1 University of Memphis.
2 Yeshiva University.
3 Pace University.
4 Hult International Business School.
World Journal of Advanced Research and Reviews, 2026, 30(01), 2064-2073
Article DOI: 10.30574/wjarr.2026.30.1.1007
Received on 09 March 2026; revised on 19 April 2026; accepted on 22 April 2026
Municipal governments and small-to-medium businesses (SMBs) represent a class of organizations that disproportionately bear the operational burden of cloud security modernization while commanding minimal dedicated cybersecurity resources relative to enterprise counterparts. This paper develops a governance-driven operating model that unifies vulnerability lifecycle management, cloud configuration hardening, and security automation within a governance architecture aligned to the NIST Cybersecurity Framework version 2.0 (NIST CSF 2.0). The model specifies decision rights, remediation service level agreements (SLAs), exception handling procedures, and evidence capture mechanisms suitable for ISO 27001 and SOC 2 audit contexts. Key performance indicators (KPIs) including mean time to remediation (MTTR), percentage of CISA KEV vulnerabilities remediated within mandated deadlines, cloud configuration compliance rate, and security automation coverage ratio are defined and operationalized within the model's measurement architecture. A municipal government case implementation demonstrates how lightweight automation including scanning-to-ticketing workflows, AWS and Azure configuration baseline enforcement, and executive dashboard deployment can materially improve cybersecurity posture and accountability within the resource constraints characteristic of the public-sector and SMB operating environment. Findings indicate that the proposed operating model achieves a 68% reduction in MTTR, a 91% KEV compliance rate, and an 82% reduction in critical cloud misconfigurations within 12 months of implementation, with a total implementation cost accessible to organizations with annual IT security budgets below USD $500,000.
NIST CSF 2.0; governance; Security automation; Municipal cybersecurity; SMB cloud security; Vulnerability management; Cloud configuration hardening; Remediation SLA; Security operations; RMF
Preview Article PDF
Kelvin Gyimah Agyei, Tendai Nemure, Salvation Gwangwava, Hilton Hatitye Chisora, Claude Anesu Samushonga, Marlon Bryce Monjoma and Munashe Naphtali Mupa. Governance-driven security automation for municipal and SMB cloud modernization: A NIST CSF 2.0–Aligned Remediation Operating Model. World Journal of Advanced Research and Reviews, 2026, 30(01), 2064-2073. Article DOI: https://doi.org/10.30574/wjarr.2026.30.1.1007