A multi-criteria evaluation of cybersecurity incident management frameworks: integrating AHP, CMMI and SWOT
| dc.authorid | 0009-0005-4549-3376 | |
| dc.authorid | 0000-0003-2865-6370 | |
| dc.contributor.author | Ağar, Hasan Çağlar | en_US |
| dc.contributor.author | Çeliktaş, Barış | en_US |
| dc.date.accessioned | 2026-03-03T07:06:47Z | |
| dc.date.available | 2026-03-03T07:06:47Z | |
| dc.date.issued | 2026-01-15 | |
| dc.department | Işık Üniversitesi, Lisansüstü Eğitim Enstitüsü, Bilgisayar Mühendisliği Yüksek Lisans Programı | en_US |
| dc.department | Işık University, School of Graduate Studies, Master’s Program in Computer Engineering | en_US |
| dc.department | Işık Üniversitesi, Mühendislik ve Doğa Bilimleri Fakültesi, Bilgisayar Mühendisliği Bölümü | en_US |
| dc.department | Işık University, Faculty of Engineering and Natural Sciences, Department of Computer Engineering | en_US |
| dc.description.abstract | With the growing complexity and frequency of cybersecurity incidents, the selection of an appropriate incident management framework has emerged as a strategic imperative and a nontrivial decision-making problem for organizations operating across diverse sectors. This study presents a multi-dimensional evaluation of four globally recognized frameworks and standards—ISO 27035, NIST 800-61, ITIL v4, and PCI DSS—to determine their effectiveness across 10 rigorously selected key performance parameters. The initial stage of the study involved the identification of 20 preliminary parameters through expert input and literature synthesis. These were then evaluated by 70 cybersecurity professionals using a hybrid decision-making model combining Likert scale scoring, standard deviation filtering, CV score, Z-score normalization and the Analytic Hierarchy Process (AHP) for pairwise comparisons. The top 10 key parameters were derived based on calculated priority weights. To assess each framework, we applied the Capability Maturity Model Integration (CMMI) and visualized results via radar charts and heatmaps, offering comparative insights into operational maturity. Additionally, SWOT analysis was conducted to examine strategic positioning and identify opportunities for improvement. The outcomes not only provide a practical benchmarking guide for practitioners but also introduce a replicable, evidence-based methodology for academic and industry adoption. This work offers a novel and structured lens to evaluate incident management maturity, addressing the pressing need for strategic alignment, automation integration, and adaptive resilience in cybersecurity operations. | en_US |
| dc.description.version | Publisher's Version | en_US |
| dc.identifier.citation | Ağar, H. Ç. & Çeliktaş, B. (2026). A Multi-Criteria Evaluation of Cybersecurity Incident Management Frameworks: Integrating AHP, CMMI and SWOT. Black Sea Journal of Engineering and Science, 9(1), 158-179. https://doi.org/10.34248/bsengineering.1729927 | en_US |
| dc.identifier.endpage | 176 | |
| dc.identifier.issn | 2619-8991 | |
| dc.identifier.issue | 1 | |
| dc.identifier.startpage | 158 | |
| dc.identifier.uri | https://hdl.handle.net/11729/7088 | |
| dc.identifier.uri | https://doi.org/10.34248/bsengineering.1729927 | |
| dc.identifier.volume | 9 | |
| dc.institutionauthor | Ağar, Hasan Çağlar | en_US |
| dc.institutionauthor | Çeliktaş, Barış | en_US |
| dc.institutionauthorid | 0009-0005-4549-3376 | |
| dc.institutionauthorid | 0000-0003-2865-6370 | |
| dc.language.iso | en | en_US |
| dc.peerreviewed | Yes | en_US |
| dc.publicationstatus | Published | en_US |
| dc.publisher | Karyay Karadeniz Yayımcılık Ve Organizasyon Ticaret Limited Şirketi | en_US |
| dc.relation.ispartof | Black Sea Journal of Engineering and Science | en_US |
| dc.relation.publicationcategory | Makale - Ulusal Hakemli Dergi - Öğrenci | en_US |
| dc.relation.publicationcategory | Makale - Ulusal Hakemli Dergi - Kurum Öğretim Elemanı | en_US |
| dc.rights | info:eu-repo/semantics/openAccess | en_US |
| dc.subject | Incident management | en_US |
| dc.subject | Framework comparison | en_US |
| dc.subject | Evaluation criteria | en_US |
| dc.subject | Maturity model | en_US |
| dc.subject | Analytic hierarchy process | en_US |
| dc.subject | SWOT analysis | en_US |
| dc.title | A multi-criteria evaluation of cybersecurity incident management frameworks: integrating AHP, CMMI and SWOT | en_US |
| dc.type | Article | en_US |
| dspace.entity.type | Publication | en_US |
Dosyalar
Orijinal paket
1 - 1 / 1
Yükleniyor...
- İsim:
- A_Multi_Criteria_Evaluation_of_Cybersecurity_Incident_Management_Frameworks_Integrating_AHP_CMMI_and_SWOT.pdf
- Boyut:
- 853.75 KB
- Biçim:
- Adobe Portable Document Format
Lisans paketi
1 - 1 / 1
Küçük Resim Yok
- İsim:
- license.txt
- Boyut:
- 1.17 KB
- Biçim:
- Item-specific license agreed upon to submission
- Açıklama:












