The Compliance Gap: Why Audit-Based Cybersecurity Models Fail Critical Infrastructure and the Case for Continuous Control

Authors

  • Chukwunenye Amadi Independent Researcher, USA Author

DOI:

https://doi.org/10.65150/EP-gjetr/V2E9/2026-12

Keywords:

critical infrastructure, audit-based compliance, continuous monitoring, configuration drift, NIST Cybersecurity Framework, operational technology security

Abstract

Critical infrastructure (CI) sectors, including energy, water, transportation, healthcare, telecommunications, and finance, continue to anchor their cybersecurity assurance in periodic, audit-based compliance: scheduled assessments that certify, at a point in time, that mandated controls exist and are documented. This conceptual review argues that this model is structurally incapable of guaranteeing security in modern CI environments and develops the case for a transition to continuous monitoring and continuous control. Drawing on standards literature, empirical studies of operational technology (OT) security, documented attacks on industrial systems, and the continuous auditing tradition in accounting information systems, the paper synthesizes five interlocking failure modes of periodic compliance: (a) the static-snapshot problem, in which audit findings describe a past state rather than the present one; (b) the error-proneness and limited depth of manual, checklist-driven assessment; (c) configuration drift, through which compliant systems silently degrade between audits; (d) the asymmetry between adversary operational tempo and annual or multi-year audit cycles; and (e) an audit-centric organizational culture that substitutes evidence production for risk reduction. The analysis situates these failures against a threat landscape defined by IT/OT convergence, industrial Internet of Things expansion, deep infrastructure interdependencies, nation-state pre-positioning, and ransomware economics. The paper then traces the intellectual and regulatory lineage of the alternative (continuous auditing, information security continuous monitoring, continuous diagnostics and mitigation, zero trust architecture, and emerging continuous control validation) and discusses implications for regulators, operators, and researchers. The compliance gap, it concludes, is not a maturity deficit but a design flaw requiring an architectural response. As a conceptual review the paper offers an analytic framework rather than an effect estimate: it presents no new data and does not establish that continuous regimes reduce realized risk relative to periodic ones, a limitation stated in full in Section 7.

References

1) Abetoh, N. F., & Atakpa, M. I. (2024). Audit analytics in healthcare financial oversight: Leveraging data science to strengthen accountability in multilateral grant ecosystems. International Journal of Scientific Research in Computer Science, Engineering and Information Technology, 10(6), 2710–2747. https://doi.org/10.32628/CSEIT2410791

2) Abioye, R. F., Okojie, J. S., Filani, O. M., Ike, P. N., Idu, J. O. O., Nnabueze, S. B., Okojokwu-Idu, J. O., & Ihwughwavwe, S. I. (2023). Automated ESG reporting in energy projects using blockchain-driven smart compliance management systems. International Journal of Multidisciplinary Evolutionary Research, 4(2), 120–129. https://doi.org/10.54660/IJMER.2023.4.2.120-129

3) Adebayo, A., Adegbite, M. P., & Ahmed, M. O. (2022). Adversarial machine learning in critical infrastructure: A conceptual framework for threat modeling AI enabled OT systems. World Journal of Innovation and Modern Technology, 6(1), 184–234.

https://doi.org/10.56201/wjimt.v6.no1.2022.pg184.234

4) Adebayo, A., Adegbite, M. P., & Ahmed, M. O. (2023). AI augmented threat detection in industrial control systems: A systematic review of machine learning approaches for ICS anomaly detection. International Journal of Engineering and Modern Technology, 9(3), 287–340. https://doi.org/10.56201/ijcsmt.v9.no3.2023.pg287.340

5) Adebayo, A., Anunagba, C. O., & Ozowara, D. E. (2025). A review of zero trust security models and cost effectiveness in healthcare infrastructure. International Journal of Advanced Multidisciplinary Research and Studies, 5(6), 2269–2283.

https://doi.org/10.62225/2583049X.2025.5.6.6051

6) Adegbite, M. P., Adebayo, A., & Ahmed, M. O. (2020). Securing operational technology networks in electric utilities: A systematic review of NERC CIP compliance and architectural threat mitigation. International Journal of Engineering and Modern Technology, 6(3), 103–146. https://doi.org/10.56201/ijemt.vol.6.no3.2020.pg103.146

7) Adegbite, M. P., Adebayo, A., & Ahmed, M. O. (2022). A security architecture model for IT and OT convergence in regulated energy networks: Design principles and governance alignment. International Journal of Computer Science and Mathematical Theory, 8(2), 81–132. https://doi.org/10.56201/ijcsmt.v8.no2.2022.pg81.132

8) Adegbite, M. P., Adebayo, A., & Ahmed, M. O. (2023). ICS and SCADA threat detection architectures in energy sector networks: A systematic review of SIEM, NDR, and anomaly detection approaches. World Journal of Innovation and Modern Technology, 7(2), 121–182. https://doi.org/10.56201/wjimt.v7.no2.2023.pg121.182

9) Adegbite, M. P., Adebayo, A., & Ahmed, M. O. (2024a). A vulnerability governance architecture for power and utilities corporations: From exposure mapping to remediation verification. World Journal of Innovation and Modern Technology, 8(6), 185–246.https://doi.org/10.56201/wjimt.v8.no6.2024.pg185.246

10) Adegbite, M. P., Adebayo, A., & Ahmed, M. O. (2024b). An AI driven security operations architecture for utility sector SOCs: Integrating threat intelligence, behavioral analytics, and automated response. International Journal of Engineering and Modern Technology, 10(11),197–256. https://doi.org/10.56201/ijemt.v10.no11.2024.pg197.256

11) Adegbite, M. P., Adebayo, A., & Ahmed, M. O. (2025). A cyber risk quantification and governance architecture for critical infrastructure: From posture measurement to executive reporting. International Journal of Computer Science and Mathematical Theory, 11(12), 232–293. https://doi.org/10.56201/ijcsmt.vol.11.no12.2025.pg232.293

12) Adelanwa, A., Basnet, A., & Anene, U. N. (2023). Data driven digital transformation models for lifecycle performance management in infrastructure delivery. International Journal of Advanced Multidisciplinary Research and Studies, 3(6), 2646–2662.https://doi.org/10.62225/2583049X.2023.3.6.5968

13) Adenuga, O. M. (2022). Smart grid architectures and energy distribution for high renewable penetration: A comprehensive review of technologies, operations, and deployment pathways. International Journal of Engineering and Modern Technology, 8(5), 125–155.https://doi.org/10.56201/ijemt.v8.no5.2022.pg125.155

14) Adeyelu, O. O. (2018). A predictive compliance monitoring framework for detecting systemic safety risks through aviation consumer complaint data. Iconic Research and Engineering Journals, 1(8), 250–276. https://doi.org/10.64388/IREV1I8-1718478

15) Adeyelu, O. O. (2019). An adaptive safety management system implementation model for aerodromes in developing economy contexts. Iconic Research and Engineering Journals, 3(4), 628–654. https://doi.org/10.64388/IREV3I4-1718479

16) Adeyelu, O. O., & Dagodzo, D. (2022). A comparative benchmarking model for aerodrome certification compliance across developing economy civil aviation authorities. International Journal of Multidisciplinary Research and Growth Evaluation, 3(6), 1016–1035.https://doi.org/10.54660/.IJMRGE.2022.3.6.1016-1035

17) Adeyelu, O. O., & Dagodzo, D. (2024). A maturity model for predicting airport safety audit outcomes in resource-constrained regulatory environments. International Journal of Scientific Research in Civil Engineering, 8(4), 132–170. https://doi.org/10.32628/IJSRCE248423

18) Agbabiaka, J., Okonkwo, C. S., Ogunwole, O., Mayo, W., & Okeke, O. T. (2019). Supply chain risk management model for EPC and gas processing projects. Iconic Research and Engineering Journals, 3(2), 968–980. https://doi.org/10.64388/IREV3I2-1713124

19) Agu, M. U., Akomolafe, O., & Bello, A. (2023). A comparative review of SOX compliance frameworks in cross-border financial auditing. International Journal of Advanced Multidisciplinary Research and Studies, 3(6), 2297–2306.https://doi.org/10.62225/2583049X.2023.3.6.5362

20) Ahmed, M. O., Adegbite, M. P., & Adebayo, A. (2021). Zero trust architecture for operational technology in North American critical infrastructure: A framework for implementation and resilience optimization. International Journal of Engineering and Modern-Technology, 7(1), 66–113. https://doi.org/10.56201/ijemt.vol.7.no1.2021.pg66.113

21) Ahmed, M., Mahmood, A. N., & Hu, J. (2016). A survey of network anomaly detection techniques. Journal of Network and Computer Applications, 60, 19–31. https://doi.org/10.1016/j.jnca.2015.11.016

22) Akeju, B., Edivri, J., Ogbole, J. I., Okoruwa, P. O., Fadayomi, O., & Abolaji, T. O. (2018). Conceptual model for insider threat classification and risk modeling in complex digital systems. Iconic Research and Engineering Journals, 1(9), 476–492.

https://doi.org/10.64388/IREV1I9-1713778

23) Akin-Oluyomi, O. T., Atima, M. E., & Akinleye, O. K. (2023). Regulatory compliance and supplier risk assessment frameworks in international pharmaceutical procurement. International Journal of Advanced Multidisciplinary Research and Studies, 3(6), 2194–2204.

24) Akinleye, O. K., & Adeyoyin, O. (2021). Process automation framework for enhancing procurement efficiency and transparency. Shodhshauryam, International Scientific Refereed Research Journal, 4(4), 356–387.

25) Akomolafe, O., & Agu, M. U. (2018). A conceptual model for enhancing internal audit quality through technology-enabled risk assessment frameworks. Iconic Research and Engineering Journals, 1(9), 458–475.

26) Akomolafe, O., Agu, M. U., & Bello, A. (2023). A conceptual model for implementing risk-based auditing in strategic financial management. International Journal of Advanced Multidisciplinary Research and Studies, 3(6), 2274–2286.

https://doi.org/10.62225/2583049X.2023.3.6.5359

27) Akomolafe, O., Agu, M. U., & Bello, A. (2025). A conceptual model for advancing risk governance through data-driven compliance analytics in financial institutions. Journal of Accounting and Financial Management, 11(11), 211–228.

https://doi.org/10.56201/jafm.vol.11.no11.2025.pg211.228

28) Alahmadi, B. A., Axon, L., & Martinovic, I. (2022). 99% false positives: A qualitative study of SOC analysts’ perspectives on security alarms. In Proceedings of the 31st USENIX Security Symposium (pp. 2783–2800). USENIX Association.

https://www.usenix.org/conference/usenixsecurity22/presentation/alahmadi

29) Alcaraz, C., & Zeadally, S. (2015). Critical infrastructure protection: Requirements and challenges for the 21st century. International Journal of Critical Infrastructure Protection, 8, 53–66. https://doi.org/10.1016/j.ijcip.2014.12.002

30) Alexander, O., Belisle, M., & Steele, J. (2020). MITRE ATT&CK for industrial control systems: Design and philosophy. The MITRE Corporation. https://attack.mitre.org/docs/ATTACK_for_ICS_Philosophy_March_2020.pdf

31) AlHogail, A. (2015). Design and validation of information security culture framework. Computers in Human Behavior, 49, 567–575.https://doi.org/10.1016/j.chb.2015.03.054

32) Aliliele, C., Mbonu, I. S., & Iwuanyanwu, U. (2023). A conceptual framework for continuous cloud misconfiguration monitoring and enterprise risk mitigation strategies. International Journal of Scientific Research in Computer Science, Engineering and Information Technology, 9(10), 373–394. https://doi.org/10.32628/CSEIT2361071

33) Aliliele, C., Mbonu, I. S., & Iwuanyanwu, U. (2024a). A conceptual framework for enterprise data sensitivity classification and regulatory traceability mechanisms. International Journal of Advanced Multidisciplinary Research and Studies, 4(6), 3103–3124.

https://doi.org/10.62225/2583049X.2024.4.6.5991

34) Aliliele, C., Mbonu, I. S., & Iwuanyanwu, U. (2024b). Advances in HIPAA compliant data architecture and secure analytics frameworks for community healthcare organizations. Shodhshauryam, International Scientific Refereed Research Journal, 7(2), 277–324.https://doi.org/10.32628/SHISRRJ2472163

35) Aliliele, C., Mbonu, I. S., Uzoka, E., & Iwuanyanwu, U. (2025a). A review of AI assisted continuous auditing systems in technology risk and cybersecurity oversight. Gyanshauryam, International Scientific Refereed Research Journal, 8(4), 210–250.

https://doi.org/10.32628/GISRRJ258369

36) Aliliele, C., Mbonu, I. S., Uzoka, E., & Iwuanyanwu, U. (2025b). Advances in data lakehouse governance architectures for enterprise data loss prevention and compliance assurance. Shodhshauryam, International Scientific Refereed Research Journal, 8(4), 171–213.https://doi.org/10.32628/SHISRRJ258474

37) Alles, M. G., Kogan, A., & Vasarhelyi, M. A. (2008). Putting continuous auditing theory into practice: Lessons from two pilot implementations. Journal of Information Systems, 22(2), 195–214. https://doi.org/10.2308/jis.2008.22.2.195

38) Amayo, E. B., Owulade, O. A., & Isi, L. R. (2023). Optimizing project governance in multinational infrastructure projects: Insights from General Electric’s global operations. International Journal of Multidisciplinary Research and Growth Evaluation, 4(1), 975–983.https://doi.org/10.54660/.IJMRGE.2023.4.1.975-983

39) Amayo, E. B., Owulade, O. A., & Isi, L. R. (2024). Best practices for managing data center lifecycle projects: Ensuring security, efficiency, and compliance in U.S. enterprises. Iconic Research and Engineering Journals, 7(7), 598–617.

40) Aminu-Ibrahim, A. Y., Ogbete, J. C., & Ambali, K. B. (2024). Governance and accountability models for public private partnerships in healthcare infrastructure development. International Journal of Advanced Multidisciplinary Research and Studies, 4(6), 2943–2960.https://doi.org/10.62225/2583049X.2024.4.6.5699

41) Aminu-Ibrahim, A. Y., Ogbete, J. C., & Iwuanyanwu, O. C. (2025a). Infrastructure resilience planning for national diagnostic systems under public health stress conditions. Gyanshauryam, International Scientific Refereed Research Journal, 8(1), 340–381.

https://doi.org/10.32628/GISRRJ2582311

42) Aminu-Ibrahim, A. Y., Ogbete, J. C., & Iwuanyanwu, O. C. (2025b). Sustainable healthcare infrastructure performance metrics for long-term asset management and value creation. International Journal of Scientific Research in Computer Science, Engineering and Information Technology, 11(4), 566–601. https://doi.org/10.32628/CSEIT251116277

43) Anene, U. N., & Clement, T. (2022). A resilient logistics framework for humanitarian supply chains: Integrating predictive analytics, IoT, and localized distribution to strengthen emergency response systems. International Journal of Scientific Research in Computer Science, Engineering and Information Technology, 8(5), 398–424.

44) Ani, U. P. D., He, H., & Tiwari, A. (2017). Review of cybersecurity issues in industrial critical infrastructure: Manufacturing in perspective. Journal of Cyber Security Technology, 1(1), 32–74. https://doi.org/10.1080/23742917.2016.1252211

45) Annan, A. O. (2025). Cybersecurity compliance as a source of competitive advantage in technology markets. International Journal of Scientific Research in Computer Science, Engineering and Information Technology, 11(5), 456–487.

46) Apruzzese, G., Colajanni, M., Ferretti, L., Guido, A., & Marchetti, M. (2018). On the effectiveness of machine and deep learning for cyber security. In 2018 10th International Conference on Cyber Conflict (CyCon) (pp. 371–390). NATO CCD COE.

https://doi.org/10.23919/CYCON.2018.8405026

47) Apruzzese, G., Laskov, P., Montes de Oca, E., Mallouli, W., Brdalo Rapa, L., Grammatopoulos, A. V., & Di Franco, F. (2023). The role of machine learning in cybersecurity. Digital Threats: Research and Practice, 4(1), 1–38. https://doi.org/10.1145/3545574

48) Arp, D., Quiring, E., Pendlebury, F., Warnecke, A., Pierazzi, F., Wressnegger, C., Cavallaro, L., & Rieck, K. (2022). Dos and don’ts of machine learning in computer security. In Proceedings of the 31st USENIX Security Symposium (pp. 3971–3988). USENIX Association. https://www.usenix.org/conference/usenixsecurity22/presentation/arp

49) Arumosoye, O. M., & Obriki, O. D. (2019). Systematic review of near-miss and hazard observation data utilization in industrial safety management. Iconic Research and Engineering Journals, 3(2), 981–999. https://doi.org/10.64388/IREV3I2-1714417

50) Arumosoye, O. M., Obriki, O. D., & Ozobu, C. O. (2026). Systematic review of predictive safety analytics applications in LNG projects with ESG implications. Global Journal of Engineering and Technology Review, 2(2), 61–73. https://doi.org/10.65150/EP-gjetr/V2E2/2026-05

51) Ashby, W. R. (1956). An introduction to cybernetics. Chapman & Hall.

52) Asiedu, W., & Quainoo, R. (2023a). How far can energy harvesting take us? A systematic review of radio frequency strategies for energy autonomous sensing. Shodhshauryam, International Scientific Refereed Research Journal, 6(1), 448–466.

53) Asiedu, W., & Quainoo, R. (2023b). Toward maintenance free wireless infrastructure: Simulating performance and reliability in large scale intermittently powered IoT networks. Gyanshauryam, International Scientific Refereed Research Journal, 6(1), 489–510.

54) Asiedu, W., & Quainoo, R. (2024). Rethinking energy, reliability, and latency trade-offs in green communication for next generation IoT. International Journal of Multidisciplinary Research and Growth Evaluation, 5(6), 1987–1994.

55) Asiedu, W., & Quainoo, R. (2025). GleanCast: Epoch-aligned reliable broadcast in batteryless intermittent sensor networks. International Journal of Engineering and Modern Technology, 11(12), 205–218. https://doi.org/10.56201/ijemt.vol.11.no12.2025.pg205.218

56) Asiedu, W., Quainoo, R., & Asiedu, A. (2025). A conceptual framework for characterizing fundamental energy, reliability, and latency trade-offs in green communication paradigms for next-generation IoT. International Journal of Advanced Multidisciplinary Research and Studies, 5(6), 2447–2453. https://doi.org/10.62225/2583049X.2025.5.6.6479

57) Asiedu, W., Quainoo, R., & Asiedu, A. (2026). Predictive power management for intermittent IoT devices using lightweight machine learning under uncertain energy harvest. Gulf Journal of Engineering and Technology, 2(4), 108–118.

