An anti-sheriff cybersecurity audit model : from compliance checklists to intelligence-supported cyber risk auditing

dc.contributor.authorRananga, Ndaedzo
dc.contributor.authorVenter, H.S. (Hein)
dc.contributor.emailu11329892@tuks.co.za
dc.contributor.emailhventer@cs.up.ac.za
dc.date.accessioned2026-03-24T07:27:19Z
dc.date.available2026-03-24T07:27:19Z
dc.date.issued2026-03
dc.descriptionDATA AVAILABILITY STATEMENT : The data presented in this study are available upon request from the corresponding author.
dc.description.abstractThe increasing adoption of data-driven techniques in cybersecurity has introduced new opportunities to enhance detection, response, and automation capabilities within the cybersecurity ecosystem; however, cybersecurity auditing remains constrained by traditional compliance-oriented approaches that rely profoundly on binary, checklist-based evaluations. Such approaches often reinforce a policing or “sheriff-style” perception of auditing, emphasizing enforcement rather than enablement, risk insight, and organizational improvement. Of primary concern is that the “sheriff-style” cybersecurity audit approach often fails to accurately portray the true state of an organization’s cybersecurity posture, often providing a misleading sense of assurance based solely on formal compliance and controls existence. This study proposes an Anti-Sheriff Cybersecurity Audit Model, that moves beyond cybersecurity control checklists, by integrating intelligence-informed risk assessments with structured human judgment to support a more robust, adaptive, and risk-oriented auditing process. Grounded in design science research (DSR), the proposed approach combines conventional binary compliance verification with intelligence-derived risk indicators and governance-based maturity assessments to evaluate cybersecurity controls across technical, operational, and organizational dimensions. The approach aligns with established standards and frameworks, including International Organization for Standardization and the International Electrotechnical Commission (ISO/IEC) 27001, the National Institute of Standards and Technology (NIST), and the Center for Internet Security (CIS) benchmarks, while extending their application beyond static compliance validation. A fictional case study is used to demonstrate the model’s applicability and to illustrate how hybrid scoring can reveal residual risk not captured by conventional cybersecurity audits. The findings indicate that combining intelligence-informed analytics with structured human judgment enhances audit depth, interpretability, and business relevance. The proposed approach, therefore, provides a foundation for evolving cybersecurity auditing from just periodic compliance assessments, toward a continuous, risk-informed, and governance-aligned assurance system.
dc.description.departmentComputer Science
dc.description.librarianhj2026
dc.description.sdgSDG-08: Decent work and economic growth
dc.description.sdgSDG-09: Industry, innovation and infrastructure
dc.description.urihttps://www.mdpi.com/journal/applsci
dc.identifier.citationRananga, N., & Venter, H. S. (2026). An Anti-Sheriff Cybersecurity Audit Model: From Compliance Checklists to Intelligence-Supported Cyber Risk Auditing. Applied Sciences, 16(5), 2315: 1-36. https://doi.org/10.3390/app16052315.
dc.identifier.issn2076-3417 (online)
dc.identifier.other10.3390/app16052315
dc.identifier.urihttp://hdl.handle.net/2263/109269
dc.language.isoen
dc.publisherMDPI
dc.rights© 2026 by the authors. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license.
dc.subjectCybersecurity risk-based auditing
dc.subjectIntelligence-supported audit
dc.subjectHuman judgment in auditing
dc.subjectControl effectiveness
dc.subjectSecurity maturity models
dc.subjectDefense-in-depth
dc.subjectContinuous assurance
dc.subjectAudit analytics
dc.titleAn anti-sheriff cybersecurity audit model : from compliance checklists to intelligence-supported cyber risk auditing
dc.typeArticle

Files

Original bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
Rananga_AntiSheriff_2026.pdf
Size:
3.17 MB
Format:
Adobe Portable Document Format
Description:
Article

License bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
license.txt
Size:
1.71 KB
Format:
Item-specific license agreed upon to submission
Description: