This study proposes a maturity model based on the Information and Communication Security Guide (ICSG), which is mandatory for public institutions and critical infrastructure businesses in Türkiye. The study developed a model consisting of 16 parameters to assess institutions' cybersecurity capacities, make their current status visible, and identify areas for improvement. The model considers criteria such as the scope of the guide's implementation, compliance with the Information Security Management System (ISMS), the correlation between asset inventories and countermeasures, the status of compensating controls, and maturity roadmaps. The scores obtained from the parameters are converted into a five-level maturity scale, which can be used to map the institutions' cybersecurity maturity. The proposed model provides a framework that can be used not only for internal institutional assessments but also for shaping nationwide cybersecurity strategies and the effective allocation of resources. This aims to strengthen national cybersecurity resilience by translating abstract security objectives into concrete and measurable steps.
Information and Communication Security Guide (ICSG) Maturity Model Information Security Management System (ISMS) Cyber Security Measurement
This article does not contain any studies involving human or animal subjects. Scientific and ethical principles were adhered to during the preparation of this study, and all referenced studies are listed in the references.
The authors would like to thank Mr. Yusuf Tancan (Vice President), Mr. Osman Turan (Expert), and Dr. Tolga Ozbilge (Expert) from abolished Digital Transformation Office of Türkiye for their valuable comments and implementation efforts on the maturity model proposal. The authors would also like to thank Dr. Ahmet Albayrak from Düzce University for his valuable comments and editorial effort.
This study proposes a maturity model based on the Information and Communication Security Guide (ICSG), which is mandatory for public institutions and critical infrastructure businesses in Türkiye. The study developed a model consisting of 16 parameters to assess institutions' cybersecurity capacities, make their current status visible, and identify areas for improvement. The model considers criteria such as the scope of the guide's implementation, compliance with the Information Security Management System (ISMS), the correlation between asset inventories and countermeasures, the status of compensating controls, and maturity roadmaps. The scores obtained from the parameters are converted into a five-level maturity scale, which can be used to map the institutions' cybersecurity maturity. The proposed model provides a framework that can be used not only for internal institutional assessments but also for shaping nationwide cybersecurity strategies and the effective allocation of resources. This aims to strengthen national cybersecurity resilience by translating abstract security objectives into concrete and measurable steps.
Information and Communication Security Guide (ICSG) Maturity model Information security management system (ISMS) Cyber security measurement
| Birincil Dil | İngilizce |
|---|---|
| Konular | Bilgi Güvenliği Yönetimi |
| Bölüm | Araştırma Makalesi |
| Yazarlar | |
| Gönderilme Tarihi | 23 Eylül 2025 |
| Kabul Tarihi | 13 Kasım 2025 |
| Yayımlanma Tarihi | 16 Aralık 2025 |
| Yayımlandığı Sayı | Yıl 2025 Cilt: 1 Sayı: 2 |