58) Atakpa, M. I., & Abetoh, N. F. (2022). A systematic review of machine learning advances in financial fraud detection for banking systems. International Journal of Scientific Research in Computer Science, Engineering and Information Technology, 8(2), 771–801.https://doi.org/10.32628/CSEIT23906220

59) Atakpa, M. I., & Fobellah, A. N. (2023). Anomaly detection in financial time-series data: A conceptual model for healthcare and banking applications. International Journal of Scientific Research in Computer Science, Engineering and Information Technology, 9(2), 967–997.https://doi.org/10.32628/CSEIT2342441

60) Axelsson, S. (2000). The base-rate fallacy and the difficulty of intrusion detection. ACM Transactions on Information and System Security, 3(3), 186–205. https://doi.org/10.1145/357830.357849

61) Beer, S. (1984). The viable system model: Its provenance, development, methodology and pathology. Journal of the Operational Research Society, 35(1), 7–25. https://doi.org/10.1057/jors.1984.2

62) Bello, A. D., Elebe, O., Hammed, N. I., Omoegun, G. O., & Fadayomi, O. (2024). A cybersecurity risk management and regulatory compliance framework for financial institutions. Iconic Research and Engineering Journals. https://www.irejournals.com/paper-details/1713553

63) Berman, D. S., Buczak, A. L., Chavis, J. S., & Corbett, C. L. (2019). A survey of deep learning methods for cyber security. Information, 10(4), Article 122. https://doi.org/10.3390/info10040122

64) Bhuyan, M. H., Bhattacharyya, D. K., & Kalita, J. K. (2014). Network anomaly detection: Methods, systems and tools. IEEE Communications Surveys & Tutorials, 16(1), 303–336. https://doi.org/10.1109/SURV.2013.052213.00046

65) Biggio, B., & Roli, F. (2018). Wild patterns: Ten years after the rise of adversarial machine learning. Pattern Recognition, 84, 317–331.https://doi.org/10.1016/j.patcog.2018.07.023

66) Boyes, H., Hallaq, B., Cunningham, J., & Watson, T. (2018). The industrial internet of things (IIoT): An analysis framework. Computers in Industry, 101, 1–12. https://doi.org/10.1016/j.compind.2018.04.015

67) Buck, C., Olenberger, C., Schweizer, A., Völter, F., & Eymann, T. (2021). Never trust, always verify: A multivocal literature review on current knowledge and research gaps of zero-trust. Computers & Security, 110(102436), Article 102436. https://doi.org/10.1016/j.cose.2021.102436

68) Buczak, A. L., & Guven, E. (2016). A survey of data mining and machine learning methods for cyber security intrusion detection. IEEE Communications Surveys & Tutorials, 18(2), 1153–1176. https://doi.org/10.1109/COMST.2015.2494502

69) Bulgurcu, B., Cavusoglu, H., & Benbasat, I. (2010). Information security policy compliance: An empirical study of rationality-based beliefs and information security awareness. MIS Quarterly, 34(3), 523–548. https://doi.org/10.2307/25750690

70) Chan, D. Y., & Vasarhelyi, M. A. (2011). Innovation and practice of continuous auditing. International Journal of Accounting Information Systems, 12(2), 152–160. https://doi.org/10.1016/j.accinf.2011.01.001

71) Chandola, V., Banerjee, A., & Kumar, V. (2009). Anomaly detection: A survey. ACM Computing Surveys, 41(3), Article 15. https://doi.org/10.1145/1541880.1541882

72) Cherdantseva, Y., Burnap, P., Blyth, A., Eden, P., Jones, K., Soulsby, H., & Stoddart, K. (2016). A review of cyber security risk assessment methods for SCADA systems. Computers & Security, 56, 1–27. https://doi.org/10.1016/j.cose.2015.09.009

73) Christopher, J. D. (2024). SANS 2024 state of ICS/OT cybersecurity [Survey report]. SANS Institute.

https://www.sans.edu/cyber-research/sans-2024-state-ics-ot-cybersecurity

74) Claroty. (2024). The global state of CPS security 2024: Business impact of disruptions. Claroty

Ltd. https://claroty.com/resources/reports/the-global-state-of-cps-security-2024-business-impact-of-disruptions

75) Committee of Sponsoring Organizations of the Treadway Commission. (2017). Enterprise risk management: Integrating with strategy and performance. COSO.

76) Critical Infrastructure Protection Reliability Standard CIP-015-1: Cyber security, internal network security monitoring, 90 Fed. Reg. (July 2, 2025). https://www.federalregister.gov/documents/2025/07/02/2025-12309/critical-infrastructure-protection-reliability-standard-cip-015-1-cyber-security-internal-network

77) Culot, G., Nassimbeni, G., Podrecca, M., & Sartor, M. (2021). The ISO/IEC 27001 information security management standard: Literature review and theory-based research agenda. The TQM Journal, 33(7), 76–105. https://doi.org/10.1108/TQM-09-2020-0202

78) Cybersecurity and Infrastructure Security Agency. (2020). Continuous Diagnostics and Mitigation (CDM) program overview [Fact sheet]. U.S. Department of Homeland Security.

https://www.cisa.gov/sites/default/files/publications/2020%2009%2003_CDM%20Program%20Overview_Fact%20Sheet_1.pdf

79) Cybersecurity and Infrastructure Security Agency. (2023a). People’s Republic of China state-sponsored cyber actor living off the land to evade detection. Joint Cybersecurity Advisory AA23-144A. https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-144a

80) Cybersecurity and Infrastructure Security Agency. (2023b). Cross-sector cybersecurity performance goals (March 2023 update). U.S. Department of Homeland Security. https://www.cisa.gov/cross-sector-cybersecurity-performance-goals

81) Cybersecurity and Infrastructure Security Agency. (2023c). Zero trust maturity model, Version 2.0. U.S. Department of Homeland Security. https://www.cisa.gov/sites/default/files/2023-04/zero_trust_maturity_model_v2_508.pdf

82) Cybersecurity and Infrastructure Security Agency. (2024). PRC state-sponsored actors compromise and maintain persistent access to U.S. critical infrastructure. Joint Cybersecurity Advisory AA24-038A. https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-038a

83) Cybersecurity and Infrastructure Security Agency. (n.d.a). Reducing the significant risk of known exploited vulnerabilities [Known Exploited Vulnerabilities Catalog]. U.S. Department of Homeland Security. https://www.cisa.gov/known-exploited-vulnerabilities

84) Cybersecurity and Infrastructure Security Agency. (n.d.b). Shields Up: Guidance for organizations. U.S. Department of Homeland Security. https://www.cisa.gov/shields-up

85) Cárdenas, A. A., Amin, S., Lin, Z.-S., Huang, Y.-L., Huang, C.-Y., & Sastry, S. (2011). Attacks against process control systems: Risk assessment, detection, and response. In Proceedings of the 6th ACM Symposium on Information, Computer and Communications Security (pp. 355–366). ACM. https://doi.org/10.1145/1966913.1966959

86) Dagodzo, D. (2018). A conceptual framework for UAV integration into national power grid inspection programs. Iconic Research and Engineering Journals, 2(5), 391–412. https://doi.org/10.64388/IREV2I5-1716082

87) Dagodzo, D., & Ahiaeke Patrick, M. C. (2021). An integrated framework for UAV, LiDAR, and GIS in infrastructure corridor management. International Journal of Scientific Research in Computer Science, Engineering and Information Technology, 7(5), 497–524. https://doi.org/10.32628/CSEIT217566

88) Dagodzo, D., & Ahiaeke Patrick, M. C. (2025). A framework for national-scale UAV deployment in power infrastructure: Lessons from developing economies. International Journal of Scientific Research in Computer Science, Engineering and Information Technology,11(4), 779–824. https://doi.org/10.32628/CSEIT251116286

89) Dasgupta, D., Akhtar, Z., & Sen, S. (2022). Machine learning in cybersecurity: A comprehensive survey. The Journal of Defense Modeling and Simulation, 19(1), 57–106. https://doi.org/10.1177/1548512920951275

90) Davis, M. C., Challenger, R., Jayewardene, D. N. W., & Clegg, C. W. (2014). Advancing socio-technical systems thinking: A call for bravery. Applied Ergonomics, 45(2), 171–180. https://doi.org/10.1016/j.apergo.2013.02.009

91) Dawson, J., & Thomson, R. (2018). The future cybersecurity workforce: Going beyond technical skills for successful cyber performance. Frontiers in Psychology, 9(744), Article 744. https://doi.org/10.3389/fpsyg.2018.00744

92) Dempsey, K., Chawla, N. S., Johnson, A., Johnston, R., Jones, A. C., Orebaugh, A., Scholl, M., & Stine, K. (2011). Information security continuous monitoring (ISCM) for federal information systems and organizations. NIST Special Publication 800-137. National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-137

93) Dempsey, K., Pillitteri, V., Baer, C., Niemeyer, R., Rudman, R., & Urban, S. (2020). Assessing information security continuous monitoring (ISCM) programs: Developing an ISCM program assessment. NIST Special Publication 800-137A. National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-137A

94) Denning, D. E. (1987). An intrusion-detection model. IEEE Transactions on Software Engineering, SE-13(2), 222–232.

https://doi.org/10.1109/TSE.1987.232894

95) Dosunmu, A. A., & Ogundele, P. O. (2019). Security audit and enterprise risk assessment frameworks for resilient information systems. Iconic Research and Engineering Journals, 3(5), 434–447. https://doi.org/10.64388/IREV3I5-1713225

96) Dosunmu, A. A., & Ogundele, P. O. (2020). Intrusion detection and prevention models for enhancing organizational cyber defense effectiveness. Iconic Research and Engineering Journals, 4(6), 310–324. https://doi.org/10.64388/IREV4I6-1713226

97) Dosunmu, A. A., & Ogundele, P. O. (2021). Incident response and digital forensics strategies for rapid cyber attack containment. Gyanshauryam, International Scientific Refereed Research Journal, 4(4), 239–258.

98) Dosunmu, A. A., & Ogundele, P. O. (2022). Threat intelligence integration frameworks supporting proactive enterprise cybersecurity decision making. Gyanshauryam, International Scientific Refereed Research Journal, 5(3), 397–416.

99) Dosunmu, A. A., & Ogundele, P. O. (2023). Cyber threat actor analysis models for strategic enterprise security planning. Shodhshauryam, International Scientific Refereed Research Journal, 6(5), 513–531.

100) Dosunmu, A. A., & Ogundele, P. O. (2024a). Breach and attack simulation frameworks for continuous validation of enterprise security controls. International Journal of Scientific Research in Computer Science, Engineering and Information Technology, 10(3), 1100–1119.

101) Dosunmu, A. A., & Ogundele, P. O. (2024b). Cyber risk quantification models for prioritizing enterprise security investment decisions. International Journal of Multidisciplinary Research and Growth Evaluation, 5(6), 1777–1785.

https://doi.org/10.54660/.IJMRGE.2024.5.6.1777-1785

102) Dosunmu, A. A., & Ogundele, P. O. (2024c). Enterprise scale continuous security validation models for regulated digital infrastructures. International Journal of Scientific Research in Humanities and Social Sciences, 1(2), 929–945.

103) Dosunmu, A. A., & Ogundele, P. O. (2024d). Threat informed defence engineering models for measuring security control effectiveness at scale. International Journal of Advanced Multidisciplinary Research and Studies, 4(6), 2847–2858.

104) Dosunmu, A. A., & Ogundele, P. O. (2025a). Adversary simulation design frameworks for proactive cyber defense in complex environments. International Journal of Computer Science and Mathematical Theory, 11(12), 193–209.

https://doi.org/10.56201/ijcsmt.vol.11.no12.2025.pg193.209

105) Dosunmu, A. A., & Ogundele, P. O. (2025b). Cyber defense performance measurement frameworks for executive and board level governance. Computer Science and IT Research Journal, 6(11), 895–913. https://doi.org/10.51594/csitrj.v6i11.2164

106) Dosunmu, A. A., & Ogundele, P. O. (2025c). Security orchestration and automation models for accelerating incident detection and response. Computer Science and IT Research Journal, 6(11), 878–894. https://doi.org/10.51594/csitrj.v6i11.2163

107) Dosunmu, A. A., & Ogundele, P. O. (2026a). Deception based defense architectures for disrupting advanced persistent threat operations. Engineering and Technology Journal, 11(1), 8475–8487. https://doi.org/10.47191/etj/v11i01.07

108) Dosunmu, A. A., & Ogundele, P. O. (2026b). Integrated threat intelligence automation and simulation models for next generation cyber defense. Engineering and Technology Journal, 11(1), 8451–8462. https://doi.org/10.47191/etj/v11i01.05

109) Dosunmu, A. A., & Ogundele, P. O. (2026c). Proxy firewall and endpoint validation frameworks using breach simulation methodologies. Engineering and Technology Journal, 11(1), 8463–8474. https://doi.org/10.47191/etj/v11i01.06

110) Dragos. (2025). Dragos 2025 OT/ICS cybersecurity report: A year in review. Dragos, Inc. https://www.dragos.com/dragos-2025-ot-cybersecurity-report-a-year-in-review

111) Ebhojie, O., Dogbatsey, E. A., & Oyeleye, A. O. (2023). Audit liaison, corrective action planning, and control compliance in multinational organisations: A systematic literature review. International Journal of Advanced Multidisciplinary Research and Studies, 3(6), 2839–2850. https://doi.org/10.62225/2583049X.2023.3.6.6200

112) Efobi, O. Z., Akinleye, O. K., & Fasawe, O. (2023). Conceptual framework for developing a resilience index for post-pandemic supply chains. Shodhshauryam, International Scientific Refereed Research Journal, 6(2), 421–432.

113) Ekechi, N. V., Ozowara, D. E., & Anunagba, C. O. (2026). Conceptual framework for AI governance, data privacy compliance, and financial sustainability in digital health. Computer Science and IT Research Journal, 7(4), 275–299.

114) Emery, F. E., & Trist, E. L. (1965). The causal texture of organizational environments. Human Relations, 18(1), 21–32.

https://doi.org/10.1177/001872676501800103

115) European Parliament and Council of the European Union. (2022). Directive (EU) 2022/2555 of the European Parliament and of the Council of 14 December 2022 on measures for a high common level of cybersecurity across the Union (NIS 2 Directive). Official Journal of the European Union, L 333, 80–152. https://eur-lex.europa.eu/eli/dir/2022/2555/oj

116) European Union Agency for Cybersecurity. (2023). ENISA threat landscape 2023.

https://www.enisa.europa.eu/publications/enisa-threat-landscape-2023

117) European Union Agency for Cybersecurity. (2024). ENISA threat landscape 2024. https://www.enisa.europa.eu/publications/enisa-threat-landscape-2024

118) European Union Agency for Cybersecurity. (2025). ENISA NIS360 2024: Maturity and criticality of NIS2 sectors.

https://www.enisa.europa.eu/publications/enisa-nis360-2024

119) Exec. Order No. 14028, Improving the Nation’s Cybersecurity, 86 Fed. Reg. 26633 (May 17, 2021).

https://www.federalregister.gov/documents/2021/05/17/2021-10460/improving-the-nations-cybersecurity

120) Eyetsemitan, R. A., Oyeleye, A. O., Ambali, K. B., & Fadayomi, O. (2022). Standard operating procedures as strategic assets in small business operations: A systematic review and implementation framework. Gyanshauryam, International Scientific Refereed Research Journal, 5(2), 438–465. https://doi.org/10.32628/GISRRJ225356

121) Eze, F. I., Akinleye, O. K., & Anene, U. N. (2024). Development of a cross-border regulatory harmonization model for African pharmaceutical markets: The ARCH-Model framework. International Journal of Health and Pharmaceutical Research, 9(5), 148–186.https://doi.org/10.56201/ijhpr.v9.no5.2024.pg148.186

122) Fadayomi, O., Abolaji, T. O., Edivri, J., Ogbole, J. I., Okoruwa, P. O., & Akeju, B. (2019). Risk-based cybersecurity assurance and data availability: Limitations, advances and future research opportunities. Iconic Research and Engineering Journals, 2(12), 602–617.https://doi.org/10.64388/IREV2I12-1713779

123) Falliere, N., Murchu, L. O., & Chien, E. (2011). W32.Stuxnet dossier (Version 1.4) [White paper]. Symantec Security Response.

124) Ferrag, M. A., Maglaras, L., Moschoyiannis, S., & Janicke, H. (2020). Deep learning for cyber security intrusion detection: Approaches, datasets, and comparative study. Journal of Information Security and Applications, 50(102419), Article 102419.

https://doi.org/10.1016/j.jisa.2019.102419

125) Filani, O. M., Nnabueze, S. B., Ike, P. N., & Wedraogo, L. (2022). Real-time risk assessment dashboards using machine learning in hospital supply chain management systems. International Journal of Multidisciplinary Evolutionary Research, 3(1), 65–76.https://doi.org/10.54660/IJMER.2022.3.1.65-76

126) Fobellah, A. N. (2025a). Cognitive biases in financial decision-making: Implications for audit and risk management in large corporations: A conceptual review. International Journal of Science and Research Archive, 16(2), 17–22. https://doi.org/10.30574/ijsra.2025.16.2.2273

127) Fobellah, A. N. (2025b). Navigating digital transformation: Auditing artificial intelligence-powered financial systems: A conceptual review. International Journal of Science and Research Archive, 16(2), 23–28. https://doi.org/10.30574/ijsra.2025.16.2.2274

128) Fobellah, A. N. (2025c). Unintended consequences of financial regulations: A study of corporate compliance burdens: A conceptual review. International Journal of Science and Research Archive, 16(2), 29–34. https://doi.org/10.30574/ijsra.2025.16.2.2275

129) Fortinet. (2024). 2024 state of operational technology and cybersecurity report. Fortinet, Inc. https://www.fortinet.com/content/dam/fortinet/assets/reports/report-state-ot-cybersecurity.pdf

130) Furnell, S. (2017). Can’t get the staff? The growing need for cyber-security skills. Computer Fraud & Security, 2017(2), 5–10.

https://doi.org/10.1016/S1361-3723(17)30013-1

131) García-Teodoro, P., Díaz-Verdejo, J., Maciá-Fernández, G., & Vázquez, E. (2009). Anomaly-based network intrusion detection: Techniques, systems and challenges. Computers & Security, 28(1–2), 18–28. https://doi.org/10.1016/j.cose.2008.08.003

132) Gartner. (2023). Gartner identifies the top 10 strategic technology trends for 2024 [Press release].

https://www.gartner.com/en/newsroom/press-releases/2023-10-16-gartner-identifies-the-top-10-strategic-technology-trends-for-2024

133) Goddard, K., Roudsari, A., & Wyatt, J. C. (2012). Automation bias: A systematic review of frequency, effect mediators, and mitigators. Journal of the American Medical Informatics Association, 19(1), 121–127. https://doi.org/10.1136/amiajnl-2011-000089

134) Gordon, L. A., & Loeb, M. P. (2002). The economics of information security investment. ACM Transactions on Information and System Security, 5(4), 438–457. https://doi.org/10.1145/581271.581274

135) Gordon, L. A., Loeb, M. P., & Zhou, L. (2020). Integrating cost-benefit analysis into the NIST Cybersecurity Framework via the Gordon-Loeb Model. Journal of Cybersecurity, 6(1), Article tyaa005. https://doi.org/10.1093/cybsec/tyaa005

136) Gordon, L. A., Loeb, M. P., Lucyshyn, W., & Zhou, L. (2015). Increasing cybersecurity investments in private sector firms. Journal of Cybersecurity, 1(1), 3–17. https://doi.org/10.1093/cybsec/tyv011

137) Gritzalis, D., Iseppi, G., Mylonas, A., & Stavrou, V. (2018). Exiting the risk assessment maze: A meta-survey. ACM Computing Surveys, 51(1), Article 11. https://doi.org/10.1145/3145905

138) Hassan, W. U., Guo, S., Li, D., Chen, Z., Jee, K., Li, Z., & Bates, A. (2019). NoDoze: Combatting threat alert fatigue with automated provenance triage. In Proceedings of the 26th Network and Distributed System Security Symposium (NDSS 2019). Internet Society. https://doi.org/10.14722/ndss.2019.23349

139) Humayed, A., Lin, J., Li, F., & Luo, B. (2017). Cyber-physical systems security: A survey. IEEE Internet of Things Journal, 4(6), 1802–1831. https://doi.org/10.1109/JIOT.2017.2703172

140) Hussain, N., & Adebayo, A. (2026). The role of artificial intelligence in strengthening modern cybersecurity systems. World Journal of Innovation and Modern Technology, 10(6), 125–181. https://doi.org/10.56201/wjimt.v10.no6.2026.pg125.181

141) Husák, M., Komárková, J., Bou-Harb, E., & Čeleda, P. (2019). Survey of attack projection, prediction, and forecasting in cyber security. IEEE Communications Surveys & Tutorials, 21(1), 640–660. https://doi.org/10.1109/COMST.2018.2871866

142) IBM. (2024). Cost of a data breach report 2024. IBM Corporation. https://www.ibm.com/reports/data-breach

143) IBM. (2025). Cost of a data breach report 2025: The AI oversight gap. IBM Corporation. https://www.ibm.com/reports/data-breach

144) Igure, V. M., Laughter, S. A., & Williams, R. D. (2006). Security issues in SCADA networks. Computers & Security, 25(7), 498–506. https://doi.org/10.1016/j.cose.2006.03.001

145) Ike, P. N., Aifuwa, S. E., Nnabueze, S. B., Olatunde-Thorpe, J., Ogbuefi, E., Oshoba, T. O., & Akokodaripon, D. (2024). Quantitative risk architecture for public-private partnerships: A multi-layered model for allocating public and private risk. International Journal of Advanced Multidisciplinary Research and Studies, 4(6), 2669–2682. https://doi.org/10.62225/2583049X.2024.4.6.5021

146) Ike, P. N., Okojie, J. S., Nnabueze, S. B., Idu, J. O. O., Filani, O. M., & Ihwughwavwe, S. I. (2025). Digital twin-driven environmental compliance models for sustainable procurement in oil, gas, and utilities. International Journal of Advanced Multidisciplinary Research and Studies, 5(5), 562–576.

