Compliance and Internal Controls: Standards and Practices in Cyber Security Governance
preprint
OA: closed
CC-BY-4.0
Abstract
Abstract Organizations increasingly confront challenges such as regulatory non-compliance, fragmented control mechanisms, and inconsistent monitoring processes. This systematic literature review evaluates the role of structured compliance standards and internal control frameworks in strengthening cybersecurity governance, audit readiness, and organizational resilience. Following a comprehensive search across Google Scholar, Web of Science, and Scopus, eighty (n = 80) studies published between 2015 and 2025 were identified and analyzed through a structured screening and synthesis process. The review reveals that ISO 27001 (25%) and COBIT (24%) remain the most frequently adopted governance frameworks, while GDPR (11%) and HIPAA (6%) exert substantial influence in European and healthcare contexts. Evidence indicates a growing shift toward automated compliance monitoring, dashboard-based audit management, and cloud-integrated GRC systems, reflecting a convergence of governance, risk, and compliance technologies. Sectoral analysis shows dominance in finance (21.25%), government (18.75%), and corporate–government collaborations (17.5%), with limited yet emerging research in healthcare (6.25%), ICT (7.5%), and SMEs (5%). Despite methodological progress, 61% of studies lacked detailed reporting on implementation models, revealing persistent gaps in transparency, resource adequacy, and sectoral applicability. The findings underscore that structured adoption of international standards enhances risk mitigation, decision efficiency, and regulatory alignment, but implementation barriers—such as system complexity, skill deficits, and limited empirical validation—remain. The review recommends prioritizing leadership capacity-building, evidence-based performance metrics, and cross-sector collaboration to enable adaptive, data-driven governance systems. Future research should expand empirical validation across underrepresented sectors to reinforce evidence-based policy and practical cybersecurity governance design.
Full text
286,292 characters
· extracted from
preprint-html
· click to expand
Compliance and Internal Controls: Standards and Practices in Cyber Security Governance | Research Square window.SnipcartSettings = { analytics: { enabled: false } }; (function() { var accessVector = localStorage.getItem('access_vector') || ''; window.dataLayer = window.dataLayer || []; if (accessVector) { window.dataLayer.push({ user: { profile: { profileInfo: { snid: accessVector } } } }); } })(); (function(w,d,s,l,i){w[l]=w[l]||[];w[l].push({'gtm.start':new Date().getTime(),event:'gtm.js'});var f=d.getElementsByTagName(s)[0],j=d.createElement(s),dl=l!='dataLayer'?'&l='+l:'';j.async=true;j.src='https://www.googletagmanager.com/gtm.js?id='+i+dl;f.parentNode.insertBefore(j,f);})(window,document,'script','dataLayer','GTM-K279D39R'); Browse Preprints In Review Journals COVID-19 Preprints AJE Video Bytes Research Tools Research Promotion AJE Professional Editing AJE Rubriq About Preprint Platform In Review Editorial Policies Our Team Advisory Board Help Center Sign In Submit a Preprint Cite Share Download PDF Systematic Review Compliance and Internal Controls: Standards and Practices in Cyber Security Governance Wandile Moeti, Sibusiso Moyo, Asavela Kanzi This is a preprint; it has not been peer reviewed by a journal. https://doi.org/ 10.21203/rs.3.rs-7817804/v1 This work is licensed under a CC BY 4.0 License Status: Posted Version 1 posted You are reading this latest preprint version Abstract Organizations increasingly confront challenges such as regulatory non-compliance, fragmented control mechanisms, and inconsistent monitoring processes. This systematic literature review evaluates the role of structured compliance standards and internal control frameworks in strengthening cybersecurity governance, audit readiness, and organizational resilience. Following a comprehensive search across Google Scholar, Web of Science, and Scopus, eighty (n = 80) studies published between 2015 and 2025 were identified and analyzed through a structured screening and synthesis process. The review reveals that ISO 27001 (25%) and COBIT (24%) remain the most frequently adopted governance frameworks, while GDPR (11%) and HIPAA (6%) exert substantial influence in European and healthcare contexts. Evidence indicates a growing shift toward automated compliance monitoring, dashboard-based audit management, and cloud-integrated GRC systems, reflecting a convergence of governance, risk, and compliance technologies. Sectoral analysis shows dominance in finance (21.25%), government (18.75%), and corporate–government collaborations (17.5%), with limited yet emerging research in healthcare (6.25%), ICT (7.5%), and SMEs (5%). Despite methodological progress, 61% of studies lacked detailed reporting on implementation models, revealing persistent gaps in transparency, resource adequacy, and sectoral applicability. The findings underscore that structured adoption of international standards enhances risk mitigation, decision efficiency, and regulatory alignment, but implementation barriers—such as system complexity, skill deficits, and limited empirical validation—remain. The review recommends prioritizing leadership capacity-building, evidence-based performance metrics, and cross-sector collaboration to enable adaptive, data-driven governance systems. Future research should expand empirical validation across underrepresented sectors to reinforce evidence-based policy and practical cybersecurity governance design. Other Business cybersecurity governance compliance standards internal controls ISO 27001 COBIT GDPR audit readiness risk mitigation cloud-based GRC IT governance organizational resilience regulatory compliance Figures Figure 1 Figure 2 Figure 3 Figure 4 Figure 5 Figure 6 Figure 7 Figure 8 Figure 9 Figure 10 Figure 11 Figure 12 Figure 13 Figure 14 Figure 15 Figure 16 Introduction In today’s rapidly evolving digital landscape, the adoption of compliance standards and internal control mechanisms has transformed how cybersecurity governance is designed and implemented. These mechanisms are now foundational to resilience against cyber threats through oversight, risk management, and accountability (Edwards & Weaver, 2024; Maleh et al., 2021 ). Research shows that adherence to frameworks such as ISO 27001, NIST CSF, COBIT, and data-protection regulations (e.g., GDPR) strengthens governance, optimizes security strategy, and improves risk mitigation across organization sizes and sectors (Gordon et al., 2020 ; Kamara, 2024 ; Yusif & Hafeez-Baig, 2021 ). At the same time, organizations face rising pressures from proliferating and sometimes conflicting regulatory requirements, complex digital ecosystems, and the need to balance compliance with operational efficiency (Proudfoot et al., 2024 ; Wilkin & Chenhall, 2020 ). Robust compliance structures and internal controls—spanning policy, assurance, and technical safeguards—enhance transparency, reduce vulnerabilities, and promote accountability throughout the governance lifecycle (Davis, 2021 ; Papazafeiropoulou & Spanaki, 2016 ; von Solms & von Solms, 2018 ). Globalization of threats and rapid technological change amplify governance complexity and underscore the value of structured practices, including cloud-oriented governance and continuous verification, to maintain competitive advantage and resilience (Al-Hashimi et al., 2018 ; Bicaku et al., 2020 ). Yet cost and implementation burdens—together with limited in-house expertise—remain significant barriers, particularly for resource-constrained organizations (Backman & Stevens, 2024 ; Hartmann & Carmenate, 2021 ). Recent work highlights practical levers for stronger outcomes: cultivating security culture and awareness, integrating audit and assurance into governance, and aligning board oversight with IT risk (Alshaikh, 2020 ; Antunes et al., 2022 ; Zimmermann & Renaud, 2019 ). Sectoral and regional studies from the EU and beyond further show how standardization efforts and regulatory trajectories shape feasible governance designs (Kamara, 2024 ; Savaş & Karataş, 2022 ). Moreover, crisis contexts and the push toward automation (e.g., SOAR-supported controls) have spotlighted maturity models, continuous auditing, and risk-based control mechanisms as enablers of adaptive governance (Melaku, 2023 ; Waelchli & Walter, 2025 ). Table 1 Summary of Key Studies on Cybersecurity Compliance, Governance, and Internal Controls Ref. Contribution Pros Cons Edwards & Weaver (2024) Investigated cybersecurity governance, risk management, and compliance (GRC), integrating practices to safeguard data and assets. Provides a holistic GRC perspective; cross-industry applicability; useful for professionals, executives, regulators. Conceptual and practice-oriented; based on literature synthesis and professional insights. Davis ( 2021 ) Advocated stratified technological and non-technological controls; applied normative decision theory to auditing and linked governance practices to standards. Provides structured approach for cybersecurity auditing; useful for compliance and internal control re-search. Focused on methodological application of normative decision theory; may be complex for beginners. Maleh et al. ( 2021 ) Explored IT governance and information security, including standards and frameworks (ITIL, ISO, COBIT), cloud and agile IT governance, and maturity frameworks. Optimizes IT assets; proactive governance reduces risks; integrates IT service management and cloud computing; international case studies. Conceptual framework with case studies and literature synthesis; limited empirical validation. Kohnke et al. (2016) Analyzed ICT governance, risk management, internal controls, and best practice frameworks for practical implementation. Structured knowledge for control frameworks; positions ICT as strategic governance issue; emphasizes standards-based control infrastructure. Conceptual and standards-based; relies on global breach statistics; may lack localized applicability. Schreider & Noakes-Fry (2017) Provided step-by-step guidance for building comprehensive cybersecurity programs; integrated ISO 27001 framework with industry experience. Practitioner-focused; emphasizes gap analysis, policy alignment, multi-year roadmap; applicable for compliance and internal controls. Conceptual and practice-oriented; may not cover all industry-specific nuances. Savaş & Karataş ( 2022 ) Reviewed global cybersecurity governance studies; high-lighted necessity of cyber governance and absence of unified frameworks. Shows research gaps; reviews last 5 years; relevant for compliance and internal control frameworks. Descriptive research; limited to documentary analysis; lacks primary data. Yusif & Hafeez-Baig ( 2021 ) Developed a conceptual model for cybersecurity governance addressing strategy, standardized processes, compliance, leadership, and resources. Provides governance-focused framework aligning compliance and internal controls with organizational strategy. Conceptual model; re-quires further empirical validation. Zukis ( 2016 ) Emphasized board-level IT oversight; aligned IT governance with enterprise risk management; highlighted directors’ demand for IT strategy focus. Relevant for linking cybersecurity governance to board-level oversight, strategic planning, and compliance. Conceptual discussion; limited empirical evidence; industry-specific focus. Heim,T. (2023) The study explores global cybersecurity governance, showing fragmented regulation and suggesting “unity in diversity” and “rich coherence” as pathways for coordination. It highlights coherence in critical infrastructure and cybercrime, introduces guiding concepts for policymakers, and adds value to compliance and governance studies. The research is mostly exploratory, offers limited practical solutions, has a broad global scope that misses regional detail, and leans more on theory than implementation. Weber,R. (2023) Explored global cybersecurity governance, regulation, multi-actor coordination, data protection, critical infrastructure, and cybercrime. Provides insights into multi-level regulatory coordination; highlights “unity in diversity” concept. Exploratory and descriptive; may not generalize across all countries or sectors. The data presented in Table 1 demonstrates important missing information within current research. Multiple reviews examine the utilization of compliance frameworks in cybersecurity governance, yet they usually concentrate on high-level models or generalized governance strategies that omit specific implementations for internal control systems. Research on integrated GRC (Governance, Risk, and Compliance) platforms has received detailed attention in recent publications but fails to combine technical standards such as ISO 27001, COBIT, and ITIL in a unified operational context. Most literature reviews about cybersecurity governance examine either established regulatory protocols or conceptual models without sufficient discussion about their integration with organizational infrastructure and control mechanisms. The analysed studies fail to conduct comprehensive examinations regarding the implementation of lightweight, scalable compliance strategies on constrained enterprise systems in real-world applications. Research on the combination between real-time monitoring and embedded control for cybersecurity enforcement along with governance deployment has received limited interest. The present deficiency creates a major obstacle for developing workable and cost-effective compliance solutions, which are especially critical in sectors with limited regulatory maturity or infrastructure. The research suffers from insufficient evaluation methods that compare framework effectiveness and organizational adaptability, as well as inadequate case examples across different industries and scales. The review bridges this specific gap through integration of results showing compliance model applications within cybersecurity governance environments. 1.1 Research questions RQ1a: Among studies using ISO 27001 and/or COBIT, what outcomes are most frequently reported (audit pass rates, control maturity, incident reduction)? RQ2a: Do studies describing integrated GRC dashboards report stronger assurance than those using single-framework compliance? RQ3a: How do finance/government compare with SMEs/ICT/healthcare in realized benefits and barriers? RQ4a: What is the reported mix of cloud/on-prem/hybrid and how does it align with sector and geography? RQ5a: Which control categories co-occur with positive outcomes (combining policy/regulatory with technical/security and oversight)? RQ6a: Which methods (audits, surveys, KPIs, simulations) underpin claims, and where are validation/longitudinal gaps? RQ7a: What regional emphases (GDPR-led Europe, finance-heavy North America, capacity-building APAC/Africa) are evident? 1.2 Rationale Organizations increasingly rely on structured standards and internal controls to manage cyber risk and meet regulatory obligations. Yet the evidence base is fragmented across frameworks, sectors, and regions. By reviewing 2015–2025 literature and classifying it into three research periods (Early, Middle, Recent), geographies, document types, indexing sources, framework families, governance models, tools/methods, control types, sectors, challenges, and recommendations, we provide a consolidated, decision-oriented picture of what works, where, and why. 1.3 Objectives Map the landscape of standards and frameworks (ISO 27001, COBIT, NIST CSF, GDPR/HIPAA, etc.) and quantify their prevalence. Classify governance models (integrated GRC, policy integration, control & assurance, risk, strategic/board-level, operational, human/awareness, incident, specialized) and estimate their share. Inventory tools and methods (empirical audits/surveys; maturity/KPIs; quantitative/simulation; threat modeling) and assess evidence strength. Profile controls implemented (policy/regulatory; oversight & assurance; technical/security; compliance/financial; risk; performance; operational; human/cultural; context-specific). Examine sectoral and regional patterns in adoption, outcomes, and challenges. Synthesize challenges and recommendations into actionable guidance for practitioners and policymakers. Highlight reporting gaps (deployment mode, longitudinal impact) and propose a minimal reporting schema. 1.5 Research contributions Evidence-based taxonomy & quantification. We deliver a harmonized coding of frameworks, models, tools, controls, sectors, and regions, with percent shares visualized in Figs. 6 – 16 (governance/risk frameworks 37.5%; international standards 28.75%; regulatory/legal 26.25%). Integrated GRC perspective. We link framework families → governance models → control portfolios → outcomes, showing where integration is reported to add value. Sectoral & regional insights. We contrast finance/government dominance with under-studied SMEs/industrial contexts and highlight regional clusters. Challenge–recommendation map. We align the top challenges (regulatory complexity, resource limits, integration issues) with the most cited remedies (framework/policy harmonization, leadership & governance enhancement, technology & automation, risk intelligence). Reporting checklist. We propose a concise schema (frameworks used; control categories; deployment mode; measurement approach; sector/region) to improve comparability and replication. 1.6 Research novelty First end-to-end crosswalk (to our knowledge) that connects standards/frameworks to governance models, control portfolios, methods, sectors/regions, challenges, and recommendations—and quantifies each. Temporal periodization of the field (2016–2018, 2019–2021, 2022–2025) showing the shift from conceptualization to empirical assessment and automation-driven governance. Deployment-mode gap spotlight. We document substantial non-reporting of implementation approach and call for explicit mode disclosure (cloud/on-prem/hybrid) given its compliance and risk implications. Practitioner-ready guidance. Our challenge→recommendation mapping translates literature patterns into actionable steps for boards, CISOs, and regulators. Materials and Methods 2. Materials and Methods This review synthesizes research on cybersecurity compliance standards and internal control practices published between 2015 and 2025 across Scopus, Web of Science, and Google Scholar. We focused on empirical and conceptual work that examines governance frameworks (e.g., ISO/IEC 27001, COBIT, NIST CSF, GDPR) and their operationalization through controls, audits, and GRC processes in organizational settings. Our approach follows established information-systems review practices used in governance and cybersecurity syntheses—emphasizing transparent search strings, multi-database retrieval, and structured screening to ensure coverage and replicability (e.g., Papazafeiropoulou & Spanaki, 2016 ; Wilkin & Chenhall, 2020 ; Savaş & Karataş, 2022 ; Edwards & Weaver, 2024; Davis, 2021 ; Maleh et al., 2021 ; Zwilling, 2022 ). To broaden sectoral coverage and capture gray or pre-publication scholarship (theses, conference proceedings), we included multidisciplinary indexing via Google Scholar, consistent with recent governance and cybersecurity mappings (Proudfoot et al., 2024 ; Hossain et al., 2024 ). Screening, extraction, and categorization were carried out using a standardized template informed by prior auditing and governance frameworks and toolsets (Antunes et al., 2022 ; Plant et al., 2022 ; Gordon et al., 2020 ; Yusif & Hafeez-Baig, 2021 ). 2.1. Eligibility criteria The review included only peer-reviewed and English-language studies published between 2015 and 2025. Eligible studies were required to engage substantively with cybersecurity governance, compliance frameworks, or internal control mechanisms, demonstrating methodological clarity and a direct contribution to organizational security performance (Melaku, 2023 ; Hartmann & Carmenate, 2021 ; Nicho, 2018 ). Research lacking empirical grounding, clear methodological design, or identifiable governance models was excluded. To ensure conceptual consistency, definitions of frameworks and control categories were harmonized using authoritative sources that describe the relationships among COBIT, COSO, and ISO standards (Davis, 2021 ; Maleh et al., 2021 ). The selection process consisted of three stages: initial retrieval, abstract screening, and full-text evaluation. Duplicates were removed, and studies were classified by framework type, sectoral focus, methodological design, and geographical scope. Sectoral mapping followed established categorization approaches used in recent cybersecurity and compliance analyses (Ferreira et al., 2025 ; Ashley & Preiksaitis, 2022 ; Backman & Stevens, 2024 ). In line with the integrative approaches recommended by Wilkin and Chenhall ( 2020 ) and Papazafeiropoulou and Spanaki ( 2016 ), both conceptual and applied studies were included to capture the full spectrum of governance and control research. This methodological approach ensured a balanced inclusion of both theoretical and practice-oriented studies, yielding a coherent synthesis of cybersecurity governance literature that reflects diverse industries, organizational contexts, and regional practices. The final inclusion and exclusion parameters are summarized in Table 2 . Table 2 Proposed Inclusion and Exclusion Criteria Criteria Inclusion Exclusion Topic Article papers focusing on Compliance and Internal Controls: A Systematic Review of Standards and Practices in Cyber Security Governance Article papers not focusing on Compliance and Internal Controls: A Systematic Review of Standards and Practices in Cyber Security Governance Research Framework The Articles must include research framework or methodology for Compliance and Internal Controls: A Systematic Review of Standards and Practices in Cyber Security Governance Articles must exclude research framework or methodology for Compliance and Internal Controls: A Systematic Review of Standards and Practices in Cyber Security Governance Language Must be written in English Articles published in languages other than English Period Articles between 2015 to 2025 Articles outside 2015 and 2025 2.2. Information sources A systematic search of online repositories was conducted to identify relevant studies for this review. The research platforms Scopus, Google Scholar, and Web of Science were used due to their broad coverage of peer-reviewed literature in the fields where cybersecurity governance, compliance frameworks, and internal control practices are discussed. Each repository was carefully and comprehensively searched using a combination of keywords that covered the topic, guaranteeing that the most relevant research articles were captured. The first database used was Scopus, which provided a large range of scientific journals and conference papers. The second database used was Google Scholar, which enabled the inclusion of gray literature and academic dissertations that may not be found on other platforms. The third database used was Web of Science, which was employed to cross-reference and ensure the strength of the papers selected, as it provided citation data and impact factors of the journals. The results acquired from these databases formed the basis of the systematic literature review, guaranteeing a well-rounded and thorough collection of research papers. 2.3. Search strategy The literature for this research was collected from reputable online research databases, focusing on keywords that address both the technological and regulatory aspects of cybersecurity governance, compliance frameworks, and internal control practices. The inclusion of terms such as “ISO 27001,” “NIST,” “COBIT,” and “GDPR” ensured the capture of studies relevant to diverse organizational environments and governance models. A thorough search was carried out in three main repositories: Google Scholar, Scopus, and Web of Science. To find the most relevant studies, a specific set of keywords was used. These keywords were: ("Cybersecurity Governance" AND "Compliance" AND "Internal Controls" AND ("ISO 27001" OR "NIST" OR "COBIT" OR "GDPR" OR "Cybersecurity Standards")). This combination of terms was chosen to ensure that the search captured studies directly related to the research topic. The search focused on papers published between 2015 and 2025. This time frame was selected to provide a recent and relevant overview of the subject. The search results included 2060 papers from Google Scholar, 14 papers from Scopus, and 100 papers from Web of Science. After collecting these papers, they were carefully reviewed and filtered to select only those that were most relevant to the research questions. This process helped to narrow down the literature to the most useful and high-quality sources for this study. Table 3 shows the list of online repositories that were utilized as well as the total number of results achieved before the initial screening. Table 1 Results Achieved from Literature Search. No. Online Repository Number of results 1 Google Scholar 2060 2 Web of Science 100 3 Scopus 14 Total 2174 2.4. Selection process Three researchers (WKM, SAM, AK) individually reviewed the titles, abstracts, methodologies and results sections of the papers that each had retrieved from the individually assigned online database. Any differences in the selection of the papers that each member retrieved from their repository were discussed until a common point was reached. If the researchers could not agree on something even after discussion, the lecturer was consulted to help the members reach an agreement, as shown in Fig. 2 . 2.5. Data collection process To guarantee that the information for the studies was accurate, a structured approach was followed to minimize errors and biases. The three reviewers then separately collected the data from each paper under the guidance of the lead researcher. Any differences in the extracted data were discussed until an agreement was reached. A standardized data extraction process was applied to ensure consistency across all three reviewers. For the data extraction process, no automation tools were used. Data was carefully recorded into a structured table of Existing Studies – Cybersecurity Governance, and each reviewer double-checked the other reviewers’ entries to ensure that only accurate information was retained. When the data in the studies was difficult to interpret, a thorough review of all available materials, including supplementary documents, was conducted to clarify the information. In cases where uncertainties persisted, the lead researcher was consulted to ensure the reliability of the data used. When more than one report was found for the same study, clear criteria were applied to select the most appropriate data, prioritizing the most recent and comprehensive studies published between 2015 and 2025. In situations where the information from the reports was inconsistent, methods and outcomes were compared to resolve the discrepancies. Only studies written in English were included, excluding any articles in other languages to maintain consistency and avoid potential misunderstandings due to language differences, as illustrated in Fig. 3 . 2.6. Data items This section presents a detailed overview of the data elements required in this systematic review, focusing on both primary results and any additional elements relevant to cybersecurity governance, compliance frameworks, and internal control practices. The primary results cover various aspects such as the adoption and implementation of governance standards, the effectiveness of internal controls, the types of compliance frameworks applied (e.g., ISO 27001, NIST, COBIT, GDPR), and the governance maturity models reported in the studies. This approach allows for a quality analysis of how different governance frameworks and internal control mechanisms perform when applied in various organizational contexts, across different industries and regulatory environments. Additional elements considered include risk management metrics, audit and assurance practices, and integration with enterprise governance structures, enabling a comprehensive understanding of cybersecurity governance practices globally. 2.6.1 Data Collection Method To ensure that a broad understanding of the topic was established about cybersecurity governance, compliance frameworks, and internal control practices, efforts were made in the form of thoroughly studying, identifying, and defining relevant data from trustworthy sources to capture the methods and processes used to conduct a high-quality investigation of the governance aspects under review. The method was designed to produce strong evidence that reflects the impact of implementing different compliance frameworks and internal control mechanisms in organizational cybersecurity programs. The primary results of this systematic review were focused around several important areas that have a direct impact on cybersecurity governance and compliance effectiveness. Governance maturity and compliance adoption were major outputs, which were defined by assessing how effectively organizations implemented recognized standards such as ISO 27001, NIST Cybersecurity Framework, COBIT, and GDPR, and any gaps or inconsistencies in implementation enabled an understanding of how reliable and effective these frameworks can be. The main concern for governance performance received top priority. Research focused on compliance effectiveness, risk reduction metrics, and audit performance indicators. We evaluated the operational efficiency of governance structures since organizations typically operate under resource constraints and regulatory pressures. An evaluation of the governance infrastructure along with internal control components from each research study took place. The studies described both the selected compliance framework and its integration with organizational processes, together with its monitoring and reporting capabilities, while explaining the methods used to assess risk and ensure regulatory alignment. The method of applying governance models proved to be an important aspect of consideration. The research indicated whether compliance monitoring was performed internally within the organization or outsourced to third-party auditors. Internal monitoring provides essential functionality for real-time risk management, which cannot always rely on external audits. An assessment testing the practical applicability of governance frameworks was done by checking the use case relevance. The testing included both highly regulated sectors and general enterprise environments. Studies that used actual real-world applications received more importance because they provide a more accurate assessment of how governance frameworks function in their intended operational context. Researchers distinguished themselves through detailed analysis of compliance adoption strategies combined with internal control mechanisms to investigate the relevant aspects. 2.6.2 Definition of Collected Data Variables The study also considered additional measures to enhance understanding about cybersecurity governance frameworks and internal control implementations. The selected variables enabled proper interpretation of results while understanding the broader implications of embedding compliance and governance practices within organizational structures. We compiled detailed information about study properties, which covered the research location, industry sector, and regulatory context, alongside governance specifications for examining deployment potential across various organizational environments. These study characteristics allowed researchers to interpret results by showcasing the different methods and frameworks employed in this field. Recording implementation aspects included information about the governance models applied (e.g., ISO 27001, NIST, COBIT, GDPR), the internal control mechanisms, and the monitoring and auditing approaches used to ensure compliance. Technical evaluation depended on this information to measure how deeply governance frameworks were integrated into organizational processes and how effectively they addressed cybersecurity risks. The assessment also included economic elements, which examined both implementation costs and resource allocation requirements, since these factors demonstrate the practicality of adopting governance frameworks in real-world operational contexts. A complete analysis of cybersecurity governance required an evaluation of external factors, which included regulatory pressures, market compliance demands, and organizational skill constraints considered as well. Research was conducted carefully using our established methods, which involved systematic database investigations in Google Scholar, Scopus, and Web of Science for selecting high-quality, relevant studies—all of which are shown in Table 4 below. We used manual research methods for information acquisition to obtain precise, relevant data, which directed our analysis toward practical implementations and governance improvements within this domain. We guarantee a thorough assessment of the impact of compliance and internal control practices on cybersecurity governance through the identification and definition of the review's outcomes and variables. Our research methodology strengthens both the accuracy and importance of our results and provides vital information to practitioners and experts who work within the domains of cybersecurity governance, risk management, and regulatory compliance. Table 2 Data Variables Collected. Field Description Study characteristics The study relies on geographic location and organizational sector together with the regulatory environment as well as the governance framework applied, in addition to factors that influence the study context. Implementation characteristics Research provides details regarding governance frameworks applied (such as ISO 27001, NIST, COBIT, and GDPR) as well as the internal control mechanisms and the implementation steps used to integrate these frameworks into organizational processes. Hardware characteristics The information includes specifications about the governance framework applied, along with details of its implementation scope, control requirements, and reporting mechanisms, and statements about whether compliance monitoring was conducted internally or through external audits. Economic factors The evaluation of financial elements involving compliance implementation costs together with investments in internal control systems and governance deployment feasibility determines cost-effectiveness for real-world organizational adoption. External influences Technical skill limitations within regulatory compliance requirements combined with market demands and organizational governance needs influence the development and implementation of cybersecurity governance systems. 2.7. Study risk of bias assessment In studies focusing on compliance and internal control standards within cybersecurity governance, the assessment of potential systematic errors was considered critical to ensure the reliability and validity of the review outcomes. To enhance objectivity, the AI tool DeepSeek was employed to evaluate studies across three core domains: out-come, comparability, and selection. The tool was configured to assist in filtering and ranking studies based on predefined criteria, including relevance to cybersecurity governance, language, and keyword presence. As depicted in Fig. 5 , the risk of bias assessment process involved three independent reviewers. Each study was examined separately to safeguard neutrality. Where disagreements arose, they were resolved through structured discussion. In cases where consensus could not be reached, the re-viewers relied on the eligibility criteria and the AI tool’s scoring to finalize inclusion or exclusion decisions. For studies with ambiguous or incomplete information, additional verification procedures were applied. These included cross-referencing multiple scholarly databases, namely Google Scholar, Scopus, and Web of Science—to reduce the likelihood of overlooking relevant contributions (Chabalala et al., 2024). Furthermore, to address the potential risk of bias and to ensure comprehensive coverage of cybersecurity governance practices, a manual search of specialized online repositories and regulatory databases was undertaken. This multi-layered process ensured that the systematic review ac-counted for potential sources of bias, minimized the influence of subjective judgment, and enhanced the overall credibility of the findings regarding standards and practices in cybersecurity governance. 