Briliyant, Obrina ORCID: https://orcid.org/0000-0002-1054-8112, Javed, Amir ORCID: https://orcid.org/0000-0001-9761-0945 and Cherdantseva, Yulia ORCID: https://orcid.org/0000-0002-3527-1121
2026.
Systematization of human-centered continuous audit for IoT security compliance.
Journal of Cybersecurity
12
(1)
, tyag021.
10.1093/cybsec/tyag021
|
|
PDF
- Published Version
Available under License Creative Commons Attribution. Download (1MB) |
Abstract
The promise of automated compliance is falling short of its real-world potential. Although extensive research has proposed many automated compliance solutions, real-world adoption shows that only 18% of organizations have implemented them. This implementation gap is especially critical in Internet of Things (IoT) environments, where even small and medium-sized business networks can see hundreds of distinct IoT devices over short period of time, rendering traditional manual auditing methods quickly overwhelmed. This study seeks to understand this implementation gap by clarifying why auditors struggle to use automated auditing tools and identifying the conditions under which adoption succeeds. In doing so, it contributes to the field of auditing by helping shift automation approaches from prototypes into used instruments that enhance security assurance in increasingly complex environments such as IoT. We propose a systematic mapping of literature relevant to technologies used for computer-assisted audit tools, from rule-based checking to artificial intelligence-powered approach. From this mapping, we introduce a human-centered auditing framework that maps the research landscape to the three core stages of human auditor workflow: planning, verification, and reporting. We use this framework to assess the state-of-the-art in IoT security compliance audit, revealing critical misalignments between technological capabilities and auditor requirements. In each workflow stage, we categorize and systematize key technologies which researchers are uniquely positioned to advance. Finally, we present a research roadmap that enables security researchers to build on strong academic foundations and meet the practical need of continuous IoT security auditing.
| Item Type: | Article |
|---|---|
| Date Type: | Published Online |
| Status: | Published |
| Schools: | Schools > Computer Science & Informatics |
| Publisher: | Oxford University Press |
| ISSN: | 2057-2085 |
| Date of First Compliant Deposit: | 20 July 2026 |
| Date of Acceptance: | 14 June 2026 |
| Last Modified: | 04 Aug 2026 21:37 |
| URI: | https://orca.cardiff.ac.uk/id/eprint/188335 |
Actions (repository staff only)
![]() |
Edit Item |





Altmetric
Altmetric