Skip to content
Review

Transition from Periodic Security Assessments to Continuous Vulnerability Management Frameworks

Aug 2026 · International Research Journal of Advanced Engineering and Technology · 0 citations

TL;DR

The article examines the transition from scheduled security assessments to continuous vulnerability management frameworks in enterprise environments with unstable external exposure and explains why periodic assessment loses completeness when asset states change between review cycles.

Abstract

The article examines the transition from scheduled security assessments to continuous vulnerability management frameworks in enterprise environments with unstable external exposure. Cloud services, SaaS use, short-lived assets, and unmanaged public interfaces reduce the decision value of annual or project-based testing. The novelty of the study lies in combining external attack surface management, continuous penetration testing, vulnerability intelligence, and remediation verification into a single operating model. The aim is to explain why periodic assessment loses completeness when asset states change between review cycles. The method combines source analysis, comparative analysis, conceptual synthesis, and typological classification. The source base covers academic papers, public vulnerability intelligence instruments, official guidance, and industry definitions of external attack surface management. The study identifies three shifts: from snapshot testing to continuous discovery, from severity ranking to exploitation-aware prioritisation, and from automated scanning to expert-verified remediation. The model helps engineering and security teams design measurable programs to reduce exposure.

View source

Similar papers

Preprint Sep 2026

Measuring the Security of the Evolving Software Supply Chain: a Research Agenda

Software supply chain security has become increasingly critical due to the widespread reliance on third-party dependencies and the growing attack surface of modern software ecosystems. However, existing quantitative, measurement-based analysis and vulnerability management approaches remain largely fragmented and ecosystem-specific, limiting their ability to provide comparable risk assessments across environments. This paper presents a structured research plan, starting with a Systematization of Knowledge (SoK) to synthesize the current state of research and identify key gaps, highlighting the limitations in dependency modeling and vulnerability propagation analysis, particularly in the treatment of transitive dependencies and their real-world exploitability. Based on these insights, we argue for a unified measurement perspective capable of consistently representing and analyzing the cross-ecosystem dependency structure. We further identify emerging challenges introduced by AI-assisted software development, where coding LLMs are likely to contribute to new dependency patterns that are not captured by traditional Software Composition Analysis (SCA) tools. These shifts motivate a rethink of dependency modeling to account for evolving software-generation practices and their long-term structural impact on software security.

Sarah Meriem Ourari · 0 citations
Review Open access Jul 2026

Penetration Testing in System Security

This review's results show that penetration testing is an important part of improving cybersecurity because it helps identify weaknesses before they become problems and reduces risk.

Shruti Agarwal, S. Sharma · 1 citation
Preprint Aug 2026

Orchestrated Vulnerability Management for Heterogeneous Networks: Adaptive Two-Stage Vulnerability Assessment, Context-Aware Risk Prioritization, and Automated Mitigation

Heterogeneous networks pose significant security challenges due to device diversity, fragile operating conditions, and heterogeneous firmware and service configurations. Traditional vulnerability management often relies on static scanning and severity-based prioritization, overlooking exploitation likelihood and asset context. This can delay mitigation and increase operational overhead. This paper proposes a SOAR-orchestrated vulnerability management framework integrating passive asset discovery, adaptive two-stage vulnerability assessment, context-aware risk assessment, and automated SDN-based mitigation. The detection engine progressively characterizes device attack surfaces using assessment strategies tailored to device capabilities, minimizing disruption to resource-constrained IoT assets. Risk assessment combines CVSS severity, EPSS exploitation probability, and contextual attributes to prioritize vulnerabilities by operational risk. Based on risk bands, mitigation is automatically enforced through coordinated OpenFlow and IDS policies, ranging from monitoring and selective service isolation to complete host quarantine. Experimental results demonstrate the framework's effectiveness. Adaptive two-stage assessment reduces scan time by up to 91% while identifying 71% of baseline vulnerabilities during the initial stage before selectively triggering further analysis. The context-aware risk model reduces vulnerabilities requiring immediate mitigation by approximately 75% without missing any vulnerability with verified exploitation. Compared with conventional assessment, the framework reduces assessment time for 32 physical hosts by up to 45% and enforces mitigation within milliseconds, enabling efficient and scalable vulnerability management through adaptive assessment, context-aware prioritization, and automated mitigation.

R. Lopes, José Moura, R. Marinheiro · 0 citations
Review Open access Sep 2026

Advanced study of Security Management in actual European Aviation

This paper develops a technical-scientific study of modern European aviation security management and complements the policy review with a numerical simulation framework in MATLAB. The simulation is not a classified or operational attack model; it is a decision-support model for comparing security management strategies under uncertainty. A stochastic Monte Carlo structure is proposed to evaluate security-system effectiveness across multiple airport-security scenarios, using variables such as baseline threat level, screening detection probability, insider-risk contribution, unpredictability measures, staffing quality, and management-response efficiency. The role of unpredictability is especially relevant because recent qualitative research indicates that European airport stakeholders use variability in controls to complement standard security systems, reduce adversary adaptation, and mitigate insider-threat advantages, though deployment remains insufficiently evaluated in a systematic way. It also includes a workable MATLAB simulation example that can be extended into sensitivity analysis, policy testing, and security performance benchmarking.

Unknown authors · 0 citations
Open access Aug 2026

Comparative Effectiveness of OWASP WSTG and Top Ten in Web Security Audits

This study evaluates the comparative effectiveness of two widely adopted cybersecurity frameworks, the OWASP Top Ten (2021) and the OWASP Web Security Testing Guide (WSTG), in the context of web application security auditing. While the OWASP Top Ten is a standard for risk awareness, it lacks the technical granularity required for comprehensive testing, creating a gap between high-level risk identification and practical verification. To bridge this gap, this study proposes a structured integration through comparative mapping and empirical validation using real-world mitigation data. A procedural analysis combined with granularity evaluation was employed to map the ten OWASP risk categories to 102 technical verification units in the WSTG. The results reveal a 920% increase in testing granularity compared to the baseline Top Ten framework. Empirical validation conducted on a government subdomain (Instansi X) demonstrated that this integrated approach identified critical vulnerabilities, including Broken Access Control and Cryptographic Failures, which are often overlooked in high-level assessments. By implementing specific WSTG-based mitigation procedures, such as middleware authorization and secure communication protocols, identified risks were successfully remediated without disrupting production stability. This study contributes a validated framework that bridges the gap between conceptual risk and actionable technical verification. The findings indicate that while the OWASP Top Ten serves as a strategic reference, the WSTG is superior as a primary technical auditing framework. This integration enhances audit consistency, precision, and efficiency in evaluating modern web environments.

Moch Wahyu Sampurno Utomo, H. Wahanani, Achmad Junaidi · 0 citations
Aug 2026

ARAMIS: A unified and scalable methodology for industrial cyber security risk assessment

The paper details the five-module structure of ARAMIS, its unique multilayered modelling of operational scenarios and its algorithmic approach to calculating security levels target (SL-T), and discusses the implementation of the methodology within the Fence risk management tool to ensure seamless reproducibility and knowledge capitalisation across global project portfolios.

Serge Benoliel, Florence Foudrain · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.