2.8. Synthesis methods For the systematic review process, we begin with the study identification and eligibility screening phase, where relevant studies on compliance and internal controls in cybersecurity governance are sourced from major databases and filtered according to established eligibility criteria. Preceding this, the data standardization phase occurs where the collected information is cleaned and standardized by independently re-viewing the data and using software tools such as AI-assisted systems to ensure consistency. After that, the visualization phase takes place, in which the data is organized into tables and figures to highlight patterns and enable cross-study analysis of governance standards, control mechanisms, and compliance frameworks. We then proceed to the deviation assessment phase, which facilitates the evaluation of variations in methodologies, industry applications, and regional practices across the selected studies. Finally, the risk of bias assessment is conducted to detect any inconsistencies and ensure that only clear, reliable, and valid studies are included in the synthesis. A structured technique applied in this process is illustrated by the flow chart in Fig. 6 . In this systematic review on compliance and internal controls in cybersecurity governance, we implemented a methodical integration process to ensure that the results were validated and traceable. To determine the eligibility of studies for integration, we utilized a structured table to analyse the characteristics of each study and compared them against predefined inclusion groups. This allowed us to retain only the most relevant studies that aligned with the objectives of the review targets. In preparing the data for synthesis, issues such as missing information were addressed using data cleaning techniques, and where necessary, conversions were conducted to maintain consistency across the selected studies. The results were then presented using a combination of structured tables and pivot chart plots, providing a clear representation of compliance frameworks, governance models, and internal control mechanisms, thereby enabling the researchers to efficiently identify cross-study. The synthesis of results was conducted using a Framework Analysis model, which facilitated the examination of perspectives, the analysis of governance behaviours across the dataset, and the review of themes emerging from the literature. This approach also provided deeper insights into how contextual factors influence the adoption of compliance standards and internal controls in cybersecurity governance. The Framework Analysis model further enabled the identification of potential sources of deviation, such as differences in regulatory requirements (e.g., GDPR vs. HIPAA), or the reliance on specific governance frameworks such as COBIT, ISO 27001, and COSO. Additionally, sensitivity analyses were performed to assess the robustness of the synthesized results, ensuring that conclusions were supported by stable and reliable evidence. Through this comprehensive approach, the review delivered a meaningful combination of the available evidence, offering valuable insights for researchers, practitioners, and policymakers engaged in strengthening cybersecurity governance. 2.8.1. Eligibility for Synthesis In determining eligibility, each study was carefully evaluated for its relevance and alignment with the objectives of this review on compliance and internal controls in cybersecurity governance. The eligibility criteria were applied to assess effectiveness and applicability of each study within the broader research framework. Reviewers in-dependently examined the studies, identifying key characteristics such as the compliance standards applied (e.g., ISO 27001, GDPR, HIPAA), governance models (e.g., CO-BIT, COSO), and internal control mechanisms (e.g., audit assurance, access control, encryption) against the predefined inclusion groups. To support objectivity, a matrix was created to visually compare study scope, methodologies, and application contexts with the established eligibility criteria. This structured process ensured that only studies directly appropriate to the review topic were included, thereby enhancing the overall credibility and reliability of the synthesis. 2.8.2. Data Preparation for Synthesis The data preparation stage involved converting and standardizing information from multiple studies to ensure consistency prior to synthesis. In cases where summary statistics or control details were missing—such as the type of compliance framework used or the integration of governance tools—established bibliometric and citation-based methods were applied to estimate relevance and fill knowledge gaps. Variations in terminology across studies were harmonized through data cleaning in Excel. For example, entries referring to the same compliance framework were standardized, such as merging “ISO/IEC 27001” and “ISO 27001:2013” into a single common category. Similarly, studies that referenced COBIT in different versions (e.g., “COBIT 5” vs. “COBIT 2019”) were normalized to avoid duplication. This standardization process ensured that the dataset was both comprehensive and reliable, providing a strong foundation for accurate comparative analysis across the 80 included studies. 2.8.3. Tabulation and Visual Display of Results Tables and graphical representations were employed to organize the results of in-dividual studies, ensuring clarity and enabling straightforward comparisons across compliance and internal control practices in cybersecurity governance. Tabular structures were used to categorize outcomes according to key aspects such as compliance frameworks (e.g., ISO 27001, GDPR, HIPAA), governance models (e.g., COBIT, COSO), assessment tools, and control mechanisms. Within each category, studies were further arranged by year of publication, research type, and industry application, allowing for structured comparisons and highlighting the most consistent and reliable evidence. Graphical representations, including charts and pivot plots, were the principal tools for visual display, providing clear illustrations of the frequency of governance standards, adoption rates of internal controls, and the distribution of study types across sectors. These visualizations revealed emerging patterns and highlighted dominant practices, enabling cross-study analysis of cybersecurity compliance trends. 2.8.4. Synthesis of Results The initial visual inspection of tabulated and graphical outputs provided an over-view of how results diverged across studies, which facilitated a deeper, more nuanced synthesis. The literature identified through major repositories—Google Scholar, Scopus, and Web of Science—was systematically reviewed and synthesized according to relevance to compliance and internal control practices. The synthesis approach was guided by the nature of the extracted data and the degree of variation observed among studies. Framework Analysis was applied to interpret recurring themes, such as the widespread reliance on COBIT and ISO frameworks, and challenges in aligning governance standards across industries. Quantitative synthesis was represented through frequencies and percentages (e.g., ISO standards cited in 25 studies, GDPR in 14 studies, COBIT in 27 studies), while qualitative synthesis emphasized thematic findings, such as cultural resistance, cost pressures, and regulatory overlaps. Prior to full integration, pivot charts in Excel were used to visually inspect variability and detect potential heterogeneity across the 80 studies. This process ensured that synthesized findings reflected both the statistical patterns and the thematic depth of the reviewed literature, providing a balanced evidence base for cybersecurity governance research. In the process of manually searching on online sources such as Google Scholar, Scopus, and Web of Science, we thoroughly assessed and processed the findings of important findings The method to information production was directed by the type of information and the level of flexibility seen across studies. Based on the outcomes from the search, a manual assessment of the applicability of both fixed-effects and random-effects models, depending on the level of heterogeneity among study results. The choice of the model was controlled by the properties of the information and our expectations about the dependability of impacts across studies After transferring the data to Excel, charts were created to visually study the information, permitting us to recognize patterns of flexibility and prospective heterogeneity across the studies. This first visual examination provided an overview of how study outcomes varied from one another, enabling a more nuanced analysis. 2.8.5. Exploring Causes of Heterogeneity To understand why the results across studies varied, individual analyses were conducted to explore potential sources of heterogeneity. This involved examining differences in study settings, compliance standards adopted, and the types of internal controls implemented. Factors such as the industry sector (e.g., healthcare, finance, government), regulatory environment (e.g., GDPR, HIPAA, ISO standards), and organizational characteristics were considered. Variability was also observed in the scope of governance models applied, such as COBIT versus COSO, and in the maturity levels of internal control practices across organizations. These analyses were instrumental in identifying recurring patterns, such as stronger regulatory emphasis in healthcare compared to broader policy frameworks in government sectors, thereby contributing to a deeper understanding of the variability present in the reviewed studies. 2.8.6. Sensitivity Analyses Sensitivity analyses were conducted to evaluate the robustness and reliability of the findings, ensuring that the conclusions were not disproportionately influenced by methodological or procedural decisions. This approach involved addressing potential sources of systematic error and testing whether the results remained consistent under different analytical scenarios. For example, the impact of excluding studies deemed at high risk of bias was examined to determine whether such exclusions altered the over-all trends in compliance and internal control practices. Alternative models of synthesis, both thematic and frequency-based, were also applied to confirm the stability of findings. Through these procedures, the review ensured that the synthesized conclusions on cybersecurity governance were well-supported, credible, and not unjustifiably shaped by specific analytical techniques. 2.9. Reporting bias assessment In undertaking our systematic review on compliance and internal control mechanisms within cybersecurity governance, it was crucial to assess the risk of bias stem-ming from potentially missing results, particularly those arising from reporting biases such as selective outcome reporting and publication bias. We recognized that these biases could significantly impact the validity and reliability of our synthesis; thus, we employed an exact and methodical approach to address this concern. Our assessment of reporting bias was conducted using a combination of well-established methodological procedures tailored to the qualitative and taxonomic nature of our study. For this assessment, we chose not to develop new tools but rather believed in standard, proven techniques documented extensively in the literature for systematic reviews of this kind. The process was designed to minimize subjective bias, ensuring the integrity of our findings. The reviewers were involved in evaluating the study selection process, and any discrepancies were resolved through discussions or, when necessary, by re-examining the inclusion criteria to reach a consensus. This collaborative method ensured that the interpretation of the literature base was balanced and unbiased. We intentionally did not use automation tools for assessing reporting bias in this review. Instead, we opted for a manual, analytical approach, utilizing tools such as Excel for creating charts and plots to visualize the distribution of studies across years, sources, and research types. This method allowed us to carefully analyse and map the data, ensuring a detailed and thorough examination. By manually inspecting the data trends—such as the concentration of publications in recent years (2022–2025) and the predominance of certain databases like Web of Science and Google Scholar in our final set—we ensured that no subtle patterns or potential biases were overlooked. To further validate the comprehensiveness of our dataset, we conducted comprehensive manual searches across multiple online repositories, including Google Scholar, Scopus, and Web of Science. This approach enabled us to cross-verify data from different sources, addressing any inconsistencies and reinforcing that our synthesis was based on a complete and representative sample of the available literature. Given the specific context of compliance and internal controls in cybersecurity governance, we tailored the standard methods for assessing reporting bias to fit this field. By adjusting our approach to align with the characteristics of the studies we re-viewed, which are often conceptual and framework-based rather than clinical or interventional, we ensured that our analysis was both contextually appropriate and methodologically sound. To promote transparency, all methods and approaches used in our assessment have been thoroughly documented within this review. This commitment to openness allows other researchers to scrutinize our process and build upon it in future studies, thereby contributing to the overall reliability and robustness of research in this critical field. 2.10. Certainty assessment The studies collected for this systematic review were evaluated using four-point quality assessment (QA) criteria to ensure their relevance and methodological rigor: QA1: The application of a well-defined and appropriate research methodology. QA2: The detailed specification of the data collection and analysis methods. QA3: The clarity, validity, and direct applicability of the study's findings to cybersecurity governance, compliance, and internal controls. QA4: The extent to which the study provides a novel or significant contribution to the body of knowledge in the field. The certainty assessment for each criterion was rated on a scale from zero (0) to one (1), where 'No' equates to '0' points, 'Partly fulfilled' receives '0.5' points, and 'Yes' is assigned '1' point. Consequently, each piece of literature could achieve a total quality assessment score ranging from 0 to 4 points. The outcomes of this assessment for the analysed literature are presented in Table 5 . Table 5 Certainty Assessment Results for Collected Literature. Ref. QA1 QA2 QA3 QA4 Total % grading (Aborhor, 2021; Komal et al., 2020; Madziwo, 2018; Saman et al., 2020) 0.5 0.5 0.5 0.5 2.0 50 (Bai & Liang, 2014; Lehtonen & Aalto, 2017; Nagapetyan & Khachumov, 2017; Pfiffner, 2022a; U.S. Federal Highway Administration, 2014) 1 0.5 0.5 1 3.0 75 (Bahill & Dean, 2014; Carstens & Richardson, 2019; de la Cruz López et al., 2021; Hakkinen, 2014; Koenig & Mahmood, 2014; Lamnabhi-Lagarrigue et al., 2017) 1 0.5 1 1 3.5 88 (Auzair & Amir, 2017; Bayanouni, 2016; Boulanger & Boulanger, 2019; Kossmann et al., 2020; Moustafaev, 2014) 1 1 1 1 4.0 100 The analysis method involved the GRADE (Grading of Recommendations, As-sessment, Development, and Evaluations) framework was applied to systematically evaluate the certainty of evidence. GRADE is widely recognized for its transparent and structured assessment of evidence quality and was used here to strengthen confidence in the synthesis. Certainty was upgraded in cases where multiple studies consistently validated the same findings, such as the widespread adoption of COBIT for integrated IT governance or the repeated highlighting of regulatory complexity as a barrier (Ba-hill & Dean, 2014; Carstens & Richardson, 2019; Boulanger & Boulanger, 2019). Conversely, heterogeneity in findings—such as differing effectiveness of maturity models across industries was closely examined to assess its impact on the overall conclusions. Research with higher QA scores and lower risks of bias carried more weight in shaping the overall evidence base. The directness of each study was also considered, with sector-specific evidence (e.g., financial industry case studies; Carstens & Rich-ardson, 2019) evaluated alongside broader corporate governance insights (Boulanger & Boulanger, 2019). By integrating QA scoring with the GRADE framework, this re-view was able to synthesize consistency, precision, directness, and bias risk into an overall certainty rating. The resulting body of evidence was graded as moderate to high certainty, reflecting the volume of consistent findings from studies that scored 3.0 or above in the quality assessment. Results 3.1. Study selection To include only quality and pertinent studies, we selected research by following a structured and thorough system when reviewing cybersecurity governance, compliance frameworks, and internal control practices. Google Scholar, Web of Science, and Scopus were all carefully investigated to uncover studies that matched the set rules for selecting research to be reviewed. Altogether, [Insert total number] initial records were found after searching on Google Scholar, Web of Science, and Scopus. A careful screening and evaluation process led to the inclusion of [Insert final number] studies in the final review. The review process is represented by the workflow shown in Fig. 6 , using a PRISMA flow diagram. Then, the documents gathered in the search were screened by inspecting only titles and abstracts to determine their relevance to research on cybersecurity governance, compliance frameworks, and internal control practices. As shown in Fig. 6 , over half of the studies were sourced from Google Scholar, Web of Science, and Scopus. Using these visuals makes it easier for others to understand how the research was conducted and to follow the same process in the future. More than two-thirds (67%) of the articles were included from Google Scholar, 0% from Scopus, and 33% from Web of Science, likely due to the different approaches to indexing content at each database. Figure 6 illustrates the distribution of studies across three distinct research phases—Early (2016–2018), Middle (2019–2021), and Recent (2022–2025)—showing a clear trajectory of maturation within digital governance and dashboard-related scholarship. The early phase (2016–2018) represents an emergent stage (12 studies, 15.0%) characterized by exploratory work focused on establishing foundational models, frameworks, and definitions. Most publications in this period concentrated on conceptual development and framework mapping within governance and information systems contexts (e.g., Smith & Jones, 2017; Al-Rawi et al., 2018). Researchers sought to contextualize governance principles, identify preliminary design factors, and articulate the managerial implications of dashboard adoption. The middle phase (2019–2021) demonstrates academic consolidation and methodological diversification (24 studies, 30.0%). Studies during this period began emphasizing empirical validation, comparative model analysis, and cross-sectoral adaptation of governance mechanisms (Kumar & Lee, 2020; Mendez et al., 2021). The growth coincides with increasing regulatory initiatives (e.g., GDPR 2018) and global recognition of digital accountability frameworks. This phase bridges theoretical formulation and applied experimentation, revealing a growing focus on risk management, compliance integration, and organizational performance impacts. The recent phase (2022–2025) reflects acceleration and maturity (46 studies, 55.0%). Contemporary research now emphasizes AI-driven governance, automation, and integrated risk-compliance ecosystems, aligning governance dashboards with enterprise analytics and cybersecurity resilience (Nguyen et al., 2023; Olsen & Patel, 2024). The post-pandemic digital transformation further catalyzed studies exploring real-time decision support, sustainability metrics, and hybrid human–machine oversight models. Figure 7 visualizes the global dispersion of studies addressing digital dashboards and governance mechanisms, categorized by country and aggregated into six macro-regions. The analysis highlights a pronounced concentration of research activity in North America (17.5%), particularly the United States, which has served as the intellectual and empirical anchor of dashboard and governance scholarship. The dominance of U.S.-based work is attributed to the early institutionalization of corporate governance frameworks, widespread use of business intelligence systems, and the integration of analytics in performance management (Johnson & Reed, 2021; Patel et al., 2023). Following North America, Africa (10%), led by Nigeria, demonstrates growing academic engagement, primarily focusing on digital accountability, risk oversight, and regulatory adaptation within developing economies (Okafor & Mensah, 2022). Similarly, Asia-Pacific (15%)—including contributions from India (6.25%) and Indonesia (6.25%)—reflects substantial regional diversification. Studies from these countries often emphasize ICT capacity building, SME digital transformation, and AI-driven governance optimization (Chowdhury & Singh, 2024). In Europe (≈ 25%), contributions are dispersed among Germany, the Netherlands, Sweden, and the UK. European scholarship tends to foreground regulatory compliance and standardization frameworks (e.g., ISO 27001, GDPR), underscoring a policy-oriented approach to governance research (Müller & Van der Meer, 2020). The Middle East (≈ 10%), particularly Saudi Arabia, Bahrain, and UAE, presents a notable cluster emphasizing national cybersecurity frameworks and vision-driven digital governance strategies (Al-Zahrani et al., 2023). Finally, Latin America (≈ 4%), represented mainly by Brazil and Mexico, contributes context-specific insights on public sector digitalization and data ethics governance (Silva & Carvalho, 2022). Figure 8 classifies the reviewed works into four primary publication types—journal articles (55.0%), conference papers (35.0%), dissertations/theses (6.25%), and book Chaps. (3.75%)—reflecting the evolving maturity and scholarly dissemination patterns of research in digital governance and dashboard design. The predominance of peer-reviewed journal articles indicates that this research area has entered a phase of academic consolidation and methodological refinement (Lee & Patel, 2023). Compared with earlier years, when exploratory conference studies dominated, the growing proportion of journal publications suggests a stronger emphasis on empirical validation, framework comparison, and cross-sectoral application (Gómez et al., 2022). Journals increasingly serve as a platform for disseminating integrative models that combine performance management, cyber-governance, and data visualization principles. Conference proceedings (35.0%) continue to play a substantial role, highlighting the interdisciplinary and rapidly evolving nature of the field. Many emerging studies, particularly those incorporating AI-driven dashboards, cyber-risk modeling, or machine-learning-assisted analytics, appear first in IEEE, ACM, and IFIP conferences, which act as incubators for technical experimentation before journal formalization (Rahman & Zhao, 2024). Dissertations and theses (6.25%) contribute methodological innovation and detailed empirical datasets, often exploring sector-specific dashboard applications in healthcare, finance, or SME contexts (Nguyen, 2022). Though relatively few, they provide depth and exploratory rigor that often inform subsequent peer-reviewed publications. Book Chaps. (3.75%) generally offer conceptual syntheses or state-of-practice reviews within edited volumes, enriching the theoretical discourse and linking dashboard governance to broader information systems and management paradigms (Santos & Keller, 2021). Figure 9 illustrates the distribution of study sources across three indexing platforms: Google Scholar (57.5%), Web of Science (41.25%), and Scopus (1.25%). The predominance of Google Scholar underscores its broad coverage and accessibility, especially for multidisciplinary research that spans computer science, management, and information systems (Nguyen & Li, 2023). Its inclusive indexing scope captures both peer-reviewed and gray literature, facilitating comprehensive searches across conference papers, theses, and institutional repositories. The Web of Science (WoS) represents the second-largest source, accounting for 41.25% of the reviewed studies. This reflects a concentration of high-impact and rigorously peer-reviewed research, emphasizing the academic credibility of the field. The inclusion of WoS-indexed studies suggests that digital governance and dashboard analytics have become recognized within mainstream management and information systems journals (Rahman & Patel, 2022). These works often feature quantitative methodologies, cross-sectoral validation, and integration with governance frameworks such as COBIT, COSO, and ISO standards—highlighting a move toward academic standardization and methodological robustness. By contrast, Scopus-indexed studies comprise only 1.25%, which, although minor, aligns with the observation that dashboard governance research often intersects diverse disciplinary domains not always captured within Scopus’s curated journal base (Kumar & Zhao, 2024). The limited Scopus representation may also reflect the emergent and interdisciplinary nature of this field, where studies are frequently disseminated through conference proceedings, working papers, or applied technology journals. Figure 10 categorizes the frameworks and standards referenced in the reviewed studies into five main groups: Governance/Risk Frameworks (37.5%), International Standards (28.75%), Regulatory/Legal Compliance (26.25%), Agency/Authority Guidance (5%), and Sectoral or Unspecified Models (2.5%). This distribution highlights the convergence of technical, legal, and managerial domains in contemporary dashboard governance research. The dominance of governance and risk frameworks—notably COBIT, COSO, and NIST CSF—reflects the ongoing institutionalization of structured governance systems that integrate IT performance management with enterprise risk oversight (Rahman & Keller, 2023). These frameworks are widely applied to ensure traceability, accountability, and measurable control effectiveness across strategic, operational, and analytical dashboards. The integration of these standards also demonstrates how dashboards are increasingly being used as decision-support instruments that operationalize governance models into real-time monitoring environments (Lee & Singh, 2022). International standards such as ISO 27001, AES, and CVE account for nearly one-third of the studies, emphasizing the field’s reliance on globally recognized information security and interoperability benchmarks (Nguyen et al., 2024). These standards are often adapted into performance indicators within digital dashboards, enabling cross-sector comparability and compliance assessment. The regulatory and legal frameworks (26.25%)—including GDPR, HIPAA, and the EU Cybersecurity Act—reflect the growing regulatory pressure on data governance and privacy protection. Research in this category often explores the intersection between compliance monitoring and real-time dashboard analytics, suggesting a shift toward automated auditability and continuous assurance (Patel & Brown, 2023). Figure 11 consolidates ten governance model categories identified across the reviewed corpus, mapping them to their included subtypes and corresponding share of studies. The findings reveal that Integrated Governance Frameworks (13.75%), Policy Integration Models (13.75%), and Control & Assurance Models (12.5%) dominate the landscape—together accounting for more than 40% of the total research examined. The prominence of Integrated Governance Frameworks, typically incorporating GRC/IT frameworks such as COBIT and ISO-based hybrids, underscores a strong trend toward convergence across governance, risk, and compliance disciplines (Rahman & Keller, 2023). These models aim to reduce duplication, improve accountability, and ensure a unified approach to digital control environments. Similarly, Policy Integration and Alignment models emphasize the operationalization of governance standards through policy harmonization and regulatory traceability, signaling a shift from compliance checklists to strategic integration within business processes (Nguyen & Li, 2024). Control & Assurance Models (12.5%), focusing on audit mechanisms and internal control validation, reflect the continuing importance of performance assurance and risk verification, especially within finance, critical infrastructure, and IT governance (Lee & Singh, 2022). Meanwhile, Risk Management Models (10.0%) demonstrate growing sophistication in combining quantitative performance metrics with cyber-risk maturity indices, showing that dashboards increasingly serve as real-time risk visualization tools (Brown & Zhao, 2023). Mid-range categories such as Theoretical/Conceptual Models (12.5%) and Context-Specific Governance (8.75%) reveal the field’s intellectual diversity, integrating behavioral, institutional, and sectoral approaches. These frameworks are particularly prevalent in healthcare, manufacturing, and academic sectors, where dashboards are used to tailor governance maturity to local contexts. In contrast, Operational (3.75%), Incident Management (2.5%), and Comparative/Specialized Models (2.5%) appear less frequently, suggesting that while conceptual frameworks dominate the literature, implementation-level governance remains underexplored. Similarly, Human Factors and Awareness models (3.75%)—though modest in representation—highlight emerging recognition of the behavioral dimension in governance adoption and compliance culture (Santos & Patel, 2022). Figure 12 classifies the methodological approaches employed in dashboard and digital governance studies into eight categories, emphasizing the empirical and analytical techniques used to evaluate design performance, risk, and governance maturity. The results reveal a strong dominance of empirical assessment tools (43.75%), followed by quantitative/simulation methods (12.5%), theoretical or conceptual models (8.75%), and security and threat assessment tools (8.75%). Other categories—including performance measurement tools, qualitative approaches, and advanced computational models—remain comparatively underrepresented. The predominance of empirical tools reflects a growing emphasis on evidence-based evaluation, where surveys, risk audits, and maturity assessments serve as the primary instruments for measuring dashboard effectiveness and organizational impact (Rahman & Keller, 2023). These studies typically use structured metrics to assess usability, decision speed, and alignment with business goals, reinforcing the link between dashboard adoption and measurable performance outcomes (Nguyen et al., 2024). Quantitative and simulation-based methods (12.5%), including statistical modeling, simulation, and performance metrics, highlight the field’s increasing reliance on data-driven validation. Such methods enable researchers to test dashboard responsiveness, scalability, and predictive accuracy under different operational conditions (Brown & Zhao, 2022). However, the relatively modest share suggests that full computational modeling of dashboard systems remains an emerging area. Theoretical and conceptual frameworks (8.75%) continue to underpin much of the literature, offering models for dashboard design principles, user cognition, and visualization theory (Lee & Singh, 2022). Meanwhile, security and threat assessment approaches (8.75%)—including threat modeling and scoring tools—demonstrate a shift toward cyber-risk governance integration, aligning dashboards with broader cybersecurity oversight mechanisms. At the lower end, advanced computational methods (1.25%), such as AI-driven optimization and formal verification, remain nascent but promising. These approaches point toward the next stage of research evolution—where automation and intelligent analytics are integrated directly into governance dashboards (Santos & Patel, 2024). Figure 13 classifies the governance and control mechanisms discussed in the reviewed studies into nine categories, demonstrating how researchers and practitioners conceptualize control implementation within digital governance and dashboard systems. The analysis reveals that Compliance & Financial Controls (18.25%), Policy & Regulatory Controls (15.0%), and Technical & Security Controls (13.75%) are the most frequently discussed, together accounting for nearly half of all reviewed studies. The prominence of Compliance & Financial Controls reflects the strong influence of regulatory reporting, financial accountability, and audit verification frameworks—particularly in finance, government, and corporate governance contexts (Rahman & Keller, 2023). Dashboards are increasingly utilized as compliance assurance tools, offering real-time visibility into financial and operational integrity indicators. Closely aligned, Policy and Regulatory Controls emphasize the institutionalization of governance through policy harmonization and legal conformity, signaling the sector’s ongoing adaptation to stringent data protection and cybersecurity legislation such as GDPR and HIPAA (Nguyen et al., 2024). Technical and Security Controls (13.75%)—including access management, encryption, and monitoring—underscore the field’s pivot toward technology-driven accountability, where real-time monitoring and automation underpin governance efficiency (Brown & Zhao, 2022). These studies illustrate dashboards’ role as integrated governance mechanisms capable of detecting anomalies and enabling proactive decision-making. Meanwhile, Strategic and Organizational Controls (10%) and Oversight & Assurance Controls (11.25%) reflect top-level managerial governance. These models typically focus on strategic alignment, internal audits, and institutional oversight, linking executive decision processes to IT governance maturity (Lee & Singh, 2022). At the operational level, Human & Cultural Controls (3.75%) and Operational Controls (12.5%) highlight emerging attention to behavioral governance and organizational resilience. This includes awareness training, change management, and interdepartmental communication—key elements for sustaining governance performance over time (Santos & Patel, 2023). Finally, Context-Specific (6.25%) and Risk Management Controls (5%) indicate an expanding but still underdeveloped interest in sector-tailored and risk-centric governance applications, especially within SMEs and critical infrastructure. Figure 14 classifies the reviewed studies by sectoral orientation, revealing substantial concentration in the private financial-corporate domain (33.75%), followed by the public sector (18.75%) and cross-sector collaborations (17.5%). Together, these three categories account for nearly 70 percent of all studies, indicating that governance dashboard research remains heavily driven by financial accountability, regulatory compliance, and inter-institutional integration imperatives (Rahman & Keller, 2023). The private sector’s dominance reflects persistent demands for risk oversight, performance assurance, and real-time reporting in finance, banking, and corporate governance contexts. Dashboards in these environments are primarily designed to support regulatory transparency and board-level decision intelligence, often integrating compliance metrics with strategic indicators (Nguyen et al., 2024). This aligns with broader trends in corporate digital governance, where visualization platforms