Skip to content
Review Open access

Ethical and Regulatory Challenges in Cybersecurity: A Survey of Data Governance and Policy Mechanisms

Jul 2026 · International Journal of Emerging Research in Engineering and Technology · 0 citations

TL;DR

The study emphasizes the need for adaptive, intelligent, and automated governance frameworks capable of supporting real-time policy enforcement, risk assessment, explainable AI, and compliance management across cloud, IoT, and multi-tenant environments.

Abstract

The rapid growth of intelligent systems has transformed the way organizations generate, manage, and secure data. While these technologies enable improved operational efficiency and data-driven decision-making, they also introduce significant challenges related to data governance, privacy, security, ethical AI, and regulatory compliance. Effective data governance and policy mechanisms are essential for ensuring data quality, integrity, accountability, and resilience in increasingly complex digital environments. This paper presents a comprehensive review of cybersecurity, data governance frameworks, policy enforcement mechanisms, and the ethical and regulatory challenges associated with managing cybersecurity data. It examines key governance principles, AI-driven governance approaches, privacy-preserving techniques, and regulatory frameworks such as the General Data Protection Regulation (GDPR) and the Nigeria Data Protection Regulation (NDPR). Furthermore, the paper provides a comparative analysis of recent studies on data governance and policy mechanisms, highlighting their objectives, contributions, limitations, and future research directions. Based on the identified research gaps, the study emphasizes the need for adaptive, intelligent, and automated governance frameworks capable of supporting real-time policy enforcement, risk assessment, explainable AI, and compliance management across cloud, IoT, and multi-tenant environments. The findings offer valuable insights for researchers, practitioners, and policymakers seeking to develop secure, trustworthy, and ethically responsible data governance solutions for next-generation cybersecurity systems.

Read PDF

Similar papers

Review Open access 2023

Cybersecurity Governance in Smart Campus Environments: Balancing ISO 27001, GDPR, and HIPAA Compliance in University IT Systems

This study examines how universities can govern cybersecurity, privacy, and healthcare information within increasingly interconnected digital environments. Its purpose is to clarify how ISO/IEC 27001, the General Data Protection Regulation, and the Health Insurance Portability and Accountability Act can be aligned without obscuring their distinct legal and operational requirements. A structured narrative review was undertaken using peer-reviewed literature, recognised standards, regulatory guidance, and relevant institutional studies published up to 2023. The analysis focused on smart campus architecture, data flows, cyber-risk exposure, information security management, privacy accountability, healthcare data protection, regulatory interoperability, governance barriers, and emerging technologies. The findings indicate that ISO/IEC 27001 provides an effective institutional backbone for risk management, leadership accountability, control assurance, and continual improvement. However, GDPR introduces broader obligations relating to lawful processing, transparency, data-subject rights, and privacy by design, while HIPAA imposes specialised safeguards for protected health information within covered university healthcare functions. Significant convergence exists in access control, incident response, supplier oversight, documentation, workforce training, and continuous monitoring, yet divergence remains in legal scope, enforcement, individual rights, and breach obligations. The review further identifies fragmented authority, legacy infrastructure, shadow systems, cross-border processing, third-party dependence, and emerging technologies as major governance challenges. The study concludes that universities require a layered, integrated governance model rather than separate compliance silos. It recommends multidisciplinary oversight, harmonised control catalogues, precise data classification, Zero Trust access, privacy and security by design, recurring impact assessments, supplier accountability, and measurable assurance. It also emphasises ethical governance of artificial intelligence, analytics, and connected infrastructure. Future research should empirically evaluate integrated models across jurisdictions, institutional types, and resource-constrained settings.

Dominic Feboh, Ayokunle Olamide Ijagbemi, Stanley Nwakamma et al. · 0 citations
Open access 2026

Aligning Cybersecurity Governance with Regulatory Compliance: Policy Integration Challenges in Healthcare Organizations

This research examines the relationship between cybersecurity governance and regulatory compliance in healthcare organizations, with a focus on policy integration challenges. As healthcare systems operate under strict regulatory frameworks, including data protection and privacy requirements, organizations must align cybersecurity practices with compliance obligations. However, compliance-driven approaches may not fully address operational cybersecurity risks, particularly in complex and rapidly evolving environments. This study adopts a conceptual governance analysis, informed by evidence from organizational cases, to explore how policy frameworks, regulatory requirements, and cybersecurity practices interact. The findings indicate that misalignment between compliance and operational security can result in gaps in risk management, reduced system effectiveness, and governance inefficiencies. The article introduces a policy–governance alignment model and provides practical implications for integrating regulatory requirements into cybersecurity governance frameworks.

D. G. B. Mengnjo, Dr. Robb Shawe · 0 citations
Open access 2022

Smart Governance: Policy Framework for Digital Public Services

Smart governance represents a modern approach to public administration that uses digital technologies, data-driven decision-making, and citizen-centric service models to improve efficiency, transparency, and accountability. With the rapid growth of information and communication technologies (ICT), governments are shifting from traditional bureaucratic systems to digitally transformed governance models that emphasize interoperability, inclusiveness, and responsiveness. Technologies such as e-governance platforms, mobile government services, artificial intelligence, blockchain, and cloud computing are reshaping the government–citizen relationship. This study proposes an integrated policy framework for smart governance to ensure secure, accessible, and sustainable digital public service delivery. Using a multidisciplinary and mixed-method approach, including policy analysis, global case studies, and quantitative performance evaluation, the research examines factors such as interoperability, citizen engagement, institutional capacity, and regulatory compliance. The findings indicate that governments with integrated policy and strong technological governance achieve higher efficiency and greater public trust. However, challenges such as cybersecurity risks, data privacy concerns, digital illiteracy, and organizational resistance remain significant barriers. The study recommends strategic policy interventions and collaborative governance models to support sustainable digital transformation in public administration.

Jose Fernandez, M. González · 0 citations
Conference Jul 2026

Navigating Ethical, Legal, and Security Challenges of IoT in the UAE: A Multi-Dimensional Analysis

The Internet of Things (IoT) is rapidly transforming societies by connecting billions of devices, enabling unprecedented levels of data collection, automation, and convenience. However, its widespread adoption brings significant ethical, legal, and security challenges that must be addressed to ensure responsible innovation. This paper explores four critical dimensions of IoT governance: ethics, privacy, intellectual property, and computer crime, with a focus on the United Arab Emirates (UAE) context. Through real-world case studies, analysis of local and international regulations such as the UAE's Personal Data Protection Law (PDPL) and the EU's General Data Protection Regulation (GDPR), and examination of ethical frameworks, the study highlights the tensions between technological advancement and societal values. Key findings emphasize the need for transparent consent mechanisms, robust cybersecurity measures, equitable access to technology, and adaptive intellectual property protections.

Alya Alhameli, Aisha Alriyami, Salama Alshamsi et al. · 0 citations
Review Open access Jul 2026

Risk-Based IT Auditing and Cybersecurity Assurance in Regulated U.S. Organizations: A Review of Governance, Methods, and Outcomes

Risk-based IT auditing and cybersecurity assurance have become central mechanisms for protecting regulated organizations amid evolving digital threats. This review synthesizes peer-reviewed literature on governance structures, auditing methods, and resulting outcomes across key sectors including financial services, capital markets, healthcare, and critical infrastructure. Drawing from a broad body of literature, it examines how regulatory frameworks shape risk identification and control deployment while highlighting assurance practices that contribute to measurable improvements in threat mitigation and compliance. The analysis reveals consistent emphasis on integrated governance approaches alongside persistent implementation tensions, such as mismatches between risk-based ideals and practical application. Key insights underscore the role of adaptive controls, outcome-focused assurance, and sector-specific adaptations in enhancing overall cybersecurity posture. The review also identifies areas where current practices fall short, offering grounded directions for advancing both theory and practice in regulated environments.

William Asare Yirenkyi, Apaflo Godson Teye, Matilda Konotey et al. · 0 citations