CORTEXA
← Browse
crossrefJournal of Cybersecurity and Privacy2026-07-22Cited by 0

AI-Enhanced Multi-Criteria Decision Support for Cybersecurity Risk Framework Selection: A Machine Learning Comparative Analysis of NIST CSF, ISO 27001, FAIR, OCTAVE and CRAMM

Oluwatosin J. Olaore, Abeer F. Alkhwaldi

As organizations lean more heavily on their IT systems, managing cyber risk is gaining increasing importance. Organizations are often challenged to determine which cybersecurity risk framework they should adopt. Choosing the right framework can have a significant impact on the quality of governance, operational resilience, and assurance in risk reporting. However, most prevalent cybersecurity risk frameworks vary significantly in their intent, design, and analytical approach. This makes it difficult for organizations to understand how each framework may meet their business needs. This study presents an AI-enhanced multi-criteria decision support approach for evaluating cybersecurity risk frameworks. The model incorporates machine learning-driven risk scoring as a conceptual input layer, enhancing the objectivity and analytical rigor of the comparison without executing new predictive algorithms. The methodology includes a hybrid approach of literature review, document analysis, and multi-criteria decision analysis (MCDA) to compare and rank NIST CSF, ISO 27001, FAIR, OCTAVE, and CRAMM based on eight criteria that are designed to represent modern requirements for risk frameworks, including governance, scalability, quantitative focus, and interoperability. These criteria also reflect differences in security metrics supported by each framework to provide an organized means to compare qualitative versus quantitative measurement methodologies. The results indicate that NIST CSF performs the best overall in agility, business alignment, and interoperability. ISO 27001 outperforms all others in established governance and compliance. FAIR outperforms all others in quantitative risk analysis and provides superior analytical depth that other frameworks do not offer. OCTAVE and CRAMM function well in legacy systems but lack scalability and are not well-suited for modern distributed systems. Robustness analysis shows that the ranking of NIST CSF, ISO 27001, and FAIR is consistent under different weighting combinations and industry types. The result of this research demonstrates that a combined or hybrid approach to cybersecurity risk framework selection, such as using NIST CSF with FAIR, can give organizations a more well-rounded foundation for applying machine learning-enabled risk analytics with cyber controls. This research also offers a reusable decision support tool that organizations can leverage when aligning their risk priorities to the features of cybersecurity risk frameworks.

View free PDFSource page

Related papers

crossrefJournal of Cybersecurity and Privacy2025-07-02Cited by 14

A Systematic Review on Hybrid AI Models Integrating Machine Learning and Federated Learning

Jallal-Eddine Moussaoui, Mehdi Kmiti, Khalid El Gholami, Yassine Maleh

Cyber threats are growing in scale and complexity, outpacing the capabilities of traditional security systems. Machine learning (ML) models offer enhanced detection accuracy but often rely on centralized data, raising privacy concerns. Federated learning (FL), by contrast, enable…

View free PDFSource page
crossrefJournal of Cybersecurity and Privacy2026-01-04Cited by 1

A Comprehensive Review: The Evolving Cat-and-Mouse Game in Network Intrusion Detection Systems Leveraging Machine Learning

Qutaiba Alasad, Meaad Ahmed, Shahad Alahmed, Omer T. Khattab, Saba Alaa Abdulwahhab, Jiann-Shuin Yuan

Machine learning (ML) techniques have significantly enhanced decision support systems to render them more accurate, efficient, and faster. ML classifiers in securing networks, on the other hand, face a disproportionate risk from the sophisticated adversarial attacks compared to o…

View free PDFSource page
crossrefJournal of Cybersecurity and Privacy2023-06-13Cited by 30

Deep Learning and Machine Learning, Better Together Than Apart: A Review on Biometrics Mobile Authentication

Sara Kokal, Mounika Vanamala, Rushit Dave

Throughout the past several decades, mobile devices have evolved in capability and popularity at growing rates while improvement in security has fallen behind. As smartphones now hold mass quantities of sensitive information from millions of people around the world, addressing th…

View free PDFSource page
crossrefJournal of Cybersecurity and Privacy2022-12-27Cited by 9

An Investigation to Detect Banking Malware Network Communication Traffic Using Machine Learning Techniques

Mohamed Ali Kazi, Steve Woodhead, Diane Gan

Banking malware are malicious programs that attempt to steal confidential information, such as banking authentication credentials, from users. Zeus is one of the most widespread banking malware variants ever discovered. Since the Zeus source code was leaked, many other variants o…

View free PDFSource page
crossref2026-06-04

AI-Enhanced Multi-Criteria Decision Support for Cybersecurity Risk Framework Selection: A Machine-Learning Comparative Analysis of NIST CSF, ISO 27001, FAIR, OCTAVE and CRAMM

Oluwatosin J. Olaore, Abeer F. Alkhwaldi

As organizations lean more heavily on their IT systems, managing cyber risk is gaining increasing importance. Organizations are often challenged to determine which cybersecurity risk framework they should adopt. Choosing the right framework can have a significant impact on the qu…

Source page