Comparative Analysis of Small and Medium-Sized Enterprises Cybersecurity Program Assessment Model
Wan Nur Eliana Wan Mohd Ludin, Masnizah Mohd, Wan Fariza Paizi Fauzi · International Journal of Advanced Computer Science and Applications · 2024
In the digital age, Small and Medium-sized Enterprises must review and improve their cybersecurity posture to combat rising risks. This paper thoroughly compares Small and Medium-sized Enterprises cybersecurity program assessment approaches. The National Institute of Standards and Technology's Cybersecurity Framework, CyberSecurity Readiness Model for SMEs, Cybersecurity Evaluation Model, and Adaptable Security Maturity Assessment and Standardisation framework were examined. The NIST CSF is adaptable and applicable to many sectors, while the CSRM provides a standardized way to assess an organization's cyber readiness. With its resource limits and operational scales, the CSRM-SME meets SMEs' particular issues. Organizations may examine and improve cybersecurity with CSEM. The approach can be used for SMEs, higher education institutions, and industrial control systems. The ASMAS architecture is flexible for continual security enhancement due to its scalability and standardization. This comparison analysis shows each framework's strengths and weaknesses, revealing their suitability for diverse SME scenarios. This paper helps SMEs choose the best model to strengthen cybersecurity, boost resilience, and meet global standards. This paper will compare the NIST CSF, CSRM-SME, CSEM, and ASMAS cybersecurity frameworks.