Analyzing Cybersecurity Risks and Threats in IT Infrastructure based on NIST Framework

King Faisal University, Osama Aljumaiah, Weiwei Jiang, Beijing University of Posts and Telecommunications, Santosh Reddy Addula, University of the Cumberlands, Mohammed Amin Almaiah, The University of Jordan

2025Published
89Citations
0References
journal articleType

Abstract

Due to the increasing frequency and complexity of cyberattacks in recent years, cybersecurity management has received significant attention, particularly concerning the critical infrastructure of targeted countries. Such infrastructure contains several vulnerabilities that may be readily exploited if not adequately managed. National cybersecurity regulators require critical infrastructure organizations to regularly monitor and report their cybersecurity activities. This study assesses whether the NIST framework can effectively address most threats facing critical infrastructure and identifies any notable gaps within the framework. In this literature review, most threats reported in critical infrastructure will be discussed and mapped according to the NIST cybersecurity functions, concluding with a discussion of the findings. The findings indicates that human vulnerabilities with (12 instances) represent one of the leading threats to critical infrastructure, appearing prominently in reviewed sources. Human errors, negligence, lack of awareness, insufficient training, and susceptibility to social engineering significantly increase the risk of successful cyberattacks.

Journal: Journal of Cyber Security and Risk Auditing

Publisher: Smart Technologies Academic Press

Citations are the number of DOI-registered works in Crossref that cite this paper; references are how many works it cites. Full text is on the publisher site via the DOI link.