A Novel Framework To Assess Cybersecurity Capability Maturity

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Liyanage, Lasini, Arachchilage, Nalin, Russello, Giovanni
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866915231294291968
author Liyanage, Lasini
Arachchilage, Nalin
Russello, Giovanni
author_facet Liyanage, Lasini
Arachchilage, Nalin
Russello, Giovanni
contents In today's rapidly evolving digital landscape, organisations face escalating cyber threats that can disrupt operations, compromise sensitive data, and inflict financial and reputational harm. A key reason for this lies in the organisations' lack of a clear understanding of their cybersecurity capabilities, leading to ineffective defences. To address this gap, Cybersecurity Capability Maturity Models (CCMMs) provide a systematic approach to assessing and enhancing an organisation's cybersecurity posture by focusing on capability maturity rather than merely implementing controls. However, their limitations, such as rigid structures, one-size-fits-all approach, complexity, gaps in security scope (i.e., technological, organisational, and human aspects) and lack of quantitative metrics, hinder their effectiveness. It makes implementing CCMMs in varying contexts challenging and results in fragmented, incomprehensive assessments. Therefore, we propose a novel Cybersecurity Capability Maturity Framework that is holistic, flexible, and measurable to provide organisations with a more relevant and impactful assessment to enhance their cybersecurity posture.
format Preprint
id arxiv_https___arxiv_org_abs_2504_01305
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle A Novel Framework To Assess Cybersecurity Capability Maturity
Liyanage, Lasini
Arachchilage, Nalin
Russello, Giovanni
Cryptography and Security
In today's rapidly evolving digital landscape, organisations face escalating cyber threats that can disrupt operations, compromise sensitive data, and inflict financial and reputational harm. A key reason for this lies in the organisations' lack of a clear understanding of their cybersecurity capabilities, leading to ineffective defences. To address this gap, Cybersecurity Capability Maturity Models (CCMMs) provide a systematic approach to assessing and enhancing an organisation's cybersecurity posture by focusing on capability maturity rather than merely implementing controls. However, their limitations, such as rigid structures, one-size-fits-all approach, complexity, gaps in security scope (i.e., technological, organisational, and human aspects) and lack of quantitative metrics, hinder their effectiveness. It makes implementing CCMMs in varying contexts challenging and results in fragmented, incomprehensive assessments. Therefore, we propose a novel Cybersecurity Capability Maturity Framework that is holistic, flexible, and measurable to provide organisations with a more relevant and impactful assessment to enhance their cybersecurity posture.
title A Novel Framework To Assess Cybersecurity Capability Maturity
topic Cryptography and Security
url https://arxiv.org/abs/2504.01305