Design and Validation Framework for Multi-Level Cybersecurity and Privacy Protection in Modern Digital Infrastructures

Authors

  • Kennedy Owino Jaramba Masters in Information Technology, Maseno University, Kenya
  • Samwel Oonge Supervisor, Maseno University, Kenya

DOI:

https://doi.org/10.61424/jcsit.v3i2.1016

Keywords:

Cybersecurity, privacy, defense in depth, multi-level security, zero trust, NIST CSF 2.0, ISO/IEC 27001, incident response, security resilience, information security

Abstract

The increasing complexity of cyber threats, interconnected technologies, and data-intensive digital services has exposed limitations in security strategies that depend on isolated controls. This study develops a multi-level cybersecurity and privacy framework that integrates complementary controls across physical, network, endpoint, application, data, identity and access management, monitoring and incident response, and human and policy domains. The framework was developed through structured synthesis of the ten cybersecurity and privacy studies reviewed in the source manuscript and alignment with established cybersecurity guidance. The revised model treats monitoring and incident response as a cross-cutting capability and privacy and governance as cross-cutting concerns. It further introduces a measurable evaluation structure based on layer-specific security indicators and an overall Multi-Level Cybersecurity Resilience Index. The framework is mapped to NIST Cybersecurity Framework 2.0, ISO/IEC 27001:2022, and Zero Trust principles. The resulting architecture provides a practical basis for coordinating preventive, detective, responsive, recovery, governance, and privacy controls. Because the source studies did not include primary empirical testing, the present manuscript does not claim empirical effectiveness; instead, it specifies a validation protocol using expert assessment and/or controlled simulation. This study contributes an integrated architectural model and a measurable evaluation approach for organizations seeking adaptive and resilient cybersecurity.

References

Ababneh, J., et al. (2025). Cybersecurity Ethical Aspects (CEA).

Ahmad, N., et al. (2022). A cybersecurity educated community.

Asha, P., et al. (2025). Multi-layered Security Approach for CI/CD Pipeline with Web Application Development.

Aniwa S.C. (2021). Impact of Supply Chain Integration on Operational Performance: Insights from Manufacturing Firms in Emerging Economies. Iconic Research And Engineering Journals, 5(4).

Cook, J., et al. (2023). Security and Privacy for Low Power IoT Devices on 5G and Beyond Networks: Challenges and Future Directions.

Golda, A., et al. (2024). Privacy and Security Concerns in Generative AI: A Comprehensive Survey.

International Organization for Standardization. (2022). ISO/IEC 27001:2022 Information security, cybersecurity and privacy protection — Information security management systems — Requirements. ISO.

Kamal, M., et al. (2023). Privacy and Security Federated Reference Architecture for Internet of Things.

Landwehr, C., et al. (2012). Privacy and Cybersecurity: The Next 100 Years.

Musa, A., et al. (2025). Our Digital Traces in Cybersecurity: Bridging the Gap Between Anonymity and Identification.

National Institute of Standards and Technology. (2020). Zero Trust Architecture. NIST Special Publication 800-207.

National Institute of Standards and Technology. (2024). NIST Cybersecurity Framework 2.0: Resource and Overview Guide. NIST SP 1299. https://doi.org/10.6028/NIST.SP.1299

National Institute of Standards and Technology. (2024). The NIST Cybersecurity Framework (CSF) 2.0. NIST Cybersecurity White Paper 29. https://doi.org/10.6028/NIST.CSWP.29

Rawat, D. B., et al. (2021). Cybersecurity in Big Data Era: From Securing Big Data to Data-Driven Security.

Zhang, et al. (2022). Accessible from the open web: A qualitative analysis of the available open-source information involving cyber security and critical infrastructure.

Downloads

Published

2026-08-27

How to Cite

Jaramba, K. O., & Oonge, S. (2026). Design and Validation Framework for Multi-Level Cybersecurity and Privacy Protection in Modern Digital Infrastructures. Journal of Computer Science and Information Technology, 3(2), 37–45. https://doi.org/10.61424/jcsit.v3i2.1016