Skip to content
Review Open access

Fragmentation and Harmonization of Cybersecurity and IT Control Frameworks: An Integrative Review of U.S. Governance Practices

Jul 2026 · Magna Scientia Advanced Research and Reviews · Vol 17, pp. 079-087 · 0 citations

TL;DR

This review synthesizes cross-sector evidence to identify structural, operational, and technological barriers to harmonization, while proposing an integrative governance perspective grounded in recent empirical and policy literature.

Abstract

Cybersecurity and information technology control frameworks in the United States exhibit significant fragmentation arising from overlapping regulatory mandates and duplicated controls. Audits and compliance activities in financial institutions and critical infrastructure sectors identify vulnerabilities but reveal limitations when applied as static mechanisms rather than adaptive processes. Mapping exercises between National Institute of Standards and Technology Cybersecurity Framework, Control Objectives for Information and Related Technology, and International Organization for Standardization 27001 consistently document both shared requirements and gaps that widen with the introduction of artificial intelligence and machine learning. Federal harmonization efforts have produced initial coordination yet face persistent barriers from agency-specific mandates and scarce longitudinal outcome data. Governance practices navigate these tensions through sector-specific applications that balance operational demands against systemic interoperability needs. The empirical studies highlight the need for continued attention to framework alignment, regulatory coordination, and empirical validation if resilience is to match evolving threats. Effective integration of controls requires addressing both practical implementation challenges and broader policy structures that shape cybersecurity governance across regulated industries. These dynamics underscore the importance of reducing unnecessary duplication while preserving essential specialization to support more resilient national cybersecurity posture. Ultimately, achieving meaningful harmonization will depend on sustained policy coordination and the development of robust evidence on post-alignment outcomes. This review synthesizes cross-sector evidence to identify structural, operational, and technological barriers to harmonization, while proposing an integrative governance perspective grounded in recent empirical and policy literature.

Read PDF

Similar papers

Review Open access Jul 2026

Risk-Based IT Auditing and Cybersecurity Assurance in Regulated U.S. Organizations: A Review of Governance, Methods, and Outcomes

This review synthesizes peer-reviewed literature on governance structures, auditing methods, and resulting outcomes across key sectors including financial services, capital markets, healthcare, and critical infrastructure to reveal consistent emphasis on integrated governance approaches alongside persistent implementation tensions.

William Asare Yirenkyi, Apaflo Godson Teye, Matilda Konotey et al. · 0 citations
Review Open access Jul 2026

From Risk Reporting to Resilience: A Narrative Integrative Review of Cybersecurity Governance Practices in Organizations

Cybersecurity has moved from a peripheral technical function to a core pillar of organizational governance, driven by the escalating frequency and cost of digital intrusions, tightening disclosure regulation, and growing recognition that technical controls alone cannot guarantee continuity of operations. This narrative integrative review synthesises contemporary academic literature on cybersecurity governance, tracing its evolution from a compliance-oriented, risk-reporting paradigm toward an integrated model of organizational cyber resilience. The review examines governance structures and board oversight arrangements, the integration of cybersecurity into enterprise risk management, the conceptual architecture of organizational cyber resilience, the human and cultural determinants of governance effectiveness, sector-specific and supply-chain vulnerabilities, financial and insurance mechanisms for risk transfer, the regulatory and standards landscape, and approaches to measuring governance maturity. Findings indicate that although disclosure obligations and formal oversight structures have proliferated, substantive board-level expertise remains scarce, enterprise risk management integration is uneven, and resilience-building efforts are frequently undermined by fragmented accountability and inconsistent measurement practices. The review argues that a durable shift from reactive risk reporting to genuine organizational resilience requires coherent alignment across governance structures, cultural investment, supply-chain oversight and outcome-based metrics. Directions for future research and the practical implications of these findings for boards, risk officers and regulators are discussed.

William Asare Yirenkyi, Apaflo Godson Teye, Matilda Konotey et al. · 0 citations
Open access Jul 2026

Cybersecurity Governance in the Ministry of Communications and Information Technology in Yemen: Empirical Evidence and a Context-Sensitive Framework

Public sector institutions in developing countries increasingly adopt cybersecurity governance frameworks, yet a persistent gap remains between formal adoption and strategic cybersecurity effectiveness. This study investigates this gap through a case study of the Ministry of Communications and Information Technology in Yemen, guided by ISO/IEC 27014. Using a descriptive-analytical approach, data were collected from 30 cybersecurity decision-makers across six governance dimensions and analyzed using PLS-SEM. The findings reveal a cybersecurity governance maturity gap, as none of the governance dimensions showed a significant impact on strategic effectiveness despite moderate to high implementation levels. Risk assessment and management exhibited a negative, non-significant relationship, indicating symbolic practices. The study proposes a context-sensitive framework to enhance strategic alignment and effectiveness. The findings offer practical guidance for policymakers in developing countries seeking to transition from compliance-oriented cybersecurity governance toward strategically integrated governance frameworks.

