Risk-Adaptive Security Authorization for Critical Information Infrastructure: A Remediation-First Framework for Dynamic Target Security Profiles

Security authorization relies on a target security profile that is relatively stable, whereas threats, exposure, control health, and assessment evidence change continuously. We present a two-stage decision-support model that separates operational remediation from structural insufficiency of an already authorized profile. The first stage tests whether an assurance-adjusted authorization-risk index can be restored to tolerance using admissible actions while the profile remains fixed. Only when this problem is infeasible does the second stage generate a minimum-burden candidate profile for assessment and reauthorization. The model defines an authorization envelope, preserves mandatory requirements, distinguishes candidate from authorized states, and treats any structural profile revision as a reauthorization event. In a 365-day synthetic critical-infrastructure benchmark with 100 paired Monte Carlo replicates, the proposed strategy averaged 0.27 days above the benchmark risk tolerance and 1.43 risk-driven profile revisions, compared with 0 days and 9.06 revisions for direct event-driven reoptimization. Matched ablation and sensitivity analyses support the remediation-first boundary while showing that its reduction in structural churn attenuates when attainable remediation quality is weaker; assumed control effectiveness remains the main source of model uncertainty. The results support frequent reassessment but selective, explainable profile revision under explicitly stated remediation and activation assumptions. This study is a computational proof of concept and does not replace legal authorization or empirical cyber-range validation.

Authors

Institutions

Publication Details

Journal
Journal of Cybersecurity and Privacy
Published
2026-10-05
DOI
https://doi.org/10.3390/jcp6050172
Primary Topic
Information and Cyber Security
Type
article
Field-Weighted Citation Impact
0.00
Controls
|||
ALL TIME
JAN
FEB
MAR
APR
MAY
JUN
JUL
AUG
SEP
OCT
article

Risk-Adaptive Security Authorization for Critical Information Infrastructure: A Remediation-First Framework for Dynamic Target Security Profiles

Volodymyr O. Artemchuk, Сергій Феодосійович Гончар, Oleksandr Potenko, Olena Dzhyhun
Journal of Cybersecurity and Privacy
Information and Cyber Security
article

Risk-Adaptive Security Authorization for Critical Information Infrastructure: A Remediation-First Framework for Dynamic Target Security Profiles

Volodymyr O. Artemchuk, Сергій Феодосійович Гончар, Oleksandr Potenko, Olena Dzhyhun
article en

Abstract

Security authorization relies on a target security profile that is relatively stable, whereas threats, exposure, control health, and assessment evidence change continuously. We present a two-stage decision-support model that separates operational remediation from structural insufficiency of an already authorized profile. The first stage tests whether an assurance-adjusted authorization-risk index can be restored to tolerance using admissible actions while the profile remains fixed. Only when this problem is infeasible does the second stage generate a minimum-burden candidate profile for assessment and reauthorization. The model defines an authorization envelope, preserves mandatory requirements, distinguishes candidate from authorized states, and treats any structural profile revision as a reauthorization event. In a 365-day synthetic critical-infrastructure benchmark with 100 paired Monte Carlo replicates, the proposed strategy averaged 0.27 days above the benchmark risk tolerance and 1.43 risk-driven profile revisions, compared with 0 days and 9.06 revisions for direct event-driven reoptimization. Matched ablation and sensitivity analyses support the remediation-first boundary while showing that its reduction in structural churn attenuates when attainable remediation quality is weaker; assumed control effectiveness remains the main source of model uncertainty. The results support frequent reassessment but selective, explainable profile revision under explicitly stated remediation and activation assumptions. This study is a computational proof of concept and does not replace legal authorization or empirical cyber-range validation.

Journal of Cybersecurity and PrivacyVol. 6(5)
Pukhov Institute for Modelling in Energy Engineering (UA), Palladin Institute of Biochemistry (UA)
Openalex Percentile: Top 5%
Information and Cyber Security
AI Navigator

Ask Laika to Summarize, Analyze, and Connect papers live on the map.

Summarize Papers & Methodologies

Extract key findings, datasets, and comparative methods across publications.

Benchmark Rankings & Visual Analytics

Rank top research institutions, authors, funders, topics, and journals by Field-Weighted Citation Impact (FWCI) and paper volume with instant charts.

Connect Distant Disciplines

Bridge topological clusters on the map to find hidden collaborative intersections.