147) Ilodigwe, L., & Adesemoye, A. C. (2021). The data backbone of health system transformation: A governance and architecture framework for interoperability, data quality, and advanced analytics at national scale. International Journal of Health and Pharmaceutical Research, 6(2), 52–76. https://doi.org/10.56201/ijhpr.vol.6.no2.2021.pg52.76

148) Ilodigwe, L., & Adesemoye, A. C. (2024). Beyond technology: A strategic framework for building sustainable and resilient health systems through organizational strategy, operational excellence, and workforce capability. International Journal of Medical Evaluation and Physical Report, 8(6), 299–319. https://doi.org/10.56201/ijmepr.v8.no6.2024.pg299.319

149) Ilodigwe, L., & Adesemoye, A. C. (2025a). Advances, risks, and implementation challenges of artificial intelligence as a force multiplier for clinical decision making and health system efficiency. International Journal of Medical Evaluation and Physical Report, 9(7), 165–185. https://doi.org/10.56201/ijmepr.v9.no7.2025.pg165.185

150) Ilodigwe, L., & Adesemoye, A. C. (2025b). Executing healthcare transformation at scale: A strategic change model derived from large programs across payers, providers, and integrated health systems. International Journal of Health and Pharmaceutical Research, 10(12), 253–272. https://doi.org/10.56201/ijhpr.vol.10.no12.2025.pg253.272

151) International Organization for Standardization & International Electrotechnical Commission. (2022a). Information security, cybersecurity and privacy protection: Information security management systems: Requirements. ISO/IEC 27001:2022.

https://www.iso.org/standard/27001

152) International Organization for Standardization & International Electrotechnical Commission. (2022b). Information security, cybersecurity and privacy protection: Guidance on managing information security risks. ISO/IEC 27005:2022.

https://www.iso.org/standard/80585.html

153) International Organization for Standardization. (2018). Risk management: Guidelines. ISO 31000:2018.

https://www.iso.org/standard/65694.html

154) Islam, C., Babar, M. A., & Nepal, S. (2019). A multi-vocal review of security orchestration. ACM Computing Surveys, 52(2), Article 37. https://doi.org/10.1145/3305268

155) Jaquith, A. (2007). Security metrics: Replacing fear, uncertainty, and doubt. Addison-Wesley.

156) Jimoh, H. O., & Ahmed, M. O. (2024). Analyzing Network Time Protocol (NTP) based amplification DDoS attack and its mitigation techniques. Journal of Digital Innovations and Contemporary Research in Science, Engineering and Technology, 12(2), 17–24.https://doi.org/10.22624/AIMS/DIGITAL/V11N2P2x

157) Jimoh, H. O., Abolle-Okoyeagu, C. J., Ahmed, M. O., & Lawal, N. O. (2023a). Advancing security in IoT-driven critical infrastructure: A focus on smart transportation system. American Journal of Engineering Research, 12(12), 33–46.

158) Jimoh, H. O., Ahmed, M. O., & Fagbade, M. O. (2023b). The role of frameworks in cybersecurity governance. Journal of Behavioural Informatics, Digital Humanities and Development Research, 9(4), 7–16. https://doi.org/10.22624/AIMS/BHI/V9N4P2

159) Joint Task Force Transformation Initiative. (2011). Managing information security risk: Organization, mission, and information system view. NIST Special Publication 800-39. National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-39

160) Joint Task Force Transformation Initiative. (2012). Guide for conducting risk assessments. NIST Special Publication 800-30, Rev. 1. National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-30r1

161) Joint Task Force. (2018). Risk management framework for information systems and organizations: A system life cycle approach for security and privacy. NIST Special Publication 800-37, Rev. 2. National Institute of Standards and Technology.

https://doi.org/10.6028/NIST.SP.800-37r2

162) Joint Task Force. (2020). Security and privacy controls for information systems and organizations. NIST Special Publication 800-53,

Rev. 5. National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-53r5

163) Joint Task Force. (2022). Assessing security and privacy controls in information systems and organizations. NIST Special Publication 800-53A, Rev. 5. National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-53Ar5

164) Knight, F. H. (1921). Risk, uncertainty and profit. Houghton Mifflin.

165) Knowles, W., Prince, D., Hutchison, D., Disso, J. F. P., & Jones, K. (2015). A survey of cyber security management in industrial control systems. International Journal of Critical Infrastructure Protection, 9, 52–80. https://doi.org/10.1016/j.ijcip.2015.02.002

166) Kokulu, F. B., Soneji, A., Bao, T., Shoshitaishvili, Y., Zhao, Z., Doupé, A., & Ahn, G.-J. (2019). Matched and mismatched SOCs: A qualitative study on security operations center issues. In Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security (pp. 1955–1970). Association for Computing Machinery.

https://doi.org/10.1145/3319535.3354239Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security (pp. 1955–). ACM, 2019. https://doi.org/10.1145/3319535.3354239

167) Komi, N. M., & Adamolekun, A. (2021). Interpretable machine learning for early failure prediction in distributed renewable energy assets. International Journal of Multidisciplinary Research and Growth Evaluation, 2(6), 1015–1038.

https://doi.org/10.54660/.IJMRGE.2021.2.6.1015-1038

168) Komi, N. M., & Adamolekun, A. (2022). Hierarchical, decentralized, or hybrid? A systematic review of control architectures for distributed energy resources. International Journal of Engineering and Modern Technology, 8(5), 141–195.

https://doi.org/10.56201/ijemt.v8.no5.2022.pg141.195

169) Komi, N. M., & Adamolekun, A. (2024). Quantifying a just transition: An econometric and skills-mapping analysis of worker displacement in the coal-to-renewable shift. International Journal of Scientific Research in Computer Science, Engineering and Information Technology, 10(3), 1242–1299. https://doi.org/10.32628/CSEIT25113587

170) Komi, N. M., & Adeniji, I. O. (2023). A tiered digital twin that brings predictive diagnostics to resource-constrained renewable energy sites. International Journal of Engineering and Modern Technology, 9(3), 287–347. https://doi.org/10.56201/ijemt.v9.no3.2023.pg287.347

171) Komi, N. M., & Adeniji, I. O. (2024). Why energy projects survive or fail: Modeling the causal link between community trust and infrastructure durability. International Journal of Advanced Multidisciplinary Research and Studies, 4(6), 3263–3296.

https://doi.org/10.62225/2583049X.2024.4.6.6459

172) Komi, N. M., & Ganiu, O. S. (2023). Edge intelligence for resilient microgrid control: Advances, energy sovereignty, and open challenges. Gyanshauryam, International Scientific Refereed Research Journal, 6(3), 525–586. https://doi.org/10.32628/GISRRJ236339

173) Kriaa, S., Pietre-Cambacedes, L., Bouissou, M., & Halgand, Y. (2015). A survey of approaches combining safety and security for industrial control systems. Reliability Engineering & System Safety, 139, 156–178. https://doi.org/10.1016/j.ress.2015.02.008

174) Krumay, B., Bernroider, E. W. N., & Walser, R. (2018). Evaluation of cybersecurity management controls and metrics of critical infrastructures: A literature review considering the NIST Cybersecurity Framework. In Secure IT Systems: NordSec 2018 (pp. 369–384). Lecture Notes in Computer Science. https://doi.org/10.1007/978-3-030-03638-6_23

175) Ladapo, O. O., Dosunmu, A. A., Jooda, D., & Abolaji, T. O. (2018). Lessons learned from offline assessment of security-critical systems: The case of Microsoft Active Directory. Iconic Research and Engineering Journals, 2(6), 277–299. https://doi.org/10.64388/IREV2I6-1717205

176) Ladapo, O. O., Dosunmu, A. A., Jooda, D., & Abolaji, T. O. (2022a). Human-in-the-loop machine learning: A state of the art. Journal of Frontiers in Multidisciplinary Research, 3(1), 656–669. https://doi.org/10.54660/.JFMR.2022.3.1.656-669

177) Ladapo, O. O., Dosunmu, A. A., Jooda, D., & Abolaji, T. O. (2023). Active Directory attacks steps, types, and signatures. International Journal of Advanced Multidisciplinary Research and Studies, 3(6), 2863–2874. https://doi.org/10.62225/2583049X.2023.3.6.6204

178) Ladapo, O. O., Dosunmu, A. A., Jooda, D., & Abolaji, T. O. (2024a). Integrated network and security operation center: A systematic analysis. International Journal of Multidisciplinary Futuristic Development, 5(1), 65–80. https://doi.org/10.54660/IJMFD.2024.5.1.65-80

179) Ladapo, O. O., Jooda, D., Dosunmu, A. A., & Abolaji, T. O. (2019). Implementation of Active Directory for efficient management of enterprise networks. Iconic Research and Engineering Journals, 3(4), 608–627. https://doi.org/10.64388/IREV3I4-1717206

180) Ladapo, O. O., Jooda, D., Dosunmu, A. A., & Abolaji, T. O. (2022b). Navigating digital transformation: Best practices for cloud migration strategies in the enterprise. Journal of Frontiers in Multidisciplinary Research, 3(1), 643–655. https://doi.org/10.54660/.JFMR.2022.3.1.643-655