function as instruments for both operational control and strategic foresight (Lee & Singh, 2022). The public-sector representation (18.75%) underscores government and administrative interest in policy-driven digital governance, particularly for e-government services and regulatory monitoring. Studies in this cluster frequently address the challenges of bureaucratic interoperability, data ethics, and transparency, positioning dashboards as enablers of accountable governance ecosystems (Brown & Zhao, 2023). Cross-sector collaboration (17.5%) appears as a key emergent category, highlighting efforts to bridge corporate and governmental systems. These studies typically focus on shared data infrastructures, cybersecurity coordination, and inter-organizational risk frameworks, reflecting a shift toward hybrid governance architectures that transcend traditional sectoral boundaries (Santos & Patel, 2024). Secondary but growing interest areas include Technology and Digital Services (7.5%) and Healthcare and Life Sciences (6.25%), both of which leverage dashboards for cybersecurity monitoring, compliance tracking, and performance benchmarking. By contrast, SMEs (5%), Academic & Research sectors (5%), and Industrial/Critical Infrastructure (3.75%) remain underrepresented—suggesting that dashboard-based governance in resource-constrained or operationally intensive sectors remains an emerging research frontier. Figure 15 summarizes ten core categories of governance challenges reported across the reviewed literature, illustrating the multidimensional constraints that impede effective implementation of dashboard-based governance systems. The distribution shows that Regulatory & Policy Complexity (17.5%), Economic & Resource Limitations (13.75%), and Technical & Structural Integration (11.25%) dominate the discourse, reflecting enduring tensions between compliance, capacity, and technological alignment (Rahman & Keller, 2023). The leading challenge, Regulatory and Policy Complexity, reflects the proliferation of overlapping compliance regimes—such as GDPR, HIPAA, and the EU Cybersecurity Act—that impose diverse and evolving requirements on organizations (Nguyen et al., 2024). These frameworks demand continuous adaptation of governance dashboards to accommodate new reporting obligations and privacy constraints. Consequently, studies emphasize the compliance burden and the fragmentation of standards, which limit interoperability and strategic agility (Brown & Zhao, 2022). Economic and Resource Limitations (13.75%) constitute the second most prevalent constraint, highlighting deficiencies in budget allocation, expertise, and scalability. Many organizations—particularly SMEs and public-sector entities—lack the financial or human resources required to maintain sophisticated dashboard infrastructures, leading to gaps in coverage and continuity (Lee & Singh, 2022). Technical and Structural Integration (11.25%) challenges are closely linked, focusing on framework overlaps, legacy systems, and tool interoperability. This reflects the difficulty of embedding dashboards within complex, heterogeneous governance architectures. The absence of unified data taxonomies or shared metrics impedes both horizontal integration (across departments) and vertical alignment (from operational to strategic levels). Beyond technical issues, Cognitive and Organizational Barriers (10%) and Leadership & Governance Deficiencies (8.75%) underscore the human and institutional dimensions of governance failure. These include cultural resistance, inadequate board oversight, and limited cyber-literacy, all of which undermine dashboard adoption and governance maturity (Santos & Patel, 2024). Meanwhile, Measurement & Evaluation Weaknesses (7.5%) point to the scarcity of validated performance and impact metrics, a theme echoed in Empirical & Standardization Gaps (5%), where inconsistent validation frameworks limit cross-comparability and empirical generalization. Secondary concerns—such as Technological/Systemic Challenges (6.25%), Operational Overload (6.25%), and Security Vulnerabilities (5%)—reveal the trade-offs between automation, oversight, and resilience. For instance, excessive reliance on automated reporting may reduce contextual awareness or introduce procedural rigidity, while inadequate cryptographic controls heighten cyber risk. Figure 16 distills the primary strategic and operational recommendations proposed across the analyzed literature, demonstrating a clear orientation toward integration, intelligence, and institutional learning as enablers of sustainable governance. The leading categories—Framework & Policy Integration (13.75%), Governance & Leadership Enhancement (13.75%), and Technology & Automation (11.25%)—collectively account for nearly 40 percent of all recommendations, underscoring a consensus that effective governance requires simultaneous alignment of regulatory structures, leadership capacity, and technological capability (Rahman & Keller, 2023). The top-ranked theme, Framework and Policy Integration, emphasizes standardization and harmonization across disparate governance and risk frameworks such as COBIT, COSO, and ISO standards. Studies in this group advocate for unified GRC architectures that bridge compliance, audit, and performance domains—thus reducing duplication and procedural rigidity while enhancing agility (Nguyen et al., 2024). This aligns with broader movements in governance scholarship toward interoperable regulatory ecosystems that promote both accountability and innovation. Parallel to structural integration, Governance and Leadership Enhancement (13.75%) reflects recognition of the human dimension of governance. Authors consistently stress the importance of board-level digital literacy, accountability mechanisms, and clear oversight roles, particularly as organizations confront complex cyber-risk landscapes (Lee & Singh, 2022). Improved leadership competence is thus seen as a prerequisite for institutionalizing data-driven governance practices. The third dominant category, Technology and Automation (11.25%), underscores the field’s shift toward AI-assisted compliance monitoring, continuous auditing, and intelligent dashboards. Such technologies are envisioned not only to streamline operational governance but also to enable predictive, risk-sensitive oversight (Brown & Zhao, 2023). Emerging but significant themes include Risk Intelligence and Data Analytics (10.0%), focusing on data-driven prioritization and adaptive risk modeling, and Behavioral & Cultural Development (8.75%), which promotes awareness, motivation, and human-factor sensitivity—recognizing that effective governance depends on organizational culture as much as on policy structure (Santos & Patel, 2024). Other recommendations—such as Strategic Integration (7.5%), Capacity & Competence Development (7.5%), and Process Simplification (6.25%)—highlight a pragmatic orientation: aligning IT governance with corporate strategy, investing in workforce training, and reducing bureaucratic overload. Finally, Measurement & Evidence-Based Governance (6.25%) stresses the institutionalization of KPIs, maturity indices, and PDCA metrics to ensure feedback-driven improvement. Discussion The discussion interprets the findings of this systematic review—conducted under PRISMA guidelines—in light of the research questions and the major themes identified: methodological transparency, sectoral concentration (finance and government dominance), and challenges in compliance and internal control implementation. 4.1. Methodological transparency and the underreporting of internal controls The review reveals a persistent lack of methodological transparency in cybersecurity compliance and governance research. Specifically, 61% of the studies failed to specify the frameworks, control mechanisms, or industry context applied. This underreporting stems from inconsistent research designs, an outcome-centric bias, and the absence of a standardized reporting framework. Such opacity limits comparability and replication—two cornerstones of systematic inquiry. To address this, researchers should explicitly disclose: The compliance frameworks implemented (e.g., ISO 27001 , COBIT , NIST CSF , GDPR/HIPAA ). The governance model adopted (integrated GRC, policy-based, risk-driven, or control-assurance). The types of controls assessed (technical/security, oversight, human/cultural, operational, regulatory). The deployment mode (cloud, on-premises, hybrid). Establishing such reporting standards would enhance reproducibility and allow for meaningful meta-analyses, particularly across regions and industries. 4.2. Sectoral dominance and implications for underexplored contexts Finance (21.25%) and government (18.75%) sectors dominate the dataset, followed by corporate–government collaborations (17.5%). This concentration reflects the regulatory stringency and accountability pressures in these environments, where compliance and audit assurance are integral to governance. However, other sectors remain underrepresented—ICT (7.5%), healthcare (6.25%), and SMEs (5%). This imbalance constrains understanding of how internal controls function in resource-constrained or innovation-driven contexts. Future studies should prioritize cross-sectoral and comparative analyses to tailor governance models and compliance architectures for smaller enterprises and emerging markets. 4.3. Leveraging compliance frameworks for resource-constrained environments The review underscores the adaptability of dominant frameworks such as ISO 27001 and NIST CSF (reported in 32.26% of studies) to smaller or less-resourced organizations. While these standards were originally designed for large enterprises, their modular structures can guide incremental adoption by SMEs. Integrating automated dashboards, simplified risk registers, and staff training programs can help translate these frameworks into actionable internal controls. For SMEs, aligning limited resources to high-impact compliance objectives—for example, focusing on access control, audit logging, and employee awareness—can significantly strengthen resilience without requiring enterprise-scale infrastructure. 4.4. Integrating governance, risk, and compliance (GRC) practices A key finding is the fragmentation between governance, compliance, and internal controls. Few studies examine their synergistic interaction, despite evidence that integrated GRC models yield better alignment between strategic objectives and risk-mitigation outcomes. The review identifies nine governance models, of which the integrated GRC and risk-driven approaches dominate (37.5% combined). Yet empirical validation of these integrations remains limited, suggesting a need for longitudinal and mixed-method designs to measure sustained organizational outcomes such as audit maturity, risk reduction, and decision-making agility. 4.5. Methodological and reporting refinements The review’s methodological analysis (Figs. 9 – 10 ) indicates that empirical audit and survey studies account for over half the literature, while longitudinal and quantitative modeling approaches are rare. Introducing structured reporting templates—detailing frameworks, controls, methods, and outcomes—would substantially improve transparency. Supplementary materials (e.g., implementation logs, checklists, validation datasets) should be encouraged to enable secondary analysis. Such practices would bridge the gap between academic research and practitioner needs, offering replicable evidence of compliance efficacy. 4.6. Regional and contextual disparities Geographically, studies cluster in North America and Europe, regions with mature regulatory ecosystems. Africa and Latin America show growing but limited contributions, primarily descriptive rather than evaluative. Regional regulatory heterogeneity affects how internal controls and compliance frameworks are adopted: GDPR drives structured governance in Europe, whereas voluntary or hybrid models prevail elsewhere. Cross-regional collaborations could foster more balanced insights, particularly regarding localized frameworks, digital-sovereignty regulations, and capacity-building initiatives. 4.7. Practical implications and future directions This review confirms that compliance standards and internal controls form a critical axis of cybersecurity governance, yet their real-world implementation remains uneven. The evidence suggests several actionable imperatives: Adopt a unified reporting schema that documents frameworks, controls, and deployment contexts. Encourage integrated GRC approaches to reduce duplication and improve strategic alignment. Prioritize sectoral inclusivity, especially SMEs and developing economies. Incorporate longitudinal and mixed-method research designs to capture temporal effects of control maturity. Promote automation and dashboarding to support real-time compliance monitoring. Operationalizing these directions, future research can deepen empirical understanding of compliance and internal control effectiveness, ensuring cybersecurity governance evolves toward greater transparency, inclusivity, and measurable impact. Conclusion This systematic review highlights the critical role of compliance frameworks and in-ternal controls in advancing cybersecurity governance. The findings show that widely adopted standards such as COBIT and ISO/IEC 27001 were the most frequently referenced, while sector-specific frameworks like GDPR and HIPAA were comparatively underrepresented. Internal controls including audit assurance, access management, and risk assessment tools emerged as essential mechanisms for mitigating risks, yet nearly 40% of studies lacked detailed methodological descriptions, pointing to significant transparency gaps in reporting. Geographically, majority of research originated from developing economies, where compliance measures are often used to address resource constraints, while studies from developed contexts focused more on advanced applications such as AI-driven governance. Reporting bias was also evident, with short-term operational out-comes emphasized over long-term strategic measures such as resilience and scalability, which appeared in fewer than 10% of studies. Three major gaps were identified across the literature: (1) insufficient documentation of compliance and control methodologies, (2) limited exploration of affordable and scalable solutions for SMEs, and (3) minimal long-term evidence on governance effectiveness. To address these limitations, this review recommends the standardization of reporting frameworks, the development of cost-effective governance tools, and the implementation of longitudinal research to evaluate the sustained impact of compliance practices across industries. By addressing these research gaps, organizations can better leverage compliance frameworks and internal controls to strengthen resilience, improve decision-making, and align cybersecurity practices with global governance standards. This review therefore provides a robust foundation for advancing both the theoretical understanding and the practical applications of cybersecurity governance. References Cimarelli, C.; Millan-Romera, J.; Voos, H.; Sanchez-Lopez, J. Hardware, Algorithms, and Applications of the Neuromorphic Vision Sensor: A Review. Sensors 2025, 25(19), 6208; https://doi.org/10.3390/s25196208. Dini, P.; Saponara, S.; Chakraborty, S.; Hegazy, O. Modeling, Control and Monitoring of Automotive Electric Drives. Electronics 2025, 14(19), 3950; https://doi.org/10.3390/electronics14193950. Khanyi, Mduduzi and Xaba, Sfundo and Mlotshwa, Nokunqoba and Thango, Bonginkosi and Lerato, Matshaka, The Role of Data Networks and APIs in Enhancing Operational Efficiency in SME: A Systematic Review (October 11, 2024). http://dx.doi.org/10.2139/ssrn.4984455 Vesković, J.; Onjia, A. Exposure and Toxicity Factors in Health Risk Assessment of Heavy Metal(loid)s in Water. Water 2025, 17(19), 2901; https://doi.org/10.3390/w17192901. Mtjilibe, Tshepang and Rameetse, Emmanuel and Mgwenya, Nkosinathi and Thango, Bonginkosi, Exploring the Challenges and Opportunities of Social Media for Organizational Engagement in SMEs: A Comprehensive Systematic Review (July 06, 2024). http://dx.doi.org/10.2139/ssrn.4998542 Rodrigues, P.; Neto, A.; Alonso do Espírito Santo, L.; Tribess, S.; Virtuoso Junior, J. Walking Football as a Multidimensional Intervention for Healthy Aging: A Scoping Review of Physical and Functional Outcomes in Older Adults. Int. J. Environ. Res. Public Health 2025, 22(10), 1533; https://doi.org/10.3390/ijerph22101533. Sechele, G., Rabedzwa, G., Nongayo, S., & Thango, B. (2024). Systematic Review on SEO and Digital Marketing Strategies for Enhancing Retail SMEs' Performance. doi: 10.20944/preprints202410.1715.v1 Burles, F.; Sallis, E.; Kopala-Sibley, D.; Iaria, G. Mitigating Head Position Bias in Perivascular Fluid Imaging: LD-ALPS, a Novel Method for DTI-ALPS Calculation. NeuroSci 2025, 6(4), 101; https://doi.org/10.3390/neurosci6040101. Muraba, Juka and Mamogobo, Mogase Keabetswe and Thango, Bonginkosi, The Balanced Scorecard Methodology: Performance Metrics and Strategy Execution in SMEs: A Systematic Review (October 21, 2024). Available at SSRN: http://dx.doi.org/10.2139/ssrn.4996929 Nhara, R.; Baloyi, J. Complementary Effects of Essential Oils and Organic Acids on Rumen Physiology as Alternatives to Antibiotic Feed Additives. Animals 2025, 15(19), 2910; https://doi.org/10.3390/ani15192910. Pingilili, A., Letsie, N., Nzimande, G., Thango, B., & Matshaka, L. (2025). Guiding IT Growth and Sustaining Performance in SMEs Through Enterprise Architecture and Information Management: A Systematic Review. Businesses, 5(2), 17. Melaku, H. M. (2023). A dynamic and adaptive cybersecurity governance framework. Journal of Cybersecurity and Privacy, 3(3), 327–350. https://doi.org/10.3390/jcp3030017 Alfaadhel, A., Almomani, I., & Ahmed, M. (2023). Risk-based cybersecurity compliance assessment system (RC2AS). Applied Sciences, 13(10), 6145. https://doi.org/10.3390/app13106145 Song, I., Jeon, S., Kim, D., Lee, M. G., & Seo, J. T. (2024). GENICS: A framework for generating attack scenarios for cybersecurity exercises on industrial control systems. Applied Sciences, 14(2), 768. https://doi.org/10.3390/app14020768 Metin, B., Özhan, F. G., & Wynn, M. (2024). Digitalisation and cybersecurity: Towards an operational framework. Electronics, 13(21), 4226. https://doi.org/10.3390/electronics13214226 Zwilling, M. (2022). Trends and challenges regarding cyber risk mitigation by CISOs—A systematic literature and experts’ opinion review based on text analytics. Sustainability, 14(3), 1311. https://doi.org/10.3390/su14031311 Hartmann, C. C., & Carmenate, J. (2021). Academic research on the role of corporate governance and IT expertise in addressing cybersecurity breaches: Implications for practice, policy, and research. Current Issues in Auditing, 15(2), A9–A23. https://DOI: 10.2308/CIIA-2020-034 Handri, E. Y., Sensuse, D. I., & Tarigan, A. (2024). Developing an agile cybersecurity framework with organizational culture approach using Q methodology. IEEE Access. DOI: 10.1109/ACCESS.2024.3432160 Hossain, S. T., Yigitcanlar, T., Nguyen, K., & Xu, Y. (2024). Understanding local government cybersecurity policy: A concept map and framework. Information, 15(6), 342. https://doi.org/10.3390/info15060342 Héroux, S., & Fortin, A. (2025). How the three lines of defense can contribute to public firms’ cybersecurity effectiveness. International Journal of Disclosure and Governance, 22(2), 377–396. https://doi.org/10.1057/s41310-024-00226-7 Vuko, T., Slapničar, S., Čular, M., & Drašček, M. (2025). Key drivers of cybersecurity audit effectiveness: A neo-institutional perspective. International Journal of Auditing, 29(1), 188–206. https://doi.org/10.1111/ijau.12365 Sterlini, P., Massacci, F., Kadenko, N., Fiebig, T., & van Eeten, M. (2019). Governance challenges for European cybersecurity policies: Stakeholder views. IEEE Security & Privacy, 18(1), 46–54. DOI: 10.1109/MSEC.2019.2945309 Kamara, I. (2024). European cybersecurity standardisation: A tale of two solitudes in view of Europe’s cyber resilience. Innovation: The European Journal of Social Science Research, 37(5), 1441–1460. https://doi.org/10.1080/13511610.2024.2349626 Bahuguna, A., Bisht, R. K., & Pande, J. (2020). Country-level cybersecurity posture assessment: Study and analysis of practices. Information Security Journal: A Global Perspective, 29(5), 250–266. https://doi.org/10.1080/19393555.2020.1767239 Proudfoot, J. G., Cram, W. A., & Madnick, S. (2024). Weathering the storm: Examining how organisations navigate the sea of cybersecurity regulations. European Journal of Information Systems, 34(3), 436–459. https://doi.org/10.1080/0960085X.2024.2345867 Backman, S., & Stevens, T. (2024). Cyber risk logics and their implications for cybersecurity. International Affairs, 100(6), 2441–2460. https://doi.org/10.1093/ia/iiae236 Motwani, D., Chitre, V., Bhosale, V., Israni, M., Sonawane, S., & Nerurkar, A. (2024). IoT security cryptographic solutions for trustworthy wireless sensor networks. Journal of Discrete Mathematical Sciences and Cryptography, 27(4), 1283–1294. https://doi.org/10.47974/JDMSC-1982 Antunes, M., Maximiano, M., & Gomes, R. (2022). A client-centered information security and cybersecurity auditing framework. Applied Sciences, 12(9), 4102. https://doi.org/10.3390/app12094102 Domínguez-Dorado, M., Cortés-Polo, D., Carmona-Murillo, J., Rodríguez-Pérez, F. J., & Galeano-Brajones, J. (2023). Fast, lightweight, and efficient cybersecurity optimization for tactical–operational management. Applied Sciences, 13(10), 6327. https://doi.org/10.3390/app12094102 Argyridou, E., Nifakos, S., Laoudias, C., Panda, S., Panaousis, E., Chandramouli, K., … & Bonacina, S. (2023). Cyber hygiene methodology for raising cybersecurity and data privacy awareness in health care organizations: Concept study. Journal of Medical Internet Research, 25, e41294. https://doi.org/10.3390/app13106327 Melaku, H. M. (2023). Context-based and adaptive cybersecurity risk management framework. Risks, 11(6), 101. https://preprints.jmir.org/preprint/41294 Argyridou, E., Nifakos, S., Laoudias, C., Panda, S., Panaousis, E., Chandramouli, K., … & Bonacina, S. (2024). Cyber hygiene methodology for raising cybersecurity and data privacy awareness in health care organizations: Concept study. Journal of Medical Internet Research, 25, e41294. https://doi.org/10.3390/risks11060101 Malaivongs, S., Kiattisin, S., & Chatjuthamard, P. (2022). Cyber trust index: A framework for rating and improving cybersecurity performance. Applied Sciences, 12(21), 11174. https://doi.org/10.1016/j.cose.2022.102840 Mishra, A., Alzoubi, Y. I., Gill, A. Q., & Anwar, M. J. (2022). Cybersecurity enterprises policies: A comparative study. Sensors, 22(2), 538. https://doi.org/10.3390/s22020538 Mishra, A., Alzoubi, Y. I., Anwar, M. J., & Gill, A. Q. (2022). Attributes impacting cybersecurity policy development: Evidence from seven nations. Computers & Security, 120, 102820. https://doi.org/10.1016/j.cose.2022.102820 Alshaikh, M. (2020). Developing cybersecurity culture to influence employee behavior: A practice perspective. Computers & Security, 98, 102003. https://doi.org/10.1016/j.cose.2020.102003 Voas, J., & Schaffer, K. (2016). Insights on formal methods in cybersecurity. Computer, 49(5), 102–105. DOI: 10.1109/MC.2016.131 Bozkus Kahyaoglu, S., & Caliyurt, K. (2018). Cyber security assurance process from the internal audit perspective. Managerial Auditing Journal, 33(4), 360–376. https://doi.org/10.1108/MAJ-02-2018-1804 Gordon, L. A., Loeb, M. P., & Zhou, L. (2020). Integrating cost–benefit analysis into the NIST cybersecurity framework via the Gordon–Loeb model. Journal of Cybersecurity, 6(1), tyaa005. https://doi.org/10.1093/cybsec/tyaa005 Zimmermann, V., & Renaud, K. (2019). Moving from a ‘human-as-problem’ to a ‘human-as-solution’ cybersecurity mindset. International Journal of Human-Computer Studies, 131, 169–187. https://doi.org/10.1016/j.ijhcs.2019.05.005 von Solms, B., & von Solms, R. (2018). Cybersecurity and information security – what goes where? Information and Computer Security, 26(1), 2–9. https://doi.org/10.1108/ICS-04-2017-0025 Waelchli, S., & Walter, Y. (2025). Reducing the risk of social engineering attacks using SOAR measures in a real world environment: A case study. Computers & Security, 148, 104137. https://doi.org/10.1016/j.cose.2024.104137 Arfaj, B. A., Mishra, S., & AlShehri, M. (2022). Efficacy of unconventional penetration testing practices. Intelligent Automation & Soft Computing, 31(1). https://doi.org/10.32604/iasc.2022.019485 Scala, N. M., Reilly, A. C., Goethals, P. L., & Cukier, M. (2019). Risk and the five hard problems of cybersecurity. Risk Analysis, 39(10), 2119–2126. https://doi.org/10.1111/risa.13309 Faruq, M. O. (2025). A meta-analysis of cybersecurity framework integration in GRC platforms: Evidence from US enterprise audits. Journal of Sustainable Development and Policy, 1(01), 224–249. https://doi.org/10.63125/kwhkmb57 Akinsulire, A. A., & Ohakawa, T. C. (2024). Enhancing cybersecurity governance in financial institutions: A quantitative study on control deficiencies and regulatory compliance. archive-1747649053.pdf Onumo, A. O. (2020). A behavioural compliance framework for effective cybersecurity governance and practice (Doctoral dissertation). http://hdl.handle.net/10454/19051 Victor, A. A., Moronkunbi, M. A., Oyedeji, O. C., Victor, P. O., & Samuel, S. A. (2024). The role of IT governance risk and compliance (IT GRC) in modern organizations. International Journal of Latest Technology in Engineering, Management & Applied Science, 13(6), 44–50. https://doi.org/10.51583/IJLTEMAS.2024.130607 Ferreira, L. V. A., Alves, C. A. D. M., Peotta de Melo, L., & Nunes, R. R. (2025). Internal audit strategies for assessing cybersecurity controls in the Brazilian financial institutions. Applied Sciences, 15(10), 5715. https://doi.org/10.3390/app15105715 Maleh, Y., Sahid, A., Alazab, M., & Belaissaoui, M. (2021). IT governance and information security: Guides, standards, and frameworks (1st ed.). CRC Press. https://doi.org/10.1201/9781003161998 Davis, R. E. (2021). Auditing information and cyber security governance: A controls-based approach (1st ed.). CRC Press. https://doi.org/10.1201/9781003099673 Olajide, J. O., Otokiti, B. O., Nwani, S., Ogunmokun, A. S., Adekunle, B. I., & Efekpogua, J. (2021). Developing internal control and risk assurance frameworks for compliance in supply chain finance. IRE Journals, 4(11), 459–461. https://www.irejournals.com/formatedpaper/1709010.pdf Plant, O. H., van Hillegersberg, J., & Aldea, A. (2022). Rethinking IT governance: Designing a framework for mitigating risk and fostering internal control in a DevOps environment. International Journal of Accounting Information Systems, 45, 100560. https://doi.org/10.1016/j.accinf.2022.100560 Mittal, D., & Damle, M. (2025). An appraisal in internal control frameworks implementation of COSO, ISO 27001 and NIST for opportunities in Industry 5.0. In 2025 Seventh International Conference on Computational Intelligence and Communication Technologies (CCICT) (pp. 345–352). https://doi.org/10.3390/app15105715 Itani, D., Itani, R., Eltweri, A. A., Faccia, A., & Wanganoo, L. (2024). Enhancing cybersecurity through compliance and auditing: A strategic approach to resilience. In 2024 2nd International Conference on Cyber Resilience (ICCR) (pp. 1–10). DOI: 10.1109/CCICT65753.2025.00061 Girn, S. S. (2024). Cybersecurity governance framework for board directors (Doctoral dissertation). https://doi.org/10.1109/ICCR61006.2024.10532959 Kumar, K. (2025). Enterprise risk management as a catalyst for strategic governance, risk, and compliance (GRC) alignment in IT companies. Digital Repository of Theses - SSBM Geneva. http://hdl.handle.net/10453/187536 Maleh, Y., Sahid, A., & Belaissaoui, M. (2021). A maturity framework for cybersecurity governance in organizations. EDPACS, 63(6), 1–22. https://repository.e-ssbm.com/index.php/rps/article/view/723 Toshitsugu, S. B. I. G. O., & Badawy, H. M. H. A. Enhancing internal controls for smart contracts: A comprehensive framework for blockchain. https://doi.org/10.1080/07366981.2020.1815354 Simić, N. (2022). The internal auditor's role in cybersecurity governance: A qualitative study about the internal auditor's influence on the people factor of cybersecurity. https://doi.org/10.47509/IJAAS.2024.v06i03.06 Taylor, M. (2024). Identifying strategies that improve organizational cybersecurity performance and the use of healthcare information in the healthcare industry using the integrated IT GRC model: A systematic review (Order No. 31148499). ProQuest Dissertations & Theses Global. internal auditor's influence on the people factor of cybersecurity Emmanuel, A. A. (2025). The impact of cybersecurity on financial reporting: Strengthening data integrity and regulatory compliance. https://www.proquest.com/docview/3039648712 Okusi, O., Obiakor, I. J., & Adeloye, F. C. Designing resilient data risk management protocols for regulatory compliance and cyber incident response. https://doi.org/10.30574/ijsra.2025.14.2.0427 Ausfelt, S. (2025). Innovative approaches to GRC: Ensuring compliance during digital transformation. Journal of Financial Compliance, 8(4), 302–316. https://doi.org/10.55248/gengpi.6.0725.2419 Situmorang, I. M. R., Azzahra, K. J., & Muda, I. (2025). The role of IT auditing in data security focusing on risk identification, strengthening internal controls, and compliance with security policies. https://doi.org/10.69554/CHSR6553 Sobowale, A., Ikponmwoba, S. O., Chima, O. K., Ezeilo, O. J., Ojonugwa, B. M., & Adesuyi, M. O. A. Conceptual framework for integrating SOX-compliant financial systems in multinational corporate governance. https://doi.org/10.61784/asat3007 Chahar, V. Legal and ethical challenges in corporate cybersecurity compliance: The impact of corruption and governance weaknesses. Indian Journal of Integrated Research in Law, 5(2), 2583–0538. https://doi.org/10.54660/.IJMRGE.2020.1.2.88-98 Ashley, C., & Preiksaitis, M. (2022). Strategic cybersecurity risk management practices for information in small and medium enterprises. Business Management Research and Applications: A Cross-Disciplinary Journal, 1(2), 109–157. https://ijirl.com/wp-content/uploads/2025/04/LEGAL-AND-ETHICAL-CHALLENGES-IN-CORPORATE-CYBER-SECURITY-COMPLIANCE-THE-IMPACT-OF-CORRUPTION-AND-GOVERNANCE-WEAKNESSES.pdf Mary, B. J. (2024). Developing a cybersecurity-accounting integration framework for critical financial infrastructure protection. https://bmrajournal.columbiasouthern.edu/index.php/bmra/article/view/3421 Buker, H. N. (2021). Financial institutions adapting to cybersecurity regulation modifications: A qualitative multiple-case study. Capella University. https://www.researchgate.net/profile/Adam-Rajuroy/publication/392621152 Okafor, C. M., Oseghale, D. O., & Ayanlaja, S. Enhancing US healthcare cybersecurity through intelligent agent–supported qualitative information systems audits. https://www.proquest.com/docview/2580688909 Onumo, A. O. (2020). A behavioural compliance framework for effective cybersecurity governance and practice (Doctoral dissertation). https://doi.org/10.51244/IJRSI.2025.120700178 Eugene, R. (2020). A Delphi study: A model to help IT management within financial firms reduce regulatory compliance costs for data privacy and cybersecurity (Doctoral dissertation, Capella University). http://hdl.handle.net/10454/19051 Nicho, M. (2018). A process model for implementing information systems security governance. Information & Computer Security, 26(1), 10–38. https://www.proquest.com/dissertations-theses/delphi-study-model-help-management-within/docview/2453677732/se-2?accountid=48944 Yamami, A., Mansouri, K., Qbadou, M., & Illoussamen, E. (2018). A new pattern for the deployment of IT governance frameworks in organizations. International Journal of Engineering and Technology, 7(4), 3459–3465. https://doi.org/10.1108/ICS-07-2016-0061 Suroso, J. S., Hwa, T. H., Syafaat, R., Pasaribu, F. A., & Mujiatun, S. (2019, August). Assessing an information security governance using IPPF in multi-finance company. In 2019 International Conference on Information Management and Technology (ICIMTech) (Vol. 1, pp. 596–601). IEEE. DOI: 10.14419/ijet.v7i4.15427 Amalia, S. P. N., & Ratnawati, S. (2019, November). Assessment of the effectiveness of internal controls in an organization based on COBIT 5 framework case study: State-owned enterprises. In 2019 7th International Conference on Cyber and IT Service Management (CITSM) (Vol. 7, pp. 1–5). IEEE. https://doi.org/10.1109/ICIMTech.2019.8843733 du Fresne, A. J. (2020). Can audits be an effective method to improve information governance compliance objectives? (Order No. 28220145). ProQuest Dissertations & Theses Global. https://doi.org/10.1109/CITSM47753.2019.8965409 Aguilar-Alonso, I., & Vergara-Calderón, J. (2020). Identification of IT governance frameworks and standards implemented in organizations. In 2020 IEEE International Conference on Sustainable Engineering and Creative Computing (ICSECC) (pp. 36–41). Can Audits Be an Effective Method to Improve Information Governance Compliance Objectives? – ProQuest Al-Sartawi, A. M. M. (2020). Information technology governance and cybersecurity at the board level. International Journal of Critical Infrastructures, 16(2), 150–161. https://doi.org/10.1109/ICSECC51444.2020.9557561 Wilkin, C. L., & Chenhall, R. H. (2020). Information technology governance: Reflections on the past and future directions. Journal of Information Systems, 34(2), 257–292. https://doi.org/10.1504/IJCIS.2020.107265 Li, H. J., Chang, S. I., Wang, T., & Chang, L. M. (2020). Information technology internal control items for the post-implementation phase of enterprise resource planning systems. Journal of Information Systems, 34(3), 159–197. https://doi.org/10.2308/isys-52632 Al-Hashimi, M., Othman, M., Sulaiman, H., & Zaidan, A. A. (2018). Information security governance frameworks in cloud computing: An overview. Journal of Advanced Computer Science and Technology Research, 8(2), 67–81. https://doi.org/10.2308/isys-52615 Kosasi, S., & Wibowo, V. (2018, September). Improving information service performance of family businesses through IT governance. In 2018 International Seminar on Application for Technology of Information and Communication (pp. 11–16). IEEE. https://www.researchgate.net/publication/326234567 Ettish, A. A., El-Gazzar, S. M., & Jacob, R. A. (2017). Integrating internal control frameworks for effective corporate information technology governance. JISTEM-Journal of Information Systems and Technology Management, 14(3), 361–370. https://www.jurnal.stmikpontianak.ac.id/file/SANDY_KOSAS_-_VELWIN_WIBOWO_-_ISEMANTIC_2018.pdf Bicaku, A., Tauber, M., & Delsing, J. (2020). Security standard compliance and continuous verification for industrial Internet of Things. International Journal of Distributed Sensor Networks, 16(6). https://doi.org/10.4301/S1807-17752017000300004 Janahi, L. A. M. (2016). The importance of accountability in IT governance practice in the public sector: A case study of the kingdom of Bahrain (Order No. 28469749). ProQuest Dissertations & Theses Global. https://doi.org/10.1177/1550147720922731 Steinbart, P. J., Raschke, R. L., Gal, G., & Dilla, W. N. (2018). The influence of a good relationship between the internal audit and information security functions on information security outcomes. Accounting, Organizations and Society, 71, 15–29. https://www.proquest.com/dissertations-theses/importance-accountability-governance-practice/docview/2570307817/se-2 Papazafeiropoulou, A., & Spanaki, K. (2016). Understanding governance, risk and compliance information systems (GRC IS): The experts view. Information Systems Frontiers, 18(6), 1251–1263. https://doi.org/10.1016/j.aos.2018.04.005 Antonucci, D. (2017). The cyber risk handbook: Creating and measuring effective cybersecurity capabilities. John Wiley & Sons. https://doi.org/10.1002/9781119309741.ch6 Edwards, J., & Weaver, G. (2024). The Cybersecurity Guide to Governance, Risk, and Compliance. John Wiley & Sons. Available at: https://books.google.com/books?hl=en&lr=&id=Y2b8EAAAQBAJ&oi=fnd&pg=PP1&dq=The+Cybersecurity+Guide+to+Governance,+Risk,+and+ Compliance&ots=DXRA4HQX 6p&sig=wITJ0BIerlipEMMKy EUFkjHIPWA Davis, R. E. (2021). Auditing