
This preprint proposes a governance-oriented framework for defining cybersecurity roles and responsibilities across organizational size, sector (public versus private), and operational criticality. It distinguishes cybersecurity governance functions (e.g., executive accountability, policy direction, and risk ownership) from cybersecurity operational functions (e.g., SOC operations, IAM, vulnerability management, DevSecOps, and incident response). Drawing on cybersecurity governance measurement models, maturity frameworks, and sector-specific governance studies, the paper provides a practical role-structuring approach to improve cyber resilience, regulatory alignment, and accountability. The framework is intended to support executives, policymakers, regulators, and security leaders in designing fit-for-purpose cybersecurity operating models that scale with organizational context.
| selected citations These citations are derived from selected sources. This is an alternative to the "Influence" indicator, which also reflects the overall/total impact of an article in the research community at large, based on the underlying citation network (diachronically). | 0 | |
| popularity This indicator reflects the "current" impact/attention (the "hype") of an article in the research community at large, based on the underlying citation network. | Average | |
| influence This indicator reflects the overall/total impact of an article in the research community at large, based on the underlying citation network (diachronically). | Average | |
| impulse This indicator reflects the initial momentum of an article directly after its publication, based on the underlying citation network. | Average |