181) Ladapo, O. O., Jooda, D., Dosunmu, A. A., & Abolaji, T. O. (2024b). Keeping humans in the loop: Human-centered automated annotation with generative AI. International Journal of Multidisciplinary Futuristic Development, 5(1), 81–95.

https://doi.org/10.54660/IJMFD.2024.5.1.81-95

182) Ladapo, O. O., Jooda, D., Dosunmu, A. A., & Abolaji, T. O. (2026). On the disagreement problem in human-in-the-loop federated machine learning. International Journal of Multidisciplinary Research and Growth Evaluation, 7(3), 178–192.

https://doi.org/10.54660/.IJMRGE.2026.7.3.178-192

183) Langner, R. (2011). Stuxnet: Dissecting a cyberwarfare weapon. IEEE Security & Privacy, 9(3), 49–51.

https://doi.org/10.1109/MSP.2011.67

184) Lee, R. M., Assante, M. J., & Conway, T. (2016). Analysis of the cyber attack on the Ukrainian power grid: Defense use case. E-ISAC & SANS Institute.https://media.kasperskycontenthub.com/wp-content/uploads/sites/43/2016/05/20081514/E-ISAC_SANS_Ukraine_DUC_5.pdf

185) Linkov, I., Eisenberg, D. A., Plourde, K., Seager, T. P., Allen, J., & Kott, A. (2013). Resilience metrics for cyber systems. Environment Systems and Decisions, 33(4), 471–476. https://doi.org/10.1007/s10669-013-9485-y

186) Liu, H., & Lang, B. (2019). Machine learning and deep learning methods for intrusion detection systems: A survey. Applied Sciences, 9(20), Article 4396. https://doi.org/10.3390/app9204396

187) Malatji, M., Von Solms, S., & Marnewick, A. (2019). Socio-technical systems cybersecurity framework. Information & Computer Security, 27(2), 233–272. https://doi.org/10.1108/ICS-03-2018-0031

188) Mbonu, I. S., Aliliele, C., Iwuanyanwu, U., & Uzoka, E. (2020a). A review of identity and access management integration strategies in hybrid and multi cloud environments. International Journal of Multidisciplinary Research and Growth Evaluation, 1(5), 795–810.https://doi.org/10.54660/.IJMRGE.2020.1.5.795-810

189) Mbonu, I. S., Aliliele, C., Iwuanyanwu, U., & Uzoka, E. (2021). Advances in artificial intelligence techniques for secure software testing and automated regression control mechanisms. International Journal of Scientific Research in Computer Science, Engineering and Information Technology, 7(5), 468–496. https://doi.org/10.32628/CSEIT217565

190) Mbonu, I. S., Aliliele, C., Iwuanyanwu, U., & Uzoka, E. (2022a). A conceptual framework for AI enabled IT general controls and SOX audit automation processes. Gyanshauryam, International Scientific Refereed Research Journal, 5(5), 384–414.

https://doi.org/10.32628/GISRRJ2256239

191) Mbonu, I. S., Aliliele, C., Uzoka, E., & Oluoha, O. M. (2019a). A review of comparative data protection regulations and secure cloud implementation strategies across jurisdictions. Iconic Research and Engineering Journals, 2(9), 482–501. https://doi.org/10.64388/IREV2I9-1714912

192) Mbonu, I. S., Iwuanyanwu, U., Aliliele, C., & Uzoka, E. (2020b). A conceptual framework for agile supply chain digital transformation with embedded IT risk and ISO compliance controls. Iconic Research and Engineering Journals, 3(11), 566–593.

https://doi.org/10.64388/IREV3I11-1714916

193) Mbonu, I. S., Iwuanyanwu, U., Aliliele, C., & Uzoka, E. (2020c). Advances in infrastructure as code governance for secure terraform based enterprise cloud deployments. International Journal of Multidisciplinary Research and Growth Evaluation, 1(5), 811–828. https://doi.org/10.54660/.IJMRGE.2020.1.5.811-828

194) Mbonu, I. S., Iwuanyanwu, U., Aliliele, C., & Uzoka, E. (2022b). Advances in cloud identity and access governance optimization in large scale AWS enterprise environments. Shodhshauryam, International Scientific Refereed Research Journal, 5(3), 403–438.

https://doi.org/10.32628/SHISRRJ225490

195) Mbonu, I. S., Iwuanyanwu, U., Uzoka, E., & Oluoha, O. M. (2019b). Advances in enterprise log analytics and automated incident response architectures using Python and SIEM platforms. Iconic Research and Engineering Journals, 3(2), 1000–1019.

https://doi.org/10.64388/IREV3I2-1714915

196) McLaughlin, S., Konstantinou, C., Wang, X., Davi, L., Sadeghi, A.-R., Maniatakos, M., & Karri, R. (2016). The cybersecurity landscape in industrial control systems. Proceedings of the IEEE, 104(5), 1039–1057. https://doi.org/10.1109/JPROC.2015.2512235

197) Medon, J. J., & Oduleye, T. E. (2022). A comprehensive financial reporting model for strengthening compliance and organizational accountability systems. International Journal of Multidisciplinary Research and Growth Evaluation, 3(6), 768–777.

198) Mirsky, Y., Doitshman, T., Elovici, Y., & Shabtai, A. (2018). Kitsune: An ensemble of autoencoders for online network intrusion detection. In Proceedings of the 25th Network and Distributed System Security Symposium (NDSS 2018). Internet Society. https://doi.org/10.14722/ndss.2018.23204

199) Mo, Y., Kim, T. H.-J., Brancik, K., Dickinson, D., Lee, H., Perrig, A., & Sinopoli, B. (2012). Cyber-physical security of a smart grid infrastructure. Proceedings of the IEEE, 100(1), 195–209. https://doi.org/10.1109/JPROC.2011.2161428

200) National Cyber Security Centre. (2024). Cyber Assessment Framework, Version 3.2. https://www.ncsc.gov.uk/collection/cyber-assessment-framework

201) National Institute of Standards and Technology. (2018). Framework for improving critical infrastructure cybersecurity, Version 1.1. NIST CSWP 6. U.S. Department of Commerce. https://doi.org/10.6028/NIST.CSWP.04162018

202) National Institute of Standards and Technology. (2023). Artificial intelligence risk management framework (AI RMF 1.0). NIST AI 100-1. U.S. Department of Commerce. https://doi.org/10.6028/NIST.AI.100-1

203) National Institute of Standards and Technology. (2024). The NIST Cybersecurity Framework (CSF) 2.0. NIST CSWP 29. U.S. Department of Commerce. https://doi.org/10.6028/NIST.CSWP.29

204) Nelson, A., Rekhi, S., Souppaya, M., & Scarfone, K. (2025). Incident response recommendations and considerations for cybersecurity risk management: A CSF 2.0 community profile. NIST Special Publication 800-61, Rev. 3. National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-61r3

205) Nnabueze, S. B., Ike, P. N., Olatunde-Thorpe, J., Aifuwa, S. E., Oshoba, T. O., Ogbuefi, E., & Akokodaripon, D. (2021). End-to-end visibility frameworks improving transparency, compliance, and traceability across complex global supply chain operations. International Journal of Multidisciplinary Futuristic Development, 2(2), 50–60. https://doi.org/10.54660/IJMFD.2021.2.2.50-60

206) North American Electric Reliability Corporation. (2026). NERC critical infrastructure protection roadmap.

https://www.nerc.com/globalassets/our-work/reports/special-reports/nerc_cip_roadmap_01122026.pdf

207) Obogo, S. F., Arumosoye, O. M., & Obriki, O. D. (2020). Advances in internal QHSE audit systems for industrial engineering operations. Iconic Research and Engineering Journals, 4(4), 399–417. https://doi.org/10.64388/IREV4I4-1715499

208) Obogo, S. F., Arumosoye, O. M., & Obriki, O. D. (2021). Advances in proactive hazard recognition and near miss reporting systems. International Journal of Multidisciplinary Research and Growth Evaluation, 2(6), 835–846. https://doi.org/10.54660/IJMRGE.2021.2.6.835-846

209) Obogo, S. F., Nwafor, M. I., & Ozobu, C. O. (2023). Conceptual leadership model for safety culture development in construction and engineering projects. International Journal of Scientific Research in Civil Engineering, 7(6), 121–153.https://doi.org/10.32628/IJSRCE237554

210) Obogo, S. F., Ozobu, C. O., & Uduokhai, D. O. (2019). Advances in leadership driven safety culture transformation in large construction workforces. Iconic Research and Engineering Journals, 3(5), 507–523. https://doi.org/10.64388/IREV3I5-1715497

211) Obogo, S. F., Ozobu, C. O., Garba, B. M. P., & Adio, S. A. (2026). Predictive safety analytics model for early detection of high-risk construction activities. Global Journal of Engineering and Technology Review, 2(3), 92–109. https://doi.org/10.65150/EP-gjetr/V2E3/2026-03

212) Obriki, O. D., & Arumosoye, O. M. (2018). Conceptual modeling of data-driven occupational safety risk control in large-scale energy infrastructure projects. Iconic Research and Engineering Journals, 1(7), 169–189. https://doi.org/10.64388/IREV1I7-714414

213) Obriki, O. D., & Arumosoye, O. M. (2020). Conceptual framework for human error causation in high-risk construction and industrial activities. International Journal of Multidisciplinary Research and Growth Evaluation, 1(5), 715–727.

https://doi.org/10.54660/.IJMRGE.2020.1.5.715-727

214) Obriki, O. D., & Arumosoye, O. M. (2023). Conceptual framework for proactive hazard identification using digital safety data streams. Gyanshauryam, International Scientific Refereed Research Journal, 6(3),457–481. https://doi.org/10.32628/GISRRJ236336

215) Obriki, O. D., & Arumosoye, O. M. (2024). Systematic review of incident investigation approaches and prevention-oriented learning in industrial operations. Shodhshauryam, International Scientific Refereed Research Journal, 7(4), 239–263.