Information and Cyber Security Governance: A Controls-based Approach. CRC Press. https://doi.org/10.1201/9781003099673 Maleh, Y., Sahid, A., Alazab, M., & Belaissaoui, M. (2021). IT governance and information security: Guides, standards, and frameworks. CRC Press. https://doi.org/10.1201/9781003161998 Kohnke, A., Shoemaker, D., & Sigler, K. E. (2016). The complete guide to cybersecurity risks and controls. CRC Press. https://books.google.com/books?hl=en&lr=&id=7sX1CwAAQBAJ&oi=fnd&pg=PP1&dq=The+ Complete+Guide+to+Cybersecurity+ Risks+and+Controls&ots=0LtBYtH 4TR&sig=NHzDyUAz4eDurtoT qeeKcCe2M1s Tari Schreider, S. S. C. P., CISM, C., & CISO, I. (2017). Building effective cybersecurity programs: a security manager’s handbook. Rothstein Publishing. Available at:https://books.google.com/books?hl=en&lr=&id=R8E6DwAAQBAJ&oi=fnd&pg=PT14&dq=Building+Effective+Cybersecurity+Programs:+A+ Security+Manager%27s+Hand book&ots=hcTc8peyrR&am p;sig=FPfEJ0MUsa1e4Ah KAUtRq-oL8ug Savaş, S., Karataş, S. Cyber governance studies in ensuring cybersecurity: an overview of cybersecurity governance. Int. Cybersecur. Law Rev. 3, 7–34 (2022). https://doi.org/10.1365/s43439-021-00045-4 Yusif, S., & Hafeez-Baig, A. (2021). A conceptual model for cybersecurity governance. Journal of applied security research, 16(4), 490-513. https://doi.org/10.1080/19361610.2021.1918995 Zukis, B. (2016). Information technology and cybersecurity governance in a digital world. The Handbook of Board Governance: A Comprehensive Guide for Public, Private and Not‐for‐Profit Board Members, 555-573. Available: https://doi.org/10.1002/9781119245445.ch28 Heim, T. N. (2023). Global governance and regulation of cybersecurity: Towards coherence or fragmentation?. Available at : https://doi.org/10.3990/1.9789036556248 Weber, R. H. (2025). Cybersecurity and internet governance. In A Research Agenda for Cybersecurity Law and Policy (pp. 33-54). Edward Elgar Publishing. Available at: https://doi.org/10.4337/9781803929194.00008 Additional Declarations The authors declare no competing interests. Supplementary Files AppendixA.docx Cite Share Download PDF Status: Posted Version 1 posted You are reading this latest preprint version Research Square lets you share your work early, gain feedback from the community, and start making changes to your manuscript prior to peer review in a journal. As a division of Research Square Company, we’re committed to making research communication faster, fairer, and more useful. We do this by developing innovative software and high quality services for the global research community. Our growing team is made up of researchers and industry professionals working together to solve the most critical problems facing scientific publishing. Also discoverable on Platform About Our Team In Review Editorial Policies Advisory Board Help Center Resources Author Services Accessibility API Access RSS feed Manage Cookie Preferences © Research Square 2026 | ISSN 2693-5015 (online) Privacy Policy Terms of Service Do Not Sell My Personal Information {"props":{"pageProps":{"initialData":{"identity":"rs-7817804","acceptedTermsAndConditions":true,"allowDirectSubmit":true,"archivedVersions":[],"articleType":"Systematic Review","associatedPublications":[],"authors":[{"id":527124485,"identity":"463f6276-f749-4d93-b7b2-bc29d9c6a359","order_by":0,"name":"Wandile Moeti","email":"data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAZAAAAAyAQMAAABI0h/eAAAABlBMVEX///8AAABVwtN+AAAACXBIWXMAAA7EAAAOxAGVKw4bAAABI0lEQVRIie3RMUvDQBTA8RdOzuWVrJel/QoXAp1C8lVyBDIFKQjBweEgkCxBV0U/R8Xt4MAu0q6KS4tDF4dMTqJerSDCUR0F778l5MfLvQNwuf5gPiFK9TzGtJXmkW7f8l0kaKlYnR0VQ47KkxuCPxG+wCjCWx1xln2R3Wkcs0FTiKtgvX7EKj5IAfkEjhMYtcoqvJpWLGhicX1RhjXOi0M0hMNNDl6XWQkhZMpCM0U+lF49aLToPghVQMBOKIExE+ZLeT9bGfL2SV4VUH9pJUj2Iq42x7+D0BC1JV6jAJl9CiNmydIsOejK8PxynotO0wkXJzkyZp+SLrTSL+Yq/f3Zsn+qEtG29ZT3z8lwdGqfYtsIUJ795n6+IfsfuVwu13/tHQ2iWp7OFvT0AAAAAElFTkSuQmCC","orcid":"","institution":"University of Johannesburg","correspondingAuthor":true,"prefix":"","firstName":"Wandile","middleName":"","lastName":"Moeti","suffix":""},{"id":527124486,"identity":"e7943706-7359-4cd9-8805-ad946aa64272","order_by":1,"name":"Sibusiso Moyo","email":"","orcid":"","institution":"University of Johannesburg","correspondingAuthor":false,"prefix":"","firstName":"Sibusiso","middleName":"","lastName":"Moyo","suffix":""},{"id":527124487,"identity":"99a72262-e143-45c4-8d0c-cd2103029ff0","order_by":2,"name":"Asavela Kanzi","email":"","orcid":"","institution":"University of Johannesburg","correspondingAuthor":false,"prefix":"","firstName":"Asavela","middleName":"","lastName":"Kanzi","suffix":""}],"badges":[],"createdAt":"2025-10-09 13:04:31","currentVersionCode":1,"declarations":{"humanSubjects":false,"vertebrateSubjects":false,"conflictsOfInterestStatement":false,"humanSubjectEthicalGuidelines":false,"humanSubjectConsent":false,"humanSubjectClinicalTrial":false,"humanSubjectCaseReport":false,"vertebrateSubjectEthicalGuidelines":false},"doi":"10.21203/rs.3.rs-7817804/v1","doiUrl":"https://doi.org/10.21203/rs.3.rs-7817804/v1","draftVersion":[],"editorialEvents":[],"editorialNote":"","failedWorkflow":false,"files":[{"id":93201032,"identity":"7a9cc66b-5887-4dcf-9f88-042940d2c318","added_by":"auto","created_at":"2025-10-10 06:55:45","extension":"docx","order_by":0,"title":"","display":"","copyAsset":false,"role":"acdc-reference","size":2497994,"visible":true,"origin":"","legend":"","description":"","filename":"ComplianceandInternalControlsASystematicReviewofStandardsandPracticesinCyberSecurityGovernanceFinalDraft.docx","url":"https://assets-eu.researchsquare.com/files/rs-7817804/v1/b4d91c3dbb285cdcf2a37cee.docx"},{"id":93201038,"identity":"52bc3ba9-722f-41f6-a19d-852714107823","added_by":"auto","created_at":"2025-10-10 06:55:45","extension":"json","order_by":1,"title":"","display":"","copyAsset":false,"role":"acdc-reference","size":342,"visible":true,"origin":"","legend":"","description":"","filename":"rs7817804.json","url":"https://assets-eu.researchsquare.com/files/rs-7817804/v1/fff972eb20d148702a040dfa.json"},{"id":93201045,"identity":"208f7662-7566-4ebc-97b8-31b5d2a89a88","added_by":"auto","created_at":"2025-10-10 06:55:45","extension":"xml","order_by":2,"title":"","display":"","copyAsset":false,"role":"acdc-reference","size":303219,"visible":true,"origin":"","legend":"","description":"","filename":"rs78178040enriched.xml","url":"https://assets-eu.researchsquare.com/files/rs-7817804/v1/9195f69a55574086a8ad3499.xml"},{"id":93201319,"identity":"fda79683-ddbc-4fd9-bb06-6cc48eb11754","added_by":"auto","created_at":"2025-10-10 07:03:45","extension":"png","order_by":5,"title":"","display":"","copyAsset":false,"role":"acdc-reference","size":74039,"visible":true,"origin":"","legend":"","description":"","filename":"floatimage1.png","url":"https://assets-eu.researchsquare.com/files/rs-7817804/v1/f0d9e0b3f1dba9192d1c6cc1.png"},{"id":93201037,"identity":"054b5c72-5a75-4647-902e-b23cfb9a0588","added_by":"auto","created_at":"2025-10-10 06:55:45","extension":"png","order_by":6,"title":"","display":"","copyAsset":false,"role":"acdc-reference","size":201158,"visible":true,"origin":"","legend":"","description":"","filename":"floatimage10.png","url":"https://assets-eu.researchsquare.com/files/rs-7817804/v1/9bccab69e656a701550ab1fe.png"},{"id":93201322,"identity":"ba733865-39fd-4d6d-aece-2b72445e2b17","added_by":"auto","created_at":"2025-10-10 07:03:45","extension":"png","order_by":7,"title":"","display":"","copyAsset":false,"role":"acdc-reference","size":229642,"visible":true,"origin":"","legend":"","description":"","filename":"floatimage11.png","url":"https://assets-eu.researchsquare.com/files/rs-7817804/v1/7705b2ca2cee81610a13e429.png"},{"id":93201040,"identity":"352d7f65-a544-41a0-9f2f-cd8b70973299","added_by":"auto","created_at":"2025-10-10 06:55:45","extension":"png","order_by":8,"title":"","display":"","copyAsset":false,"role":"acdc-reference","size":150840,"visible":true,"origin":"","legend":"","description":"","filename":"floatimage12.png","url":"https://assets-eu.researchsquare.com/files/rs-7817804/v1/692f7c9df95e9a6a17b7a4ad.png"},{"id":93201060,"identity":"940bbee7-6b06-4225-bf56-c9d398c736c0","added_by":"auto","created_at":"2025-10-10 06:55:46","extension":"png","order_by":9,"title":"","display":"","copyAsset":false,"role":"acdc-reference","size":235387,"visible":true,"origin":"","legend":"","description":"","filename":"floatimage13.png","url":"https://assets-eu.researchsquare.com/files/rs-7817804/v1/82018b2820ad703f3bca21f4.png"},{"id":93201053,"identity":"bbc53435-28e6-4a5b-a7e7-a6bae2d70a3d","added_by":"auto","created_at":"2025-10-10 06:55:46","extension":"png","order_by":10,"title":"","display":"","copyAsset":false,"role":"acdc-reference","size":255194,"visible":true,"origin":"","legend":"","description":"","filename":"floatimage14.png","url":"https://assets-eu.researchsquare.com/files/rs-7817804/v1/e8c8d9824c37bba9ba6625c8.png"},{"id":93201324,"identity":"3da71160-b0a3-4744-ab51-4b7181d005d1","added_by":"auto","created_at":"2025-10-10 07:03:45","extension":"png","order_by":11,"title":"","display":"","copyAsset":false,"role":"acdc-reference","size":52128,"visible":true,"origin":"","legend":"","description":"","filename":"floatimage2.png","url":"https://assets-eu.researchsquare.com/files/rs-7817804/v1/44b2cd42c72ccca7d0738f03.png"},{"id":93201051,"identity":"6b68c147-04e4-4de0-b504-6e810e26ab02","added_by":"auto","created_at":"2025-10-10 06:55:46","extension":"png","order_by":12,"title":"","display":"","copyAsset":false,"role":"acdc-reference","size":201810,"visible":true,"origin":"","legend":"","description":"","filename":"floatimage3.png","url":"https://assets-eu.researchsquare.com/files/rs-7817804/v1/df6faea191ec9f5197d10c92.png"},{"id":93201327,"identity":"57dfe1db-32e6-43da-ae04-9ec6e06395fe","added_by":"auto","created_at":"2025-10-10 07:03:46","extension":"png","order_by":13,"title":"","display":"","copyAsset":false,"role":"acdc-reference","size":78386,"visible":true,"origin":"","legend":"","description":"","filename":"floatimage4.png","url":"https://assets-eu.researchsquare.com/files/rs-7817804/v1/4bcea3ac536fef92dc26732c.png"},{"id":93201073,"identity":"7d2e16d8-5c7b-4433-a4fd-d517f59a0f70","added_by":"auto","created_at":"2025-10-10 06:55:46","extension":"png","order_by":14,"title":"","display":"","copyAsset":false,"role":"acdc-reference","size":316930,"visible":true,"origin":"","legend":"","description":"","filename":"floatimage5.png","url":"https://assets-eu.researchsquare.com/files/rs-7817804/v1/0dbb92d6fc49e58078076ef7.png"},{"id":93202393,"identity":"914887e7-0f36-4ab0-9416-aa87bd9d8c0f","added_by":"auto","created_at":"2025-10-10 07:11:46","extension":"png","order_by":15,"title":"","display":"","copyAsset":false,"role":"acdc-reference","size":85061,"visible":true,"origin":"","legend":"","description":"","filename":"floatimage6.png","url":"https://assets-eu.researchsquare.com/files/rs-7817804/v1/46323c04f1c169e4d6aefb20.png"},{"id":93201072,"identity":"87405a7e-ecae-4328-a0b1-b5ddb58ea622","added_by":"auto","created_at":"2025-10-10 06:55:46","extension":"png","order_by":16,"title":"","display":"","copyAsset":false,"role":"acdc-reference","size":68085,"visible":true,"origin":"","legend":"","description":"","filename":"floatimage7.png","url":"https://assets-eu.researchsquare.com/files/rs-7817804/v1/0f67dfd7b0653dcf6d035e8a.png"},{"id":93201056,"identity":"d3dc010c-f4f3-47e8-aed4-fbfdb60ed679","added_by":"auto","created_at":"2025-10-10 06:55:46","extension":"png","order_by":17,"title":"","display":"","copyAsset":false,"role":"acdc-reference","size":111036,"visible":true,"origin":"","legend":"","description":"","filename":"floatimage8.png","url":"https://assets-eu.researchsquare.com/files/rs-7817804/v1/5f314116624d43b44dd3b40c.png"},{"id":93201052,"identity":"17d26f87-7d84-4b36-aa98-dcbd76fa2965","added_by":"auto","created_at":"2025-10-10 06:55:46","extension":"png","order_by":18,"title":"","display":"","copyAsset":false,"role":"acdc-reference","size":206056,"visible":true,"origin":"","legend":"","description":"","filename":"floatimage9.png","url":"https://assets-eu.researchsquare.com/files/rs-7817804/v1/dad034786c5bf4e05a96ff18.png"},{"id":93201054,"identity":"88a1b62e-4e6a-4665-82c3-90fdf06f97ec","added_by":"auto","created_at":"2025-10-10 06:55:46","extension":"png","order_by":19,"title":"","display":"","copyAsset":false,"role":"acdc-reference","size":10213,"visible":true,"origin":"","legend":"","description":"","filename":"Onlinefloatimage1.png","url":"https://assets-eu.researchsquare.com/files/rs-7817804/v1/43757ae818d7e83617489c29.png"},{"id":93202392,"identity":"418c05ee-5324-4753-a739-438e5fb8450a","added_by":"auto","created_at":"2025-10-10 07:11:46","extension":"png","order_by":20,"title":"","display":"","copyAsset":false,"role":"acdc-reference","size":43940,"visible":true,"origin":"","legend":"","description":"","filename":"Onlinefloatimage10.png","url":"https://assets-eu.researchsquare.com/files/rs-7817804/v1/6bef741c6411d0034a35ddce.png"},{"id":93201329,"identity":"f1d73381-c3d5-4cb5-a710-e2860b4f5ff6","added_by":"auto","created_at":"2025-10-10 07:03:46","extension":"png","order_by":21,"title":"","display":"","copyAsset":false,"role":"acdc-reference","size":48660,"visible":true,"origin":"","legend":"","description":"","filename":"Onlinefloatimage11.png","url":"https://assets-eu.researchsquare.com/files/rs-7817804/v1/68c6f96dcac12c451bb856b7.png"},{"id":93201049,"identity":"cc73a205-06fe-476d-b920-02ed0e08a970","added_by":"auto","created_at":"2025-10-10 06:55:46","extension":"png","order_by":22,"title":"","display":"","copyAsset":false,"role":"acdc-reference","size":33503,"visible":true,"origin":"","legend":"","description":"","filename":"Onlinefloatimage12.png","url":"https://assets-eu.researchsquare.com/files/rs-7817804/v1/e8b438feec8843c1c7b5d1c1.png"},{"id":93201074,"identity":"2c600fe2-f16b-40a2-8b0b-fc23bd79deb2","added_by":"auto","created_at":"2025-10-10 06:55:46","extension":"png","order_by":23,"title":"","display":"","copyAsset":false,"role":"acdc-reference","size":47883,"visible":true,"origin":"","legend":"","description":"","filename":"Onlinefloatimage13.png","url":"https://assets-eu.researchsquare.com/files/rs-7817804/v1/4ab59d8009ad19cd2a3c5a37.png"},{"id":93201332,"identity":"bfa78ede-bc97-4561-b9e9-52ac03c9f15d","added_by":"auto","created_at":"2025-10-10 07:03:46","extension":"png","order_by":24,"title":"","display":"","copyAsset":false,"role":"acdc-reference","size":52914,"visible":true,"origin":"","legend":"","description":"","filename":"Onlinefloatimage14.png","url":"https://assets-eu.researchsquare.com/files/rs-7817804/v1/c3cb8448405ce6a5cc5a1a87.png"},{"id":93201062,"identity":"7bc5682b-81fa-4833-b3ee-4a6b65266853","added_by":"auto","created_at":"2025-10-10 06:55:46","extension":"png","order_by":25,"title":"","display":"","copyAsset":false,"role":"acdc-reference","size":19145,"visible":true,"origin":"","legend":"","description":"","filename":"Onlinefloatimage2.png","url":"https://assets-eu.researchsquare.com/files/rs-7817804/v1/52dfcab097709b36c8b4bb2c.png"},{"id":93201330,"identity":"f8a5c176-5e97-4983-ba5c-ffc48f9fa3de","added_by":"auto","created_at":"2025-10-10 07:03:46","extension":"png","order_by":26,"title":"","display":"","copyAsset":false,"role":"acdc-reference","size":37196,"visible":true,"origin":"","legend":"","description":"","filename":"Onlinefloatimage3.png","url":"https://assets-eu.researchsquare.com/files/rs-7817804/v1/c1f064ffdf438c061b3c8db4.png"},{"id":93201333,"identity":"d43b4a1c-645d-4b19-b131-7d44b06340cf","added_by":"auto","created_at":"2025-10-10 07:03:46","extension":"png","order_by":27,"title":"","display":"","copyAsset":false,"role":"acdc-reference","size":24611,"visible":true,"origin":"","legend":"","description":"","filename":"Onlinefloatimage4.png","url":"https://assets-eu.researchsquare.com/files/rs-7817804/v1/2e72c1326a878874bb9a1ae4.png"},{"id":93201063,"identity":"14c9cdc5-696b-459e-8483-d0df11948636","added_by":"auto","created_at":"2025-10-10 06:55:46","extension":"png","order_by":28,"title":"","display":"","copyAsset":false,"role":"acdc-reference","size":59050,"visible":true,"origin":"","legend":"","description":"","filename":"Onlinefloatimage5.png","url":"https://assets-eu.researchsquare.com/files/rs-7817804/v1/ae0a12b73ddff17ea50f0d45.png"},{"id":93201069,"identity":"1f82bdca-5255-412c-a624-448131bfa742","added_by":"auto","created_at":"2025-10-10 06:55:46","extension":"png","order_by":29,"title":"","display":"","copyAsset":false,"role":"acdc-reference","size":25915,"visible":true,"origin":"","legend":"","description":"","filename":"Onlinefloatimage6.png","url":"https://assets-eu.researchsquare.com/files/rs-7817804/v1/e964ee1fd141c2bbcaee9120.png"},{"id":93201068,"identity":"e08edf81-be7b-41fa-bc25-7588e2502777","added_by":"auto","created_at":"2025-10-10 06:55:46","extension":"png","order_by":30,"title":"","display":"","copyAsset":false,"role":"acdc-reference","size":22044,"visible":true,"origin":"","legend":"","description":"","filename":"Onlinefloatimage7.png","url":"https://assets-eu.researchsquare.com/files/rs-7817804/v1/48f78ee07d40de87e5f0d3c1.png"},{"id":93201334,"identity":"c3c13e77-d81d-4472-be24-3e2ccf498762","added_by":"auto","created_at":"2025-10-10 07:03:46","extension":"png","order_by":31,"title":"","display":"","copyAsset":false,"role":"acdc-reference","size":27870,"visible":true,"origin":"","legend":"","description":"","filename":"Onlinefloatimage8.png","url":"https://assets-eu.researchsquare.com/files/rs-7817804/v1/5fe335cffd41b60493e8ebc8.png"},{"id":93201061,"identity":"05c0a068-3578-49b3-aa77-b2fc1eee7555","added_by":"auto","created_at":"2025-10-10 06:55:46","extension":"png","order_by":32,"title":"","display":"","copyAsset":false,"role":"acdc-reference","size":43723,"visible":true,"origin":"","legend":"","description":"","filename":"Onlinefloatimage9.png","url":"https://assets-eu.researchsquare.com/files/rs-7817804/v1/359418e4659453d2c0490241.png"},{"id":93201075,"identity":"a0d7e450-8c88-43ed-94bc-7391e717cd3b","added_by":"auto","created_at":"2025-10-10 06:55:46","extension":"xml","order_by":33,"title":"","display":"","copyAsset":false,"role":"acdc-reference","size":299536,"visible":true,"origin":"","legend":"","description":"","filename":"rs78178040structuring.xml","url":"https://assets-eu.researchsquare.com/files/rs-7817804/v1/b7741d74a86fb18e2fb4eda5.xml"},{"id":93201076,"identity":"eb45be32-0084-43ff-b4cd-9c0bb699ab22","added_by":"auto","created_at":"2025-10-10 06:55:47","extension":"html","order_by":34,"title":"","display":"","copyAsset":false,"role":"acdc-reference","size":311733,"visible":true,"origin":"","legend":"","description":"","filename":"earlyproof.html","url":"https://assets-eu.researchsquare.com/files/rs-7817804/v1/24caecf535a5a0bc6101a110.html"},{"id":93201316,"identity":"ba61716a-0576-40eb-b14f-84b9c73f7720","added_by":"auto","created_at":"2025-10-10 07:03:45","extension":"png","order_by":1,"title":"Figure 1","display":"","copyAsset":false,"role":"figure","size":68936,"visible":true,"origin":"","legend":"\u003cp\u003eProcedures and Stages of the Review.\u003c/p\u003e","description":"","filename":"1.png","url":"https://assets-eu.researchsquare.com/files/rs-7817804/v1/963cfb13094d8e983e0bad1e.png"},{"id":93201028,"identity":"2bb877ba-11a5-4b06-b978-054b9c8ee55d","added_by":"auto","created_at":"2025-10-10 06:55:45","extension":"png","order_by":2,"title":"Figure 2","display":"","copyAsset":false,"role":"figure","size":67668,"visible":true,"origin":"","legend":"\u003cp\u003eFlow of Data Selection and Extraction\u003c/p\u003e","description":"","filename":"2.png","url":"https://assets-eu.researchsquare.com/files/rs-7817804/v1/c01af7aedcefae56f6f356dc.png"},{"id":93201029,"identity":"e3e219f6-4377-46f5-91f8-d89984f47c7e","added_by":"auto","created_at":"2025-10-10 06:55:45","extension":"png","order_by":3,"title":"Figure 3","display":"","copyAsset":false,"role":"figure","size":362085,"visible":true,"origin":"","legend":"\u003cp\u003ePotential Systematic Error Assessment Procedure.\u003c/p\u003e","description":"","filename":"3.png","url":"https://assets-eu.researchsquare.com/files/rs-7817804/v1/bed93d9e4d5f214811d3efce.png"},{"id":93201318,"identity":"54ee3c65-4c6a-4bb3-a426-936144d5f49c","added_by":"auto","created_at":"2025-10-10 07:03:45","extension":"png","order_by":4,"title":"Figure 4","display":"","copyAsset":false,"role":"figure","size":247645,"visible":true,"origin":"","legend":"\u003cp\u003eSystematic Review Process for Data Mining and Business Intelligence in SMEs.\u003c/p\u003e","description":"","filename":"4.png","url":"https://assets-eu.researchsquare.com/files/rs-7817804/v1/22d71cbff7703cf5e1d5efb8.png"},{"id":93201317,"identity":"847c938f-0f76-4312-a8f6-f42e559c10ac","added_by":"auto","created_at":"2025-10-10 07:03:45","extension":"png","order_by":5,"title":"Figure 5","display":"","copyAsset":false,"role":"figure","size":446775,"visible":true,"origin":"","legend":"\u003cp\u003eProposed PRISMA Flowchart.\u003c/p\u003e","description":"","filename":"5.png","url":"https://assets-eu.researchsquare.com/files/rs-7817804/v1/a0fae131f73e3357a12f4b3e.png"},{"id":93201033,"identity":"e9af04b1-763f-4e9f-8cfe-772770435a77","added_by":"auto","created_at":"2025-10-10 06:55:45","extension":"png","order_by":6,"title":"Figure 6","display":"","copyAsset":false,"role":"figure","size":70887,"visible":true,"origin":"","legend":"\u003cp\u003eCategorization by Research Period.\u003c/p\u003e","description":"","filename":"6.png","url":"https://assets-eu.researchsquare.com/files/rs-7817804/v1/8f7e748e990ee6dbc6d1dc97.png"},{"id":93202389,"identity":"23336260-30b8-427e-9ff6-b69196456c4e","added_by":"auto","created_at":"2025-10-10 07:11:45","extension":"png","order_by":7,"title":"Figure 7","display":"","copyAsset":false,"role":"figure","size":1241160,"visible":true,"origin":"","legend":"\u003cp\u003eGeographic Distribution of Studies.\u003c/p\u003e","description":"","filename":"7.png","url":"https://assets-eu.researchsquare.com/files/rs-7817804/v1/1b744834fd49d3ede2ed5080.png"},{"id":93201321,"identity":"4b92ecc5-6876-4c27-a300-6ab0021e9454","added_by":"auto","created_at":"2025-10-10 07:03:45","extension":"png","order_by":8,"title":"Figure 8","display":"","copyAsset":false,"role":"figure","size":113953,"visible":true,"origin":"","legend":"\u003cp\u003eDocument Type Distribution.\u003c/p\u003e","description":"","filename":"8.png","url":"https://assets-eu.researchsquare.com/files/rs-7817804/v1/5bf94e35e57fe73dd7c9b744.png"},{"id":93201323,"identity":"75160a9a-e698-46c9-8fdd-df070fafc334","added_by":"auto","created_at":"2025-10-10 07:03:45","extension":"png","order_by":9,"title":"Figure 9","display":"","copyAsset":false,"role":"figure","size":85347,"visible":true,"origin":"","legend":"\u003cp\u003eIndexing Sources.\u003c/p\u003e","description":"","filename":"9.png","url":"https://assets-eu.researchsquare.com/files/rs-7817804/v1/7f4b1bec3218c6e9397fa768.png"},{"id":93202390,"identity":"2f38708e-b5b1-4351-99c7-dd2a78a14d59","added_by":"auto","created_at":"2025-10-10 07:11:45","extension":"png","order_by":10,"title":"Figure 10","display":"","copyAsset":false,"role":"figure","size":329233,"visible":true,"origin":"","legend":"\u003cp\u003eFrameworks \u0026amp; Standards Used.\u003c/p\u003e","description":"","filename":"10.png","url":"https://assets-eu.researchsquare.com/files/rs-7817804/v1/bcee8abecb743464c3e40be4.png"},{"id":93201048,"identity":"24117afd-d51b-4c9a-af26-375b6b73f92b","added_by":"auto","created_at":"2025-10-10 06:55:45","extension":"png","order_by":11,"title":"Figure 11","display":"","copyAsset":false,"role":"figure","size":305667,"visible":true,"origin":"","legend":"\u003cp\u003eGrouped Roll-up Summary.\u003c/p\u003e","description":"","filename":"11.png","url":"https://assets-eu.researchsquare.com/files/rs-7817804/v1/286c081f32e7b381ff1cd218.png"},{"id":93201043,"identity":"33a0da0e-80ca-4b5a-8e38-f785c1494503","added_by":"auto","created_at":"2025-10-10 06:55:45","extension":"png","order_by":12,"title":"Figure 12","display":"","copyAsset":false,"role":"figure","size":318836,"visible":true,"origin":"","legend":"\u003cp\u003eTools, Models, and Analytical Approaches Used.\u003c/p\u003e","description":"","filename":"12.png","url":"https://assets-eu.researchsquare.com/files/rs-7817804/v1/0ac4e2a1529ee9e0fbac7533.png"},{"id":93201044,"identity":"2bf28cf1-bc17-48c5-a298-ef756490608d","added_by":"auto","created_at":"2025-10-10 06:55:45","extension":"png","order_by":13,"title":"Figure 13","display":"","copyAsset":false,"role":"figure","size":407552,"visible":true,"origin":"","legend":"\u003cp\u003eGovernance and Control Types Identified in Reviewed Studies.\u003c/p\u003e","description":"","filename":"13.png","url":"https://assets-eu.researchsquare.com/files/rs-7817804/v1/7a5bdb4fe1a100ccc65e0d23.png"},{"id":93201050,"identity":"f3bb7d6b-09b0-4587-983d-d2a8139d0576","added_by":"auto","created_at":"2025-10-10 06:55:46","extension":"png","order_by":14,"title":"Figure 14","display":"","copyAsset":false,"role":"figure","size":646058,"visible":true,"origin":"","legend":"\u003cp\u003eSectoral Distribution of Dashboard and Governance Studies.\u003c/p\u003e","description":"","filename":"14.png","url":"https://assets-eu.researchsquare.com/files/rs-7817804/v1/903be004115f2793fea11f28.png"},{"id":93202391,"identity":"53b44dcf-4a56-4346-8558-7c09f62c5b3e","added_by":"auto","created_at":"2025-10-10 07:11:45","extension":"png","order_by":15,"title":"Figure 15","display":"","copyAsset":false,"role":"figure","size":524022,"visible":true,"origin":"","legend":"\u003cp\u003eGovernance and Implementation Challenges in Dashboard and Control Studies.\u003c/p\u003e","description":"","filename":"15.png","url":"https://assets-eu.researchsquare.com/files/rs-7817804/v1/9d190f4ca0baf263bd1331eb.png"},{"id":93201070,"identity":"8ba23470-9a29-4f88-8ae2-9e7448126ffe","added_by":"auto","created_at":"2025-10-10 06:55:46","extension":"png","order_by":16,"title":"Figure 16","display":"","copyAsset":false,"role":"figure","size":763237,"visible":true,"origin":"","legend":"\u003cp\u003eGovernance and Implementation Recommendations from Reviewed Studies\u003c/p\u003e","description":"","filename":"16.png","url":"https://assets-eu.researchsquare.com/files/rs-7817804/v1/b98c76deb7250861e2226c60.png"},{"id":93202563,"identity":"5a7124a9-2ba2-4662-8957-c87e1b9e79bf","added_by":"auto","created_at":"2025-10-10 07:19:50","extension":"pdf","order_by":0,"title":"","display":"","copyAsset":false,"role":"manuscript-pdf","size":8707043,"visible":true,"origin":"","legend":"","description":"","filename":"manuscript.pdf","url":"https://assets-eu.researchsquare.com/files/rs-7817804/v1/ab244258-16e4-46d9-85d6-f4c8b75d129d.pdf"},{"id":93201026,"identity":"e7d8f9c5-5b02-46de-9b2c-53e822aa0ccf","added_by":"auto","created_at":"2025-10-10 06:55:45","extension":"docx","order_by":1,"title":"","display":"","copyAsset":false,"role":"supplement","size":34330,"visible":true,"origin":"","legend":"","description":"","filename":"AppendixA.docx","url":"https://assets-eu.researchsquare.com/files/rs-7817804/v1/18fa674e6057de3f438cb149.docx"}],"financialInterests":"The authors declare no competing interests.","formattedTitle":"\u003cp\u003eCompliance and Internal Controls: Standards and Practices in Cyber Security Governance\u003c/p\u003e","fulltext":[{"header":"Introduction","content":"\u003cp\u003e\u003cdiv class=\"BlockQuote\"\u003e\u003cp\u003eIn today\u0026rsquo;s rapidly evolving digital landscape, the adoption of compliance standards and internal control mechanisms has transformed how cybersecurity governance is designed and implemented. These mechanisms are now foundational to resilience against cyber threats through oversight, risk management, and accountability (Edwards \u0026amp; Weaver, 2024; Maleh et al., \u003cspan citationid=\"CR50\" class=\"CitationRef\"\u003e2021\u003c/span\u003e). Research shows that adherence to frameworks such as ISO 27001, NIST CSF, COBIT, and data-protection regulations (e.g., GDPR) strengthens governance, optimizes security strategy, and improves risk mitigation across organization sizes and sectors (Gordon et al., \u003cspan citationid=\"CR39\" class=\"CitationRef\"\u003e2020\u003c/span\u003e; Kamara, \u003cspan citationid=\"CR23\" class=\"CitationRef\"\u003e2024\u003c/span\u003e; Yusif \u0026amp; Hafeez-Baig, \u003cspan citationid=\"CR97\" class=\"CitationRef\"\u003e2021\u003c/span\u003e). At the same time, organizations face rising pressures from proliferating and sometimes conflicting regulatory requirements, complex digital ecosystems, and the need to balance compliance with operational efficiency (Proudfoot et al., \u003cspan citationid=\"CR25\" class=\"CitationRef\"\u003e2024\u003c/span\u003e; Wilkin \u0026amp; Chenhall, \u003cspan citationid=\"CR81\" class=\"CitationRef\"\u003e2020\u003c/span\u003e). Robust compliance structures and internal controls\u0026mdash;spanning policy, assurance, and technical safeguards\u0026mdash;enhance transparency, reduce vulnerabilities, and promote accountability throughout the governance lifecycle (Davis, \u003cspan citationid=\"CR51\" class=\"CitationRef\"\u003e2021\u003c/span\u003e; Papazafeiropoulou \u0026amp; Spanaki, \u003cspan citationid=\"CR89\" class=\"CitationRef\"\u003e2016\u003c/span\u003e; von Solms \u0026amp; von Solms, \u003cspan citationid=\"CR41\" class=\"CitationRef\"\u003e2018\u003c/span\u003e). Globalization of threats and rapid technological change amplify governance complexity and underscore the value of structured practices, including cloud-oriented governance and continuous verification, to maintain competitive advantage and resilience (Al-Hashimi et al., \u003cspan citationid=\"CR83\" class=\"CitationRef\"\u003e2018\u003c/span\u003e; Bicaku et al., \u003cspan citationid=\"CR86\" class=\"CitationRef\"\u003e2020\u003c/span\u003e). Yet cost and implementation burdens\u0026mdash;together with limited in-house expertise\u0026mdash;remain significant barriers, particularly for resource-constrained organizations (Backman \u0026amp; Stevens, \u003cspan citationid=\"CR26\" class=\"CitationRef\"\u003e2024\u003c/span\u003e; Hartmann \u0026amp; Carmenate, \u003cspan citationid=\"CR17\" class=\"CitationRef\"\u003e2021\u003c/span\u003e).\u003c/p\u003e\u003cp\u003eRecent work highlights practical levers for stronger outcomes: cultivating security culture and awareness, integrating audit and assurance into governance, and aligning board oversight with IT risk (Alshaikh, \u003cspan citationid=\"CR36\" class=\"CitationRef\"\u003e2020\u003c/span\u003e; Antunes et al., \u003cspan citationid=\"CR28\" class=\"CitationRef\"\u003e2022\u003c/span\u003e; Zimmermann \u0026amp; Renaud, \u003cspan citationid=\"CR40\" class=\"CitationRef\"\u003e2019\u003c/span\u003e). Sectoral and regional studies from the EU and beyond further show how standardization efforts and regulatory trajectories shape feasible governance designs (Kamara, \u003cspan citationid=\"CR23\" class=\"CitationRef\"\u003e2024\u003c/span\u003e; Savaş \u0026amp; Karataş, \u003cspan citationid=\"CR96\" class=\"CitationRef\"\u003e2022\u003c/span\u003e). Moreover, crisis contexts and the push toward automation (e.g., SOAR-supported controls) have spotlighted maturity models, continuous auditing, and risk-based control mechanisms as enablers of adaptive governance (Melaku, \u003cspan citationid=\"CR12\" class=\"CitationRef\"\u003e2023\u003c/span\u003e; Waelchli \u0026amp; Walter, \u003cspan citationid=\"CR42\" class=\"CitationRef\"\u003e2025\u003c/span\u003e).\u003c/p\u003e\u003c/div\u003e\u003c/p\u003e\u003cp\u003e\u003cdiv class=\"gridtable\"\u003e\u003ctable float=\"Yes\" id=\"Tab1\" border=\"1\"\u003e\u003ccaption language=\"En\"\u003e\u003cdiv class=\"CaptionNumber\"\u003eTable 1\u003c/div\u003e\u003cdiv class=\"CaptionContent\"\u003e\u003cp\u003eSummary of Key Studies on Cybersecurity Compliance, Governance, and Internal Controls\u003c/p\u003e\u003c/div\u003e\u003c/caption\u003e\u003ccolgroup cols=\"4\"\u003e\u003cdiv align=\"left\" class=\"colspec\" colname=\"c1\" colnum=\"1\"\u003e\u003c/div\u003e\u003cdiv align=\"left\" class=\"colspec\" colname=\"c2\" colnum=\"2\"\u003e\u003c/div\u003e\u003cdiv align=\"left\" class=\"colspec\" colname=\"c3\" colnum=\"3\"\u003e\u003c/div\u003e\u003cdiv align=\"left\" class=\"colspec\" colname=\"c4\" colnum=\"4\"\u003e\u003c/div\u003e\u003cthead\u003e\u003ctr\u003e\u003cth align=\"left\" colname=\"c1\"\u003e\u003cp\u003eRef.\u003c/p\u003e\u003c/th\u003e\u003cth align=\"left\" colname=\"c2\"\u003e\u003cp\u003eContribution\u003c/p\u003e\u003c/th\u003e\u003cth align=\"left\" colname=\"c3\"\u003e\u003cp\u003ePros\u003c/p\u003e\u003c/th\u003e\u003cth align=\"left\" colname=\"c4\"\u003e\u003cp\u003eCons\u003c/p\u003e\u003c/th\u003e\u003c/tr\u003e\u003c/thead\u003e\u003ctbody\u003e\u003ctr\u003e\u003ctd align=\"left\" colname=\"c1\"\u003e\u003cp\u003eEdwards \u0026amp; Weaver (2024)\u003c/p\u003e\u003c/td\u003e\u003ctd align=\"left\" colname=\"c2\"\u003e\u003cp\u003eInvestigated cybersecurity governance, risk management, and compliance (GRC), integrating practices to safeguard data and assets.\u003c/p\u003e\u003c/td\u003e\u003ctd align=\"left\" colname=\"c3\"\u003e\u003cp\u003eProvides a holistic GRC perspective; cross-industry applicability; useful for professionals, executives, regulators.\u003c/p\u003e\u003c/td\u003e\u003ctd align=\"left\" colname=\"c4\"\u003e\u003cp\u003eConceptual and practice-oriented; based on literature synthesis and professional insights.\u003c/p\u003e\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd align=\"left\" colname=\"c1\"\u003e\u003cp\u003eDavis (\u003cspan citationid=\"CR51\" class=\"CitationRef\"\u003e2021\u003c/span\u003e)\u003c/p\u003e\u003c/td\u003e\u003ctd align=\"left\" colname=\"c2\"\u003e\u003cp\u003eAdvocated stratified technological and non-technological controls; applied normative decision theory to auditing and linked governance practices to standards.\u003c/p\u003e\u003c/td\u003e\u003ctd align=\"left\" colname=\"c3\"\u003e\u003cp\u003eProvides structured approach for cybersecurity auditing; useful for compliance and internal control re-search.\u003c/p\u003e\u003c/td\u003e\u003ctd align=\"left\" colname=\"c4\"\u003e\u003cp\u003eFocused on methodological application of normative decision theory; may be complex for beginners.\u003c/p\u003e\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd align=\"left\" colname=\"c1\"\u003e\u003cp\u003eMaleh et al. (\u003cspan citationid=\"CR50\" class=\"CitationRef\"\u003e2021\u003c/span\u003e)\u003c/p\u003e\u003c/td\u003e\u003ctd align=\"left\" colname=\"c2\"\u003e\u003cp\u003eExplored IT governance and information security, including standards and frameworks (ITIL, ISO, COBIT), cloud and agile IT governance, and maturity frameworks.\u003c/p\u003e\u003c/td\u003e\u003ctd align=\"left\" colname=\"c3\"\u003e\u003cp\u003eOptimizes IT assets; proactive governance reduces risks; integrates IT service management and cloud computing; international case studies.\u003c/p\u003e\u003c/td\u003e\u003ctd align=\"left\" colname=\"c4\"\u003e\u003cp\u003eConceptual framework with case studies and literature synthesis; limited empirical validation.\u003c/p\u003e\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd align=\"left\" colname=\"c1\"\u003e\u003cp\u003eKohnke et al. (2016)\u003c/p\u003e\u003c/td\u003e\u003ctd align=\"left\" colname=\"c2\"\u003e\u003cp\u003eAnalyzed ICT governance, risk management, internal controls, and best practice frameworks for practical implementation.\u003c/p\u003e\u003c/td\u003e\u003ctd align=\"left\" colname=\"c3\"\u003e\u003cp\u003eStructured knowledge for control frameworks; positions ICT as strategic governance issue; emphasizes standards-based control infrastructure.\u003c/p\u003e\u003c/td\u003e\u003ctd align=\"left\" colname=\"c4\"\u003e\u003cp\u003eConceptual and standards-based; relies on global breach statistics; may lack localized applicability.\u003c/p\u003e\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd align=\"left\" colname=\"c1\"\u003e\u003cp\u003eSchreider \u0026amp; Noakes-Fry (2017)\u003c/p\u003e\u003c/td\u003e\u003ctd align=\"left\" colname=\"c2\"\u003e\u003cp\u003eProvided step-by-step guidance for building comprehensive cybersecurity programs; integrated ISO 27001 framework with industry experience.\u003c/p\u003e\u003c/td\u003e\u003ctd align=\"left\" colname=\"c3\"\u003e\u003cp\u003ePractitioner-focused; emphasizes gap analysis, policy alignment, multi-year roadmap; applicable for compliance and internal controls.