Risk-Adaptive Security Authorization for Critical Information Infrastructure: A Remediation-First Framework for Dynamic Target Security Profiles
Security authorization relies on a target security profile that is relatively stable, whereas threats, exposure, control health, and assessment evidence change continuously. We present a two-stage decision-support model that separates operational remediation from structural insufficiency of an already authorized profile. The first stage tests whether an assurance-adjusted authorization-risk index can be restored to tolerance using admissible actions while the profile remains fixed. Only when this problem is infeasible does the second stage generate a minimum-burden candidate profile for assessment and reauthorization. The model defines an authorization envelope, preserves mandatory requirements, distinguishes candidate from authorized states, and treats any structural profile revision as a reauthorization event. In a 365-day synthetic critical-infrastructure benchmark with 100 paired Monte Carlo replicates, the proposed strategy averaged 0.27 days above the benchmark risk tolerance and 1.43 risk-driven profile revisions, compared with 0 days and 9.06 revisions for direct event-driven reoptimization. Matched ablation and sensitivity analyses support the remediation-first boundary while showing that its reduction in structural churn attenuates when attainable remediation quality is weaker; assumed control effectiveness remains the main source of model uncertainty. The results support frequent reassessment but selective, explainable profile revision under explicitly stated remediation and activation assumptions. This study is a computational proof of concept and does not replace legal authorization or empirical cyber-range validation.
Authors
- Volodymyr O. Artemchuk (ORCID: https://orcid.org/0000-0001-8819-4564)
- Сергій Феодосійович Гончар (ORCID: https://orcid.org/0000-0002-9978-8998)
- Oleksandr Potenko (ORCID: https://orcid.org/0009-0009-4067-1267)
- Olena Dzhyhun (ORCID: https://orcid.org/0009-0007-0433-9537)
Institutions
- Pukhov Institute for Modelling in Energy Engineering (UA)
- Palladin Institute of Biochemistry (UA)
Publication Details
- Journal
- Journal of Cybersecurity and Privacy
- Published
- 2026-10-05
- DOI
- https://doi.org/10.3390/jcp6050172
- Primary Topic
- Information and Cyber Security
- Type
- article
- Field-Weighted Citation Impact
- 0.00