https://doi.org/10.32628/SHISRRJ247163

216) Obriki, O. D., Arumosoye, O. M., & Obogo, S. F. (2023). Advances in continuous hazard monitoring systems for workplace safety. International Journal of Advanced Multidisciplinary Research and Studies, 3(6), 2742–2759. https://doi.org/10.62225/2583049X.2023.3.6.6075

217) Obriki, O. D., Arumosoye, O. M., & Ozobu, C. O. (2025). Conceptual model linking leading safety signals to sustained injury-free project performance. International Journal of Scientific Research in Humanities and Social Sciences, 2(3), 233–254.

https://doi.org/10.32628/IJSRHSS252342

218) Odejobi, O. D., Okonkwo, C. S., Ahiaeke Patrick, M. C., Okeke, O. T., & Mayo, W. (2025). AI-augmented secure software engineering: Leveraging deep learning for autonomous threat detection and mitigation. International Journal of Engineering and Modern Technology, 11(12), 101–121. https://doi.org/10.56201/ijemt.vol.11.no12.2025.pg101.121

219) Ogbole, J. I., Okoruwa, P. O., Fadayomi, O., Abolaji, T. O., Edivri, J., & Akeju, B. (2021). Conceptual model for identity-centric zero trust architecture in enterprise security governance. International Journal of Scientific Research in Computer Science, Engineering and Information Technology, 7(5), 393–415. https://doi.org/10.32628/IJSRCSEIT217562

220) Ogbole, J. I., Okoruwa, P. O., Fadayomi, O., Akeju, B., Edivri, J., & Abolaji, T. O. (2025). Security analytics and digital forensics for enterprise risk management, advances and practical implications. International Journal of Advanced Multidisciplinary Research and Studies, 5(6), 2017–2028.

221) Ogunwola, T. A., & Alozie, C. (2026). Architecting secure and compliant distributed healthcare networks: Operational approaches to health insurance portability and accountability act and health information trust alliance alignment. International Journal of Computer Applications, 187(111), 1–6.

222) Ogunwola, T. A., & Deborah, F. O. (2025). Enterprise network resilience as a national security imperative: Strategies for protecting United States critical infrastructure. International Advanced Research Journal in Science, Engineering and Technology, 12(10).https://doi.org/10.17148/iarjset.2025.121048

223) Ogunwole, O., Okonkwo, C. S., Agbabiaka, J., Mayo, W., & Okeke, O. T. (2021). Supply chain resilience framework for critical infrastructure and gas processing plants. Shodhshauryam, International Scientific Refereed Research Journal, 4(4), 444–461.

https://doi.org/10.32628/SHISRRJ214462

224) Okonkwo, C. S., Agbabiaka, J., Mayo, W., & Okeke, O. T. (2024a). Conceptual framework for digital supply chain governance in energy and infrastructure sectors. Gyanshauryam, International Scientific Refereed Research Journal, 7(4), 335–356.

https://doi.org/10.32628/GISRRJ247423

225) Okonkwo, C. S., Agbabiaka, J., Mayo, W., & Okeke, O. T. (2024b). Framework for secure and scalable supply chain systems supporting national energy reliability. International Journal of Advanced Multidisciplinary Research and Studies, 4(6), 2816–2826.

https://doi.org/10.62225/2583049X.2024.4.6.5494

226) Okonkwo, C. S., Agbabiaka, J., Okeke, O. T., & Mayo, W. (2025). Framework for national-scale supply chain optimization through integrated IT and procurement systems. Gulf Journal of Advance Business Research, 3(12), 1610–1625.

https://doi.org/10.51594/gjabr.v3i12.189

227) Okonkwo, C. S., Ogunwole, O., Mayo, W., & Okeke, O. T. (2021). Framework for regulatory-compliant procurement in high-risk energy environments. International Journal of Multidisciplinary Research and Growth Evaluation, 2(6), 595–605.

https://doi.org/10.54660/IJMRGE.2021.2.6.595-605

228) Okoruwa, P. O., Fadayomi, O., Abolaji, T. O., Edivri, J., Ogbole, J. I., & Akeju, B. (2024). Enterprise cybersecurity trends and threat evolution, advances and emerging research directions. Global Multidisciplinary Perspectives Journal, 1(6), 194–204.

https://doi.org/10.54660/GMPJ.2024.1.6.194-204

229) Okoruwa, P. O., Fadayomi, O., Akeju, B., Edivri, J., Ogbole, J. I., & Abolaji, T. O. (2020). Conceptual model for privacy-centric security engineering in digital and cloud computing systems. International Journal of Scientific Research in Computer Science, Engineering and Information Technology, 7(5), 371–389.

230) Onche, V. O., Adegbite, M. P., & Ogbonna, C. S. (2026). Human factors in information security: A capability framework for administrative professionals in the digital workplace. World Journal of Innovation and Modern Technology, 10(5), 154–179.

https://doi.org/10.56201/wjimt.v10.no5.2026.pg154.179

231) Onche, V. O., Ogbonna, C. S., & Adegbite, M. P. (2024). Effectiveness of cybersecurity awareness training on insider-threat behavior among university administrators: An integrative academic review. International Journal of Computer Science and Mathematical Theory, 10(2), 117–144. https://doi.org/10.56201/ijcsmt.v10.no2.2024.pg117.144

232) Ouyang, M. (2014). Review on modeling and simulation of interdependent critical infrastructure systems. Reliability Engineering & System Safety, 121, 43–60. https://doi.org/10.1016/j.ress.2013.06.040

233) Oyeleke, A. V., Eze, F. C., & Asiedu, W. (2026). Reliability-centered maintenance strategies for minimizing downtime and maximizing performance in high-density GPU cluster environments. International Journal of Engineering Technology Research & Management, 10(7), 18–38.

234) Oyeleye, A. O., Dogbatsey, E. A., & Ebhojie, O. (2025). Embedding automated close controls in public sector ERP systems: A conceptual model for audit readiness and financial reporting quality. Zenodo. https://doi.org/10.5281/zenodo.20097950 [Originally numbered 2(1), 110-130; journal name not captured in source.]

235) Ozowara, D. E., Adebayo, A., & Anunagba, C. O. (2022). A systematic review of cybersecurity investments and their impact on healthcare financial performance. Shodhshauryam, International Scientific Refereed Research Journal, 5(1), 404–427.

236) Ozowara, D. E., Anunagba, C. O., & Adepoju, P. A. (2025). A review of ransomware economics and financial resilience strategies in hospital networks. International Journal of Advanced Multidisciplinary Research and Studies, 5(6), 2284–2298.

https://doi.org/10.62225/2583049X.2025.5.6.6052

237) Parasuraman, R., & Manzey, D. H. (2010). Complacency and bias in human use of automation: An attentional integration. Human Factors, 52(3), 381–410. https://doi.org/10.1177/0018720810376055

238) Pfleeger, S. L., & Cunningham, R. K. (2010). Why measuring security is hard. IEEE Security & Privacy, 8(4), 46–54.

https://doi.org/10.1109/MSP.2010.60

239) Posthumus, S., & von Solms, R. (2004). A framework for the governance of information security. Computers & Security, 23(8), 638–646. https://doi.org/10.1016/j.cose.2004.10.006

240) Quainoo, R., & Ogundapo, O. (2026a). A system-level power behavior model for Bluetooth and Wi-Fi coexistence in dual-mode wireless devices. International Journal of Computer Science and Mathematical Theory, 12(2), 298–358.

https://doi.org/10.56201/ijcsmt.vol.12.no2.2026.pg298.358

241) Quainoo, R., & Ogundapo, O. (2026b). Wireless system-on-chip performance in next-generation Internet of Things devices: A systematic review of integrated transceiver testing methodologies. World Journal of Innovation and Modern Technology, 10(5), 76–126.https://doi.org/10.56201/wjimt.v10.no5.2026.pg76.126

242) Quainoo, R., Ogundapo, O., & Asiedu, W. A. (2024). Modeling the impact of impedance mismatch on wireless link performance: A framework for prototype development and system optimization. International Journal of Computer Science and Mathematical Theory, 10(2), 62–116. https://doi.org/10.56201/ijcsmt.v10.no2.2024.pg62.116

243) Quainoo, R., Ogundapo, O., & Asiedu, W. A. (2025a). Predicting throughput degradation in Wi-Fi 6 networks under varying channel conditions: A physical layer performance model. International Journal of Engineering and Modern Technology, 11(12), 205–264. https://doi.org/10.56201/ijemt.vol.11.no12.2025.pg205.264

244) Quainoo, R., Ogundapo, O., & Asiedu, W. A. (2025b). Test automation in wireless hardware engineering: A comprehensive review of scripting frameworks and instrument control strategies. International Journal of Engineering and Modern Technology, 11(10), 405–464. https://doi.org/10.56201/ijemt.vol.11.no10.2025.pg405.464

245) Rahman, A., Parnin, C., & Williams, L. (2019). The seven sins: Security smells in infrastructure as code scripts. In Proceedings of the 41st International Conference on Software Engineering (ICSE 2019) (pp. 164–175). IEEE. https://doi.org/10.1109/ICSE.2019.00033

246) Ralston, P. A. S., Graham, J. H., & Hieb, J. L. (2007). Cyber security risk assessment for SCADA and DCS networks. ISA Transactions, 46(4), 583–594. https://doi.org/10.1016/j.isatra.2007.04.003

247) Rinaldi, S. M., Peerenboom, J. P., & Kelly, T. K. (2001). Identifying, understanding, and analyzing critical infrastructure interdependencies. IEEE Control Systems Magazine, 21(6), 11–25. https://doi.org/10.1109/37.969131

248) Rose, S., Borchert, O., Mitchell, S., & Connelly, S. (2020). Zero trust architecture. NIST Special Publication 800-207. National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-207

249) Ross, R., & Pillitteri, V. (2024). Protecting controlled unclassified information in nonfederal systems and organizations. NIST Special Publication 800-171, Rev. 3. National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-171r3

250) Ross, R., Winstead, M., & McEvilley, M. (2022). Engineering trustworthy secure systems. NIST Special Publication 800-160, Vol. 1, Rev. 1. National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-160v1r1

251) Safa, N. S., Von Solms, R., & Furnell, S. (2016). Information security policy compliance model in organizations. Computers & Security, 56, 70–82. https://doi.org/10.1016/j.cose.2015.10.006

252) Sarker, I. H., Furhad, M. H., & Nowrozy, R. (2021). AI-driven cybersecurity: An overview, security intelligence modeling and research directions. SN Computer Science, 2(173), Article 173. https://doi.org/10.1007/s42979-021-00557-0

253) Sarker, I. H., Kayes, A. S. M., Badsha, S., Alqahtani, H., Watters, P., & Ng, A. (2020). Cybersecurity data science: An overview from machine learning perspective. Journal of Big Data, 7(41), Article 41. https://doi.org/10.1186/s40537-020-00318-5

254) Shone, N., Ngoc, T. N., Phai, V. D., & Shi, Q. (2018). A deep learning approach to network intrusion detection. IEEE Transactions on Emerging Topics in Computational Intelligence, 2(1), 41–50. https://doi.org/10.1109/TETCI.2017.2772792

255) Sisinni, E., Saifullah, A., Han, S., Jennehag, U., & Gidlund, M. (2018). Industrial internet of things: Challenges, opportunities, and directions. IEEE Transactions on Industrial Informatics, 14(11), 4724–4734. https://doi.org/10.1109/TII.2018.2852491

256) Sommer, R., & Paxson, V. (2010). Outside the closed world: On using machine learning for network intrusion detection. In 2010 IEEE Symposium on Security and Privacy (pp. 305–316). IEEE. https://doi.org/10.1109/SP.2010.25

257) Soomro, Z. A., Shah, M. H., & Ahmed, J. (2016). Information security management needs more holistic approach: A literature review. International Journal of Information Management, 36(2), 215–225. https://doi.org/10.1016/j.ijinfomgt.2015.11.009

258) Stine, K., Quinn, S., Witte, G., & Gardner, R. K. (2020). Integrating cybersecurity and enterprise risk management (ERM). NISTIR 8286. National Institute of Standards and Technology. https://doi.org/10.6028/NIST.IR.8286

259) Stouffer, K., Pease, M., Tang, C., Zimmerman, T., Pillitteri, V., Lightman, S., Hahn, A., Saravia, S., Sherule, A., & Thompson, M. (2023). Guide to operational technology (OT) security. NIST Special Publication 800-82, Rev. 3. National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-82r3

260) Strom, B. E., Applebaum, A., Miller, D. P., Nickels, K. C., Pennington, A. G., & Thomas, C. B. (2020). MITRE ATT&CK: Design and philosophy (March 2020 revision). The MITRE Corporation. https://attack.mitre.org/docs/ATTACK_Design_and_Philosophy_March_2020.pdf

261) Sundaramurthy, S. C., Bardas, A. G., Case, J., Ou, X., Wesch, M., McHugh, J., & Rajagopalan, S. R. (2015). A human capital model for mitigating security analyst burnout. In Proceedings of the Eleventh Symposium On Usable Privacy and Security (SOUPS 2015) (pp. 347–359). USENIX Association. https://www.usenix.org/conference/soups2015/proceedings/presentation/sundaramurthy

262) Sunday, E. A., Omoegun, G. O., Essien, M. A., & Oluokun, O. A. (2020). Transitioning from reactive to predictive maintenance in mechanical systems. International Journal of Scientific Research in Computer Science, Engineering and Information Technology, 6(6), 425–447.

263) Syed, N. F., Shah, S. W., Shaghaghi, A., Anwar, A., Baig, Z., & Doss, R. (2022). Zero trust architecture (ZTA): A comprehensive survey. IEEE Access, 10, 57143–57179. https://doi.org/10.1109/ACCESS.2022.3174679

264) Taddeo, M., McCutcheon, T., & Floridi, L. (2019). Trusting artificial intelligence in cybersecurity is a double-edged sword. Nature Machine Intelligence, 1(12), 557–560. https://doi.org/10.1038/s42256-019-0109-1

265) Ten, C.-W., Liu, C.-C., & Manimaran, G. (2008). Vulnerability assessment of cybersecurity for SCADA systems. IEEE Transactions on Power Systems, 23(4), 1836–1846. https://doi.org/10.1109/TPWRS.2008.2002298

266) Tonoyan, A., Dada, O., & Ayivi-Donkor, S. S. (2021). Advances in demand forecasting: Machine learning algorithms for revenue projection and financial planning accuracy. Gyanshauryam, International Scientific Refereed Research Journal, 4(1), 282–317.

267) Tonoyan, A., Dada, O., & Ayivi-Donkor, S. S. (2024a). Advances in supply chain resilience: Predictive models for vendor risk assessment and procurement cost optimization. International Journal of Social Sciences and Management Research, 10(11), 525–551.https://doi.org/10.56201/ijssmr.v10.no11.2024.pg.525.551

268) Tonoyan, A., Dada, O., & Ayivi-Donkor, S. S. (2024b). Real-time KPI tracking systems: A review of automated performance monitoring and data-driven decision making. World Journal of Innovation and Modern Technology, 8(6), 247–281.

https://doi.org/10.56201/wjimt.v8.no6.2024.pg247.281

269) Torkura, K. A., Sukmana, M. I. H., Cheng, F., & Meinel, C. (2020). CloudStrike: Chaos engineering for security and resiliency in cloud infrastructure. IEEE Access, 8, 123044–123060. https://doi.org/10.1109/ACCESS.2020.3007338

270) Torkura, K. A., Sukmana, M. I. H., Cheng, F., & Meinel, C. (2021). Continuous auditing and threat detection in multi-cloud infrastructure. Computers & Security, 102(102124), Article 102124. https://doi.org/10.1016/j.cose.2020.102124

271) Trist, E. L., & Bamforth, K. W. (1951). Some social and psychological consequences of the longwall method of coal-getting. Human Relations, 4(1), 3–38. https://doi.org/10.1177/001872675100400101

272) U.S. Department of Defense, Office of the Chief Information Officer. (2024). Cybersecurity Maturity Model Certification (CMMC) model overview (Version 2.13). https://dodcio.defense.gov/Portals/0/Documents/CMMC/ModelOverviewv2.pdf

273) van Ede, T., Aghakhani, H., Spahn, N., Bortolameotti, R., Cova, M., Continella, A., van Steen, M., Peter, A., Kruegel, C., & Vigna, G. (2022). DeepCASE: Semi-supervised contextual analysis of security events. In 2022 IEEE Symposium on Security and Privacy (SP). IEEE. https://doi.org/10.1109/SP46214.2022.9833671

274) Vasarhelyi, M. A., & Halper, F. B. (1991).The continuous audit of online systems. Auditing: A Journal of Practice & Theory,10(1),110–125.

275) Vasarhelyi, M. A., Alles, M., Kuenkaikaew, S., & Littley, J. (2012). The acceptance and adoption of continuous auditing by internal auditors: A micro analysis. International Journal of Accounting Information Systems, 13(3), 267–281.

https://doi.org/10.1016/j.accinf.2012.06.011

276) Verizon. (2024). 2024 data breach investigations report. Verizon Business.

https://www.verizon.com/business/resources/reports/2024-dbir-data-breach-investigations-report.pdf

277) Verizon. (2025). 2025 data breach investigations report. Verizon Business.

https://www.verizon.com/business/resources/reports/2025-dbir-data-breach-investigations-report.pdf

278) Vielberth, M., Böhm, F., Fichtinger, I., & Pernul, G. (2020). Security operations center: A systematic study and open challenges. IEEE Access, 8, 227756–227779. https://doi.org/10.1109/ACCESS.2020.3045514

279) Vinayakumar, R., Alazab, M., Soman, K. P., Poornachandran, P., Al-Nemrat, A., & Venkatraman, S. (2019). Deep learning approach for intelligent intrusion detection system. IEEE Access, 7, 41525–41550. https://doi.org/10.1109/ACCESS.2019.2895334

280) von Solms, B., & von Solms, R. (2004). The 10 deadly sins of information security management. Computers & Security, 23(5), 371–376.https://doi.org/10.1016/j.cose.2004.05.002

281) von Solms, R., & van Niekerk, J. (2013). From information security to cyber security. Computers & Security, 38, 97–102.

https://doi.org/10.1016/j.cose.2013.04.004

282) Walawalkar, G., Adesuyi, M. O., Kalu, A., & Oduleye, T. E. (2025). Executive financial dashboards for real-time strategic oversight. International Journal of Advanced Multidisciplinary Research and Studies, 5(6), 2042–2054.

283) Wang, W., & Lu, Z. (2013). Cyber security in the smart grid: Survey and challenges. Computer Networks, 57(5), 1344–1371.

https://doi.org/10.1016/j.comnet.2012.12.017

284) Wiener, N. (1948). Cybernetics: Or control and communication in the animal and the machine. MIT Press.

285) World Economic Forum. (2024). Global cybersecurity outlook 2024: Insight report.

https://www3.weforum.org/docs/WEF_Global_Cybersecurity_Outlook_2024.pdf

286) World Economic Forum. (2025). Global cybersecurity outlook 2025: Insight report. https://www.weforum.org/publications/global-cybersecurity-outlook-2025/

287) Xin, Y., Kong, L., Liu, Z., Chen, Y., Li, Y., Zhu, H., Gao, M., Hou, H., & Wang, C. (2018). Machine learning and deep learning methods for cybersecurity. IEEE Access, 6, 35365–35381. https://doi.org/10.1109/ACCESS.2018.2836950

288) Zhu, B., Joseph, A., & Sastry, S. (2011). A taxonomy of cyber attacks on SCADA systems. In Proceedings of the 2011 International Conference on Internet of Things and 4th International Conference on Cyber, Physical and Social Computing (pp. 380–388). IEEE. https://doi.org/10.1109/iThings/CPSCom.2011.34

Downloads

Published

2026-09-10

How to Cite

Amadi, C. (2026). The Compliance Gap: Why Audit-Based Cybersecurity Models Fail Critical Infrastructure and the Case for Continuous Control. Global Journal of Engineering and Technology Research, 2(09), 536-562. https://doi.org/10.65150/EP-gjetr/V2E9/2026-12

Most read articles by the same author(s)