Proceedings of the International Conference on Digital Transformation in Business and Organisations (ICDTBO 2026)

International Conference on Digital Transformation in Business and Organisations (ICDTBO 2026)

📍Bandung, Indonesia🗓️ 25 June 2026

A Proactive Cyber Asset Discovery Framework for Enhancing Vulnerability Management and Cyber Risk Governance

Authors
Syaiful Andy1, *
1Telkom Corporate University, Jakarta, Indonesia
*Corresponding author. Email: syaifulandy@gmail.com
Corresponding Author
Syaiful Andy
Available Online 2 September 2026.
DOI
10.2991/978-94-6239-754-5_9How to use a DOI?
Keywords
Cyber Asset Discovery; Vulnerability Management; Shadow IT; Cyber Risk Governance; Cyber Resilience
Abstract

The rapid expansion of digital transformation initiatives has increased organizational exposure to cybersecurity risks through unmanaged, undocumented, or insufficiently governed cyber assets. In this study, shadow IT is specifically scoped as technically discoverable cyber assets, such as IP-addressed systems, domains, subdomains, applications, and reachable services that are active but not properly registered within formal asset inventory or vulnerability assessment coverage. Traditional vulnerability assessment practices are often request-driven, relying on assets formally submitted by system owners, which may leave such assets outside regular security review. This study proposes a proactive cyber asset discovery framework designed to enhance enterprise asset visibility, vulnerability management, and cyber risk governance. The framework is developed by synthesizing established cybersecurity and governance references, including ISO/IEC 27001, NIST Cybersecurity Framework 2.0, CIS Critical Security Controls, and the OWASP Vulnerability Management Guide. The proposed framework consists of five stages: baseline asset identification, proactive asset discovery, asset gap analysis, vulnerability assessment, aggregation, and prioritization, and governance integration and lifecycle decision-making. By integrating proactive discovery, vulnerability aggregation, remediation consolidation, and asset lifecycle governance, the framework supports compliance readiness, audit evidence, cyber risk governance, and cyber resilience. This study contributes a practical and governance-oriented design framework for transitioning from request driven vulnerability assessment toward proactive and accountable cyber risk management.

Copyright
© 2026 The Author(s)
Open Access
Open Access This chapter is licensed under the terms of the Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International License (http://creativecommons.org/licenses/by-nc-nd/4.0/), which permits any noncommercial use, sharing, distribution and reproduction in any medium or format, as long as you give appropriate credit to the original author(s) and the source, provide a link to the Creative Commons license and indicate if you modified the licensed material. You do not have permission under this license to share adapted material derived from this chapter or parts of it.

Download article (PDF)

Volume Title
Proceedings of the International Conference on Digital Transformation in Business and Organisations (ICDTBO 2026)
Series
Advances in Economics, Business and Management Research
Publication Date
2 September 2026
ISBN
978-94-6239-754-5
ISSN
2352-5428
DOI
10.2991/978-94-6239-754-5_9How to use a DOI?
Copyright
© 2026 The Author(s)
Open Access
Open Access This chapter is licensed under the terms of the Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International License (http://creativecommons.org/licenses/by-nc-nd/4.0/), which permits any noncommercial use, sharing, distribution and reproduction in any medium or format, as long as you give appropriate credit to the original author(s) and the source, provide a link to the Creative Commons license and indicate if you modified the licensed material. You do not have permission under this license to share adapted material derived from this chapter or parts of it.

Cite this article

TY  - CONF
AU  - Syaiful Andy
PY  - 2026
DA  - 2026/09/02
TI  - A Proactive Cyber Asset Discovery Framework for Enhancing Vulnerability Management and Cyber Risk Governance
BT  - Proceedings of the International Conference on Digital Transformation in Business and Organisations (ICDTBO 2026)
PB  - Atlantis Press
SP  - 92
EP  - 103
SN  - 2352-5428
UR  - https://doi.org/10.2991/978-94-6239-754-5_9
DO  - 10.2991/978-94-6239-754-5_9
ID  - Andy2026
ER  -