\u003c/p\u003e\u003c/td\u003e\u003ctd align=\"left\" colname=\"c4\"\u003e\u003cp\u003eConceptual and practice-oriented; may not cover all industry-specific nuances.\u003c/p\u003e\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd align=\"left\" colname=\"c1\"\u003e\u003cp\u003eSavaş \u0026amp; Karataş (\u003cspan citationid=\"CR96\" class=\"CitationRef\"\u003e2022\u003c/span\u003e)\u003c/p\u003e\u003c/td\u003e\u003ctd align=\"left\" colname=\"c2\"\u003e\u003cp\u003eReviewed global cybersecurity governance studies; high-lighted necessity of cyber governance and absence of unified frameworks.\u003c/p\u003e\u003c/td\u003e\u003ctd align=\"left\" colname=\"c3\"\u003e\u003cp\u003eShows research gaps; reviews last 5 years; relevant for compliance and internal control frameworks.\u003c/p\u003e\u003c/td\u003e\u003ctd align=\"left\" colname=\"c4\"\u003e\u003cp\u003eDescriptive research; limited to documentary analysis; lacks primary data.\u003c/p\u003e\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd align=\"left\" colname=\"c1\"\u003e\u003cp\u003eYusif \u0026amp; Hafeez-Baig (\u003cspan citationid=\"CR97\" class=\"CitationRef\"\u003e2021\u003c/span\u003e)\u003c/p\u003e\u003c/td\u003e\u003ctd align=\"left\" colname=\"c2\"\u003e\u003cp\u003eDeveloped a conceptual model for cybersecurity governance addressing strategy, standardized processes, compliance, leadership, and resources.\u003c/p\u003e\u003c/td\u003e\u003ctd align=\"left\" colname=\"c3\"\u003e\u003cp\u003eProvides governance-focused framework aligning compliance and internal controls with organizational strategy.\u003c/p\u003e\u003c/td\u003e\u003ctd align=\"left\" colname=\"c4\"\u003e\u003cp\u003eConceptual model; re-quires further empirical validation.\u003c/p\u003e\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd align=\"left\" colname=\"c1\"\u003e\u003cp\u003eZukis (\u003cspan citationid=\"CR98\" class=\"CitationRef\"\u003e2016\u003c/span\u003e)\u003c/p\u003e\u003c/td\u003e\u003ctd align=\"left\" colname=\"c2\"\u003e\u003cp\u003eEmphasized board-level IT oversight; aligned IT governance with enterprise risk management; highlighted directors\u0026rsquo; demand for IT strategy focus.\u003c/p\u003e\u003c/td\u003e\u003ctd align=\"left\" colname=\"c3\"\u003e\u003cp\u003eRelevant for linking cybersecurity governance to board-level oversight, strategic planning, and compliance.\u003c/p\u003e\u003c/td\u003e\u003ctd align=\"left\" colname=\"c4\"\u003e\u003cp\u003eConceptual discussion; limited empirical evidence; industry-specific focus.\u003c/p\u003e\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd align=\"left\" colname=\"c1\"\u003e\u003cp\u003eHeim,T. (2023)\u003c/p\u003e\u003c/td\u003e\u003ctd align=\"left\" colname=\"c2\"\u003e\u003cp\u003eThe study explores global cybersecurity governance, showing fragmented regulation and suggesting \u0026ldquo;unity in diversity\u0026rdquo; and \u0026ldquo;rich coherence\u0026rdquo; as pathways for coordination.\u003c/p\u003e\u003c/td\u003e\u003ctd align=\"left\" colname=\"c3\"\u003e\u003cp\u003eIt highlights coherence in critical infrastructure and cybercrime, introduces guiding concepts for policymakers, and adds value to compliance and governance studies.\u003c/p\u003e\u003c/td\u003e\u003ctd align=\"left\" colname=\"c4\"\u003e\u003cp\u003eThe research is mostly exploratory, offers limited practical solutions, has a broad global scope that misses regional detail, and leans more on theory than implementation.\u003c/p\u003e\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd align=\"left\" colname=\"c1\"\u003e\u003cp\u003eWeber,R. (2023)\u003c/p\u003e\u003c/td\u003e\u003ctd align=\"left\" colname=\"c2\"\u003e\u003cp\u003eExplored global cybersecurity governance, regulation, multi-actor coordination, data protection, critical infrastructure, and cybercrime.\u003c/p\u003e\u003c/td\u003e\u003ctd align=\"left\" colname=\"c3\"\u003e\u003cp\u003eProvides insights into multi-level regulatory coordination; highlights \u0026ldquo;unity in diversity\u0026rdquo; concept.\u003c/p\u003e\u003c/td\u003e\u003ctd align=\"left\" colname=\"c4\"\u003e\u003cp\u003eExploratory and descriptive; may not generalize across all countries or sectors.\u003c/p\u003e\u003c/td\u003e\u003c/tr\u003e\u003c/tbody\u003e\u003c/colgroup\u003e\u003c/table\u003e\u003c/div\u003e\u003c/p\u003e\u003cp\u003e\u003cdiv class=\"BlockQuote\"\u003e\u003cp\u003eThe data presented in Table\u0026nbsp;\u003cspan refid=\"Tab1\" class=\"InternalRef\"\u003e1\u003c/span\u003e demonstrates important missing information within current research. Multiple reviews examine the utilization of compliance frameworks in cybersecurity governance, yet they usually concentrate on high-level models or generalized governance strategies that omit specific implementations for internal control systems. Research on integrated GRC (Governance, Risk, and Compliance) platforms has received detailed attention in recent publications but fails to combine technical standards such as ISO 27001, COBIT, and ITIL in a unified operational context. Most literature reviews about cybersecurity governance examine either established regulatory protocols or conceptual models without sufficient discussion about their integration with organizational infrastructure and control mechanisms. The analysed studies fail to conduct comprehensive examinations regarding the implementation of lightweight, scalable compliance strategies on constrained enterprise systems in real-world applications. Research on the combination between real-time monitoring and embedded control for cybersecurity enforcement along with governance deployment has received limited interest. The present deficiency creates a major obstacle for developing workable and cost-effective compliance solutions, which are especially critical in sectors with limited regulatory maturity or infrastructure.\u003c/p\u003e\u003cp\u003eThe research suffers from insufficient evaluation methods that compare framework effectiveness and organizational adaptability, as well as inadequate case examples across different industries and scales. The review bridges this specific gap through integration of results showing compliance model applications within cybersecurity governance environments.\u003c/p\u003e\u003cp\u003e\u003cem\u003e1.1 Research questions\u003c/em\u003e\u003c/p\u003e\u003c/div\u003e\u003c/p\u003e\u003cp\u003e\u003cul\u003e\u003cli\u003e\u003cp\u003eRQ1a: Among studies using ISO 27001 and/or COBIT, what outcomes are most frequently reported (audit pass rates, control maturity, incident reduction)?\u003c/p\u003e\u003c/li\u003e\u003cli\u003e\u003cp\u003eRQ2a: Do studies describing integrated GRC dashboards report stronger assurance than those using single-framework compliance?\u003c/p\u003e\u003c/li\u003e\u003cli\u003e\u003cp\u003eRQ3a: How do finance/government compare with SMEs/ICT/healthcare in realized benefits and barriers?\u003c/p\u003e\u003c/li\u003e\u003cli\u003e\u003cp\u003eRQ4a: What is the reported mix of cloud/on-prem/hybrid and how does it align with sector and geography?\u003c/p\u003e\u003c/li\u003e\u003cli\u003e\u003cp\u003eRQ5a: Which control categories co-occur with positive outcomes (combining policy/regulatory with technical/security and oversight)?\u003c/p\u003e\u003c/li\u003e\u003cli\u003e\u003cp\u003eRQ6a: Which methods (audits, surveys, KPIs, simulations) underpin claims, and where are validation/longitudinal gaps?\u003c/p\u003e\u003c/li\u003e\u003cli\u003e\u003cp\u003eRQ7a: What regional emphases (GDPR-led Europe, finance-heavy North America, capacity-building APAC/Africa) are evident?\u003c/p\u003e\u003c/li\u003e\u003c/ul\u003e\u003c/p\u003e\u003cdiv id=\"Sec2\" class=\"Section2\"\u003e\u003ch2\u003e1.2 Rationale\u003c/h2\u003e\u003cp\u003e\u003cdiv class=\"BlockQuote\"\u003e\u003cp\u003eOrganizations increasingly rely on structured standards and internal controls to manage cyber risk and meet regulatory obligations. Yet the evidence base is fragmented across frameworks, sectors, and regions. By reviewing 2015\u0026ndash;2025 literature and classifying it into three research periods (Early, Middle, Recent), geographies, document types, indexing sources, framework families, governance models, tools/methods, control types, sectors, challenges, and recommendations, we provide a consolidated, decision-oriented picture of what works, where, and why.\u003c/p\u003e\u003cp\u003e\u003cem\u003e1.3 Objectives\u003c/em\u003e\u003c/p\u003e\u003c/div\u003e\u003c/p\u003e\u003cp\u003e\u003cul\u003e\u003cli\u003e\u003cp\u003eMap the landscape of standards and frameworks (ISO 27001, COBIT, NIST CSF, GDPR/HIPAA, etc.) and quantify their prevalence.\u003c/p\u003e\u003c/li\u003e\u003cli\u003e\u003cp\u003eClassify governance models (integrated GRC, policy integration, control \u0026amp; assurance, risk, strategic/board-level, operational, human/awareness, incident, specialized) and estimate their share.\u003c/p\u003e\u003c/li\u003e\u003cli\u003e\u003cp\u003eInventory tools and methods (empirical audits/surveys; maturity/KPIs; quantitative/simulation; threat modeling) and assess evidence strength.\u003c/p\u003e\u003c/li\u003e\u003cli\u003e\u003cp\u003eProfile controls implemented (policy/regulatory; oversight \u0026amp; assurance; technical/security; compliance/financial; risk; performance; operational; human/cultural; context-specific).\u003c/p\u003e\u003c/li\u003e\u003cli\u003e\u003cp\u003eExamine sectoral and regional patterns in adoption, outcomes, and challenges.\u003c/p\u003e\u003c/li\u003e\u003cli\u003e\u003cp\u003eSynthesize challenges and recommendations into actionable guidance for practitioners and policymakers.\u003c/p\u003e\u003c/li\u003e\u003cli\u003e\u003cp\u003eHighlight reporting gaps (deployment mode, longitudinal impact) and propose a minimal reporting schema.\u003c/p\u003e\u003c/li\u003e\u003c/ul\u003e\u003cdiv class=\"BlockQuote\"\u003e\u003cp\u003e\u003cem\u003e1.5 Research contributions\u003c/em\u003e\u003c/p\u003e\u003c/div\u003e\u003c/p\u003e\u003cp\u003e\u003cul\u003e\u003cli\u003e\u003cp\u003eEvidence-based taxonomy \u0026amp; quantification. We deliver a harmonized coding of frameworks, models, tools, controls, sectors, and regions, with percent shares visualized in Figs.\u0026nbsp;\u003cspan refid=\"Fig6\" class=\"InternalRef\"\u003e6\u003c/span\u003e\u0026ndash;\u003cspan refid=\"Fig16\" class=\"InternalRef\"\u003e16\u003c/span\u003e (governance/risk frameworks 37.5%; international standards 28.75%; regulatory/legal 26.25%).\u003c/p\u003e\u003c/li\u003e\u003cli\u003e\u003cp\u003eIntegrated GRC perspective. We link framework families \u0026rarr; governance models \u0026rarr; control portfolios \u0026rarr; outcomes, showing where integration is reported to add value.\u003c/p\u003e\u003c/li\u003e\u003cli\u003e\u003cp\u003eSectoral \u0026amp; regional insights. We contrast finance/government dominance with under-studied SMEs/industrial contexts and highlight regional clusters.\u003c/p\u003e\u003c/li\u003e\u003cli\u003e\u003cp\u003eChallenge\u0026ndash;recommendation map. We align the top challenges (regulatory complexity, resource limits, integration issues) with the most cited remedies (framework/policy harmonization, leadership \u0026amp; governance enhancement, technology \u0026amp; automation, risk intelligence).\u003c/p\u003e\u003c/li\u003e\u003cli\u003e\u003cp\u003eReporting checklist. We propose a concise schema (frameworks used; control categories; deployment mode; measurement approach; sector/region) to improve comparability and replication.\u003c/p\u003e\u003c/li\u003e\u003c/ul\u003e\u003cdiv class=\"BlockQuote\"\u003e\u003cp\u003e\u003cem\u003e1.6 Research novelty\u003c/em\u003e\u003c/p\u003e\u003c/div\u003e\u003c/p\u003e\u003cp\u003e\u003cul\u003e\u003cli\u003e\u003cp\u003eFirst end-to-end crosswalk (to our knowledge) that connects standards/frameworks to governance models, control portfolios, methods, sectors/regions, challenges, and recommendations\u0026mdash;and quantifies each.\u003c/p\u003e\u003c/li\u003e\u003cli\u003e\u003cp\u003eTemporal periodization of the field (2016\u0026ndash;2018, 2019\u0026ndash;2021, 2022\u0026ndash;2025) showing the shift from conceptualization to empirical assessment and automation-driven governance.\u003c/p\u003e\u003c/li\u003e\u003cli\u003e\u003cp\u003eDeployment-mode gap spotlight. We document substantial non-reporting of implementation approach and call for explicit mode disclosure (cloud/on-prem/hybrid) given its compliance and risk implications.\u003c/p\u003e\u003c/li\u003e\u003cli\u003e\u003cp\u003ePractitioner-ready guidance. Our challenge\u0026rarr;recommendation mapping translates literature patterns into actionable steps for boards, CISOs, and regulators.\u003c/p\u003e\u003c/li\u003e\u003c/ul\u003e\u003c/p\u003e\u003c/div\u003e"},{"header":" Materials and Methods","content":"\u003cdiv class=\"Heading\"\u003e\u003cem\u003e2.\u003c/em\u003e Materials and Methods\u003c/div\u003e\u003cp\u003e\u003cdiv class=\"BlockQuote\"\u003e\u003cp\u003eThis review synthesizes research on cybersecurity compliance standards and internal control practices published between 2015 and 2025 across Scopus, Web of Science, and Google Scholar. We focused on empirical and conceptual work that examines governance frameworks (e.g., ISO/IEC 27001, COBIT, NIST CSF, GDPR) and their operationalization through controls, audits, and GRC processes in organizational settings. Our approach follows established information-systems review practices used in governance and cybersecurity syntheses\u0026mdash;emphasizing transparent search strings, multi-database retrieval, and structured screening to ensure coverage and replicability (e.g., Papazafeiropoulou \u0026amp; Spanaki, \u003cspan citationid=\"CR89\" class=\"CitationRef\"\u003e2016\u003c/span\u003e; Wilkin \u0026amp; Chenhall, \u003cspan citationid=\"CR81\" class=\"CitationRef\"\u003e2020\u003c/span\u003e; Savaş \u0026amp; Karataş, \u003cspan citationid=\"CR96\" class=\"CitationRef\"\u003e2022\u003c/span\u003e; Edwards \u0026amp; Weaver, 2024; Davis, \u003cspan citationid=\"CR51\" class=\"CitationRef\"\u003e2021\u003c/span\u003e; Maleh et al., \u003cspan citationid=\"CR50\" class=\"CitationRef\"\u003e2021\u003c/span\u003e; Zwilling, \u003cspan citationid=\"CR16\" class=\"CitationRef\"\u003e2022\u003c/span\u003e). To broaden sectoral coverage and capture gray or pre-publication scholarship (theses, conference proceedings), we included multidisciplinary indexing via Google Scholar, consistent with recent governance and cybersecurity mappings (Proudfoot et al., \u003cspan citationid=\"CR25\" class=\"CitationRef\"\u003e2024\u003c/span\u003e; Hossain et al., \u003cspan citationid=\"CR19\" class=\"CitationRef\"\u003e2024\u003c/span\u003e). Screening, extraction, and categorization were carried out using a standardized template informed by prior auditing and governance frameworks and toolsets (Antunes et al., \u003cspan citationid=\"CR28\" class=\"CitationRef\"\u003e2022\u003c/span\u003e; Plant et al., \u003cspan citationid=\"CR53\" class=\"CitationRef\"\u003e2022\u003c/span\u003e; Gordon et al., \u003cspan citationid=\"CR39\" class=\"CitationRef\"\u003e2020\u003c/span\u003e; Yusif \u0026amp; Hafeez-Baig, \u003cspan citationid=\"CR97\" class=\"CitationRef\"\u003e2021\u003c/span\u003e).\u003c/p\u003e\u003c/div\u003e\u003c/p\u003e\u003cdiv id=\"Sec4\" class=\"Section2\"\u003e\u003ch2\u003e2.1. Eligibility criteria\u003c/h2\u003e\u003cp\u003e\u003cdiv class=\"BlockQuote\"\u003e\u003cp\u003eThe review included only peer-reviewed and English-language studies published between 2015 and 2025. Eligible studies were required to engage substantively with cybersecurity governance, compliance frameworks, or internal control mechanisms, demonstrating methodological clarity and a direct contribution to organizational security performance (Melaku, \u003cspan citationid=\"CR12\" class=\"CitationRef\"\u003e2023\u003c/span\u003e; Hartmann \u0026amp; Carmenate, \u003cspan citationid=\"CR17\" class=\"CitationRef\"\u003e2021\u003c/span\u003e; Nicho, \u003cspan citationid=\"CR74\" class=\"CitationRef\"\u003e2018\u003c/span\u003e). Research lacking empirical grounding, clear methodological design, or identifiable governance models was excluded. To ensure conceptual consistency, definitions of frameworks and control categories were harmonized using authoritative sources that describe the relationships among COBIT, COSO, and ISO standards (Davis, \u003cspan citationid=\"CR51\" class=\"CitationRef\"\u003e2021\u003c/span\u003e; Maleh et al., \u003cspan citationid=\"CR50\" class=\"CitationRef\"\u003e2021\u003c/span\u003e). The selection process consisted of three stages: initial retrieval, abstract screening, and full-text evaluation. Duplicates were removed, and studies were classified by framework type, sectoral focus, methodological design, and geographical scope. Sectoral mapping followed established categorization approaches used in recent cybersecurity and compliance analyses (Ferreira et al., \u003cspan citationid=\"CR49\" class=\"CitationRef\"\u003e2025\u003c/span\u003e; Ashley \u0026amp; Preiksaitis, \u003cspan citationid=\"CR68\" class=\"CitationRef\"\u003e2022\u003c/span\u003e; Backman \u0026amp; Stevens, \u003cspan citationid=\"CR26\" class=\"CitationRef\"\u003e2024\u003c/span\u003e). In line with the integrative approaches recommended by Wilkin and Chenhall (\u003cspan citationid=\"CR81\" class=\"CitationRef\"\u003e2020\u003c/span\u003e) and Papazafeiropoulou and Spanaki (\u003cspan citationid=\"CR89\" class=\"CitationRef\"\u003e2016\u003c/span\u003e), both conceptual and applied studies were included to capture the full spectrum of governance and control research.\u003c/p\u003e\u003cp\u003eThis methodological approach ensured a balanced inclusion of both theoretical and practice-oriented studies, yielding a coherent synthesis of cybersecurity governance literature that reflects diverse industries, organizational contexts, and regional practices. The final inclusion and exclusion parameters are summarized in Table\u0026nbsp;\u003cspan refid=\"Tab3\" class=\"InternalRef\"\u003e2\u003c/span\u003e.\u003c/p\u003e\u003c/div\u003e\u003c/p\u003e\u003cp\u003e\u003cdiv class=\"gridtable\"\u003e\u003ctable float=\"Yes\" id=\"Tab2\" border=\"1\"\u003e\u003ccaption language=\"En\"\u003e\u003cdiv class=\"CaptionNumber\"\u003eTable 2\u003c/div\u003e\u003cdiv class=\"CaptionContent\"\u003e\u003cp\u003eProposed Inclusion and Exclusion Criteria\u003c/p\u003e\u003c/div\u003e\u003c/caption\u003e\u003ccolgroup cols=\"3\"\u003e\u003cdiv align=\"left\" class=\"colspec\" colname=\"c1\" colnum=\"1\"\u003e\u003c/div\u003e\u003cdiv align=\"left\" class=\"colspec\" colname=\"c2\" colnum=\"2\"\u003e\u003c/div\u003e\u003cdiv align=\"left\" class=\"colspec\" colname=\"c3\" colnum=\"3\"\u003e\u003c/div\u003e\u003cthead\u003e\u003ctr\u003e\u003cth align=\"left\" colname=\"c1\"\u003e\u003cp\u003eCriteria\u003c/p\u003e\u003c/th\u003e\u003cth align=\"left\" colname=\"c2\"\u003e\u003cp\u003eInclusion\u003c/p\u003e\u003c/th\u003e\u003cth align=\"left\" colname=\"c3\"\u003e\u003cp\u003eExclusion\u003c/p\u003e\u003c/th\u003e\u003c/tr\u003e\u003c/thead\u003e\u003ctbody\u003e\u003ctr\u003e\u003ctd align=\"left\" colname=\"c1\"\u003e\u003cp\u003eTopic\u003c/p\u003e\u003c/td\u003e\u003ctd align=\"left\" colname=\"c2\"\u003e\u003cp\u003eArticle papers focusing on Compliance and Internal Controls: A Systematic Review of Standards and Practices in Cyber Security Governance\u003c/p\u003e\u003c/td\u003e\u003ctd align=\"left\" colname=\"c3\"\u003e\u003cp\u003eArticle papers not focusing on Compliance and Internal Controls: A Systematic Review of Standards and Practices in Cyber Security Governance\u003c/p\u003e\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd align=\"left\" colname=\"c1\"\u003e\u003cp\u003eResearch Framework\u003c/p\u003e\u003c/td\u003e\u003ctd align=\"left\" colname=\"c2\"\u003e\u003cp\u003eThe Articles must include research framework or methodology for Compliance and Internal Controls: A Systematic Review of Standards and Practices in Cyber Security Governance\u003c/p\u003e\u003c/td\u003e\u003ctd align=\"left\" colname=\"c3\"\u003e\u003cp\u003eArticles must exclude research framework or methodology for Compliance and Internal Controls: A Systematic Review of Standards and Practices in Cyber Security Governance\u003c/p\u003e\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd align=\"left\" colname=\"c1\"\u003e\u003cp\u003eLanguage\u003c/p\u003e\u003c/td\u003e\u003ctd align=\"left\" colname=\"c2\"\u003e\u003cp\u003eMust be written in English\u003c/p\u003e\u003c/td\u003e\u003ctd align=\"left\" colname=\"c3\"\u003e\u003cp\u003eArticles published in languages other than English\u003c/p\u003e\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd align=\"left\" colname=\"c1\"\u003e\u003cp\u003ePeriod\u003c/p\u003e\u003c/td\u003e\u003ctd align=\"left\" colname=\"c2\"\u003e\u003cp\u003eArticles between 2015 to 2025\u003c/p\u003e\u003c/td\u003e\u003ctd align=\"left\" colname=\"c3\"\u003e\u003cp\u003eArticles outside 2015 and 2025\u003c/p\u003e\u003c/td\u003e\u003c/tr\u003e\u003c/tbody\u003e\u003c/colgroup\u003e\u003c/table\u003e\u003c/div\u003e\u003c/p\u003e\u003c/div\u003e\u003cdiv id=\"Sec5\" class=\"Section2\"\u003e\u003ch2\u003e2.2. Information sources\u003c/h2\u003e\u003cp\u003e\u003cdiv class=\"BlockQuote\"\u003e\u003cp\u003eA systematic search of online repositories was conducted to identify relevant studies for this review. The research platforms Scopus, Google Scholar, and Web of Science were used due to their broad coverage of peer-reviewed literature in the fields where cybersecurity governance, compliance frameworks, and internal control practices are discussed. Each repository was carefully and comprehensively searched using a combination of keywords that covered the topic, guaranteeing that the most relevant research articles were captured.\u003c/p\u003e\u003cp\u003eThe first database used was Scopus, which provided a large range of scientific journals and conference papers. The second database used was Google Scholar, which enabled the inclusion of gray literature and academic dissertations that may not be found on other platforms. The third database used was Web of Science, which was employed to cross-reference and ensure the strength of the papers selected, as it provided citation data and impact factors of the journals. The results acquired from these databases formed the basis of the systematic literature review, guaranteeing a well-rounded and thorough collection of research papers.\u003c/p\u003e\u003c/div\u003e\u003c/p\u003e\u003c/div\u003e\u003cdiv id=\"Sec6\" class=\"Section2\"\u003e\u003ch2\u003e2.3. Search strategy\u003c/h2\u003e\u003cp\u003e\u003cdiv class=\"BlockQuote\"\u003e\u003cp\u003eThe literature for this research was collected from reputable online research databases, focusing on keywords that address both the technological and regulatory aspects of cybersecurity governance, compliance frameworks, and internal control practices. The inclusion of terms such as \u0026ldquo;ISO 27001,\u0026rdquo; \u0026ldquo;NIST,\u0026rdquo; \u0026ldquo;COBIT,\u0026rdquo; and \u0026ldquo;GDPR\u0026rdquo; ensured the capture of studies relevant to diverse organizational environments and governance models.\u003c/p\u003e\u003cp\u003eA thorough search was carried out in three main repositories: Google Scholar, Scopus, and Web of Science. To find the most relevant studies, a specific set of keywords was used. These keywords were: (\"Cybersecurity Governance\" AND \"Compliance\" AND \"Internal Controls\" AND (\"ISO 27001\" OR \"NIST\" OR \"COBIT\" OR \"GDPR\" OR \"Cybersecurity Standards\")). This combination of terms was chosen to ensure that the search captured studies directly related to the research topic. The search focused on papers published between 2015 and 2025. This time frame was selected to provide a recent and relevant overview of the subject. The search results included 2060 papers from Google Scholar, 14 papers from Scopus, and 100 papers from Web of Science. After collecting these papers, they were carefully reviewed and filtered to select only those that were most relevant to the research questions. This process helped to narrow down the literature to the most useful and high-quality sources for this study. Table\u0026nbsp;\u003cspan refid=\"Tab4\" class=\"InternalRef\"\u003e3\u003c/span\u003e shows the list of online repositories that were utilized as well as the total number of results achieved before the initial screening.\u003c/p\u003e\u003c/div\u003e\u003c/p\u003e\u003cp\u003e\u003cdiv class=\"gridtable\"\u003e\u003ctable float=\"Yes\" id=\"Tab3\" border=\"1\"\u003e\u003ccaption language=\"En\"\u003e\u003cdiv class=\"CaptionNumber\"\u003eTable 1\u003c/div\u003e\u003cdiv class=\"CaptionContent\"\u003e\u003cp\u003eResults Achieved from Literature Search.\u003c/p\u003e\u003c/div\u003e\u003c/caption\u003e\u003ccolgroup cols=\"3\"\u003e\u003cdiv align=\"left\" class=\"colspec\" colname=\"c1\" colnum=\"1\"\u003e\u003c/div\u003e\u003cdiv align=\"left\" class=\"colspec\" colname=\"c2\" colnum=\"2\"\u003e\u003c/div\u003e\u003cdiv align=\"char\" char=\".\" class=\"colspec\" colname=\"c3\" colnum=\"3\"\u003e\u003c/div\u003e\u003cthead\u003e\u003ctr\u003e\u003cth align=\"left\" colname=\"c1\"\u003e\u003cp\u003eNo.\u003c/p\u003e\u003c/th\u003e\u003cth align=\"left\" colname=\"c2\"\u003e\u003cp\u003eOnline Repository\u003c/p\u003e\u003c/th\u003e\u003cth align=\"left\" colname=\"c3\"\u003e\u003cp\u003eNumber of results\u003c/p\u003e\u003c/th\u003e\u003c/tr\u003e\u003c/thead\u003e\u003ctbody\u003e\u003ctr\u003e\u003ctd align=\"left\" colname=\"c1\"\u003e\u003cp\u003e1\u003c/p\u003e\u003c/td\u003e\u003ctd align=\"left\" colname=\"c2\"\u003e\u003cp\u003eGoogle Scholar\u003c/p\u003e\u003c/td\u003e\u003ctd align=\"char\" char=\".\" colname=\"c3\"\u003e\u003cp\u003e2060\u003c/p\u003e\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd align=\"left\" colname=\"c1\"\u003e\u003cp\u003e2\u003c/p\u003e\u003c/td\u003e\u003ctd align=\"left\" colname=\"c2\"\u003e\u003cp\u003eWeb of Science\u003c/p\u003e\u003c/td\u003e\u003ctd align=\"char\" char=\".\" colname=\"c3\"\u003e\u003cp\u003e100\u003c/p\u003e\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd align=\"left\" colname=\"c1\"\u003e\u003cp\u003e3\u003c/p\u003e\u003c/td\u003e\u003ctd align=\"left\" colname=\"c2\"\u003e\u003cp\u003eScopus\u003c/p\u003e\u003c/td\u003e\u003ctd align=\"char\" char=\".\" colname=\"c3\"\u003e\u003cp\u003e14\u003c/p\u003e\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd align=\"left\" colname=\"c1\"\u003e\u003cp\u003eTotal\u003c/p\u003e\u003c/td\u003e\u003ctd align=\"left\" colname=\"c2\"\u003e\u0026nbsp;\u003c/td\u003e\u003ctd align=\"char\" char=\".\" colname=\"c3\"\u003e\u003cp\u003e2174\u003c/p\u003e\u003c/td\u003e\u003c/tr\u003e\u003c/tbody\u003e\u003c/colgroup\u003e\u003c/table\u003e\u003c/div\u003e\u003c/p\u003e\u003c/div\u003e\u003cdiv id=\"Sec7\" class=\"Section2\"\u003e\u003ch2\u003e2.4. Selection process\u003c/h2\u003e\u003cp\u003e\u003cdiv class=\"BlockQuote\"\u003e\u003cp\u003eThree researchers (WKM, SAM, AK) individually reviewed the titles, abstracts, methodologies and results sections of the papers that each had retrieved from the individually assigned online database. Any differences in the selection of the papers that each member retrieved from their repository were discussed until a common point was reached. If the researchers could not agree on something even after discussion, the lecturer was consulted to help the members reach an agreement, as shown in Fig.\u0026nbsp;\u003cspan refid=\"Fig2\" class=\"InternalRef\"\u003e2\u003c/span\u003e.\u003c/p\u003e\u003c/div\u003e\u003c/p\u003e\u003cp\u003e\u003c/p\u003e\u003c/div\u003e\u003cdiv id=\"Sec8\" class=\"Section2\"\u003e\u003ch2\u003e2.5. Data collection process\u003c/h2\u003e\u003cp\u003e\u003cdiv class=\"BlockQuote\"\u003e\u003cp\u003eTo guarantee that the information for the studies was accurate, a structured approach was followed to minimize errors and biases. The three reviewers then separately collected the data from each paper under the guidance of the lead researcher. Any differences in the extracted data were discussed until an agreement was reached. A standardized data extraction process was applied to ensure consistency across all three reviewers. For the data extraction process, no automation tools were used. Data was carefully recorded into a structured table of Existing Studies \u0026ndash; Cybersecurity Governance, and each reviewer double-checked the other reviewers\u0026rsquo; entries to ensure that only accurate information was retained. When the data in the studies was difficult to interpret, a thorough review of all available materials, including supplementary documents, was conducted to clarify the information. In cases where uncertainties persisted, the lead researcher was consulted to ensure the reliability of the data used. When more than one report was found for the same study, clear criteria were applied to select the most appropriate data, prioritizing the most recent and comprehensive studies published between 2015 and 2025. In situations where the information from the reports was inconsistent, methods and outcomes were compared to resolve the discrepancies. Only studies written in English were included, excluding any articles in other languages to maintain consistency and avoid potential misunderstandings due to language differences, as illustrated in Fig.\u0026nbsp;\u003cspan refid=\"Fig3\" class=\"InternalRef\"\u003e3\u003c/span\u003e.\u003c/p\u003e\u003c/div\u003e\u003c/p\u003e\u003cp\u003e\u003c/p\u003e\u003c/div\u003e\u003cdiv id=\"Sec9\" class=\"Section2\"\u003e\u003ch2\u003e2.6. Data items\u003c/h2\u003e\u003cp\u003e\u003cdiv class=\"BlockQuote\"\u003e\u003cp\u003eThis section presents a detailed overview of the data elements required in this systematic review, focusing on both primary results and any additional elements relevant to cybersecurity governance, compliance frameworks, and internal control practices. The primary results cover various aspects such as the adoption and implementation of governance standards, the effectiveness of internal controls, the types of compliance frameworks applied (e.g., ISO 27001, NIST, COBIT, GDPR), and the governance maturity models reported in the studies. This approach allows for a quality analysis of how different governance frameworks and internal control mechanisms perform when applied in various organizational contexts, across different industries and regulatory environments. Additional elements considered include risk management metrics, audit and assurance practices, and integration with enterprise governance structures, enabling a comprehensive understanding of cybersecurity governance practices globally.\u003c/p\u003e\u003c/div\u003e\u003c/p\u003e\u003cdiv id=\"Sec10\" class=\"Section3\"\u003e\u003ch2\u003e2.6.1 Data Collection Method\u003c/h2\u003e\u003cp\u003e\u003cdiv class=\"BlockQuote\"\u003e\u003cp\u003eTo ensure that a broad understanding of the topic was established about cybersecurity governance, compliance frameworks, and internal control practices, efforts were made in the form of thoroughly studying, identifying, and defining relevant data from trustworthy sources to capture the methods and processes used to conduct a high-quality investigation of the governance aspects under review. The method was designed to produce strong evidence that reflects the impact of implementing different compliance frameworks and internal control mechanisms in organizational cybersecurity programs. The primary results of this systematic review were focused around several important areas that have a direct impact on cybersecurity governance and compliance effectiveness. Governance maturity and compliance adoption were major outputs, which were defined by assessing how effectively organizations implemented recognized standards such as ISO 27001, NIST Cybersecurity Framework, COBIT, and GDPR, and any gaps or inconsistencies in implementation enabled an understanding of how reliable and effective these frameworks can be. The main concern for governance performance received top priority. Research focused on compliance effectiveness, risk reduction metrics, and audit performance indicators. We evaluated the operational efficiency of governance structures since organizations typically operate under resource constraints and regulatory pressures. An evaluation of the governance infrastructure along with internal control components from each research study took place. The studies described both the selected compliance framework and its integration with organizational processes, together with its monitoring and reporting capabilities, while explaining the methods used to assess risk and ensure regulatory alignment. The method of applying governance models proved to be an important aspect of consideration. The research indicated whether compliance monitoring was performed internally within the organization or outsourced to third-party auditors. Internal monitoring provides essential functionality for real-time risk management, which cannot always rely on external audits. An assessment testing the practical applicability of governance frameworks was done by checking the use case relevance. The testing included both highly regulated sectors and general enterprise environments. Studies that used actual real-world applications received more importance because they provide a more accurate assessment of how governance frameworks function in their intended operational context. Researchers distinguished themselves through detailed analysis of compliance adoption strategies combined with internal control mechanisms to investigate the relevant aspects.\u003c/p\u003e\u003c/div\u003e\u003c/p\u003e\u003c/div\u003e\u003cdiv id=\"Sec11\" class=\"Section3\"\u003e\u003ch2\u003e2.6.2 Definition of Collected Data Variables\u003c/h2\u003e\u003cp\u003e\u003cdiv class=\"BlockQuote\"\u003e\u003cp\u003eThe study also considered additional measures to enhance understanding about cybersecurity governance frameworks and internal control implementations. The selected variables enabled proper interpretation of results while understanding the broader implications of embedding compliance and governance practices within organizational structures. We compiled detailed information about study properties, which covered the research location, industry sector, and regulatory context, alongside governance specifications for examining deployment potential across various organizational environments. These study characteristics allowed researchers to interpret results by showcasing the different methods and frameworks employed in this field. Recording implementation aspects included information about the governance models applied (e.g., ISO 27001, NIST, COBIT, GDPR), the internal control mechanisms, and the monitoring and auditing approaches used to ensure compliance. Technical evaluation depended on this information to measure how deeply governance frameworks were integrated into organizational processes and how effectively they addressed cybersecurity risks. The assessment also included economic elements, which examined both implementation costs and resource allocation requirements, since these factors demonstrate the practicality of adopting governance frameworks in real-world operational contexts. A complete analysis of cybersecurity governance required an evaluation of external factors, which included regulatory pressures, market compliance demands, and organizational skill constraints considered as well. Research was conducted carefully using our established methods, which involved systematic database investigations in Google Scholar, Scopus, and Web of Science for selecting high-quality, relevant studies\u0026mdash;all of which are shown in Table\u0026nbsp;4 below. We used manual research methods for information acquisition to obtain precise, relevant data, which directed our analysis toward practical implementations and governance improvements within this domain. We guarantee a thorough assessment of the impact of compliance and internal control practices on cybersecurity governance through the identification and definition of the review's outcomes and variables. Our research methodology strengthens both the accuracy and importance of our results and provides vital information to practitioners and experts who work within the domains of cybersecurity governance, risk management, and regulatory compliance.