Cardiff University | Prifysgol Caerdydd ORCA
Online Research @ Cardiff 
WelshClear Cookie - decide language by browser settings

Systematization of human-centered continuous audit for IoT security compliance

Briliyant, Obrina ORCID: https://orcid.org/0000-0002-1054-8112, Javed, Amir ORCID: https://orcid.org/0000-0001-9761-0945 and Cherdantseva, Yulia ORCID: https://orcid.org/0000-0002-3527-1121 2026. Systematization of human-centered continuous audit for IoT security compliance. Journal of Cybersecurity 12 (1) , tyag021. 10.1093/cybsec/tyag021

[thumbnail of tyag021.pdf] PDF - Published Version
Available under License Creative Commons Attribution.

Download (1MB)

Abstract

The promise of automated compliance is falling short of its real-world potential. Although extensive research has proposed many automated compliance solutions, real-world adoption shows that only 18% of organizations have implemented them. This implementation gap is especially critical in Internet of Things (IoT) environments, where even small and medium-sized business networks can see hundreds of distinct IoT devices over short period of time, rendering traditional manual auditing methods quickly overwhelmed. This study seeks to understand this implementation gap by clarifying why auditors struggle to use automated auditing tools and identifying the conditions under which adoption succeeds. In doing so, it contributes to the field of auditing by helping shift automation approaches from prototypes into used instruments that enhance security assurance in increasingly complex environments such as IoT. We propose a systematic mapping of literature relevant to technologies used for computer-assisted audit tools, from rule-based checking to artificial intelligence-powered approach. From this mapping, we introduce a human-centered auditing framework that maps the research landscape to the three core stages of human auditor workflow: planning, verification, and reporting. We use this framework to assess the state-of-the-art in IoT security compliance audit, revealing critical misalignments between technological capabilities and auditor requirements. In each workflow stage, we categorize and systematize key technologies which researchers are uniquely positioned to advance. Finally, we present a research roadmap that enables security researchers to build on strong academic foundations and meet the practical need of continuous IoT security auditing.

Item Type: Article
Date Type: Published Online
Status: Published
Schools: Schools > Computer Science & Informatics
Publisher: Oxford University Press
ISSN: 2057-2085
Date of First Compliant Deposit: 20 July 2026
Date of Acceptance: 14 June 2026
Last Modified: 04 Aug 2026 21:37
URI: https://orca.cardiff.ac.uk/id/eprint/188335

Actions (repository staff only)

Edit Item Edit Item

Downloads

Downloads per month over past year

View more statistics