Published June 17, 2026 | Version 1.0

Governance as the Integration Layer: Uniting Enterprise Risk Management and Cybersecurity for the Cloud and IoT Era

  • 1. University of the Cumberlands

Description

Volume 6 of 10 in the Engineering-to-Research Monograph Series. Cybersecurity is still too often run as a technical silo bolted onto an organization rather than woven into how it understands and prices risk, and that separation is the root cause of the most consequential failures: risks that fall between the business and the security team, controls that satisfy an audit but not a threat, and recovery plans that exist only on paper. This report argues that governance is the integration layer that dissolves the silo: the mechanism by which cyber risk becomes enterprise risk and enterprise strategy becomes technical control. It builds the argument in four layers, from the enterprise-risk portfolio view, through governance (the NIST Cybersecurity Framework 2.0 Govern function and NIST IR 8286), down to technical control (a hybrid role-and-attribute access model and Zero Trust) and a governed resilience layer. It contributes a layered governance-to-control reference model and two design principles, and shows the chain holds across cloud and IoT because enforcement is decoupled from infrastructure.
The paper and figures are licensed CC BY 4.0. This work contains no confidential or proprietary employer information.

Files

05_Monograph_6_ERM_and_Cybersecurity_Governance.pdf

Files (466.5 kB)

Name Size Download all
md5:2b797bcf363adf0ba287095fe6219780
169.9 kB Download
md5:c21fa96d640e892a564ef0ef7b17ef8a
296.6 kB Preview Download

Additional details