inklap

SEMI-AUTOMATED MULTI-STANDARD CYBER MATURITY ASSESSMENT TOOL BASED ON NIST CSF 2.0, ISO/IEC 27001:2022, COBIT 2019 AND CIS CONTROLS V8

Svitlana Shevchenko, Yuliia Zhdanovа, Oleksii Kiia · Cybersecurity: Education, Science, Technique · 2025

In today's cyber threat landscape, no software or hardware tool can fully compensate for the lack of a comprehensive approach to security management, which includes both technological and organizational aspects. Modern organizations are often forced to comply with the requirements of several international standards at the same time (NIST CSF 2.0, ISO/IEC 27001:2022, COBIT 2019, CIS Controls v8) due to regulatory obligations, customer requirements and internal policies, which leads to fragmentation of efforts, duplication of work and inefficient use of limited resources. This article is devoted to the development of a semi-automated multi-standard cyber maturity assessment tool that allows organizations to assess compliance with all four frameworks through a single point of entry — a structured survey using the NIST CSF 2.0 framework as a basic measurement tool, COBIT 2019 as a mechanism for determining the target state through prioritization of business processes, ISO/IEC 27001:2022 as a reference for documented controls, and CIS Controls v8 as additional practical detail for small and medium-sized organizations (SMEs). Based on a systematic analysis of scientific literature and pr

📖 افتح في inklap 🔗 DOI 📮 اطلب بحثاً