proposed framework emphasizes that cyber resilience should be considered an integrated organizational capability rather than a purely technical cybersecurity function.
کلیدواژه ها:
نویسندگان
Mohammad reza Jahan khah
Shiraz Municipality