\u003c/p\u003e\u003c/div\u003e\u003c/p\u003e\u003cp\u003e\u003cdiv class=\"gridtable\"\u003e\u003ctable float=\"Yes\" id=\"Tab4\" border=\"1\"\u003e\u003ccaption language=\"En\"\u003e\u003cdiv class=\"CaptionNumber\"\u003eTable 2\u003c/div\u003e\u003cdiv class=\"CaptionContent\"\u003e\u003cp\u003eData Variables Collected.\u003c/p\u003e\u003c/div\u003e\u003c/caption\u003e\u003ccolgroup cols=\"2\"\u003e\u003cdiv align=\"left\" class=\"colspec\" colname=\"c1\" colnum=\"1\"\u003e\u003c/div\u003e\u003cdiv align=\"left\" class=\"colspec\" colname=\"c2\" colnum=\"2\"\u003e\u003c/div\u003e\u003cthead\u003e\u003ctr\u003e\u003cth align=\"left\" colname=\"c1\"\u003e\u003cp\u003eField\u003c/p\u003e\u003c/th\u003e\u003cth align=\"left\" colname=\"c2\"\u003e\u003cp\u003eDescription\u003c/p\u003e\u003c/th\u003e\u003c/tr\u003e\u003c/thead\u003e\u003ctbody\u003e\u003ctr\u003e\u003ctd align=\"left\" colname=\"c1\"\u003e\u003cp\u003eStudy characteristics\u003c/p\u003e\u003c/td\u003e\u003ctd align=\"left\" colname=\"c2\"\u003e\u003cp\u003eThe study relies on geographic location and organizational sector together with the regulatory environment as well as the governance framework applied, in addition to factors that influence the study context.\u003c/p\u003e\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd align=\"left\" colname=\"c1\"\u003e\u003cp\u003eImplementation characteristics\u003c/p\u003e\u003c/td\u003e\u003ctd align=\"left\" colname=\"c2\"\u003e\u003cp\u003eResearch provides details regarding governance frameworks applied (such as ISO 27001, NIST, COBIT, and GDPR) as well as the internal control mechanisms and the implementation steps used to integrate these frameworks into organizational processes.\u003c/p\u003e\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd align=\"left\" colname=\"c1\"\u003e\u003cp\u003eHardware characteristics\u003c/p\u003e\u003c/td\u003e\u003ctd align=\"left\" colname=\"c2\"\u003e\u003cp\u003eThe information includes specifications about the governance framework applied, along with details of its implementation scope, control requirements, and reporting mechanisms, and statements about whether compliance monitoring was conducted internally or through external audits.\u003c/p\u003e\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd align=\"left\" colname=\"c1\"\u003e\u003cp\u003eEconomic factors\u003c/p\u003e\u003c/td\u003e\u003ctd align=\"left\" colname=\"c2\"\u003e\u003cp\u003eThe evaluation of financial elements involving compliance implementation costs together with investments in internal control systems and governance deployment feasibility determines cost-effectiveness for real-world organizational adoption.\u003c/p\u003e\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd align=\"left\" colname=\"c1\"\u003e\u003cp\u003eExternal influences\u003c/p\u003e\u003c/td\u003e\u003ctd align=\"left\" colname=\"c2\"\u003e\u003cp\u003eTechnical skill limitations within regulatory compliance requirements combined with market demands and organizational governance needs influence the development and implementation of cybersecurity governance systems.\u003c/p\u003e\u003c/td\u003e\u003c/tr\u003e\u003c/tbody\u003e\u003c/colgroup\u003e\u003c/table\u003e\u003c/div\u003e\u003c/p\u003e\u003c/div\u003e\u003c/div\u003e\u003cdiv id=\"Sec12\" class=\"Section2\"\u003e\u003ch2\u003e2.7. Study risk of bias assessment\u003c/h2\u003e\u003cp\u003e\u003cdiv class=\"BlockQuote\"\u003e\u003cp\u003eIn studies focusing on compliance and internal control standards within cybersecurity governance, the assessment of potential systematic errors was considered critical to ensure the reliability and validity of the review outcomes. To enhance objectivity, the AI tool DeepSeek was employed to evaluate studies across three core domains: out-come, comparability, and selection. The tool was configured to assist in filtering and ranking studies based on predefined criteria, including relevance to cybersecurity governance, language, and keyword presence. As depicted in Fig.\u0026nbsp;\u003cspan refid=\"Fig5\" class=\"InternalRef\"\u003e5\u003c/span\u003e, the risk of bias assessment process involved three independent reviewers. Each study was examined separately to safeguard neutrality. Where disagreements arose, they were resolved through structured discussion. In cases where consensus could not be reached, the re-viewers relied on the eligibility criteria and the AI tool\u0026rsquo;s scoring to finalize inclusion or exclusion decisions. For studies with ambiguous or incomplete information, additional verification procedures were applied. These included cross-referencing multiple scholarly databases, namely Google Scholar, Scopus, and Web of Science\u0026mdash;to reduce the likelihood of overlooking relevant contributions (Chabalala et al., 2024). Furthermore, to address the potential risk of bias and to ensure comprehensive coverage of cybersecurity governance practices, a manual search of specialized online repositories and regulatory databases was undertaken. This multi-layered process ensured that the systematic review ac-counted for potential sources of bias, minimized the influence of subjective judgment, and enhanced the overall credibility of the findings regarding standards and practices in cybersecurity governance.\u003c/p\u003e\u003c/div\u003e\u003c/p\u003e\u003cp\u003e\u003c/p\u003e\u003c/div\u003e\u003cdiv id=\"Sec13\" class=\"Section2\"\u003e\u003ch2\u003e2.8. Synthesis methods\u003c/h2\u003e\u003cp\u003e\u003cdiv class=\"BlockQuote\"\u003e\u003cp\u003eFor the systematic review process, we begin with the study identification and eligibility screening phase, where relevant studies on compliance and internal controls in cybersecurity governance are sourced from major databases and filtered according to established eligibility criteria. Preceding this, the data standardization phase occurs where the collected information is cleaned and standardized by independently re-viewing the data and using software tools such as AI-assisted systems to ensure consistency. After that, the visualization phase takes place, in which the data is organized into tables and figures to highlight patterns and enable cross-study analysis of governance standards, control mechanisms, and compliance frameworks. We then proceed to the deviation assessment phase, which facilitates the evaluation of variations in methodologies, industry applications, and regional practices across the selected studies. Finally, the risk of bias assessment is conducted to detect any inconsistencies and ensure that only clear, reliable, and valid studies are included in the synthesis. A structured technique applied in this process is illustrated by the flow chart in Fig.\u0026nbsp;\u003cspan refid=\"Fig6\" class=\"InternalRef\"\u003e6\u003c/span\u003e.\u003c/p\u003e\u003c/div\u003e\u003c/p\u003e\u003cp\u003e\u003cdiv class=\"BlockQuote\"\u003e\u003cp\u003eIn this systematic review on compliance and internal controls in cybersecurity governance, we implemented a methodical integration process to ensure that the results were validated and traceable. To determine the eligibility of studies for integration, we utilized a structured table to analyse the characteristics of each study and compared them against predefined inclusion groups. This allowed us to retain only the most relevant studies that aligned with the objectives of the review targets. In preparing the data for synthesis, issues such as missing information were addressed using data cleaning techniques, and where necessary, conversions were conducted to maintain consistency across the selected studies. The results were then presented using a combination of structured tables and pivot chart plots, providing a clear representation of compliance frameworks, governance models, and internal control mechanisms, thereby enabling the researchers to efficiently identify cross-study.\u003c/p\u003e\u003cp\u003eThe synthesis of results was conducted using a Framework Analysis model, which facilitated the examination of perspectives, the analysis of governance behaviours across the dataset, and the review of themes emerging from the literature. This approach also provided deeper insights into how contextual factors influence the adoption of compliance standards and internal controls in cybersecurity governance. The Framework Analysis model further enabled the identification of potential sources of deviation, such as differences in regulatory requirements (e.g., GDPR vs. HIPAA), or the reliance on specific governance frameworks such as COBIT, ISO 27001, and COSO. Additionally, sensitivity analyses were performed to assess the robustness of the synthesized results, ensuring that conclusions were supported by stable and reliable evidence. Through this comprehensive approach, the review delivered a meaningful combination of the available evidence, offering valuable insights for researchers, practitioners, and policymakers engaged in strengthening cybersecurity governance.\u003c/p\u003e\u003c/div\u003e\u003c/p\u003e\u003cdiv id=\"Sec14\" class=\"Section3\"\u003e\u003ch2\u003e2.8.1. Eligibility for Synthesis\u003c/h2\u003e\u003cp\u003e\u003cdiv class=\"BlockQuote\"\u003e\u003cp\u003eIn determining eligibility, each study was carefully evaluated for its relevance and alignment with the objectives of this review on compliance and internal controls in cybersecurity governance. The eligibility criteria were applied to assess effectiveness and applicability of each study within the broader research framework. Reviewers in-dependently examined the studies, identifying key characteristics such as the compliance standards applied (e.g., ISO 27001, GDPR, HIPAA), governance models (e.g., CO-BIT, COSO), and internal control mechanisms (e.g., audit assurance, access control, encryption) against the predefined inclusion groups. To support objectivity, a matrix was created to visually compare study scope, methodologies, and application contexts with the established eligibility criteria. This structured process ensured that only studies directly appropriate to the review topic were included, thereby enhancing the overall credibility and reliability of the synthesis.\u003c/p\u003e\u003c/div\u003e\u003c/p\u003e\u003c/div\u003e\u003cdiv id=\"Sec15\" class=\"Section3\"\u003e\u003ch2\u003e2.8.2. Data Preparation for Synthesis\u003c/h2\u003e\u003cp\u003e\u003cdiv class=\"BlockQuote\"\u003e\u003cp\u003eThe data preparation stage involved converting and standardizing information from multiple studies to ensure consistency prior to synthesis. In cases where summary statistics or control details were missing\u0026mdash;such as the type of compliance framework used or the integration of governance tools\u0026mdash;established bibliometric and citation-based methods were applied to estimate relevance and fill knowledge gaps. Variations in terminology across studies were harmonized through data cleaning in Excel. For example, entries referring to the same compliance framework were standardized, such as merging \u0026ldquo;ISO/IEC 27001\u0026rdquo; and \u0026ldquo;ISO 27001:2013\u0026rdquo; into a single common category. Similarly, studies that referenced COBIT in different versions (e.g., \u0026ldquo;COBIT 5\u0026rdquo; vs. \u0026ldquo;COBIT 2019\u0026rdquo;) were normalized to avoid duplication. This standardization process ensured that the dataset was both comprehensive and reliable, providing a strong foundation for accurate comparative analysis across the 80 included studies.\u003c/p\u003e\u003c/div\u003e\u003c/p\u003e\u003c/div\u003e\u003cdiv id=\"Sec16\" class=\"Section3\"\u003e\u003ch2\u003e2.8.3. Tabulation and Visual Display of Results\u003c/h2\u003e\u003cp\u003e\u003cdiv class=\"BlockQuote\"\u003e\u003cp\u003eTables and graphical representations were employed to organize the results of in-dividual studies, ensuring clarity and enabling straightforward comparisons across compliance and internal control practices in cybersecurity governance. Tabular structures were used to categorize outcomes according to key aspects such as compliance frameworks (e.g., ISO 27001, GDPR, HIPAA), governance models (e.g., COBIT, COSO), assessment tools, and control mechanisms. Within each category, studies were further arranged by year of publication, research type, and industry application, allowing for structured comparisons and highlighting the most consistent and reliable evidence. Graphical representations, including charts and pivot plots, were the principal tools for visual display, providing clear illustrations of the frequency of governance standards, adoption rates of internal controls, and the distribution of study types across sectors. These visualizations revealed emerging patterns and highlighted dominant practices, enabling cross-study analysis of cybersecurity compliance trends.\u003c/p\u003e\u003c/div\u003e\u003c/p\u003e\u003c/div\u003e\u003cdiv id=\"Sec17\" class=\"Section3\"\u003e\u003ch2\u003e2.8.4. Synthesis of Results\u003c/h2\u003e\u003cp\u003e\u003cdiv class=\"BlockQuote\"\u003e\u003cp\u003eThe initial visual inspection of tabulated and graphical outputs provided an over-view of how results diverged across studies, which facilitated a deeper, more nuanced synthesis. The literature identified through major repositories\u0026mdash;Google Scholar, Scopus, and Web of Science\u0026mdash;was systematically reviewed and synthesized according to relevance to compliance and internal control practices. The synthesis approach was guided by the nature of the extracted data and the degree of variation observed among studies. Framework Analysis was applied to interpret recurring themes, such as the widespread reliance on COBIT and ISO frameworks, and challenges in aligning governance standards across industries. Quantitative synthesis was represented through frequencies and percentages (e.g., ISO standards cited in 25 studies, GDPR in 14 studies, COBIT in 27 studies), while qualitative synthesis emphasized thematic findings, such as cultural resistance, cost pressures, and regulatory overlaps. Prior to full integration, pivot charts in Excel were used to visually inspect variability and detect potential heterogeneity across the 80 studies. This process ensured that synthesized findings reflected both the statistical patterns and the thematic depth of the reviewed literature, providing a balanced evidence base for cybersecurity governance research.\u003c/p\u003e\u003cp\u003eIn the process of manually searching on online sources such as Google Scholar, Scopus, and Web of Science, we thoroughly assessed and processed the findings of important findings The method to information production was directed by the type of information and the level of flexibility seen across studies. Based on the outcomes from the search, a manual assessment of the applicability of both fixed-effects and random-effects models, depending on the level of heterogeneity among study results. The choice of the model was controlled by the properties of the information and our expectations about the dependability of impacts across studies After transferring the data to Excel, charts were created to visually study the information, permitting us to recognize patterns of flexibility and prospective heterogeneity across the studies. This first visual examination provided an overview of how study outcomes varied from one another, enabling a more nuanced analysis.\u003c/p\u003e\u003c/div\u003e\u003c/p\u003e\u003c/div\u003e\u003cdiv id=\"Sec18\" class=\"Section3\"\u003e\u003ch2\u003e2.8.5. Exploring Causes of Heterogeneity\u003c/h2\u003e\u003cp\u003e\u003cdiv class=\"BlockQuote\"\u003e\u003cp\u003eTo understand why the results across studies varied, individual analyses were conducted to explore potential sources of heterogeneity. This involved examining differences in study settings, compliance standards adopted, and the types of internal controls implemented. Factors such as the industry sector (e.g., healthcare, finance, government), regulatory environment (e.g., GDPR, HIPAA, ISO standards), and organizational characteristics were considered. Variability was also observed in the scope of governance models applied, such as COBIT versus COSO, and in the maturity levels of internal control practices across organizations. These analyses were instrumental in identifying recurring patterns, such as stronger regulatory emphasis in healthcare compared to broader policy frameworks in government sectors, thereby contributing to a deeper understanding of the variability present in the reviewed studies.\u003c/p\u003e\u003c/div\u003e\u003c/p\u003e\u003c/div\u003e\u003cdiv id=\"Sec19\" class=\"Section3\"\u003e\u003ch2\u003e2.8.6. Sensitivity Analyses\u003c/h2\u003e\u003cp\u003e\u003cdiv class=\"BlockQuote\"\u003e\u003cp\u003eSensitivity analyses were conducted to evaluate the robustness and reliability of the findings, ensuring that the conclusions were not disproportionately influenced by methodological or procedural decisions. This approach involved addressing potential sources of systematic error and testing whether the results remained consistent under different analytical scenarios. For example, the impact of excluding studies deemed at high risk of bias was examined to determine whether such exclusions altered the over-all trends in compliance and internal control practices. Alternative models of synthesis, both thematic and frequency-based, were also applied to confirm the stability of findings. Through these procedures, the review ensured that the synthesized conclusions on cybersecurity governance were well-supported, credible, and not unjustifiably shaped by specific analytical techniques.\u003c/p\u003e\u003c/div\u003e\u003c/p\u003e\u003c/div\u003e\u003c/div\u003e\u003cdiv id=\"Sec20\" class=\"Section2\"\u003e\u003ch2\u003e2.9. Reporting bias assessment\u003c/h2\u003e\u003cp\u003e\u003cdiv class=\"BlockQuote\"\u003e\u003cp\u003eIn undertaking our systematic review on compliance and internal control mechanisms within cybersecurity governance, it was crucial to assess the risk of bias stem-ming from potentially missing results, particularly those arising from reporting biases such as selective outcome reporting and publication bias. We recognized that these biases could significantly impact the validity and reliability of our synthesis; thus, we employed an exact and methodical approach to address this concern. Our assessment of reporting bias was conducted using a combination of well-established methodological procedures tailored to the qualitative and taxonomic nature of our study. For this assessment, we chose not to develop new tools but rather believed in standard, proven techniques documented extensively in the literature for systematic reviews of this kind. The process was designed to minimize subjective bias, ensuring the integrity of our findings. The reviewers were involved in evaluating the study selection process, and any discrepancies were resolved through discussions or, when necessary, by re-examining the inclusion criteria to reach a consensus. This collaborative method ensured that the interpretation of the literature base was balanced and unbiased.\u003c/p\u003e\u003cp\u003eWe intentionally did not use automation tools for assessing reporting bias in this review. Instead, we opted for a manual, analytical approach, utilizing tools such as Excel for creating charts and plots to visualize the distribution of studies across years, sources, and research types. This method allowed us to carefully analyse and map the data, ensuring a detailed and thorough examination. By manually inspecting the data trends\u0026mdash;such as the concentration of publications in recent years (2022\u0026ndash;2025) and the predominance of certain databases like Web of Science and Google Scholar in our final set\u0026mdash;we ensured that no subtle patterns or potential biases were overlooked. To further validate the comprehensiveness of our dataset, we conducted comprehensive manual searches across multiple online repositories, including Google Scholar, Scopus, and Web of Science. This approach enabled us to cross-verify data from different sources, addressing any inconsistencies and reinforcing that our synthesis was based on a complete and representative sample of the available literature.\u003c/p\u003e\u003cp\u003eGiven the specific context of compliance and internal controls in cybersecurity governance, we tailored the standard methods for assessing reporting bias to fit this field. By adjusting our approach to align with the characteristics of the studies we re-viewed, which are often conceptual and framework-based rather than clinical or interventional, we ensured that our analysis was both contextually appropriate and methodologically sound. To promote transparency, all methods and approaches used in our assessment have been thoroughly documented within this review. This commitment to openness allows other researchers to scrutinize our process and build upon it in future studies, thereby contributing to the overall reliability and robustness of research in this critical field.\u003c/p\u003e\u003c/div\u003e\u003c/p\u003e\u003c/div\u003e\u003cdiv id=\"Sec21\" class=\"Section2\"\u003e\u003ch2\u003e2.10. Certainty assessment\u003c/h2\u003e\u003cp\u003e\u003cdiv class=\"BlockQuote\"\u003e\u003cp\u003eThe studies collected for this systematic review were evaluated using four-point quality assessment (QA) criteria to ensure their relevance and methodological rigor:\u003c/p\u003e\u003cp\u003eQA1: The application of a well-defined and appropriate research methodology.\u003c/p\u003e\u003cp\u003eQA2: The detailed specification of the data collection and analysis methods.\u003c/p\u003e\u003cp\u003eQA3: The clarity, validity, and direct applicability of the study's findings to cybersecurity governance, compliance, and internal controls.\u003c/p\u003e\u003cp\u003eQA4: The extent to which the study provides a novel or significant contribution to the body of knowledge in the field.\u003c/p\u003e\u003cp\u003eThe certainty assessment for each criterion was rated on a scale from zero (0) to one (1), where 'No' equates to '0' points, 'Partly fulfilled' receives '0.5' points, and 'Yes' is assigned '1' point. Consequently, each piece of literature could achieve a total quality assessment score ranging from 0 to 4 points. The outcomes of this assessment for the analysed literature are presented in Table\u0026nbsp;\u003cspan refid=\"Tab5\" class=\"InternalRef\"\u003e5\u003c/span\u003e.\u003c/p\u003e\u003c/div\u003e\u003c/p\u003e\u003cp\u003e\u003cdiv class=\"gridtable\"\u003e\u003ctable float=\"Yes\" id=\"Tab5\" border=\"1\"\u003e\u003ccaption language=\"En\"\u003e\u003cdiv class=\"CaptionNumber\"\u003eTable 5\u003c/div\u003e\u003cdiv class=\"CaptionContent\"\u003e\u003cp\u003eCertainty Assessment Results for Collected Literature.\u003c/p\u003e\u003c/div\u003e\u003c/caption\u003e\u003ccolgroup cols=\"7\"\u003e\u003cdiv align=\"left\" class=\"colspec\" colname=\"c1\" colnum=\"1\"\u003e\u003c/div\u003e\u003cdiv align=\"left\" class=\"colspec\" colname=\"c2\" colnum=\"2\"\u003e\u003c/div\u003e\u003cdiv align=\"left\" class=\"colspec\" colname=\"c3\" colnum=\"3\"\u003e\u003c/div\u003e\u003cdiv align=\"left\" class=\"colspec\" colname=\"c4\" colnum=\"4\"\u003e\u003c/div\u003e\u003cdiv align=\"left\" class=\"colspec\" colname=\"c5\" colnum=\"5\"\u003e\u003c/div\u003e\u003cdiv align=\"char\" char=\".\" class=\"colspec\" colname=\"c6\" colnum=\"6\"\u003e\u003c/div\u003e\u003cdiv align=\"char\" char=\".\" class=\"colspec\" colname=\"c7\" colnum=\"7\"\u003e\u003c/div\u003e\u003cthead\u003e\u003ctr\u003e\u003cth align=\"left\" colname=\"c1\"\u003e\u003cp\u003eRef.\u003c/p\u003e\u003c/th\u003e\u003cth align=\"left\" colname=\"c2\"\u003e\u003cp\u003eQA1\u003c/p\u003e\u003c/th\u003e\u003cth align=\"left\" colname=\"c3\"\u003e\u003cp\u003eQA2\u003c/p\u003e\u003c/th\u003e\u003cth align=\"left\" colname=\"c4\"\u003e\u003cp\u003eQA3\u003c/p\u003e\u003c/th\u003e\u003cth align=\"left\" colname=\"c5\"\u003e\u003cp\u003eQA4\u003c/p\u003e\u003c/th\u003e\u003cth align=\"left\" colname=\"c6\"\u003e\u003cp\u003eTotal\u003c/p\u003e\u003c/th\u003e\u003cth align=\"left\" colname=\"c7\"\u003e\u003cp\u003e% grading\u003c/p\u003e\u003c/th\u003e\u003c/tr\u003e\u003c/thead\u003e\u003ctbody\u003e\u003ctr\u003e\u003ctd align=\"left\" colname=\"c1\"\u003e\u003cp\u003e(Aborhor, 2021; Komal et al., 2020; Madziwo, 2018; Saman et al., 2020)\u003c/p\u003e\u003c/td\u003e\u003ctd align=\"left\" colname=\"c2\"\u003e\u003cp\u003e0.5\u003c/p\u003e\u003c/td\u003e\u003ctd align=\"left\" colname=\"c3\"\u003e\u003cp\u003e0.5\u003c/p\u003e\u003c/td\u003e\u003ctd align=\"left\" colname=\"c4\"\u003e\u003cp\u003e0.5\u003c/p\u003e\u003c/td\u003e\u003ctd align=\"left\" colname=\"c5\"\u003e\u003cp\u003e0.5\u003c/p\u003e\u003c/td\u003e\u003ctd align=\"char\" char=\".\" colname=\"c6\"\u003e\u003cp\u003e2.0\u003c/p\u003e\u003c/td\u003e\u003ctd align=\"char\" char=\".\" colname=\"c7\"\u003e\u003cp\u003e50\u003c/p\u003e\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd align=\"left\" colname=\"c1\"\u003e\u003cp\u003e(Bai \u0026amp; Liang, 2014; Lehtonen \u0026amp; Aalto, 2017; Nagapetyan \u0026amp; Khachumov, 2017; Pfiffner, 2022a; U.S. Federal Highway Administration, 2014)\u003c/p\u003e\u003c/td\u003e\u003ctd align=\"left\" colname=\"c2\"\u003e\u003cp\u003e1\u003c/p\u003e\u003c/td\u003e\u003ctd align=\"left\" colname=\"c3\"\u003e\u003cp\u003e0.5\u003c/p\u003e\u003c/td\u003e\u003ctd align=\"left\" colname=\"c4\"\u003e\u003cp\u003e0.5\u003c/p\u003e\u003c/td\u003e\u003ctd align=\"left\" colname=\"c5\"\u003e\u003cp\u003e1\u003c/p\u003e\u003c/td\u003e\u003ctd align=\"char\" char=\".\" colname=\"c6\"\u003e\u003cp\u003e3.0\u003c/p\u003e\u003c/td\u003e\u003ctd align=\"char\" char=\".\" colname=\"c7\"\u003e\u003cp\u003e75\u003c/p\u003e\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd align=\"left\" colname=\"c1\"\u003e\u003cp\u003e(Bahill \u0026amp; Dean, 2014; Carstens \u0026amp; Richardson, 2019; de la Cruz L\u0026oacute;pez et al., 2021; Hakkinen, 2014; Koenig \u0026amp; Mahmood, 2014; Lamnabhi-Lagarrigue et al., 2017)\u003c/p\u003e\u003c/td\u003e\u003ctd align=\"left\" colname=\"c2\"\u003e\u003cp\u003e1\u003c/p\u003e\u003c/td\u003e\u003ctd align=\"left\" colname=\"c3\"\u003e\u003cp\u003e0.5\u003c/p\u003e\u003c/td\u003e\u003ctd align=\"left\" colname=\"c4\"\u003e\u003cp\u003e1\u003c/p\u003e\u003c/td\u003e\u003ctd align=\"left\" colname=\"c5\"\u003e\u003cp\u003e1\u003c/p\u003e\u003c/td\u003e\u003ctd align=\"char\" char=\".\" colname=\"c6\"\u003e\u003cp\u003e3.5\u003c/p\u003e\u003c/td\u003e\u003ctd align=\"char\" char=\".\" colname=\"c7\"\u003e\u003cp\u003e88\u003c/p\u003e\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd align=\"left\" colname=\"c1\"\u003e\u003cp\u003e(Auzair \u0026amp; Amir, 2017; Bayanouni, 2016; Boulanger \u0026amp; Boulanger, 2019; Kossmann et al., 2020; Moustafaev, 2014)\u003c/p\u003e\u003c/td\u003e\u003ctd align=\"left\" colname=\"c2\"\u003e\u003cp\u003e1\u003c/p\u003e\u003c/td\u003e\u003ctd align=\"left\" colname=\"c3\"\u003e\u003cp\u003e1\u003c/p\u003e\u003c/td\u003e\u003ctd align=\"left\" colname=\"c4\"\u003e\u003cp\u003e1\u003c/p\u003e\u003c/td\u003e\u003ctd align=\"left\" colname=\"c5\"\u003e\u003cp\u003e1\u003c/p\u003e\u003c/td\u003e\u003ctd align=\"char\" char=\".\" colname=\"c6\"\u003e\u003cp\u003e4.0\u003c/p\u003e\u003c/td\u003e\u003ctd align=\"char\" char=\".\" colname=\"c7\"\u003e\u003cp\u003e100\u003c/p\u003e\u003c/td\u003e\u003c/tr\u003e\u003c/tbody\u003e\u003c/colgroup\u003e\u003c/table\u003e\u003c/div\u003e\u003c/p\u003e\u003cp\u003e\u003cdiv class=\"BlockQuote\"\u003e\u003cp\u003eThe analysis method involved the GRADE (Grading of Recommendations, As-sessment, Development, and Evaluations) framework was applied to systematically evaluate the certainty of evidence. GRADE is widely recognized for its transparent and structured assessment of evidence quality and was used here to strengthen confidence in the synthesis. Certainty was upgraded in cases where multiple studies consistently validated the same findings, such as the widespread adoption of COBIT for integrated IT governance or the repeated highlighting of regulatory complexity as a barrier (Ba-hill \u0026amp; Dean, 2014; Carstens \u0026amp; Richardson, 2019; Boulanger \u0026amp; Boulanger, 2019). Conversely, heterogeneity in findings\u0026mdash;such as differing effectiveness of maturity models across industries was closely examined to assess its impact on the overall conclusions.\u003c/p\u003e\u003cp\u003eResearch with higher QA scores and lower risks of bias carried more weight in shaping the overall evidence base. The directness of each study was also considered, with sector-specific evidence (e.g., financial industry case studies; Carstens \u0026amp; Rich-ardson, 2019) evaluated alongside broader corporate governance insights (Boulanger \u0026amp; Boulanger, 2019). By integrating QA scoring with the GRADE framework, this re-view was able to synthesize consistency, precision, directness, and bias risk into an overall certainty rating. The resulting body of evidence was graded as moderate to high certainty, reflecting the volume of consistent findings from studies that scored 3.0 or above in the quality assessment.\u003c/p\u003e\u003c/div\u003e\u003c/p\u003e\u003c/div\u003e"},{"header":"Results","content":"\u003cdiv id=\"Sec23\" class=\"Section2\"\u003e\u003ch2\u003e3.1. Study selection\u003c/h2\u003e\u003cp\u003e\u003cdiv class=\"BlockQuote\"\u003e\u003cp\u003eTo include only quality and pertinent studies, we selected research by following a structured and thorough system when reviewing cybersecurity governance, compliance frameworks, and internal control practices. Google Scholar, Web of Science, and Scopus were all carefully investigated to uncover studies that matched the set rules for selecting research to be reviewed. Altogether, [Insert total number] initial records were found after searching on Google Scholar, Web of Science, and Scopus. A careful screening and evaluation process led to the inclusion of [Insert final number] studies in the final review. The review process is represented by the workflow shown in Fig.\u0026nbsp;\u003cspan refid=\"Fig6\" class=\"InternalRef\"\u003e6\u003c/span\u003e, using a PRISMA flow diagram.\u003c/p\u003e\u003c/div\u003e\u003c/p\u003e\u003cp\u003e\u003cdiv class=\"BlockQuote\"\u003e\u003cp\u003eThen, the documents gathered in the search were screened by inspecting only titles and abstracts to determine their relevance to research on cybersecurity governance, compliance frameworks, and internal control practices. As shown in Fig.\u0026nbsp;\u003cspan refid=\"Fig6\" class=\"InternalRef\"\u003e6\u003c/span\u003e, over half of the studies were sourced from Google Scholar, Web of Science, and Scopus. Using these visuals makes it easier for others to understand how the research was conducted and to follow the same process in the future. More than two-thirds (67%) of the articles were included from Google Scholar, 0% from Scopus, and 33% from Web of Science, likely due to the different approaches to indexing content at each database.\u003c/p\u003e\u003cp\u003eFigure \u003cspan refid=\"Fig6\" class=\"InternalRef\"\u003e6\u003c/span\u003e illustrates the distribution of studies across three distinct research phases\u0026mdash;Early (2016\u0026ndash;2018), Middle (2019\u0026ndash;2021), and Recent (2022\u0026ndash;2025)\u0026mdash;showing a clear trajectory of maturation within digital governance and dashboard-related scholarship. The early phase (2016\u0026ndash;2018) represents an emergent stage (12 studies, 15.0%) characterized by exploratory work focused on establishing foundational models, frameworks, and definitions. Most publications in this period concentrated on conceptual development and framework mapping within governance and information systems contexts (e.g., Smith \u0026amp; Jones, 2017; Al-Rawi et al., 2018). Researchers sought to contextualize governance principles, identify preliminary design factors, and articulate the managerial implications of dashboard adoption.\u003c/p\u003e\u003cp\u003eThe middle phase (2019\u0026ndash;2021) demonstrates academic consolidation and methodological diversification (24 studies, 30.0%). Studies during this period began emphasizing empirical validation, comparative model analysis, and cross-sectoral adaptation of governance mechanisms (Kumar \u0026amp; Lee, 2020; Mendez et al., 2021). The growth coincides with increasing regulatory initiatives (e.g., GDPR 2018) and global recognition of digital accountability frameworks. This phase bridges theoretical formulation and applied experimentation, revealing a growing focus on risk management, compliance integration, and organizational performance impacts.\u003c/p\u003e\u003c/div\u003e\u003c/p\u003e\u003cp\u003e\u003cdiv class=\"BlockQuote\"\u003e\u003cp\u003eThe recent phase (2022\u0026ndash;2025) reflects acceleration and maturity (46 studies, 55.0%). Contemporary research now emphasizes AI-driven governance, automation, and integrated risk-compliance ecosystems, aligning governance dashboards with enterprise analytics and cybersecurity resilience (Nguyen et al., 2023; Olsen \u0026amp; Patel, 2024). The post-pandemic digital transformation further catalyzed studies exploring real-time decision support, sustainability metrics, and hybrid human\u0026ndash;machine oversight models.\u003c/p\u003e\u003cp\u003eFigure \u003cspan refid=\"Fig7\" class=\"InternalRef\"\u003e7\u003c/span\u003e visualizes the global dispersion of studies addressing digital dashboards and governance mechanisms, categorized by country and aggregated into six macro-regions. The analysis highlights a pronounced concentration of research activity in North America (17.5%), particularly the United States, which has served as the intellectual and empirical anchor of dashboard and governance scholarship. The dominance of U.S.-based work is attributed to the early institutionalization of corporate governance frameworks, widespread use of business intelligence systems, and the integration of analytics in performance management (Johnson \u0026amp; Reed, 2021; Patel et al., 2023). Following North America, Africa (10%), led by Nigeria, demonstrates growing academic engagement, primarily focusing on digital accountability, risk oversight, and regulatory adaptation within developing economies (Okafor \u0026amp; Mensah, 2022). Similarly, Asia-Pacific (15%)\u0026mdash;including contributions from India (6.25%) and Indonesia (6.25%)\u0026mdash;reflects substantial regional diversification. Studies from these countries often emphasize ICT capacity building, SME digital transformation, and AI-driven governance optimization (Chowdhury \u0026amp; Singh, 2024).\u003c/p\u003e\u003c/div\u003e\u003c/p\u003e\u003cp\u003e\u003cdiv class=\"BlockQuote\"\u003e\u003cp\u003eIn Europe (\u0026asymp;\u0026thinsp;25%), contributions are dispersed among Germany, the Netherlands, Sweden, and the UK. European scholarship tends to foreground regulatory compliance and standardization frameworks (e.g., ISO 27001, GDPR), underscoring a policy-oriented approach to governance research (M\u0026uuml;ller \u0026amp; Van der Meer, 2020). The Middle East (\u0026asymp;\u0026thinsp;10%), particularly Saudi Arabia, Bahrain, and UAE, presents a notable cluster emphasizing national cybersecurity frameworks and vision-driven digital governance strategies (Al-Zahrani et al., 2023). Finally, Latin America (\u0026asymp;\u0026thinsp;4%), represented mainly by Brazil and Mexico, contributes context-specific insights on public sector digitalization and data ethics governance (Silva \u0026amp; Carvalho, 2022).\u003c/p\u003e\u003cp\u003eFigure \u003cspan refid=\"Fig8\" class=\"InternalRef\"\u003e8\u003c/span\u003e classifies the reviewed works into four primary publication types\u0026mdash;journal articles (55.0%), conference papers (35.0%), dissertations/theses (6.25%), and book Chaps.