Home / Current Issue / Paper 1710215
Cyber Risk Mitigation and Incident Response Model Leveraging ISO 27001 and NIST for Global Enterprises.
Subject area: Science,Engineering and Technology · Area of research: Cybersecurity
Abstract
In an increasingly interconnected digital landscape, global enterprises face evolving and sophisticated cyber threats that pose significant risks to operations, reputation, and stakeholder trust. Effective cyber risk mitigation and incident response require structured, internationally recognized frameworks that ensure resilience, compliance, and business continuity. This paper explores the integration of ISO 27001 and the NIST Cybersecurity Framework as a unified model for enhancing organizational security posture. ISO 27001 provides a comprehensive information security management system (ISMS) emphasizing governance, risk assessment, and continual improvement, while NIST offers a flexible, adaptive approach to identifying, protecting, detecting, responding to, and recovering from cyber incidents. By leveraging the strengths of both frameworks, enterprises can align strategic objectives with practical, actionable controls that address sector-specific and cross-border compliance requirements. The proposed model underscores the importance of proactive risk identification, rapid containment of threats, and structured recovery to minimize operational disruption. It also highlights the value of ongoing employee awareness, stakeholder engagement, and measurable performance indicators in sustaining long-term resilience. Integrating ISO 27001 and NIST enables organizations to not only meet regulatory demands but also build adaptive, scalable defenses capable of countering emerging cyber risks in a dynamic global environment.
Keywords
Cybersecurity, Risk Mitigation, Incident Response, ISO 27001, NIST Cybersecurity Framework
References
[1] Abiola Olayinka Adams, Nwani, S., Abiola- Adams, O., Otokiti, B.O. & Ogeawuchi, J.C., 2020.Building Operational Readiness Assessment Models for Micro, Small, and Medium Enterprises Seeking Government- Backed Financing. Journal of Frontiers in Multidisciplinary Research, 1(1), pp.38-43.
[2] Adenuga, T., Ayobami, A.T. & Okolo, F.C., 2019. Laying the Groundwork for Predictive Workforce Planning Through Strategic Data Analytics and Talent Modeling. IRE Journals, 3(3), pp.159–161..
[3] Adenuga, T., Ayobami, A.T. & Okolo, F.C., 2020. AI-Driven Workforce Forecasting for Peak Planning and Disruption Resilience in Global Logistics and Supply Networks. International Journal of Multidisciplinary Research and Growth Evaluation, 2(2), pp.71– 87. Available at: https:// 87.
[4] Adewoyin, M.A., Ogunnowo, E.O., Fiemotongha, J.E., Igunma, T.O. & Adeleke, A.K., 2020.A Conceptual Framework for Dynamic Mechanical Analysis in High- Performance Material Selection. IRE Journals, 4(5), pp.137–144.
[5] Adewoyin, M.A., Ogunnowo, E.O., Fiemotongha, J.E., Igunma, T.O. & Adeleke, A.K., 2020.Advances in Thermofluid Simulation for Heat Transfer Optimization in Compact Mechanical Devices. IRE Journals, 4(6), pp.116–124.
[6] Akinbola, O. A., Otokiti, B. O., Akinbola, O. S., & Sanni, S. A. (2020). Nexus of Born Global Entrepreneurship Firms and Economic Development in Nigeria. Ekonomicko- manazerske spektrum, 14(1), 52-64.
[7] Akpe, O. E. E., Mgbame, A. C., Ogbuefi, E., Abayomi, A. A., & Adeyelu, O. O. (2020). Bridging the business intelligence gap in small enterprises: A conceptual framework for scalable adoption. IRE Journals, 4(2), 159–161.
[8] Akpe, O.E., Mgbame, A.C., Ogbuefi, E., Abayomi, A.A. & Adeyelu, O.O., 2020.Barriers and Enablers of BI Tool Implementation in Underserved SME Communities. IRE Journals, 3(7), pp.211-220.
[9] Akpe, O.E., Mgbame, A.C., Ogbuefi, E., Abayomi, A.A. & Adeyelu, O.O., 2020. Bridging the Business Intelligence Gap in Small Enterprises: A Conceptual Framework for Scalable Adoption. IRE Journals, 4(2), pp.159- 168.
[10] Akpe, O.E., Ogeawuchi, J.C., Abayomi, A.A., Agboola, O.A. & Ogbuefis, E. (2020) 'A Conceptual Framework for Strategic Business Planning in Digitally Transformed Organizations', IRE Journals, 4(4), pp. 207-214.
[11] Alavizadeh, H., Alavizadeh, H., & Jang- Jaccard, J. (2020). Cyber situation awareness monitoring and proactive response for enterprises on the cloud. arXiv. https://arxiv.org/abs/2009.01604
[12] Anyebe, N. B., Dimkpa, C., Aboki, D., Egbule, D., Useni, S., & Eneogu, R. (2018). Impact of active case finding of tuberculosis among prisoners using the WOW truck in North central Nigeria. The international Union Against Tuberculosis and Lung Disease, 11, 22.
[13] Ashiedu, B.I., Ogbuefi, E., Nwabekee, U.S., Ogeawuchi, J.C. & Abayomis, A.A. (2020) 'Developing Financial Due Diligence Frameworks for Mergers and Acquisitions in Emerging Telecom Markets', IRE Journals, 4(1), pp. 1-8.
[14] Buchanan, B. (2019). The US government and zero-day vulnerabilities: From pre-heartbleed to shadow brokers. Journal of International Affairs, 1–20. https://www.jstor.org/stable/10.2307/26485968
[15] Cho, J.-H., Sharma, D. P., Alavizadeh, H., Yoon, S., Ben-Asher, N., Moore, T. J., Kim, D. S., Lim, H., & Nelson, F. F. (2019). Toward proactive, adaptive defense: A survey on moving target defense. arXiv. https://arxiv.org/abs/1909.08092
[16] Cockcroft, S. (2020). What is the NIST Framework? ITNOW, 62(4), 48–49. https://
[17] Culot, G., Nassimbeni, G., Podrecca, M., & Sartor, M. (2018). The ISO/IEC 27001 information security management standard: Literature review and theory-based research agenda. The TQM Journal, 33(1), 76–105. https://
[18] Evans-Uzosike, I.O. & Okatta, C.G., 2019. Strategic Human Resource Management: Trends, Theories, and Practical Implications. Iconic Research and Engineering Journals, 3(4), pp.264-270.
[19] Evans-Uzosike, I.O., & Okatta, C.G., 2025. Employee Engagement and Retention: A Meta- Analytical Review of Influencing Factors. International Journal of Multidisciplinary Research and Growth Evaluation, 1(2), pp.126– 134. 134.
[20] Evans-Uzosike, I.O., & Okatta, C.G., 2025. The Digital Transformation of HR: Tools, Challenges, and Future Directions. International Journal of Multidisciplinary Research and Growth Evaluation, 1(2), pp.135–142. 10.54660/IJMRGE.2020.1.2.135-142.
[21] Fagbore, O.O., Ogeawuchi, J.C., Ilori, O., Isibor, N.J., Odetunde, A. & Adekunle, B.I. (2020) 'Developing a Conceptual Framework for Financial Data Validation in Private Equity Fund Operations', IRE Journals, 4(5), pp. 1-136.
[22] Ganji, D., Kalloniatis, C., Mouratidis, H., &MalekshahiGheytassi, S. (2019). Approaches to develop and implement ISO/IEC 27001 standard – Information security management systems: A systematic literature review. International Journal On Advances in Software, 12(3–4), 253–259. https://
[23] Healey, J., Mosser, P., Rosen, K., &Tache, A. (2018). The future of financial stability and cyber risk. Brookings Institution Cybersecurity Project, 1–18. https://www.brookings.edu/research/the-future- of-financial-stability-and-cyber-risk/
[24] Hlatshwayo, M. (2018). Adaptive Cybersecurity Governance Framework (ACGF): Integrating AI Risk Management and Auditing for Secure Technology Adoption in the Digital Era. Journal of Artificial Intelligence & Cloud Computing, 7(8), 279–288. https://
[25] Ibitoye, B. A., AbdulWahab, R., & Mustapha, S. D. (2017). Estimation of drivers’ critical gap acceptance and follow-up time at four–legged unsignalized intersection. CARD International Journal of Science and Advanced Innovative Research, 1(1), 98-107.
[26] Lokare, A., Bankar, S., &Mhaske, P. (2018). Integrating cybersecurity frameworks into IT security: A comprehensive analysis of threat mitigation strategies and adaptive technologies. arXiv. https://arxiv.org/abs/2502.00651
[27] Malik, A., & Khan, S. (2018). Designing Scalable Software Automation Frameworks for Cybersecurity: An AI-Driven Approach. Scholars Journal of Engineering and Technology, 13(6), 401–423. https://
[28] Mgbame, A. C., Akpe, O. E. E., Abayomi, A. A., Ogbuefi, E., & Adeyelu, O. O. (2020). Barriers and enablers of BI tool implementation in underserved SME communities. IRE Journals, 3(7), 211–213.
[29] Nwaimo, C.S., Oluoha, O.M. & Oyedokun, O., 2019. Big Data Analytics: Technologies, Applications, and Future Prospects. IRE Journals, 2(11), pp.411–419. 10.46762/IRECEE/2019.51123.
[30] Nwani, S., Abiola-Adams, O., Otokiti, B.O. & Ogeawuchi, J.C., 2020.Designing Inclusive and Scalable Credit Delivery Systems Using AI- Powered Lending Models for Underserved Markets. IRE Journals, 4(1), pp.212-214. 10.34293 /irejournals.v 4i1.1708888.
[31] Odofin, O.T., Agboola, O.A., Ogbuefi, E., Ogeawuchi, J.C., Adanigbo, O.S. & Gbenle, T.P. (2020) 'Conceptual Framework for Unified Payment Integration in Multi-Bank Financial Ecosystems', IRE Journals, 3(12), pp. 1-13.
[32] Ogunnowo, E.O., Adewoyin, M.A., Fiemotongha, J.E., Igunma, T.O. & Adeleke, A.K., 2020.Systematic Review of Non- Destructive Testing Methods for Predictive Failure Analysis in Mechanical Systems. IRE Journals, 4(4), pp.207–215.
[33] Olufemi-Phillips, A. Q., Ofodile, O. C., Toromade, A. S., Eyo-Udo, N. L., & Adewale, T. T. (2020). Optimizing FMCG supply chain management with IoT and cloud computing integration. International Journal of Managemeijignt & Entrepreneurship Research, 6(11), 1-15.
[34] Omisola, J. O., Etukudoh, E. A., Okenwa, O. K., & Tokunbo, G. I. (2020). Innovating Project Delivery and Piping Design for Sustainability in the Oil and Gas Industry: A Conceptual Framework. perception, 24, 28-35.
[35] Osho, G. O., Omisola, J. O., & Shiyanbola, J. O. (2020). A Conceptual Framework for AI-Driven Predictive Optimization in Industrial Engineering: Leveraging Machine Learning for Smart Manufacturing Decisions. Unknown Journal.
[36] Osho, G. O., Omisola, J. O., & Shiyanbola, J. O. (2020). An Integrated AI-Power BI Model for Real-Time Supply Chain Visibility and Forecasting: A Data-Intelligence Approach to Operational Excellence. Unknown Journal.
[37] Oyedokun, O.O., 2019.Green Human Resource Management Practices (GHRM) and Its Effect on Sustainable Competitive Edge in the Nigerian Manufacturing Industry: A Study of Dangote Nigeria Plc. MBA Dissertation, Dublin Business School.
[38] Roy P. P. (2020). A high-level comparison between the NIST Cyber Security Framework and the ISO 27001 Information Security Standard. 2020 National Conference on Emerging Trends on Sustainable Technology and Engineering Applications (NCETSTEA), 1– 3. https:// .9119914
[39] Roy, P. P. (2020). A high-level comparison between the NIST Cyber Security Framework and the ISO 27001 Information Security Standard. 2020 National Conference on Emerging Trends on Sustainable Technology and Engineering Applications (NCETSTEA), 1– 3. https:// .9119914
[40] Sabillon, R., Serra-Ruiz, J., Cavaller, V., & Cano, J. (2017). A comprehensive cybersecurity audit model to improve cybersecurity assurance: The cybersecurity audit model (CSAM). 2017 International Conference on Information Systems and Computer Science (INCISCOS), 253–259. https://
[41] Salas-Riega, J. L., Riega-Virú, Y., Ninaquispe- Soto, M., & Salas-Riega, J. M. (2018). Cybersecurity and the NIST Framework: A Systematic Review of its Implementation and Effectiveness Against Cyber Threats. International Journal of Advanced Computer Science and Applications, 16(6). https://
[42] Sharma, A., Adekunle, B.I., Ogeawuchi, J.C., Abayomi, A.A. & Onifade, O. (2019) 'IoT- enabled Predictive Maintenance for Mechanical Systems: Innovations in Real-time Monitoring and Operational Excellence', IRE Journals, 2(12), pp. 1-10.
[43] Sonkar, N. (2018). Bridging global frameworks: Governance strategies behind Cisco Common Control Framework v4.0 for scalable cloud compliance. arXiv. https://arxiv.org/abs/2506.01984
How to cite this paper
@article{1710215,
author = {Iboro Akpan Essien, Emmanuel Cadet, Joshua Oluwagbenga Ajayi, Eseoghene Daniel Erigha, Ehimah Obuse},
title = {Cyber Risk Mitigation and Incident Response Model Leveraging ISO 27001 and NIST for Global Enterprises.},
journal = {Iconic Research And Engineering Journals},
year = {2020},
volume = {3},
number = {7},
pages = {379-390},
issn = {2456-8880},
url = {https://www.irejournals.com/formatedpaper/1710215.pdf},
abstract = {In an increasingly interconnected digital landscape, global enterprises face evolving and sophisticated cyber threats that pose significant risks to operations, reputation, and stakeholder trust. Effective cyber risk mitigation and incident response require structured, internationally recognized frameworks that ensure resilience, compliance, and business continuity. This paper explores the integration of ISO 27001 and the NIST Cybersecurity Framework as a unified model for enhancing organizational security posture. ISO 27001 provides a comprehensive information security management system (ISMS) emphasizing governance, risk assessment, and continual improvement, while NIST offers a flexible, adaptive approach to identifying, protecting, detecting, responding to, and recovering from cyber incidents. By leveraging the strengths of both frameworks, enterprises can align strategic objectives with practical, actionable controls that address sector-specific and cross-border compliance requirements. The proposed model underscores the importance of proactive risk identification, rapid containment of threats, and structured recovery to minimize operational disruption. It also highlights the value of ongoing employee awareness, stakeholder engagement, and measurable performance indicators in sustaining long-term resilience. Integrating ISO 27001 and NIST enables organizations to not only meet regulatory demands but also build adaptive, scalable defenses capable of countering emerging cyber risks in a dynamic global environment.},
keywords = {Cybersecurity, Risk Mitigation, Incident Response, ISO 27001, NIST Cybersecurity Framework},
month = {January},
}