Riam Abdulbaset AL-Hakimi AL-Hakimi, Nagi Al-shaibany · 0 citations
Review Open access 2026

Cybersecurity Risks in Digitized Capital Markets: A Comparative Regulatory Analysis of Operational Resilience, Disclosure, and Market Integrity

The digitization of capital markets has increased efficiency, connectivity, and innovation, but it has also transformed cybersecurity from an institution-specific technical concern into a systemic threat to market integrity and financial stability. This study evaluates the adequacy and coherence of cybersecurity regulation in digitized capital markets. It employs qualitative policy analysis, doctrinal review, and comparative analysis of the United States Securities and Exchange Commission framework, the European Union’s Digital Operational Resilience Act, and IOSCO/CPMI-IOSCO standards. Regulatory documents and scholarly evidence covering 2020–2026 are assessed through directed content analysis and a comparative matrix spanning governance, incident reporting, disclosure, resilience testing, third-party risk, business continuity, enforcement, and systemic resilience. The findings reveal partial regulatory convergence but persistent structural fragmentation. The United States prioritizes disclosure and investor protection; the European Union adopts a broader operational-resilience model; and international standards emphasize financial-market infrastructures, coordination, and systemic stability. Major deficiencies include weak integration between disclosure and resilience requirements, uneven oversight of critical technology providers, inconsistent incident definitions and reporting timelines, limited cross-border enforcement, and inadequate treatment of contagion and market outages. The study proposes a multilayered regulatory model that aligns entity-specific obligations with harmonized reporting, proportionate disclosure, direct oversight of critical third parties, coordinated recovery planning, and market-wide resilience testing. Such integration is essential for protecting investors, preserving market continuity, and containing systemic cyber risk.

Akomolehin F. Olugbenga · 0 citations
Review Open access Aug 2026

Cybersecurity Governance Deficiencies in External Audit: A Structured Review and Control-to-Assertion Framework

Digital financial reporting depends on identity services, enterprise systems, cloud platforms, automated controls and system-generated evidence. Cybersecurity weaknesses therefore enter external audit when a governance condition or control deficiency affects a material reporting process, an assertion, a disclosure, an estimate or the reliability of audit evidence. This article develops a non-deterministic control-to-assertion framework through a structured integrative review. The search, completed on 16 July 2026, covered English-language journal work published from 2000 to 15 July 2026 through Google Scholar and publisher search services. The final analytic set contains 32 peer-reviewed journal articles, four institutional sources and two public company filings used for worked application. The revision separates organisation-level cybersecurity governance deficiencies from process-level cyber control deficiencies. It also locates the model against COSO, COBIT 2019, NIST CSF 2.0, IT general control methods and relevant International Standards on Auditing. Existing sources provide taxonomies for governance, internal control, security outcomes and audit procedures. The new framework supplies the missing translation route between those taxonomies: governance condition, control state, financial reporting dependency, assertion-level misstatement risk, audit-evidence reliability, audit response and reassessment. Compensating, detective and corrective controls might interrupt or reduce the route, so no governance deficiency automatically produces a control failure or a material misstatement. Two worked documentary applications, The Clorox Company and MGM Resorts International, show how public incident facts enter account, assertion, evidence and procedure analysis. The framework does not estimate incident probability, expected loss or a cyber risk score. It provides a file-ready reasoning structure for entity-specific risk assessment under the auditing standards. Its main contribution lies in the separate treatment of misstatement risk and evidence reliability, followed by a traceable link to accounts, assertions, evidence sources, specialist input and audit procedures.

Alessio Faccia, S. Tangjitsitcharoen · 0 citations
Review Open access Jul 2026

A Critical Integrative Review of Technology Assurance for Operational Resilience in U.S. Regulated Organizations

Technology assurance practices have become central to efforts aimed at strengthening operational resilience across U.S. regulated sectors, including finance, healthcare, and critical infrastructure. This integrative review examines how audits, compliance mechanisms, governance frameworks, and emerging-technology controls are discussed in the recent peer-reviewed literature. Drawing on a synthesis of recent peer-reviewed studies, the analysis reveals recurring attention to traditional compliance-oriented approaches alongside growing interest in adaptive practices and data-protection balances. Studies consistently identify resource constraints, static checklists, and dynamic threats as barriers that limit the translation of assurance activities into sustained resilience. In financial and healthcare contexts, audits and regulatory implementation show promise for risk mitigation but frequently lack integration with broader operational strategies. Similar patterns appear in utility-sector discussions of cyber-physical threats and in examinations of AI governance, where qualitative reviews emphasize ethical and compliance balances without extensive empirical outcome data. Disclosure quality and framework application are linked to market or organizational responses, yet long-term quantitative evaluation remains underdeveloped. Overall, the literature suggests alignment around the identification of barriers and the need for adaptive cultures, while remaining fragmented on consistent linkages to resilience outcomes and silent on cross-sector empirical validation. These insights point to practical implications for regulated organizations seeking to move beyond compliance checklists toward more responsive assurance systems. The review contributes a grounded perspective on current evidence and highlights targeted areas for future inquiry.

Matilda Konotey, Daniel Bamfo, G. Apaflo · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.