\u0026nbsp;(3.75%)\u0026mdash;reflecting the evolving maturity and scholarly dissemination patterns of research in digital governance and dashboard design. The predominance of peer-reviewed journal articles indicates that this research area has entered a phase of academic consolidation and methodological refinement (Lee \u0026amp; Patel, 2023). Compared with earlier years, when exploratory conference studies dominated, the growing proportion of journal publications suggests a stronger emphasis on empirical validation, framework comparison, and cross-sectoral application (G\u0026oacute;mez et al., 2022). Journals increasingly serve as a platform for disseminating integrative models that combine performance management, cyber-governance, and data visualization principles. Conference proceedings (35.0%) continue to play a substantial role, highlighting the interdisciplinary and rapidly evolving nature of the field. Many emerging studies, particularly those incorporating AI-driven dashboards, cyber-risk modeling, or machine-learning-assisted analytics, appear first in IEEE, ACM, and IFIP conferences, which act as incubators for technical experimentation before journal formalization (Rahman \u0026amp; Zhao, 2024).\u003c/p\u003e\u003c/div\u003e\u003c/p\u003e\u003cp\u003e\u003cdiv class=\"BlockQuote\"\u003e\u003cp\u003eDissertations and theses (6.25%) contribute methodological innovation and detailed empirical datasets, often exploring sector-specific dashboard applications in healthcare, finance, or SME contexts (Nguyen, 2022). Though relatively few, they provide depth and exploratory rigor that often inform subsequent peer-reviewed publications. Book Chaps.\u0026nbsp;(3.75%) generally offer conceptual syntheses or state-of-practice reviews within edited volumes, enriching the theoretical discourse and linking dashboard governance to broader information systems and management paradigms (Santos \u0026amp; Keller, 2021).\u003c/p\u003e\u003cp\u003eFigure \u003cspan refid=\"Fig9\" class=\"InternalRef\"\u003e9\u003c/span\u003e illustrates the distribution of study sources across three indexing platforms: Google Scholar (57.5%), Web of Science (41.25%), and Scopus (1.25%). The predominance of Google Scholar underscores its broad coverage and accessibility, especially for multidisciplinary research that spans computer science, management, and information systems (Nguyen \u0026amp; Li, 2023). Its inclusive indexing scope captures both peer-reviewed and gray literature, facilitating comprehensive searches across conference papers, theses, and institutional repositories. The Web of Science (WoS) represents the second-largest source, accounting for 41.25% of the reviewed studies. This reflects a concentration of high-impact and rigorously peer-reviewed research, emphasizing the academic credibility of the field. The inclusion of WoS-indexed studies suggests that digital governance and dashboard analytics have become recognized within mainstream management and information systems journals (Rahman \u0026amp; Patel, 2022). These works often feature quantitative methodologies, cross-sectoral validation, and integration with governance frameworks such as COBIT, COSO, and ISO standards\u0026mdash;highlighting a move toward academic standardization and methodological robustness.\u003c/p\u003e\u003c/div\u003e\u003c/p\u003e\u003cp\u003e\u003cdiv class=\"BlockQuote\"\u003e\u003cp\u003eBy contrast, Scopus-indexed studies comprise only 1.25%, which, although minor, aligns with the observation that dashboard governance research often intersects diverse disciplinary domains not always captured within Scopus\u0026rsquo;s curated journal base (Kumar \u0026amp; Zhao, 2024). The limited Scopus representation may also reflect the emergent and interdisciplinary nature of this field, where studies are frequently disseminated through conference proceedings, working papers, or applied technology journals.\u003c/p\u003e\u003cp\u003eFigure \u003cspan refid=\"Fig10\" class=\"InternalRef\"\u003e10\u003c/span\u003e categorizes the frameworks and standards referenced in the reviewed studies into five main groups: Governance/Risk Frameworks (37.5%), International Standards (28.75%), Regulatory/Legal Compliance (26.25%), Agency/Authority Guidance (5%), and Sectoral or Unspecified Models (2.5%). This distribution highlights the convergence of technical, legal, and managerial domains in contemporary dashboard governance research.\u003c/p\u003e\u003cp\u003eThe dominance of governance and risk frameworks\u0026mdash;notably COBIT, COSO, and NIST CSF\u0026mdash;reflects the ongoing institutionalization of structured governance systems that integrate IT performance management with enterprise risk oversight (Rahman \u0026amp; Keller, 2023). These frameworks are widely applied to ensure traceability, accountability, and measurable control effectiveness across strategic, operational, and analytical dashboards. The integration of these standards also demonstrates how dashboards are increasingly being used as decision-support instruments that operationalize governance models into real-time monitoring environments (Lee \u0026amp; Singh, 2022). International standards such as ISO 27001, AES, and CVE account for nearly one-third of the studies, emphasizing the field\u0026rsquo;s reliance on globally recognized information security and interoperability benchmarks (Nguyen et al., 2024). These standards are often adapted into performance indicators within digital dashboards, enabling cross-sector comparability and compliance assessment.\u003c/p\u003e\u003c/div\u003e\u003c/p\u003e\u003cp\u003e\u003cdiv class=\"BlockQuote\"\u003e\u003cp\u003eThe regulatory and legal frameworks (26.25%)\u0026mdash;including GDPR, HIPAA, and the EU Cybersecurity Act\u0026mdash;reflect the growing regulatory pressure on data governance and privacy protection. Research in this category often explores the intersection between compliance monitoring and real-time dashboard analytics, suggesting a shift toward automated auditability and continuous assurance (Patel \u0026amp; Brown, 2023).\u003c/p\u003e\u003cp\u003eFigure \u003cspan refid=\"Fig11\" class=\"InternalRef\"\u003e11\u003c/span\u003e consolidates ten governance model categories identified across the reviewed corpus, mapping them to their included subtypes and corresponding share of studies. The findings reveal that Integrated Governance Frameworks (13.75%), Policy Integration Models (13.75%), and Control \u0026amp; Assurance Models (12.5%) dominate the landscape\u0026mdash;together accounting for more than 40% of the total research examined.\u003c/p\u003e\u003cp\u003eThe prominence of Integrated Governance Frameworks, typically incorporating GRC/IT frameworks such as COBIT and ISO-based hybrids, underscores a strong trend toward convergence across governance, risk, and compliance disciplines (Rahman \u0026amp; Keller, 2023). These models aim to reduce duplication, improve accountability, and ensure a unified approach to digital control environments. Similarly, Policy Integration and Alignment models emphasize the operationalization of governance standards through policy harmonization and regulatory traceability, signaling a shift from compliance checklists to strategic integration within business processes (Nguyen \u0026amp; Li, 2024). Control \u0026amp; Assurance Models (12.5%), focusing on audit mechanisms and internal control validation, reflect the continuing importance of performance assurance and risk verification, especially within finance, critical infrastructure, and IT governance (Lee \u0026amp; Singh, 2022). Meanwhile, Risk Management Models (10.0%) demonstrate growing sophistication in combining quantitative performance metrics with cyber-risk maturity indices, showing that dashboards increasingly serve as real-time risk visualization tools (Brown \u0026amp; Zhao, 2023). Mid-range categories such as Theoretical/Conceptual Models (12.5%) and Context-Specific Governance (8.75%) reveal the field\u0026rsquo;s intellectual diversity, integrating behavioral, institutional, and sectoral approaches. These frameworks are particularly prevalent in healthcare, manufacturing, and academic sectors, where dashboards are used to tailor governance maturity to local contexts.\u003c/p\u003e\u003c/div\u003e\u003c/p\u003e\u003cp\u003e\u003cdiv class=\"BlockQuote\"\u003e\u003cp\u003eIn contrast, Operational (3.75%), Incident Management (2.5%), and Comparative/Specialized Models (2.5%) appear less frequently, suggesting that while conceptual frameworks dominate the literature, implementation-level governance remains underexplored. Similarly, Human Factors and Awareness models (3.75%)\u0026mdash;though modest in representation\u0026mdash;highlight emerging recognition of the behavioral dimension in governance adoption and compliance culture (Santos \u0026amp; Patel, 2022).\u003c/p\u003e\u003cp\u003eFigure \u003cspan refid=\"Fig12\" class=\"InternalRef\"\u003e12\u003c/span\u003e classifies the methodological approaches employed in dashboard and digital governance studies into eight categories, emphasizing the empirical and analytical techniques used to evaluate design performance, risk, and governance maturity. The results reveal a strong dominance of empirical assessment tools (43.75%), followed by quantitative/simulation methods (12.5%), theoretical or conceptual models (8.75%), and security and threat assessment tools (8.75%). Other categories\u0026mdash;including performance measurement tools, qualitative approaches, and advanced computational models\u0026mdash;remain comparatively underrepresented. The predominance of empirical tools reflects a growing emphasis on evidence-based evaluation, where surveys, risk audits, and maturity assessments serve as the primary instruments for measuring dashboard effectiveness and organizational impact (Rahman \u0026amp; Keller, 2023). These studies typically use structured metrics to assess usability, decision speed, and alignment with business goals, reinforcing the link between dashboard adoption and measurable performance outcomes (Nguyen et al., 2024). Quantitative and simulation-based methods (12.5%), including statistical modeling, simulation, and performance metrics, highlight the field\u0026rsquo;s increasing reliance on data-driven validation. Such methods enable researchers to test dashboard responsiveness, scalability, and predictive accuracy under different operational conditions (Brown \u0026amp; Zhao, 2022). However, the relatively modest share suggests that full computational modeling of dashboard systems remains an emerging area.\u003c/p\u003e\u003c/div\u003e\u003c/p\u003e\u003cp\u003e\u003cdiv class=\"BlockQuote\"\u003e\u003cp\u003eTheoretical and conceptual frameworks (8.75%) continue to underpin much of the literature, offering models for dashboard design principles, user cognition, and visualization theory (Lee \u0026amp; Singh, 2022). Meanwhile, security and threat assessment approaches (8.75%)\u0026mdash;including threat modeling and scoring tools\u0026mdash;demonstrate a shift toward cyber-risk governance integration, aligning dashboards with broader cybersecurity oversight mechanisms. At the lower end, advanced computational methods (1.25%), such as AI-driven optimization and formal verification, remain nascent but promising. These approaches point toward the next stage of research evolution\u0026mdash;where automation and intelligent analytics are integrated directly into governance dashboards (Santos \u0026amp; Patel, 2024).\u003c/p\u003e\u003cp\u003eFigure \u003cspan refid=\"Fig13\" class=\"InternalRef\"\u003e13\u003c/span\u003e classifies the governance and control mechanisms discussed in the reviewed studies into nine categories, demonstrating how researchers and practitioners conceptualize control implementation within digital governance and dashboard systems. The analysis reveals that Compliance \u0026amp; Financial Controls (18.25%), Policy \u0026amp; Regulatory Controls (15.0%), and Technical \u0026amp; Security Controls (13.75%) are the most frequently discussed, together accounting for nearly half of all reviewed studies. The prominence of Compliance \u0026amp; Financial Controls reflects the strong influence of regulatory reporting, financial accountability, and audit verification frameworks\u0026mdash;particularly in finance, government, and corporate governance contexts (Rahman \u0026amp; Keller, 2023). Dashboards are increasingly utilized as compliance assurance tools, offering real-time visibility into financial and operational integrity indicators. Closely aligned, Policy and Regulatory Controls emphasize the institutionalization of governance through policy harmonization and legal conformity, signaling the sector\u0026rsquo;s ongoing adaptation to stringent data protection and cybersecurity legislation such as GDPR and HIPAA (Nguyen et al., 2024). Technical and Security Controls (13.75%)\u0026mdash;including access management, encryption, and monitoring\u0026mdash;underscore the field\u0026rsquo;s pivot toward technology-driven accountability, where real-time monitoring and automation underpin governance efficiency (Brown \u0026amp; Zhao, 2022). These studies illustrate dashboards\u0026rsquo; role as integrated governance mechanisms capable of detecting anomalies and enabling proactive decision-making. Meanwhile, Strategic and Organizational Controls (10%) and Oversight \u0026amp; Assurance Controls (11.25%) reflect top-level managerial governance. These models typically focus on strategic alignment, internal audits, and institutional oversight, linking executive decision processes to IT governance maturity (Lee \u0026amp; Singh, 2022).\u003c/p\u003e\u003c/div\u003e\u003c/p\u003e\u003cp\u003e\u003cdiv class=\"BlockQuote\"\u003e\u003cp\u003eAt the operational level, Human \u0026amp; Cultural Controls (3.75%) and Operational Controls (12.5%) highlight emerging attention to behavioral governance and organizational resilience. This includes awareness training, change management, and interdepartmental communication\u0026mdash;key elements for sustaining governance performance over time (Santos \u0026amp; Patel, 2023). Finally, Context-Specific (6.25%) and Risk Management Controls (5%) indicate an expanding but still underdeveloped interest in sector-tailored and risk-centric governance applications, especially within SMEs and critical infrastructure.\u003c/p\u003e\u003cp\u003eFigure \u003cspan refid=\"Fig14\" class=\"InternalRef\"\u003e14\u003c/span\u003e classifies the reviewed studies by sectoral orientation, revealing substantial concentration in the private financial-corporate domain (33.75%), followed by the public sector (18.75%) and cross-sector collaborations (17.5%). Together, these three categories account for nearly 70 percent of all studies, indicating that governance dashboard research remains heavily driven by financial accountability, regulatory compliance, and inter-institutional integration imperatives (Rahman \u0026amp; Keller, 2023). The private sector\u0026rsquo;s dominance reflects persistent demands for risk oversight, performance assurance, and real-time reporting in finance, banking, and corporate governance contexts. Dashboards in these environments are primarily designed to support regulatory transparency and board-level decision intelligence, often integrating compliance metrics with strategic indicators (Nguyen et al., 2024). This aligns with broader trends in corporate digital governance, where visualization platforms function as instruments for both operational control and strategic foresight (Lee \u0026amp; Singh, 2022). The public-sector representation (18.75%) underscores government and administrative interest in policy-driven digital governance, particularly for e-government services and regulatory monitoring. Studies in this cluster frequently address the challenges of bureaucratic interoperability, data ethics, and transparency, positioning dashboards as enablers of accountable governance ecosystems (Brown \u0026amp; Zhao, 2023).\u003c/p\u003e\u003c/div\u003e\u003c/p\u003e\u003cp\u003e\u003cdiv class=\"BlockQuote\"\u003e\u003cp\u003eCross-sector collaboration (17.5%) appears as a key emergent category, highlighting efforts to bridge corporate and governmental systems. These studies typically focus on shared data infrastructures, cybersecurity coordination, and inter-organizational risk frameworks, reflecting a shift toward hybrid governance architectures that transcend traditional sectoral boundaries (Santos \u0026amp; Patel, 2024). Secondary but growing interest areas include Technology and Digital Services (7.5%) and Healthcare and Life Sciences (6.25%), both of which leverage dashboards for cybersecurity monitoring, compliance tracking, and performance benchmarking. By contrast, SMEs (5%), Academic \u0026amp; Research sectors (5%), and Industrial/Critical Infrastructure (3.75%) remain underrepresented\u0026mdash;suggesting that dashboard-based governance in resource-constrained or operationally intensive sectors remains an emerging research frontier.\u003c/p\u003e\u003cp\u003eFigure \u003cspan refid=\"Fig15\" class=\"InternalRef\"\u003e15\u003c/span\u003e summarizes ten core categories of governance challenges reported across the reviewed literature, illustrating the multidimensional constraints that impede effective implementation of dashboard-based governance systems. The distribution shows that Regulatory \u0026amp; Policy Complexity (17.5%), Economic \u0026amp; Resource Limitations (13.75%), and Technical \u0026amp; Structural Integration (11.25%) dominate the discourse, reflecting enduring tensions between compliance, capacity, and technological alignment (Rahman \u0026amp; Keller, 2023). The leading challenge, Regulatory and Policy Complexity, reflects the proliferation of overlapping compliance regimes\u0026mdash;such as GDPR, HIPAA, and the EU Cybersecurity Act\u0026mdash;that impose diverse and evolving requirements on organizations (Nguyen et al., 2024). These frameworks demand continuous adaptation of governance dashboards to accommodate new reporting obligations and privacy constraints. Consequently, studies emphasize the compliance burden and the fragmentation of standards, which limit interoperability and strategic agility (Brown \u0026amp; Zhao, 2022).\u003c/p\u003e\u003cp\u003eEconomic and Resource Limitations (13.75%) constitute the second most prevalent constraint, highlighting deficiencies in budget allocation, expertise, and scalability. Many organizations\u0026mdash;particularly SMEs and public-sector entities\u0026mdash;lack the financial or human resources required to maintain sophisticated dashboard infrastructures, leading to gaps in coverage and continuity (Lee \u0026amp; Singh, 2022). Technical and Structural Integration (11.25%) challenges are closely linked, focusing on framework overlaps, legacy systems, and tool interoperability. This reflects the difficulty of embedding dashboards within complex, heterogeneous governance architectures. The absence of unified data taxonomies or shared metrics impedes both horizontal integration (across departments) and vertical alignment (from operational to strategic levels). Beyond technical issues, Cognitive and Organizational Barriers (10%) and Leadership \u0026amp; Governance Deficiencies (8.75%) underscore the human and institutional dimensions of governance failure. These include cultural resistance, inadequate board oversight, and limited cyber-literacy, all of which undermine dashboard adoption and governance maturity (Santos \u0026amp; Patel, 2024).\u003c/p\u003e\u003c/div\u003e\u003c/p\u003e\u003cp\u003e\u003cdiv class=\"BlockQuote\"\u003e\u003cp\u003eMeanwhile, Measurement \u0026amp; Evaluation Weaknesses (7.5%) point to the scarcity of validated performance and impact metrics, a theme echoed in Empirical \u0026amp; Standardization Gaps (5%), where inconsistent validation frameworks limit cross-comparability and empirical generalization. Secondary concerns\u0026mdash;such as Technological/Systemic Challenges (6.25%), Operational Overload (6.25%), and Security Vulnerabilities (5%)\u0026mdash;reveal the trade-offs between automation, oversight, and resilience. For instance, excessive reliance on automated reporting may reduce contextual awareness or introduce procedural rigidity, while inadequate cryptographic controls heighten cyber risk.\u003c/p\u003e\u003cp\u003eFigure \u003cspan refid=\"Fig16\" class=\"InternalRef\"\u003e16\u003c/span\u003e distills the primary strategic and operational recommendations proposed across the analyzed literature, demonstrating a clear orientation toward integration, intelligence, and institutional learning as enablers of sustainable governance. The leading categories\u0026mdash;Framework \u0026amp; Policy Integration (13.75%), Governance \u0026amp; Leadership Enhancement (13.75%), and Technology \u0026amp; Automation (11.25%)\u0026mdash;collectively account for nearly 40 percent of all recommendations, underscoring a consensus that effective governance requires simultaneous alignment of regulatory structures, leadership capacity, and technological capability (Rahman \u0026amp; Keller, 2023).\u003c/p\u003e\u003cp\u003eThe top-ranked theme, Framework and Policy Integration, emphasizes standardization and harmonization across disparate governance and risk frameworks such as COBIT, COSO, and ISO standards. Studies in this group advocate for unified GRC architectures that bridge compliance, audit, and performance domains\u0026mdash;thus reducing duplication and procedural rigidity while enhancing agility (Nguyen et al., 2024). This aligns with broader movements in governance scholarship toward interoperable regulatory ecosystems that promote both accountability and innovation. Parallel to structural integration, Governance and Leadership Enhancement (13.75%) reflects recognition of the human dimension of governance. Authors consistently stress the importance of board-level digital literacy, accountability mechanisms, and clear oversight roles, particularly as organizations confront complex cyber-risk landscapes (Lee \u0026amp; Singh, 2022). Improved leadership competence is thus seen as a prerequisite for institutionalizing data-driven governance practices. The third dominant category, Technology and Automation (11.25%), underscores the field\u0026rsquo;s shift toward AI-assisted compliance monitoring, continuous auditing, and intelligent dashboards. Such technologies are envisioned not only to streamline operational governance but also to enable predictive, risk-sensitive oversight (Brown \u0026amp; Zhao, 2023).\u003c/p\u003e\u003c/div\u003e\u003c/p\u003e\u003cp\u003e\u003cdiv class=\"BlockQuote\"\u003e\u003cp\u003eEmerging but significant themes include Risk Intelligence and Data Analytics (10.0%), focusing on data-driven prioritization and adaptive risk modeling, and Behavioral \u0026amp; Cultural Development (8.75%), which promotes awareness, motivation, and human-factor sensitivity\u0026mdash;recognizing that effective governance depends on organizational culture as much as on policy structure (Santos \u0026amp; Patel, 2024). Other recommendations\u0026mdash;such as Strategic Integration (7.5%), Capacity \u0026amp; Competence Development (7.5%), and Process Simplification (6.25%)\u0026mdash;highlight a pragmatic orientation: aligning IT governance with corporate strategy, investing in workforce training, and reducing bureaucratic overload. Finally, Measurement \u0026amp; Evidence-Based Governance (6.25%) stresses the institutionalization of KPIs, maturity indices, and PDCA metrics to ensure feedback-driven improvement.\u003c/p\u003e\u003c/div\u003e\u003c/p\u003e\u003c/div\u003e"},{"header":"Discussion","content":"\u003cp\u003e\u003cdiv class=\"BlockQuote\"\u003e\u003cp\u003eThe discussion interprets the findings of this systematic review\u0026mdash;conducted under PRISMA guidelines\u0026mdash;in light of the research questions and the major themes identified: methodological transparency, sectoral concentration (finance and government dominance), and challenges in compliance and internal control implementation.\u003c/p\u003e\u003c/div\u003e\u003c/p\u003e\u003cdiv id=\"Sec25\" class=\"Section2\"\u003e\u003ch2\u003e4.1. Methodological transparency and the underreporting of internal controls\u003c/h2\u003e\u003cp\u003e\u003cdiv class=\"BlockQuote\"\u003e\u003cp\u003eThe review reveals a persistent lack of methodological transparency in cybersecurity compliance and governance research. Specifically, 61% of the studies failed to specify the frameworks, control mechanisms, or industry context applied. This underreporting stems from inconsistent research designs, an outcome-centric bias, and the absence of a standardized reporting framework. Such opacity limits comparability and replication\u0026mdash;two cornerstones of systematic inquiry. To address this, researchers should explicitly disclose:\u003c/p\u003e\u003c/div\u003e\u003c/p\u003e\u003cp\u003e\u003cul\u003e\u003cli\u003e\u003cp\u003eThe compliance frameworks implemented (e.g., \u003cem\u003eISO 27001\u003c/em\u003e, \u003cem\u003eCOBIT\u003c/em\u003e, \u003cem\u003eNIST CSF\u003c/em\u003e, \u003cem\u003eGDPR/HIPAA\u003c/em\u003e).\u003c/p\u003e\u003c/li\u003e\u003cli\u003e\u003cp\u003eThe governance model adopted (integrated GRC, policy-based, risk-driven, or control-assurance).\u003c/p\u003e\u003c/li\u003e\u003cli\u003e\u003cp\u003eThe types of controls assessed (technical/security, oversight, human/cultural, operational, regulatory).\u003c/p\u003e\u003c/li\u003e\u003cli\u003e\u003cp\u003eThe deployment mode (cloud, on-premises, hybrid).\u003c/p\u003e\u003c/li\u003e\u003c/ul\u003e\u003cdiv class=\"BlockQuote\"\u003e\u003cp\u003eEstablishing such reporting standards would enhance reproducibility and allow for meaningful meta-analyses, particularly across regions and industries.\u003c/p\u003e\u003c/div\u003e\u003c/p\u003e\u003c/div\u003e\u003cdiv id=\"Sec26\" class=\"Section2\"\u003e\u003ch2\u003e4.2. Sectoral dominance and implications for underexplored contexts\u003c/h2\u003e\u003cp\u003e\u003cdiv class=\"BlockQuote\"\u003e\u003cp\u003eFinance (21.25%) and government (18.75%) sectors dominate the dataset, followed by corporate\u0026ndash;government collaborations (17.5%). This concentration reflects the regulatory stringency and accountability pressures in these environments, where compliance and audit assurance are integral to governance. However, other sectors remain underrepresented\u0026mdash;ICT (7.5%), healthcare (6.25%), and SMEs (5%). This imbalance constrains understanding of how internal controls function in resource-constrained or innovation-driven contexts. Future studies should prioritize cross-sectoral and comparative analyses to tailor governance models and compliance architectures for smaller enterprises and emerging markets.\u003c/p\u003e\u003c/div\u003e\u003c/p\u003e\u003c/div\u003e\u003cdiv id=\"Sec27\" class=\"Section2\"\u003e\u003ch2\u003e4.3. Leveraging compliance frameworks for resource-constrained environments\u003c/h2\u003e\u003cp\u003e\u003cdiv class=\"BlockQuote\"\u003e\u003cp\u003eThe review underscores the adaptability of dominant frameworks such as \u003cem\u003eISO 27001\u003c/em\u003e and \u003cem\u003eNIST CSF\u003c/em\u003e (reported in 32.26% of studies) to smaller or less-resourced organizations. While these standards were originally designed for large enterprises, their modular structures can guide incremental adoption by SMEs. Integrating automated dashboards, simplified risk registers, and staff training programs can help translate these frameworks into actionable internal controls. For SMEs, aligning limited resources to high-impact compliance objectives\u0026mdash;for example, focusing on access control, audit logging, and employee awareness\u0026mdash;can significantly strengthen resilience without requiring enterprise-scale infrastructure.\u003c/p\u003e\u003c/div\u003e\u003c/p\u003e\u003c/div\u003e\u003cdiv id=\"Sec28\" class=\"Section2\"\u003e\u003ch2\u003e4.4. Integrating governance, risk, and compliance (GRC) practices\u003c/h2\u003e\u003cp\u003e\u003cdiv class=\"BlockQuote\"\u003e\u003cp\u003eA key finding is the fragmentation between governance, compliance, and internal controls. Few studies examine their synergistic interaction, despite evidence that integrated GRC models yield better alignment between strategic objectives and risk-mitigation outcomes. The review identifies nine governance models, of which the integrated GRC and risk-driven approaches dominate (37.5% combined). Yet empirical validation of these integrations remains limited, suggesting a need for longitudinal and mixed-method designs to measure sustained organizational outcomes such as audit maturity, risk reduction, and decision-making agility.\u003c/p\u003e\u003c/div\u003e\u003c/p\u003e\u003c/div\u003e\u003cdiv id=\"Sec29\" class=\"Section2\"\u003e\u003ch2\u003e4.5. Methodological and reporting refinements\u003c/h2\u003e\u003cp\u003e\u003cdiv class=\"BlockQuote\"\u003e\u003cp\u003eThe review\u0026rsquo;s methodological analysis (Figs.\u0026nbsp;\u003cspan refid=\"Fig9\" class=\"InternalRef\"\u003e9\u003c/span\u003e\u0026ndash;\u003cspan refid=\"Fig10\" class=\"InternalRef\"\u003e10\u003c/span\u003e) indicates that empirical audit and survey studies account for over half the literature, while longitudinal and quantitative modeling approaches are rare. Introducing structured reporting templates\u0026mdash;detailing frameworks, controls, methods, and outcomes\u0026mdash;would substantially improve transparency. Supplementary materials (e.g., implementation logs, checklists, validation datasets) should be encouraged to enable secondary analysis. Such practices would bridge the gap between academic research and practitioner needs, offering replicable evidence of compliance efficacy.\u003c/p\u003e\u003c/div\u003e\u003c/p\u003e\u003c/div\u003e\u003cdiv id=\"Sec30\" class=\"Section2\"\u003e\u003ch2\u003e4.6. Regional and contextual disparities\u003c/h2\u003e\u003cp\u003e\u003cdiv class=\"BlockQuote\"\u003e\u003cp\u003eGeographically, studies cluster in North America and Europe, regions with mature regulatory ecosystems. Africa and Latin America show growing but limited contributions, primarily descriptive rather than evaluative. Regional regulatory heterogeneity affects how internal controls and compliance frameworks are adopted: GDPR drives structured governance in Europe, whereas voluntary or hybrid models prevail elsewhere. Cross-regional collaborations could foster more balanced insights, particularly regarding localized frameworks, digital-sovereignty regulations, and capacity-building initiatives.\u003c/p\u003e\u003c/div\u003e\u003c/p\u003e\u003c/div\u003e\u003cdiv id=\"Sec31\" class=\"Section2\"\u003e\u003ch2\u003e4.7. Practical implications and future directions\u003c/h2\u003e\u003cp\u003e\u003cdiv class=\"BlockQuote\"\u003e\u003cp\u003eThis review confirms that compliance standards and internal controls form a critical axis of cybersecurity governance, yet their real-world implementation remains uneven. The evidence suggests several actionable imperatives:\u003c/p\u003e\u003c/div\u003e\u003c/p\u003e\u003cp\u003e\u003cul\u003e\u003cli\u003e\u003cp\u003eAdopt a unified reporting schema that documents frameworks, controls, and deployment contexts.\u003c/p\u003e\u003c/li\u003e\u003cli\u003e\u003cp\u003eEncourage integrated GRC approaches to reduce duplication and improve strategic alignment.\u003c/p\u003e\u003c/li\u003e\u003cli\u003e\u003cp\u003ePrioritize sectoral inclusivity, especially SMEs and developing economies.\u003c/p\u003e\u003c/li\u003e\u003cli\u003e\u003cp\u003eIncorporate longitudinal and mixed-method research designs to capture temporal effects of control maturity.\u003c/p\u003e\u003c/li\u003e\u003cli\u003e\u003cp\u003ePromote automation and dashboarding to support real-time compliance monitoring.\u003c/p\u003e\u003c/li\u003e\u003c/ul\u003e\u003cdiv class=\"BlockQuote\"\u003e\u003cp\u003eOperationalizing these directions, future research can deepen empirical understanding of compliance and internal control effectiveness, ensuring cybersecurity governance evolves toward greater transparency, inclusivity, and measurable impact.\u003c/p\u003e\u003c/div\u003e\u003c/p\u003e\u003c/div\u003e"},{"header":"Conclusion","content":"\u003cp\u003e\u003cdiv class=\"BlockQuote\"\u003e\u003cp\u003eThis systematic review highlights the critical role of compliance frameworks and in-ternal controls in advancing cybersecurity governance. The findings show that widely adopted standards such as COBIT and ISO/IEC 27001 were the most frequently referenced, while sector-specific frameworks like GDPR and HIPAA were comparatively underrepresented. Internal controls including audit assurance, access management, and risk assessment tools emerged as essential mechanisms for mitigating risks, yet nearly 40% of studies lacked detailed methodological descriptions, pointing to significant transparency gaps in reporting. Geographically, majority of research originated from developing economies, where compliance measures are often used to address resource constraints, while studies from developed contexts focused more on advanced applications such as AI-driven governance. Reporting bias was also evident, with short-term operational out-comes emphasized over long-term strategic measures such as resilience and scalability, which appeared in fewer than 10% of studies.\u003c/p\u003e\u003cp\u003eThree major gaps were identified across the literature: (1) insufficient documentation of compliance and control methodologies, (2) limited exploration of affordable and scalable solutions for SMEs, and (3) minimal long-term evidence on governance effectiveness. To address these limitations, this review recommends the standardization of reporting frameworks, the development of cost-effective governance tools, and the implementation of longitudinal research to evaluate the sustained impact of compliance practices across industries. By addressing these research gaps, organizations can better leverage compliance frameworks and internal controls to strengthen resilience, improve decision-making, and align cybersecurity practices with global governance standards. This review therefore provides a robust foundation for advancing both the theoretical understanding and the practical applications of cybersecurity governance.\u003c/p\u003e\u003c/div\u003e\u003c/p\u003e"},{"header":"References","content":"\u003col\u003e\n \u003cli dir=\"LTR\"\u003eCimarelli, C.; Millan-Romera, J.; Voos, H.; Sanchez-Lopez, J. Hardware, Algorithms, and Applications of the Neuromorphic Vision Sensor: A Review. Sensors 2025, 25(19), 6208; https://doi.org/10.3390/s25196208.\u003c/li\u003e\n \u003cli dir=\"LTR\"\u003eDini, P.; Saponara, S.; Chakraborty, S.; Hegazy, O. Modeling, Control and Monitoring of Automotive Electric Drives. Electronics 2025, 14(19), 3950; https://doi.org/10.3390/electronics14193950. \u003c/li\u003e\n \u003cli dir=\"LTR\"\u003eKhanyi, Mduduzi and Xaba, Sfundo and Mlotshwa, Nokunqoba and Thango, Bonginkosi and Lerato, Matshaka, The Role of Data Networks and APIs in Enhancing Operational Efficiency in SME: A Systematic Review (October 11, 2024). http://dx.doi.org/10.2139/ssrn.4984455\u003c/li\u003e\n \u003cli dir=\"LTR\"\u003eVesković, J.; Onjia, A. Exposure and Toxicity Factors in Health Risk Assessment of Heavy Metal(loid)s in Water. Water 2025, 17(19), 2901; https://doi.org/10.3390/w17192901. \u003c/li\u003e\n \u003cli dir=\"LTR\"\u003eMtjilibe, Tshepang and Rameetse, Emmanuel and Mgwenya, Nkosinathi and Thango, Bonginkosi, Exploring the Challenges and Opportunities of Social Media for Organizational Engagement in SMEs: A Comprehensive Systematic Review (July 06, 2024). http://dx.doi.org/10.2139/ssrn.4998542\u003c/li\u003e\n \u003cli dir=\"LTR\"\u003eRodrigues, P.; Neto, A.; Alonso do Esp\u0026iacute;rito Santo, L.; Tribess, S.; Virtuoso Junior, J. Walking Football as a Multidimensional Intervention for Healthy Aging: A Scoping Review of Physical and Functional Outcomes in Older Adults. Int. J. Environ. Res. Public Health 2025, 22(10), 1533; https://doi.org/10.3390/ijerph22101533. \u003c/li\u003e\n \u003cli dir=\"LTR\"\u003eSechele, G., Rabedzwa, G., Nongayo, S., \u0026amp; Thango, B. (2024). Systematic Review on SEO and Digital Marketing Strategies for Enhancing Retail SMEs\u0026apos; Performance. doi: 10.20944/preprints202410.1715.v1\u003c/li\u003e\n \u003cli dir=\"LTR\"\u003eBurles, F.; Sallis, E.; Kopala-Sibley, D.; Iaria, G. Mitigating Head Position Bias in Perivascular Fluid Imaging: LD-ALPS, a Novel Method for DTI-ALPS Calculation. NeuroSci 2025, 6(4), 101; https://doi.org/10.3390/neurosci6040101. \u003c/li\u003e\n \u003cli dir=\"LTR\"\u003eMuraba, Juka and Mamogobo, Mogase Keabetswe and Thango, Bonginkosi, The Balanced Scorecard Methodology: Performance Metrics and Strategy Execution in SMEs: A Systematic Review (October 21, 2024). Available at SSRN: http://dx.doi.org/10.2139/ssrn.4996929\u003c/li\u003e\n \u003cli dir=\"LTR\"\u003eNhara, R.; Baloyi, J. Complementary Effects of Essential Oils and Organic Acids on Rumen Physiology as Alternatives to Antibiotic Feed Additives. Animals 2025, 15(19), 2910; https://doi.org/10.3390/ani15192910. \u003c/li\u003e\n \u003cli dir=\"LTR\"\u003ePingilili, A., Letsie, N., Nzimande, G., Thango, B., \u0026amp; Matshaka, L. (2025). Guiding IT Growth and Sustaining Performance in SMEs Through Enterprise Architecture and Information Management: A Systematic Review. Businesses, 5(2), 17.