Validating cybersecurity framework: a case study framework for critical information infrastructure protection
Prasetyo Adi Wibowo Putro, Dana Indra Sensuse, M. Baihaqi, Wahyu Setiawan Wibowo · Information and Computer Security · 2025
Purpose This study aims to address the pressing need for robust critical information infrastructure protection frameworks by empirically validating a proposed framework to ensure its effectiveness and applicability in real-world scenarios. Design/methodology/approach This study uses a comprehensive methodology, combining the partial least squares structural equation model (PLS-SEM), focus group discussions (FGD) and content validity index (CVI) measurements to assess the framework’s construct, criterion and content validity. Findings The findings reveal an iterative validation process involving six components, 26 variables and 36 indicators, with five non-contributory indicators being removed. The refined framework aligns with critical information infrastructure requirements, significantly enhancing cybersecurity in smart governance systems. Practical implications This study’s methodological contributions are highlighted by its use of three types of validation, creating a comprehensive approach to addressing cybersecurity challenges. Originality/value A comprehensive methodology, combining the PLS-SEM, FGD and CVI measurements to assess the framework’s construct, criterion and content validity.