Security decision-making in socio-technical systems can often be limited by fragmented analytical approaches that may struggle to address the complexities of modern threats. This article proposes an integrated multidisciplinary framework that synthesises five key pillars: Goal-Oriented Requirements Engineering (GORE), Risk Assessment (RA), Crime Scripting (CSA), Quantitative Decision Analysis (QDA), and Attack-Graph Modelling (AGM). By incorporating attack graphs as a fifth layer, the framework seeks to provide a dual-view of the adversary, bridging the gap between human procedural behaviour (the script) and technical exploit dependencies (the graph). This integrated approach is designed to assist decision-makers in systematically identifying stakeholder goals, characterising multi-path attack trajectories, and evaluating resolution actions using explicit uncertainty ranges. The framework generates a Unified Conceptual Model —a visual, auditable artefact intended to reveal underlying trade-offs between security, usability, and profitability. Illustrated through a demonstrative case study, this research offers practitioners a structured decision-support model with potential applicability to finance, critical infrastructure, and cloud environments.
No takes yet. Share an insight, caveat, or question.
Manny Niri (2026) studied this question.
Synapse has enriched 5 closely related papers on similar clinical questions. Consider them for comparative context: