Sep 2026· Global Journal of Engineering and Technology Research· 0 citations
TL;DR
A conceptual review argues that this model is structurally incapable of guaranteeing security in modern CI environments and develops the case for a transition to continuous monitoring and continuous control and traces the intellectual and regulatory lineage of the alternative.
Abstract
Critical infrastructure (CI) sectors, including energy, water, transportation, healthcare, telecommunications, and finance, continue to anchor their cybersecurity assurance in periodic, audit-based compliance: scheduled assessments that certify, at a point in time, that mandated controls exist and are documented. This conceptual review argues that this model is structurally incapable of guaranteeing security in modern CI environments and develops the case for a transition to continuous monitoring and continuous control. Drawing on standards literature, empirical studies of operational technology (OT) security, documented attacks on industrial systems, and the continuous auditing tradition in accounting information systems, the paper synthesizes five interlocking failure modes of periodic compliance: (a) the static-snapshot problem, in which audit findings describe a past state rather than the present one; (b) the error-proneness and limited depth of manual, checklist-driven assessment; (c) configuration drift, through which compliant systems silently degrade between audits; (d) the asymmetry between adversary operational tempo and annual or multi-year audit cycles; and (e) an audit-centric organizational culture that substitutes evidence production for risk reduction. The analysis situates these failures against a threat landscape defined by IT/OT convergence, industrial Internet of Things expansion, deep infrastructure interdependencies, nation-state pre-positioning, and ransomware economics. The paper then traces the intellectual and regulatory lineage of the alternative (continuous auditing, information security continuous monitoring, continuous diagnostics and mitigation, zero trust architecture, and emerging continuous control validation) and discusses implications for regulators, operators, and researchers. The compliance gap, it concludes, is not a maturity deficit but a design flaw requiring an architectural response. As a conceptual review the paper offers an analytic framework rather than an effect estimate: it presents no new data and does not establish that continuous regimes reduce realized risk relative to periodic ones, a limitation stated in full in Section 7.
A model that integrates real-time Security Operations Center log analytics with continuous auditing processes and aims to bridge the technical gap between operational threat monitoring activities and the internal audit function indicates that log-level visibility reduces blind spots in internal audit, strengthens contr...
The NERC CIP standards have been mandatory for more than fifteen years and are widely regarded as a baseline for securing the bulk power system, yet little is known about how the people who implement, audit, and write them experience the regulatory lifecycle in practice. Drawing on interviews with twenty two auditors,...
Sena Şahin, Burak Sahin, Robin Berthier et al.· IEEE Power and Energy Magazi...· 0 citations
This article proposes an eleven- stage risk-based remediation framework running from finding validation through continuous monitoring, together with eight measures spanning timeliness, ownership, verification quality, and business linkage, which is proposed rather than empirically validated.
Josephat Deogratius Katundabwile, David Mbui Kamau· International journal of res...· 0 citations
Organisations operating in regulated and critical-infrastructure sectors must satisfy multiple, heterogeneous cybersecurity and privacy instruments simultaneously, including but not limited to ISO/IEC~27001, the NIST Cybersecurity Framework~2.0, Cyber Essentials, and the GDPR. In practice, these obligations are managed...
Tsafac Nkombong Regine Cyrille, Hasan Dağ, R. Creutzburg et al.· 0 citations
Large language model (LLM)-based repository auditors are increasingly deployed as security controls within continuous integration (CI) pipelines, where their findings admit, block, or delay software changes. As Agentic Software Development Life Cycle (SDLC) Security Controls, their non-deterministic behaviour changes t...
Guy Lupo, Nguyen Hung Nguyen, V. Vo et al.· 0 citations
Industrial Control Systems (ICS) are increasingly connected to enterprise networks, cloud platforms, remote engineering services, and industrial Internet of Things devices. Saudi Arabia is a particularly relevant setting because NCA OTCC-1:2022 establishes minimum cybersecurity requirements for relevant government orga...
Ishaq Siddiqui Mohammed· Global academic journal of e...· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.