A Proactive Cyber Asset Discovery Framework for Enhancing Vulnerability Management and Cyber Risk Governance
- DOI
- 10.2991/978-94-6239-754-5_9How to use a DOI?
- Keywords
- Cyber Asset Discovery; Vulnerability Management; Shadow IT; Cyber Risk Governance; Cyber Resilience
- Abstract
The rapid expansion of digital transformation initiatives has increased organizational exposure to cybersecurity risks through unmanaged, undocumented, or insufficiently governed cyber assets. In this study, shadow IT is specifically scoped as technically discoverable cyber assets, such as IP-addressed systems, domains, subdomains, applications, and reachable services that are active but not properly registered within formal asset inventory or vulnerability assessment coverage. Traditional vulnerability assessment practices are often request-driven, relying on assets formally submitted by system owners, which may leave such assets outside regular security review. This study proposes a proactive cyber asset discovery framework designed to enhance enterprise asset visibility, vulnerability management, and cyber risk governance. The framework is developed by synthesizing established cybersecurity and governance references, including ISO/IEC 27001, NIST Cybersecurity Framework 2.0, CIS Critical Security Controls, and the OWASP Vulnerability Management Guide. The proposed framework consists of five stages: baseline asset identification, proactive asset discovery, asset gap analysis, vulnerability assessment, aggregation, and prioritization, and governance integration and lifecycle decision-making. By integrating proactive discovery, vulnerability aggregation, remediation consolidation, and asset lifecycle governance, the framework supports compliance readiness, audit evidence, cyber risk governance, and cyber resilience. This study contributes a practical and governance-oriented design framework for transitioning from request driven vulnerability assessment toward proactive and accountable cyber risk management.
- Copyright
- © 2026 The Author(s)
- Open Access
- Open Access This chapter is licensed under the terms of the Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International License (http://creativecommons.org/licenses/by-nc-nd/4.0/), which permits any noncommercial use, sharing, distribution and reproduction in any medium or format, as long as you give appropriate credit to the original author(s) and the source, provide a link to the Creative Commons license and indicate if you modified the licensed material. You do not have permission under this license to share adapted material derived from this chapter or parts of it.
Cite this article
TY - CONF AU - Syaiful Andy PY - 2026 DA - 2026/09/02 TI - A Proactive Cyber Asset Discovery Framework for Enhancing Vulnerability Management and Cyber Risk Governance BT - Proceedings of the International Conference on Digital Transformation in Business and Organisations (ICDTBO 2026) PB - Atlantis Press SP - 92 EP - 103 SN - 2352-5428 UR - https://doi.org/10.2991/978-94-6239-754-5_9 DO - 10.2991/978-94-6239-754-5_9 ID - Andy2026 ER -