Home
World Journal of Advanced Research and Reviews
International Journal with High Impact Factor for fast publication of Research and Review articles

Main navigation

  • Home
    • Journal Information
    • Editorial Board Members
    • Reviewer Panel
    • Abstracting and Indexing
    • Journal Policies
    • Our CrossMark Policy
    • Publication Ethics
    • Issue in Progress
    • Current Issue
    • Past Issues
    • Instructions for Authors
    • Article processing fee
    • Track Manuscript Status
    • Get Publication Certificate
    • Join Editorial Board
    • Join Reviewer Panel
  • Contact us
  • Downloads

eISSN: 2581-9615 || CODEN: WJARAI || Impact Factor 8.2 ||  CrossRef DOI

Research and review articles are invited for publication in May 2026 (Volume 30, Issue 2) Submit manuscript

Governance-driven security automation for municipal and SMB cloud modernization: A NIST CSF 2.0–Aligned Remediation Operating Model

Breadcrumb

  • Home
  • Governance-driven security automation for municipal and SMB cloud modernization: A NIST CSF 2.0–Aligned Remediation Operating Model

Kelvin Gyimah Agyei 1, *, Tendai Nemure 2, Salvation Gwangwava 2, Hilton Hatitye Chisora 2, Claude Anesu Samushonga 2, Marlon Bryce Monjoma 3 and Munashe Naphtali Mupa 4

1 University of Memphis.
2 Yeshiva University.
3 Pace University.
4 Hult International Business School.

Research Article

World Journal of Advanced Research and Reviews, 2026, 30(01), 2064-2073

Article DOI: 10.30574/wjarr.2026.30.1.1007

DOI url: https://doi.org/10.30574/wjarr.2026.30.1.1007

Received on 09 March 2026; revised on 19 April 2026; accepted on 22 April 2026

Municipal governments and small-to-medium businesses (SMBs) represent a class of organizations that disproportionately bear the operational burden of cloud security modernization while commanding minimal dedicated cybersecurity resources relative to enterprise counterparts. This paper develops a governance-driven operating model that unifies vulnerability lifecycle management, cloud configuration hardening, and security automation within a governance architecture aligned to the NIST Cybersecurity Framework version 2.0 (NIST CSF 2.0). The model specifies decision rights, remediation service level agreements (SLAs), exception handling procedures, and evidence capture mechanisms suitable for ISO 27001 and SOC 2 audit contexts. Key performance indicators (KPIs) including mean time to remediation (MTTR), percentage of CISA KEV vulnerabilities remediated within mandated deadlines, cloud configuration compliance rate, and security automation coverage ratio are defined and operationalized within the model's measurement architecture. A municipal government case implementation demonstrates how lightweight automation including scanning-to-ticketing workflows, AWS and Azure configuration baseline enforcement, and executive dashboard deployment can materially improve cybersecurity posture and accountability within the resource constraints characteristic of the public-sector and SMB operating environment. Findings indicate that the proposed operating model achieves a 68% reduction in MTTR, a 91% KEV compliance rate, and an 82% reduction in critical cloud misconfigurations within 12 months of implementation, with a total implementation cost accessible to organizations with annual IT security budgets below USD $500,000.

NIST CSF 2.0; governance; Security automation; Municipal cybersecurity; SMB cloud security; Vulnerability management; Cloud configuration hardening; Remediation SLA; Security operations; RMF

https://wjarr.com/sites/default/files/fulltext_pdf/WJARR-2026-1007.pdf

Preview Article PDF

Kelvin Gyimah Agyei, Tendai Nemure, Salvation Gwangwava, Hilton Hatitye Chisora, Claude Anesu Samushonga, Marlon Bryce Monjoma and Munashe Naphtali Mupa. Governance-driven security automation for municipal and SMB cloud modernization: A NIST CSF 2.0–Aligned Remediation Operating Model. World Journal of Advanced Research and Reviews, 2026, 30(01), 2064-2073. Article DOI: https://doi.org/10.30574/wjarr.2026.30.1.1007

Copyright © Author(s). All rights reserved. This article is published under the terms of the Creative Commons Attribution 4.0 International License (CC BY 4.0), which permits use, sharing, adaptation, distribution, and reproduction in any medium or format, as long as appropriate credit is given to the original author(s) and source, a link to the license is provided, and any changes made are indicated.


All statements, opinions, and data contained in this publication are solely those of the individual author(s) and contributor(s). The journal, editors, reviewers, and publisher disclaim any responsibility or liability for the content, including accuracy, completeness, or any consequences arising from its use.

Get Certificates

Get Publication Certificate

Download LoA

Check Corssref DOI details

Issue details

Issue Cover Page

Editorial Board

Table of content

Copyright © 2026 World Journal of Advanced Research and Reviews - All rights reserved

Developed & Designed by VS Infosolution