PulseExploreJournal ClubDebatesTrendingResearchersJournals
Instagram
HomeExploreJournal ClubTrending
Synapse
⌘+K
Synapse
April 5, 2026Scientific Reports2 citationsOpen Access

Security evaluation framework for cloud ERP systems using NIST and ISO standards

AQAdiah QaziUniversity of the SciencesSASadiqa ArshadNational University of Sciences and TechnologyAJAmmad Ali Khan JadoonNational University of Sciences and Technology

Key Points

  • Develop and apply a Security Maturity Assessment Framework to evaluate cloud ERP security based on standards.
  • Develop a structured Security Maturity Assessment Framework (SMAF) based on NIST and ISO standards.
  • Evaluate eleven cloud-based and hybrid ERP platforms across five security domains.
  • Utilize a weighted multi-criteria decision analysis (MCDA) approach supported by expert surveys and vendor documentation.
  • Assign quantifiable security maturity scores from 1 to 5 for objective comparisons.
  • Enterprise-grade solutions like Oracle NetSuite and SAP Business One show significantly higher maturity scores.
  • Mean security maturity score for enterprise solutions is 4.63, while SME-targeted solutions average 2.76.
  • Identified limitations in statistical inference due to small sample sizes for specific segments.

Abstract

Abstract Enterprise Resource Planning (ERP) systems serve as critical infrastructure for modern organizations, yet their security assessment lacks standardized evaluation frameworks. This study develops and applies a structured Security Maturity Assessment Framework (SMAF) grounded in NIST Cybersecurity Framework (CSF) 2. 0 and ISO/IEC 27001: 2022 standards to evaluate eleven cloud-based and hybrid ERP platforms, including both full-suite ERP systems and widely adopted inventory and manufacturing management systems that serve as ERP alternatives for SMEs. Using a weighted multi-criteria decision analysis (MCDA) approach validated by expert surveys (n=47) and vendor documentation analysis, we assess security across five domains: authentication mechanisms, encryption protocols, access control models, vulnerability management, and compliance certifications. Our framework introduces quantifiable security maturity scores ranging from 1 (basic) to 5 (advanced), enabling objective comparison across platforms. Results indicate that enterprise-grade solutions (Oracle NetSuite OneWorld, SAP Business One Professional, Microsoft Dynamics 365) achieve consistently higher security maturity scores (=4. 63, =0. 17) compared to SME-targeted solutions (=2. 76, =0. 39), though small per-segment sample sizes (n=3 –4) limit formal statistical inference. We extend our analysis to emerging security paradigms including Zero-Trust Architecture (ZTA) integration, federated learning for privacy-preserving analytics, blockchain-based audit trails, and digital twin implementations for Industry 5. 0 alignment. The proposed SMAF provides organizations with an evidence-based methodology for ERP security evaluation, addressing a critical gap in both academic literature and practitioner guidance.

Ask AI
Helpful
Bookmark
Share
View Full Paper

Cite This Study

Qazi et al. (2026) studied this question.

synapsesocial.com/papers/69d1fdbfa79560c99a0a3f2chttps://doi.org/10.1038/s41598-026-45550-w
Ask AI
Helpful
Bookmark
Share
View Full Paper