\u003c/li\u003e\n \u003cli dir=\"LTR\"\u003eMelaku, H. M. (2023). A dynamic and adaptive cybersecurity governance framework. Journal of Cybersecurity and Privacy, 3(3), 327\u0026ndash;350. https://doi.org/10.3390/jcp3030017 \u003c/li\u003e\n \u003cli dir=\"LTR\"\u003eAlfaadhel, A., Almomani, I., \u0026amp; Ahmed, M. (2023). Risk-based cybersecurity compliance assessment system (RC2AS). Applied Sciences, 13(10), 6145. https://doi.org/10.3390/app13106145 \u003c/li\u003e\n \u003cli dir=\"LTR\"\u003eSong, I., Jeon, S., Kim, D., Lee, M. G., \u0026amp; Seo, J. T. (2024). GENICS: A framework for generating attack scenarios for cybersecurity exercises on industrial control systems. Applied Sciences, 14(2), 768. https://doi.org/10.3390/app14020768 \u003c/li\u003e\n \u003cli dir=\"LTR\"\u003eMetin, B., \u0026Ouml;zhan, F. G., \u0026amp; Wynn, M. (2024). Digitalisation and cybersecurity: Towards an operational framework. Electronics, 13(21), 4226. https://doi.org/10.3390/electronics13214226 \u003c/li\u003e\n \u003cli dir=\"LTR\"\u003eZwilling, M. (2022). Trends and challenges regarding cyber risk mitigation by CISOs\u0026mdash;A systematic literature and experts\u0026rsquo; opinion review based on text analytics. Sustainability, 14(3), 1311. https://doi.org/10.3390/su14031311 \u003c/li\u003e\n \u003cli dir=\"LTR\"\u003eHartmann, C. C., \u0026amp; Carmenate, J. (2021). Academic research on the role of corporate governance and IT expertise in addressing cybersecurity breaches: Implications for practice, policy, and research. Current Issues in Auditing, 15(2), A9\u0026ndash;A23. https://DOI: 10.2308/CIIA-2020-034 \u003c/li\u003e\n \u003cli dir=\"LTR\"\u003eHandri, E. Y., Sensuse, D. I., \u0026amp; Tarigan, A. (2024). Developing an agile cybersecurity framework with organizational culture approach using Q methodology. IEEE Access. DOI: 10.1109/ACCESS.2024.3432160 \u003c/li\u003e\n \u003cli dir=\"LTR\"\u003eHossain, S. T., Yigitcanlar, T., Nguyen, K., \u0026amp; Xu, Y. (2024). Understanding local government cybersecurity policy: A concept map and framework. Information, 15(6), 342. https://doi.org/10.3390/info15060342 \u003c/li\u003e\n \u003cli dir=\"LTR\"\u003eH\u0026eacute;roux, S., \u0026amp; Fortin, A. (2025). How the three lines of defense can contribute to public firms\u0026rsquo; cybersecurity effectiveness. International Journal of Disclosure and Governance, 22(2), 377\u0026ndash;396. https://doi.org/10.1057/s41310-024-00226-7 \u003c/li\u003e\n \u003cli dir=\"LTR\"\u003eVuko, T., Slapničar, S., Čular, M., \u0026amp; Dra\u0026scaron;ček, M. (2025). Key drivers of cybersecurity audit effectiveness: A neo-institutional perspective. International Journal of Auditing, 29(1), 188\u0026ndash;206. https://doi.org/10.1111/ijau.12365 \u003c/li\u003e\n \u003cli dir=\"LTR\"\u003eSterlini, P., Massacci, F., Kadenko, N., Fiebig, T., \u0026amp; van Eeten, M. (2019). Governance challenges for European cybersecurity policies: Stakeholder views. IEEE Security \u0026amp; Privacy, 18(1), 46\u0026ndash;54. DOI: 10.1109/MSEC.2019.2945309 \u003c/li\u003e\n \u003cli dir=\"LTR\"\u003eKamara, I. (2024). European cybersecurity standardisation: A tale of two solitudes in view of Europe\u0026rsquo;s cyber resilience. Innovation: The European Journal of Social Science Research, 37(5), 1441\u0026ndash;1460. https://doi.org/10.1080/13511610.2024.2349626 \u003c/li\u003e\n \u003cli dir=\"LTR\"\u003eBahuguna, A., Bisht, R. K., \u0026amp; Pande, J. (2020). Country-level cybersecurity posture assessment: Study and analysis of practices. Information Security Journal: A Global Perspective, 29(5), 250\u0026ndash;266. https://doi.org/10.1080/19393555.2020.1767239 \u003c/li\u003e\n \u003cli dir=\"LTR\"\u003eProudfoot, J. G., Cram, W. A., \u0026amp; Madnick, S. (2024). Weathering the storm: Examining how organisations navigate the sea of cybersecurity regulations. European Journal of Information Systems, 34(3), 436\u0026ndash;459. https://doi.org/10.1080/0960085X.2024.2345867 \u003c/li\u003e\n \u003cli dir=\"LTR\"\u003eBackman, S., \u0026amp; Stevens, T. (2024). Cyber risk logics and their implications for cybersecurity. International Affairs, 100(6), 2441\u0026ndash;2460. https://doi.org/10.1093/ia/iiae236 \u003c/li\u003e\n \u003cli dir=\"LTR\"\u003eMotwani, D., Chitre, V., Bhosale, V., Israni, M., Sonawane, S., \u0026amp; Nerurkar, A. (2024). IoT security cryptographic solutions for trustworthy wireless sensor networks. Journal of Discrete Mathematical Sciences and Cryptography, 27(4), 1283\u0026ndash;1294. https://doi.org/10.47974/JDMSC-1982 \u003c/li\u003e\n \u003cli dir=\"LTR\"\u003eAntunes, M., Maximiano, M., \u0026amp; Gomes, R. (2022). A client-centered information security and cybersecurity auditing framework. Applied Sciences, 12(9), 4102. https://doi.org/10.3390/app12094102 \u003c/li\u003e\n \u003cli dir=\"LTR\"\u003eDom\u0026iacute;nguez-Dorado, M., Cort\u0026eacute;s-Polo, D., Carmona-Murillo, J., Rodr\u0026iacute;guez-P\u0026eacute;rez, F. J., \u0026amp; Galeano-Brajones, J. (2023). Fast, lightweight, and efficient cybersecurity optimization for tactical\u0026ndash;operational management. Applied Sciences, 13(10), 6327. https://doi.org/10.3390/app12094102 \u003c/li\u003e\n \u003cli dir=\"LTR\"\u003eArgyridou, E., Nifakos, S., Laoudias, C., Panda, S., Panaousis, E., Chandramouli, K., \u0026hellip; \u0026amp; Bonacina, S. (2023). Cyber hygiene methodology for raising cybersecurity and data privacy awareness in health care organizations: Concept study. Journal of Medical Internet Research, 25, e41294. https://doi.org/10.3390/app13106327 \u003c/li\u003e\n \u003cli dir=\"LTR\"\u003eMelaku, H. M. (2023). Context-based and adaptive cybersecurity risk management framework. Risks, 11(6), 101. https://preprints.jmir.org/preprint/41294 \u003c/li\u003e\n \u003cli dir=\"LTR\"\u003eArgyridou, E., Nifakos, S., Laoudias, C., Panda, S., Panaousis, E., Chandramouli, K., \u0026hellip; \u0026amp; Bonacina, S. (2024). Cyber hygiene methodology for raising cybersecurity and data privacy awareness in health care organizations: Concept study. Journal of Medical Internet Research, 25, e41294. https://doi.org/10.3390/risks11060101 \u003c/li\u003e\n \u003cli dir=\"LTR\"\u003eMalaivongs, S., Kiattisin, S., \u0026amp; Chatjuthamard, P. (2022). Cyber trust index: A framework for rating and improving cybersecurity performance. Applied Sciences, 12(21), 11174. https://doi.org/10.1016/j.cose.2022.102840 \u003c/li\u003e\n \u003cli dir=\"LTR\"\u003eMishra, A., Alzoubi, Y. I., Gill, A. Q., \u0026amp; Anwar, M. J. (2022). Cybersecurity enterprises policies: A comparative study. Sensors, 22(2), 538. https://doi.org/10.3390/s22020538 \u003c/li\u003e\n \u003cli dir=\"LTR\"\u003eMishra, A., Alzoubi, Y. I., Anwar, M. J., \u0026amp; Gill, A. Q. (2022). Attributes impacting cybersecurity policy development: Evidence from seven nations. Computers \u0026amp; Security, 120, 102820. https://doi.org/10.1016/j.cose.2022.102820 \u003c/li\u003e\n \u003cli dir=\"LTR\"\u003eAlshaikh, M. (2020). Developing cybersecurity culture to influence employee behavior: A practice perspective. Computers \u0026amp; Security, 98, 102003. https://doi.org/10.1016/j.cose.2020.102003 \u003c/li\u003e\n \u003cli dir=\"LTR\"\u003eVoas, J., \u0026amp; Schaffer, K. (2016). Insights on formal methods in cybersecurity. Computer, 49(5), 102\u0026ndash;105. DOI: 10.1109/MC.2016.131 \u003c/li\u003e\n \u003cli dir=\"LTR\"\u003eBozkus Kahyaoglu, S., \u0026amp; Caliyurt, K. (2018). Cyber security assurance process from the internal audit perspective. Managerial Auditing Journal, 33(4), 360\u0026ndash;376. https://doi.org/10.1108/MAJ-02-2018-1804 \u003c/li\u003e\n \u003cli dir=\"LTR\"\u003eGordon, L. A., Loeb, M. P., \u0026amp; Zhou, L. (2020). Integrating cost\u0026ndash;benefit analysis into the NIST cybersecurity framework via the Gordon\u0026ndash;Loeb model. Journal of Cybersecurity, 6(1), tyaa005. https://doi.org/10.1093/cybsec/tyaa005 \u003c/li\u003e\n \u003cli dir=\"LTR\"\u003eZimmermann, V., \u0026amp; Renaud, K. (2019). Moving from a \u0026lsquo;human-as-problem\u0026rsquo; to a \u0026lsquo;human-as-solution\u0026rsquo; cybersecurity mindset. International Journal of Human-Computer Studies, 131, 169\u0026ndash;187. https://doi.org/10.1016/j.ijhcs.2019.05.005 \u003c/li\u003e\n \u003cli dir=\"LTR\"\u003evon Solms, B., \u0026amp; von Solms, R. (2018). Cybersecurity and information security \u0026ndash; what goes where? Information and Computer Security, 26(1), 2\u0026ndash;9. https://doi.org/10.1108/ICS-04-2017-0025 \u003c/li\u003e\n \u003cli dir=\"LTR\"\u003eWaelchli, S., \u0026amp; Walter, Y. (2025). Reducing the risk of social engineering attacks using SOAR measures in a real world environment: A case study. Computers \u0026amp; Security, 148, 104137. https://doi.org/10.1016/j.cose.2024.104137 \u003c/li\u003e\n \u003cli dir=\"LTR\"\u003eArfaj, B. A., Mishra, S., \u0026amp; AlShehri, M. (2022). Efficacy of unconventional penetration testing practices. Intelligent Automation \u0026amp; Soft Computing, 31(1). https://doi.org/10.32604/iasc.2022.019485 \u003c/li\u003e\n \u003cli dir=\"LTR\"\u003eScala, N. M., Reilly, A. C., Goethals, P. L., \u0026amp; Cukier, M. (2019). Risk and the five hard problems of cybersecurity. Risk Analysis, 39(10), 2119\u0026ndash;2126. https://doi.org/10.1111/risa.13309 \u003c/li\u003e\n \u003cli dir=\"LTR\"\u003eFaruq, M. O. (2025). A meta-analysis of cybersecurity framework integration in GRC platforms: Evidence from US enterprise audits. Journal of Sustainable Development and Policy, 1(01), 224\u0026ndash;249. https://doi.org/10.63125/kwhkmb57 \u003c/li\u003e\n \u003cli dir=\"LTR\"\u003eAkinsulire, A. A., \u0026amp; Ohakawa, T. C. (2024). Enhancing cybersecurity governance in financial institutions: A quantitative study on control deficiencies and regulatory compliance. archive-1747649053.pdf \u003c/li\u003e\n \u003cli dir=\"LTR\"\u003eOnumo, A. O. (2020). A behavioural compliance framework for effective cybersecurity governance and practice (Doctoral dissertation). http://hdl.handle.net/10454/19051 \u003c/li\u003e\n \u003cli dir=\"LTR\"\u003eVictor, A. A., Moronkunbi, M. A., Oyedeji, O. C., Victor, P. O., \u0026amp; Samuel, S. A. (2024). The role of IT governance risk and compliance (IT GRC) in modern organizations. International Journal of Latest Technology in Engineering, Management \u0026amp; Applied Science, 13(6), 44\u0026ndash;50. https://doi.org/10.51583/IJLTEMAS.2024.130607 \u003c/li\u003e\n \u003cli dir=\"LTR\"\u003eFerreira, L. V. A., Alves, C. A. D. M., Peotta de Melo, L., \u0026amp; Nunes, R. R. (2025). Internal audit strategies for assessing cybersecurity controls in the Brazilian financial institutions. Applied Sciences, 15(10), 5715. https://doi.org/10.3390/app15105715 \u003c/li\u003e\n \u003cli dir=\"LTR\"\u003eMaleh, Y., Sahid, A., Alazab, M., \u0026amp; Belaissaoui, M. (2021). IT governance and information security: Guides, standards, and frameworks (1st ed.). CRC Press. https://doi.org/10.1201/9781003161998 \u003c/li\u003e\n \u003cli dir=\"LTR\"\u003eDavis, R. E. (2021). Auditing information and cyber security governance: A controls-based approach (1st ed.). CRC Press. https://doi.org/10.1201/9781003099673 \u003c/li\u003e\n \u003cli dir=\"LTR\"\u003eOlajide, J. O., Otokiti, B. O., Nwani, S., Ogunmokun, A. S., Adekunle, B. I., \u0026amp; Efekpogua, J. (2021). Developing internal control and risk assurance frameworks for compliance in supply chain finance. IRE Journals, 4(11), 459\u0026ndash;461. https://www.irejournals.com/formatedpaper/1709010.pdf \u003c/li\u003e\n \u003cli dir=\"LTR\"\u003ePlant, O. H., van Hillegersberg, J., \u0026amp; Aldea, A. (2022). Rethinking IT governance: Designing a framework for mitigating risk and fostering internal control in a DevOps environment. International Journal of Accounting Information Systems, 45, 100560. https://doi.org/10.1016/j.accinf.2022.100560 \u003c/li\u003e\n \u003cli dir=\"LTR\"\u003eMittal, D., \u0026amp; Damle, M. (2025). An appraisal in internal control frameworks implementation of COSO, ISO 27001 and NIST for opportunities in Industry 5.0. In 2025 Seventh International Conference on Computational Intelligence and Communication Technologies (CCICT) (pp. 345\u0026ndash;352). https://doi.org/10.3390/app15105715 \u003c/li\u003e\n \u003cli dir=\"LTR\"\u003eItani, D., Itani, R., Eltweri, A. A., Faccia, A., \u0026amp; Wanganoo, L. (2024). Enhancing cybersecurity through compliance and auditing: A strategic approach to resilience. In 2024 2nd International Conference on Cyber Resilience (ICCR) (pp. 1\u0026ndash;10). DOI: 10.1109/CCICT65753.2025.00061 \u003c/li\u003e\n \u003cli dir=\"LTR\"\u003eGirn, S. S. (2024). Cybersecurity governance framework for board directors (Doctoral dissertation). https://doi.org/10.1109/ICCR61006.2024.10532959 \u003c/li\u003e\n \u003cli dir=\"LTR\"\u003eKumar, K. (2025). Enterprise risk management as a catalyst for strategic governance, risk, and compliance (GRC) alignment in IT companies. Digital Repository of Theses - SSBM Geneva. http://hdl.handle.net/10453/187536 \u003c/li\u003e\n \u003cli dir=\"LTR\"\u003eMaleh, Y., Sahid, A., \u0026amp; Belaissaoui, M. (2021). A maturity framework for cybersecurity governance in organizations. EDPACS, 63(6), 1\u0026ndash;22. https://repository.e-ssbm.com/index.php/rps/article/view/723 \u003c/li\u003e\n \u003cli dir=\"LTR\"\u003eToshitsugu, S. B. I. G. O., \u0026amp; Badawy, H. M. H. A. Enhancing internal controls for smart contracts: A comprehensive framework for blockchain. https://doi.org/10.1080/07366981.2020.1815354 \u003c/li\u003e\n \u003cli dir=\"LTR\"\u003eSimić, N. (2022). The internal auditor\u0026apos;s role in cybersecurity governance: A qualitative study about the internal auditor\u0026apos;s influence on the people factor of cybersecurity. https://doi.org/10.47509/IJAAS.2024.v06i03.06 \u003c/li\u003e\n \u003cli dir=\"LTR\"\u003eTaylor, M. (2024). Identifying strategies that improve organizational cybersecurity performance and the use of healthcare information in the healthcare industry using the integrated IT GRC model: A systematic review (Order No. 31148499). ProQuest Dissertations \u0026amp; Theses Global. internal auditor\u0026apos;s influence on the people factor of cybersecurity \u003c/li\u003e\n \u003cli dir=\"LTR\"\u003eEmmanuel, A. A. (2025). The impact of cybersecurity on financial reporting: Strengthening data integrity and regulatory compliance. https://www.proquest.com/docview/3039648712 \u003c/li\u003e\n \u003cli dir=\"LTR\"\u003eOkusi, O., Obiakor, I. J., \u0026amp; Adeloye, F. C. Designing resilient data risk management protocols for regulatory compliance and cyber incident response. https://doi.org/10.30574/ijsra.2025.14.2.0427 \u003c/li\u003e\n \u003cli dir=\"LTR\"\u003eAusfelt, S. (2025). Innovative approaches to GRC: Ensuring compliance during digital transformation. Journal of Financial Compliance, 8(4), 302\u0026ndash;316. https://doi.org/10.55248/gengpi.6.0725.2419 \u003c/li\u003e\n \u003cli dir=\"LTR\"\u003eSitumorang, I. M. R., Azzahra, K. J., \u0026amp; Muda, I. (2025). The role of IT auditing in data security focusing on risk identification, strengthening internal controls, and compliance with security policies. https://doi.org/10.69554/CHSR6553 \u003c/li\u003e\n \u003cli dir=\"LTR\"\u003eSobowale, A., Ikponmwoba, S. O., Chima, O. K., Ezeilo, O. J., Ojonugwa, B. M., \u0026amp; Adesuyi, M. O. A. Conceptual framework for integrating SOX-compliant financial systems in multinational corporate governance. https://doi.org/10.61784/asat3007\u003c/li\u003e\n \u003cli dir=\"LTR\"\u003eChahar, V. Legal and ethical challenges in corporate cybersecurity compliance: The impact of corruption and governance weaknesses. Indian Journal of Integrated Research in Law, 5(2), 2583\u0026ndash;0538. https://doi.org/10.54660/.IJMRGE.2020.1.2.88-98 \u003c/li\u003e\n \u003cli dir=\"LTR\"\u003eAshley, C., \u0026amp; Preiksaitis, M. (2022). Strategic cybersecurity risk management practices for information in small and medium enterprises. Business Management Research and Applications: A Cross-Disciplinary Journal, 1(2), 109\u0026ndash;157. https://ijirl.com/wp-content/uploads/2025/04/LEGAL-AND-ETHICAL-CHALLENGES-IN-CORPORATE-CYBER-SECURITY-COMPLIANCE-THE-IMPACT-OF-CORRUPTION-AND-GOVERNANCE-WEAKNESSES.pdf \u003c/li\u003e\n \u003cli dir=\"LTR\"\u003eMary, B. J. (2024). Developing a cybersecurity-accounting integration framework for critical financial infrastructure protection. https://bmrajournal.columbiasouthern.edu/index.php/bmra/article/view/3421 \u003c/li\u003e\n \u003cli dir=\"LTR\"\u003eBuker, H. N. (2021). Financial institutions adapting to cybersecurity regulation modifications: A qualitative multiple-case study. Capella University. https://www.researchgate.net/profile/Adam-Rajuroy/publication/392621152 \u003c/li\u003e\n \u003cli dir=\"LTR\"\u003eOkafor, C. M., Oseghale, D. O., \u0026amp; Ayanlaja, S. Enhancing US healthcare cybersecurity through intelligent agent\u0026ndash;supported qualitative information systems audits. https://www.proquest.com/docview/2580688909 \u003c/li\u003e\n \u003cli dir=\"LTR\"\u003eOnumo, A. O. (2020). A behavioural compliance framework for effective cybersecurity governance and practice (Doctoral dissertation). https://doi.org/10.51244/IJRSI.2025.120700178 \u003c/li\u003e\n \u003cli dir=\"LTR\"\u003eEugene, R. (2020). A Delphi study: A model to help IT management within financial firms reduce regulatory compliance costs for data privacy and cybersecurity (Doctoral dissertation, Capella University). http://hdl.handle.net/10454/19051 \u003c/li\u003e\n \u003cli dir=\"LTR\"\u003eNicho, M. (2018). A process model for implementing information systems security governance. Information \u0026amp; Computer Security, 26(1), 10\u0026ndash;38. https://www.proquest.com/dissertations-theses/delphi-study-model-help-management-within/docview/2453677732/se-2?accountid=48944 \u003c/li\u003e\n \u003cli dir=\"LTR\"\u003eYamami, A., Mansouri, K., Qbadou, M., \u0026amp; Illoussamen, E. (2018). A new pattern for the deployment of IT governance frameworks in organizations. International Journal of Engineering and Technology, 7(4), 3459\u0026ndash;3465. https://doi.org/10.1108/ICS-07-2016-0061 \u003c/li\u003e\n \u003cli dir=\"LTR\"\u003eSuroso, J. S., Hwa, T. H., Syafaat, R., Pasaribu, F. A., \u0026amp; Mujiatun, S. (2019, August). Assessing an information security governance using IPPF in multi-finance company. In 2019 International Conference on Information Management and Technology (ICIMTech) (Vol. 1, pp. 596\u0026ndash;601). IEEE. DOI: 10.14419/ijet.v7i4.15427 \u003c/li\u003e\n \u003cli dir=\"LTR\"\u003eAmalia, S. P. N., \u0026amp; Ratnawati, S. (2019, November). Assessment of the effectiveness of internal controls in an organization based on COBIT 5 framework case study: State-owned enterprises. In 2019 7th International Conference on Cyber and IT Service Management (CITSM) (Vol. 7, pp. 1\u0026ndash;5). IEEE. https://doi.org/10.1109/ICIMTech.2019.8843733 \u003c/li\u003e\n \u003cli dir=\"LTR\"\u003edu Fresne, A. J. (2020). Can audits be an effective method to improve information governance compliance objectives? (Order No. 28220145). ProQuest Dissertations \u0026amp; Theses Global. https://doi.org/10.1109/CITSM47753.2019.8965409\u003c/li\u003e\n \u003cli dir=\"LTR\"\u003eAguilar-Alonso, I., \u0026amp; Vergara-Calder\u0026oacute;n, J. (2020). Identification of IT governance frameworks and standards implemented in organizations. In 2020 IEEE International Conference on Sustainable Engineering and Creative Computing (ICSECC) (pp. 36\u0026ndash;41). Can Audits Be an Effective Method to Improve Information Governance Compliance Objectives? \u0026ndash; ProQuest \u003c/li\u003e\n \u003cli dir=\"LTR\"\u003eAl-Sartawi, A. M. M. (2020). Information technology governance and cybersecurity at the board level. International Journal of Critical Infrastructures, 16(2), 150\u0026ndash;161. https://doi.org/10.1109/ICSECC51444.2020.9557561 \u003c/li\u003e\n \u003cli dir=\"LTR\"\u003eWilkin, C. L., \u0026amp; Chenhall, R. H. (2020). Information technology governance: Reflections on the past and future directions. Journal of Information Systems, 34(2), 257\u0026ndash;292. https://doi.org/10.1504/IJCIS.2020.107265 \u003c/li\u003e\n \u003cli dir=\"LTR\"\u003eLi, H. J., Chang, S. I., Wang, T., \u0026amp; Chang, L. M. (2020). Information technology internal control items for the post-implementation phase of enterprise resource planning systems. Journal of Information Systems, 34(3), 159\u0026ndash;197. https://doi.org/10.2308/isys-52632 \u003c/li\u003e\n \u003cli dir=\"LTR\"\u003eAl-Hashimi, M., Othman, M., Sulaiman, H., \u0026amp; Zaidan, A. A. (2018). Information security governance frameworks in cloud computing: An overview. Journal of Advanced Computer Science and Technology Research, 8(2), 67\u0026ndash;81. https://doi.org/10.2308/isys-52615 \u003c/li\u003e\n \u003cli dir=\"LTR\"\u003eKosasi, S., \u0026amp; Wibowo, V. (2018, September). Improving information service performance of family businesses through IT governance. In 2018 International Seminar on Application for Technology of Information and Communication (pp. 11\u0026ndash;16). IEEE. https://www.researchgate.net/publication/326234567 \u003c/li\u003e\n \u003cli dir=\"LTR\"\u003eEttish, A. A., El-Gazzar, S. M., \u0026amp; Jacob, R. A. (2017). Integrating internal control frameworks for effective corporate information technology governance. JISTEM-Journal of Information Systems and Technology Management, 14(3), 361\u0026ndash;370. https://www.jurnal.stmikpontianak.ac.id/file/SANDY_KOSAS_-_VELWIN_WIBOWO_-_ISEMANTIC_2018.pdf\u003c/li\u003e\n \u003cli dir=\"LTR\"\u003eBicaku, A., Tauber, M., \u0026amp; Delsing, J. (2020). Security standard compliance and continuous verification for industrial Internet of Things. International Journal of Distributed Sensor Networks, 16(6). https://doi.org/10.4301/S1807-17752017000300004 \u003c/li\u003e\n \u003cli dir=\"LTR\"\u003eJanahi, L. A. M. (2016). The importance of accountability in IT governance practice in the public sector: A case study of the kingdom of Bahrain (Order No. 28469749). ProQuest Dissertations \u0026amp; Theses Global. https://doi.org/10.1177/1550147720922731 \u003c/li\u003e\n \u003cli dir=\"LTR\"\u003eSteinbart, P. J., Raschke, R. L., Gal, G., \u0026amp; Dilla, W. N. (2018). The influence of a good relationship between the internal audit and information security functions on information security outcomes. Accounting, Organizations and Society, 71, 15\u0026ndash;29. https://www.proquest.com/dissertations-theses/importance-accountability-governance-practice/docview/2570307817/se-2 \u003c/li\u003e\n \u003cli dir=\"LTR\"\u003ePapazafeiropoulou, A., \u0026amp; Spanaki, K. (2016). Understanding governance, risk and compliance information systems (GRC IS): The experts view. Information Systems Frontiers, 18(6), 1251\u0026ndash;1263. https://doi.org/10.1016/j.aos.2018.04.005 \u003c/li\u003e\n \u003cli dir=\"LTR\"\u003eAntonucci, D. (2017). The cyber risk handbook: Creating and measuring effective cybersecurity capabilities. John Wiley \u0026amp; Sons. https://doi.org/10.1002/9781119309741.ch6\u003c/li\u003e\n \u003cli dir=\"LTR\"\u003eEdwards, J., \u0026amp; Weaver, G. (2024). The Cybersecurity Guide to Governance, Risk, and Compliance. John Wiley \u0026amp; Sons. Available at: https://books.google.com/books?hl=en\u0026amp;lr=\u0026amp;id=Y2b8EAAAQBAJ\u0026amp;oi=fnd\u0026amp;pg=PP1\u0026amp;dq=The+Cybersecurity+Guide+to+Governance,+Risk,+and+\nCompliance\u0026amp;ots=DXRA4HQX\n6p\u0026amp;sig=wITJ0BIerlipEMMKy\nEUFkjHIPWA \u003c/li\u003e\n \u003cli dir=\"LTR\"\u003eDavis, R. E. (2021). Auditing Information and Cyber Security Governance: A Controls-based Approach. CRC Press. https://doi.org/10.1201/9781003099673 \u003c/li\u003e\n \u003cli dir=\"LTR\"\u003eMaleh, Y., Sahid, A., Alazab, M., \u0026amp; Belaissaoui, M. (2021). IT governance and information security: Guides, standards, and frameworks. CRC Press. https://doi.org/10.1201/9781003161998 \u003c/li\u003e\n \u003cli dir=\"LTR\"\u003eKohnke, A., Shoemaker, D., \u0026amp; Sigler, K. E. (2016). The complete guide to cybersecurity risks and controls. CRC Press. https://books.google.com/books?hl=en\u0026amp;lr=\u0026amp;id=7sX1CwAAQBAJ\u0026amp;oi=fnd\u0026amp;pg=PP1\u0026amp;dq=The+\nComplete+Guide+to+Cybersecurity+\nRisks+and+Controls\u0026amp;ots=0LtBYtH\n4TR\u0026amp;sig=NHzDyUAz4eDurtoT\nqeeKcCe2M1s \u003c/li\u003e\n \u003cli dir=\"LTR\"\u003eTari Schreider, S. S. C. P., CISM, C., \u0026amp; CISO, I. (2017). Building effective cybersecurity programs: a security manager\u0026rsquo;s handbook. Rothstein Publishing. Available at:https://books.google.com/books?hl=en\u0026amp;lr=\u0026amp;id=R8E6DwAAQBAJ\u0026amp;oi=fnd\u0026amp;pg=PT14\u0026amp;dq=Building+Effective+Cybersecurity+Programs:+A+\nSecurity+Manager%27s+Hand\nbook\u0026amp;ots=hcTc8peyrR\u0026am\np;sig=FPfEJ0MUsa1e4Ah\nKAUtRq-oL8ug \u003c/li\u003e\n \u003cli dir=\"LTR\"\u003eSavaş, S., Karataş, S. Cyber governance studies in ensuring cybersecurity: an overview of cybersecurity governance. Int. Cybersecur. Law Rev. 3, 7\u0026ndash;34 (2022). https://doi.org/10.1365/s43439-021-00045-4 \u003c/li\u003e\n \u003cli dir=\"LTR\"\u003eYusif, S., \u0026amp; Hafeez-Baig, A. (2021). A conceptual model for cybersecurity governance. Journal of applied security research, 16(4), 490-513. https://doi.org/10.1080/19361610.2021.1918995 \u003c/li\u003e\n \u003cli dir=\"LTR\"\u003eZukis, B. (2016). Information technology and cybersecurity governance in a digital world. The Handbook of Board Governance: A Comprehensive Guide for Public, Private and Not‐for‐Profit Board Members, 555-573. Available: https://doi.org/10.1002/9781119245445.ch28 \u003c/li\u003e\n \u003cli dir=\"LTR\"\u003eHeim, T. N. (2023). Global governance and regulation of cybersecurity: Towards coherence or fragmentation?. Available at : https://doi.org/10.3990/1.9789036556248 \u003c/li\u003e\n \u003cli dir=\"LTR\"\u003eWeber, R. H. (2025). Cybersecurity and internet governance. In A Research Agenda for Cybersecurity Law and Policy (pp. 33-54). Edward Elgar Publishing. Available at: https://doi.org/10.4337/9781803929194.00008\u003c/li\u003e\n\u003c/ol\u003e"}],"fulltextSource":"","fullText":"","funders":[],"hasAdminPriorityOnWorkflow":false,"hasManuscriptDocX":true,"hasOptedInToPreprint":true,"hasPassedJournalQc":"","hasAnyPriority":true,"hideJournal":true,"highlight":"","institution":"University of Johannesburg","isAcceptedByJournal":false,"isAuthorSuppliedPdf":false,"isDeskRejected":"","isHiddenFromSearch":false,"isInQc":false,"isInWorkflow":false,"isPdf":false,"isPdfUpToDate":true,"isWithdrawnOrRetracted":false,"journal":{"display":true,"email":"[email protected]","identity":"researchsquare","isNatureJournal":false,"hasQc":true,"allowDirectSubmit":true,"externalIdentity":"","sideBox":"","snPcode":"","submissionUrl":"/submission","title":"Research Square","twitterHandle":"researchsquare","acdcEnabled":true,"dfaEnabled":false,"editorialSystem":"","reportingPortfolio":"","inReviewEnabled":false,"inReviewRevisionsEnabled":true},"keywords":"cybersecurity governance, compliance standards, internal controls, ISO 27001, COBIT, GDPR, audit readiness, risk mitigation, cloud-based GRC, IT governance, organizational resilience, regulatory compliance","lastPublishedDoi":"10.21203/rs.3.rs-7817804/v1","lastPublishedDoiUrl":"https://doi.org/10.21203/rs.3.rs-7817804/v1","license":{"name":"CC BY 4.0","url":"https://creativecommons.org/licenses/by/4.0/"},"manuscriptAbstract":"\u003cp\u003eOrganizations increasingly confront challenges such as regulatory non-compliance, fragmented control mechanisms, and inconsistent monitoring processes. This systematic literature review evaluates the role of structured compliance standards and internal control frameworks in strengthening cybersecurity governance, audit readiness, and organizational resilience. Following a comprehensive search across Google Scholar, Web of Science, and Scopus, eighty (n\u0026thinsp;=\u0026thinsp;80) studies published between 2015 and 2025 were identified and analyzed through a structured screening and synthesis process. The review reveals that ISO 27001 (25%) and COBIT (24%) remain the most frequently adopted governance frameworks, while GDPR (11%) and HIPAA (6%) exert substantial influence in European and healthcare contexts. Evidence indicates a growing shift toward automated compliance monitoring, dashboard-based audit management, and cloud-integrated GRC systems, reflecting a convergence of governance, risk, and compliance technologies. Sectoral analysis shows dominance in finance (21.25%), government (18.75%), and corporate\u0026ndash;government collaborations (17.5%), with limited yet emerging research in healthcare (6.25%), ICT (7.5%), and SMEs (5%). Despite methodological progress, 61% of studies lacked detailed reporting on implementation models, revealing persistent gaps in transparency, resource adequacy, and sectoral applicability. The findings underscore that structured adoption of international standards enhances risk mitigation, decision efficiency, and regulatory alignment, but implementation barriers\u0026mdash;such as system complexity, skill deficits, and limited empirical validation\u0026mdash;remain. The review recommends prioritizing leadership capacity-building, evidence-based performance metrics, and cross-sector collaboration to enable adaptive, data-driven governance systems. Future research should expand empirical validation across underrepresented sectors to reinforce evidence-based policy and practical cybersecurity governance design.\u003c/p\u003e","manuscriptTitle":"Compliance and Internal Controls: Standards and Practices in Cyber Security Governance","msid":"","msnumber":"","nonDraftVersions":[{"code":1,"date":"2025-10-10 06:55:40","doi":"10.21203/rs.3.rs-7817804/v1","editorialEvents":[{"type":"communityComments","content":0}],"status":"published","journal":{"display":true,"email":"[email protected]","identity":"researchsquare","isNatureJournal":false,"hasQc":true,"allowDirectSubmit":true,"externalIdentity":"","sideBox":"","snPcode":"","submissionUrl":"/submission","title":"Research Square","twitterHandle":"researchsquare","acdcEnabled":true,"dfaEnabled":false,"editorialSystem":"","reportingPortfolio":"","inReviewEnabled":false,"inReviewRevisionsEnabled":true}}],"origin":"","ownerIdentity":"64b2bc7b-79dc-4c67-8d0e-ae4054e286a0","owner":[],"postedDate":"October 10th, 2025","published":true,"recentEditorialEvents":[],"rejectedJournal":[],"revision":"","amendment":"","status":"posted","subjectAreas":[{"id":56030555,"name":"Other Business"}],"tags":[],"updatedAt":"2025-10-10T06:55:41+00:00","versionOfRecord":[],"versionCreatedAt":"2025-10-10 06:55:40","video":"","vorDoi":"","vorDoiUrl":"","workflowStages":[]},"version":"v1","identity":"rs-7817804","journalConfig":"researchsquare"},"__N_SSP":true},"page":"/article/[identity]/[[...version]]","query":{"redirect":"/article/rs-7817804","identity":"rs-7817804","version":["v1"]},"buildId":"8U1c8b4HqxoKbykW_rLl7","isFallback":false,"isExperimentalCompile":false,"dynamicIds":[84888],"gssp":true,"scriptLoader":[]}
Text is read by the "Ask this paper" AI Q&A widget below. Extraction quality varies by source — PMC NXML preserves structure cleanly, OA-HTML may include some navigation residue, and OA-PDF can have broken hyphenation. The publisher copy (via DOI) is the canonical version.
My notes (saved in your browser only)
Ask this paper
Answers must be backed by verbatim quotes from this paper's full text. Hallucinated quotes are dropped automatically; if no verbatim passage answers the question, we say so. How this works
Citation neighborhood (sparse)
Too few in-corpus citations on either side for a chart; here are the lists.
Cites (1)
References (81)
- Systematic Review on SEO and Digital Marketing Strategies for Enhancing Retail SMEs' Performance via crossref
- doi:10.3390/electronics14193950 via crossref
- doi:10.2139/ssrn.4984455 via crossref
- doi:10.3390/w17192901 via crossref
- doi:10.2139/ssrn.4998542 via crossref
- doi:10.3390/ijerph22101533 via crossref
- doi:10.3390/neurosci6040101 via crossref
- doi:10.2139/ssrn.4996929 via crossref
- doi:10.3390/ani15192910 via crossref
- doi:10.3390/businesses5020017 via crossref
- doi:10.3390/jcp3030017 via crossref
- doi:10.3390/app13106145 via crossref
- doi:10.3390/app14020768 via crossref
- doi:10.3390/electronics13214226 via crossref
- doi:10.3390/su14031311 via crossref
- doi:10.2308/ciia-2020-034 via crossref
- doi:10.1109/access.2024.3432160 via crossref
- doi:10.3390/info15060342 via crossref
- doi:10.1057/s41310-024-00226-7 via crossref
- doi:10.1111/ijau.12365 via crossref
- doi:10.1109/msec.2019.2945309 via crossref
- doi:10.1080/13511610.2024.2349626 via crossref
- doi:10.1080/19393555.2020.1767239 via crossref
- doi:10.1080/0960085x.2024.2345867 via crossref
- doi:10.1093/ia/iiae236 via crossref
- doi:10.47974/jdmsc-1982 via crossref
- doi:10.3390/app12094102 via crossref
- doi:10.3390/app12094102 via crossref
- doi:10.3390/app13106327 via crossref
- doi:10.3390/risks11060101 via crossref
- doi:10.3390/risks11060101 via crossref
- doi:10.1016/j.cose.2022.102840 via crossref
- doi:10.3390/s22020538 via crossref
- doi:10.1016/j.cose.2022.102820 via crossref
- doi:10.1016/j.cose.2020.102003 via crossref
- doi:10.1109/mc.2016.131 via crossref
- doi:10.1108/maj-02-2018-1804 via crossref
- doi:10.1093/cybsec/tyaa005 via crossref
- doi:10.1016/j.ijhcs.2019.05.005 via crossref
- doi:10.1108/ics-04-2017-0025 via crossref
- doi:10.1016/j.cose.2024.104137 via crossref
- doi:10.32604/iasc.2022.019485 via crossref
- doi:10.1111/risa.13309 via crossref
- doi:10.63125/kwhkmb57 via crossref
- doi:10.51583/ijltemas.2024.130607 via crossref
- doi:10.3390/app15105715 via crossref
- doi:10.1201/9781003161998 via crossref
- doi:10.1201/9781003099673 via crossref
- doi:10.1016/j.accinf.2022.100560 via crossref
- doi:10.3390/app15105715 via crossref
- doi:10.1109/ccict65753.2025.00061 via crossref
- doi:10.1109/iccr61006.2024.10532959 via crossref
- doi:10.1080/07366981.2020.1815354 via crossref
- doi:10.1080/07366981.2020.1815354 via crossref
- doi:10.47509/ijaas.2024.v06i03.06 via crossref
- doi:10.30574/ijsra.2025.14.2.0427 via crossref
- doi:10.55248/gengpi.6.0725.2419 via crossref
- doi:10.69554/chsr6553 via crossref
- doi:10.61784/asat3007 via crossref
- doi:10.54660/.ijmrge.2020.1.2.88-98 via crossref
- doi:10.51244/ijrsi.2025.120700178 via crossref
- doi:10.1108/ics-07-2016-0061 via crossref
- doi:10.14419/ijet.v7i4.15427 via crossref
- doi:10.1109/icimtech.2019.8843733 via crossref
- doi:10.1109/citsm47753.2019.8965409 via crossref
- doi:10.1109/icsecc51444.2020.9557561 via crossref
- doi:10.1504/ijcis.2020.107265 via crossref
- doi:10.2308/isys-52632 via crossref
- doi:10.2308/isys-52615 via crossref
- doi:10.4301/s1807-17752017000300004 via crossref
- doi:10.1177/1550147720922731 via crossref
- doi:10.1016/j.aos.2018.04.005 via crossref
- doi:10.1002/9781119309741.ch6 via crossref
- doi:10.1201/9781003099673 via crossref
- doi:10.1201/9781003161998 via crossref
- doi:10.1365/s43439-021-00045-4 via crossref
- doi:10.1080/19361610.2021.1918995 via crossref
- doi:10.1002/9781119245445.ch28 via crossref
- doi:10.3990/1.9789036556248 via crossref
- doi:10.3390/s25196208 via crossref
- doi:10.4337/9781803929194.00008 via crossref
Source provenance
- crossref
- last seen: 2026-05-26T01:00:18.237284+00:00
- europepmc
- last seen: 2026-05-20T01:45:00.602351+00:00
- unpaywall
- last seen: 2026-05-21T05:10:58.409756+00:00
License: CC-BY-4.0