Araştırma Makalesi

A Multi-Criteria Evaluation of Cybersecurity Incident Management Frameworks: Integrating AHP, CMMI and SWOT

Cilt: 9 Sayı: 1 15 Ocak 2026
PDF İndir
EN TR

A Multi-Criteria Evaluation of Cybersecurity Incident Management Frameworks: Integrating AHP, CMMI and SWOT

Öz

With the growing complexity and frequency of cybersecurity incidents, the selection of an appropriate incident management framework has emerged as a strategic imperative and a nontrivial decision-making problem for organizations operating across diverse sectors. This study presents a multi-dimensional evaluation of four globally recognized frameworks and standards—ISO 27035, NIST 800-61, ITIL v4, and PCI DSS—to determine their effectiveness across 10 rigorously selected key performance parameters. The initial stage of the study involved the identification of 20 preliminary parameters through expert input and literature synthesis. These were then evaluated by 70 cybersecurity professionals using a hybrid decision-making model combining Likert scale scoring, standard deviation filtering, CV score, Z-score normalization and the Analytic Hierarchy Process (AHP) for pairwise comparisons. The top 10 key parameters were derived based on calculated priority weights. To assess each framework, we applied the Capability Maturity Model Integration (CMMI) and visualized results via radar charts and heatmaps, offering comparative insights into operational maturity. Additionally, SWOT analysis was conducted to examine strategic positioning and identify opportunities for improvement. The outcomes not only provide a practical benchmarking guide for practitioners but also introduce a replicable, evidence-based methodology for academic and industry adoption. This work offers a novel and structured lens to evaluate incident management maturity, addressing the pressing need for strategic alignment, automation integration, and adaptive resilience in cybersecurity operations.

Anahtar Kelimeler

Etik Beyan

Ethics committee approval was not required for this study because of there was no study on animals or humans.

Kaynakça

  1. Abid, M., Nanda, P., & Mohanty, M. (2024). Incident Response Adaptive Metrics Framework. 17th International Conference on Security Information Networking (SIN), Sydney, Australia, 1–8.
  2. Aguiar, J., Pereira, R., Vasconcelos, J. B., & Bianchi, I. (2018). An overlapless incident management maturity model for multi-framework assessment (ITIL, COBIT, CMMI-SVC). Interdisciplinary Journal of Information, Knowledge, and Management, 13, 137–163.
  3. Agutter, C. (2020). ITIL Foundation Essentials ITIL 4 Edition: The ultimate revision guide. IT Governance Publishing Ltd.
  4. Agyepong, E., & Onwubiko, C. (2025). An Exemplar Incident Response Plan for Security Operations Centre Analysts. In M. G. Jaatun et al. (Eds.), Proceedings of the International Conference on Cybersecurity Situational Awareness, Social Media and Cyber Science Proceedings of Complex. Springer, Singapore.
  5. Ahmad, A., Desouza, K. C., Maynard, S. B., Naseer, H., & Baskerville, R. L. (2020). How integration of cyber security management and incident response enables organizational learning. Journal of the Association for Information Science and Technology, 71(8), 939–953.
  6. Ak, M. F., & Gul, M. (2019). AHP–TOPSIS integration extended with Pythagorean fuzzy sets for information security risk analysis. Complex & Intelligent Systems, 5(2), 113–126.
  7. Alevizos, L. (2025). Automated cybersecurity compliance and threat response using AI, blockchain and smart contracts. International Journal of Information Technology, 17, 767–781.
  8. AlHogail, A. (2015). Design and validation of information security culture framework. Computers in Human Behavior, 49, 567–575.

Ayrıntılar

Birincil Dil

İngilizce

Konular

Bilgi Güvenliği Yönetimi, Bilgi Sistemleri (Diğer)

Bölüm

Araştırma Makalesi

Erken Görünüm Tarihi

4 Aralık 2025

Yayımlanma Tarihi

15 Ocak 2026

Gönderilme Tarihi

30 Haziran 2025

Kabul Tarihi

22 Kasım 2025

Yayımlandığı Sayı

Yıl 2026 Cilt: 9 Sayı: 1

Kaynak Göster

APA
Ağar, H. Ç., & Celiktas, B. (2026). A Multi-Criteria Evaluation of Cybersecurity Incident Management Frameworks: Integrating AHP, CMMI and SWOT. Black Sea Journal of Engineering and Science, 9(1), 158-179. https://doi.org/10.34248/bsengineering.1729927
AMA
1.Ağar HÇ, Celiktas B. A Multi-Criteria Evaluation of Cybersecurity Incident Management Frameworks: Integrating AHP, CMMI and SWOT. BSJ Eng. Sci. 2026;9(1):158-179. doi:10.34248/bsengineering.1729927
Chicago
Ağar, Hasan Çağlar, ve Baris Celiktas. 2026. “A Multi-Criteria Evaluation of Cybersecurity Incident Management Frameworks: Integrating AHP, CMMI and SWOT”. Black Sea Journal of Engineering and Science 9 (1): 158-79. https://doi.org/10.34248/bsengineering.1729927.
EndNote
Ağar HÇ, Celiktas B (01 Ocak 2026) A Multi-Criteria Evaluation of Cybersecurity Incident Management Frameworks: Integrating AHP, CMMI and SWOT. Black Sea Journal of Engineering and Science 9 1 158–179.
IEEE
[1]H. Ç. Ağar ve B. Celiktas, “A Multi-Criteria Evaluation of Cybersecurity Incident Management Frameworks: Integrating AHP, CMMI and SWOT”, BSJ Eng. Sci., c. 9, sy 1, ss. 158–179, Oca. 2026, doi: 10.34248/bsengineering.1729927.
ISNAD
Ağar, Hasan Çağlar - Celiktas, Baris. “A Multi-Criteria Evaluation of Cybersecurity Incident Management Frameworks: Integrating AHP, CMMI and SWOT”. Black Sea Journal of Engineering and Science 9/1 (01 Ocak 2026): 158-179. https://doi.org/10.34248/bsengineering.1729927.
JAMA
1.Ağar HÇ, Celiktas B. A Multi-Criteria Evaluation of Cybersecurity Incident Management Frameworks: Integrating AHP, CMMI and SWOT. BSJ Eng. Sci. 2026;9:158–179.
MLA
Ağar, Hasan Çağlar, ve Baris Celiktas. “A Multi-Criteria Evaluation of Cybersecurity Incident Management Frameworks: Integrating AHP, CMMI and SWOT”. Black Sea Journal of Engineering and Science, c. 9, sy 1, Ocak 2026, ss. 158-79, doi:10.34248/bsengineering.1729927.
Vancouver
1.Hasan Çağlar Ağar, Baris Celiktas. A Multi-Criteria Evaluation of Cybersecurity Incident Management Frameworks: Integrating AHP, CMMI and SWOT. BSJ Eng. Sci. 01 Ocak 2026;9(1):158-79. doi:10.34248/bsengineering.1729927

                           24890