2026· International journal of advanced engineering and management research· Vol 11, pp. 112-127· 0 citations· 3 references
TL;DR
It is shown that misalignment between compliance and operational security can result in gaps in risk management, reduced system effectiveness, and governance inefficiencies, and practical implications for integrating regulatory requirements into cybersecurity governance frameworks.
Abstract
This research examines the relationship between cybersecurity governance and regulatory
compliance in healthcare organizations, with a focus on policy integration challenges. As
healthcare systems operate under strict regulatory frameworks, including data protection and
privacy requirements, organizations must align cybersecurity practices with compliance
obligations. However, compliance-driven approaches may not fully address operational
cybersecurity risks, particularly in complex and rapidly evolving environments. This study
adopts a conceptual governance analysis, informed by evidence from organizational cases, to
explore how policy frameworks, regulatory requirements, and cybersecurity practices interact.
The findings indicate that misalignment between compliance and operational security can result
in gaps in risk management, reduced system effectiveness, and governance inefficiencies. The
article introduces a policy–governance alignment model and provides practical implications for
integrating regulatory requirements into cybersecurity governance frameworks.
The study concludes that universities require a layered, integrated governance model rather than separate compliance silos, and recommends multidisciplinary oversight, harmonised control catalogues, precise data classification, Zero Trust access, privacy and security by design, recurring impact assessments, supplier accountability, and measurable assurance.
Dominic Feboh, Ayokunle Olamide Ijagbemi, Stanley Nwakamma et al.· International Journal of Mul...· 0 citations
This review synthesizes peer-reviewed literature on governance structures, auditing methods, and resulting outcomes across key sectors including financial services, capital markets, healthcare, and critical infrastructure to reveal consistent emphasis on integrated governance approaches alongside persistent implementation tensions.
William Asare Yirenkyi, Apaflo Godson Teye, Matilda Konotey et al.· Magna Scientia Advanced Rese...· 0 citations
The article examines cybersecurity in public health in the context of the dynamic development of digital technologies and the growing role of health data as a strategic resource. The starting point is the assumption that despite numerous legal regulations, technical standards and guidelines at the national and EU levels, the healthcare system operates in conditions of significant regulatory and organizational fragmentation. The varying levels of digital maturity among healthcare entities, limited financial and human resources and insufficient implementation coordination translate into a fragmented and inconsistent approach to cyber risk management. The article discusses the importance of health data for the innovation and competitiveness of the European Union and identifies key cyber threats in the healthcare sector. The conclusion presents directions for systemic change, pointing to the need for a more integrated regulatory model combining legal, technical and organizational standards with investments in competencies, infrastructure and building institutional resilience.
Agnieszka Jankowska· Discourse of Law and Adminis...· 0 citations
Cybersecurity has moved from a peripheral technical function to a core pillar of organizational governance, driven by the escalating frequency and cost of digital intrusions, tightening disclosure regulation, and growing recognition that technical controls alone cannot guarantee continuity of operations. This narrative integrative review synthesises contemporary academic literature on cybersecurity governance, tracing its evolution from a compliance-oriented, risk-reporting paradigm toward an integrated model of organizational cyber resilience. The review examines governance structures and board oversight arrangements, the integration of cybersecurity into enterprise risk management, the conceptual architecture of organizational cyber resilience, the human and cultural determinants of governance effectiveness, sector-specific and supply-chain vulnerabilities, financial and insurance mechanisms for risk transfer, the regulatory and standards landscape, and approaches to measuring governance maturity. Findings indicate that although disclosure obligations and formal oversight structures have proliferated, substantive board-level expertise remains scarce, enterprise risk management integration is uneven, and resilience-building efforts are frequently undermined by fragmented accountability and inconsistent measurement practices. The review argues that a durable shift from reactive risk reporting to genuine organizational resilience requires coherent alignment across governance structures, cultural investment, supply-chain oversight and outcome-based metrics. Directions for future research and the practical implications of these findings for boards, risk officers and regulators are discussed.
William Asare Yirenkyi, Apaflo Godson Teye, Matilda Konotey et al.· Asian journal of current res...· 0 citations
: As cybersecurity regulations such as ISO/IEC 27001 and the NIS2 Directive continue to expand in scope and complexity, organizations face growing challenges in translating regulatory obligations into actionable security policies and audit-ready evidence. Conventional compliance approaches rely on manual interpretation of regulatory texts, fragmented documentation repositories, and ad hoc audit preparation, introducing operational bottlenecks and exposing organizations to non-compliance risks. This paper presents a compliance management platform that operationalizes regulatory requirements through structured, expert-guided control implementation. It combines NLP extraction with human-supervised annotation to convert regulatory texts into machine-readable frameworks, enabling multi-framework management (ISO/IEC 27001:2022 and NIS2), control mapping, evidence tracking, and role-based audit workflows. In a task-based usability study with twelve participants, the platform scored 83.3 on the System Usability Scale (SUS), rated “excellent,” indicating that embedded guidance can reduce expertise barriers in cybersecurity compliance management.
Mariana Andrade, João Rafael Almeida, J. Oliveira· International Conference on...· 0 citations
Cybersecurity threats pose a growing challenge for organizations in digitally dependent economies, with South African organizations facing increasing incidents of data breaches and ransomware, among other threats. This study investigates how organizations can enhance cybersecurity resilience by aligning data privacy regulations with business resilience strategies. A quantitative survey of 201 professionals across multiple industries in South Africa was conducted, guided by Protection Motivation Theory (PMT), Diffusion of Innovation Theory (DIT), and Resilience Theory. Analysis revealed that while organizations perceive the severity of cyber threats, internal threat perception alone does not drive innovation. Instead, external regulatory and institutional pressures emerged strong driver of cybersecurity innovation, which in turn strengthens cybersecurity resilience. Based on these insights, a Cybersecurity Resilience Model was developed as a defence mechanism against cybersecurity threats and attacks.
Delilah Yevayi Mureriwa, K. Njenga· International Journal of Bus...· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.