Preprint
Article

This version is not peer-reviewed.

Risk-Adaptive Security Authorization for Critical Information Infrastructure: A Remediation-First Framework for Dynamic Target Security Profiles

Submitted:

22 September 2026

Posted:

22 September 2026

You are already at the latest version

Abstract
Security authorization relies on a target security profile that is relatively stable, whereas threats, exposure, control health, and assessment evidence change continuously. We present a two-stage decision-support model that separates operational remediation from structural insufficiency of an already authorized profile. The first stage tests whether an assurance-adjusted authorization-risk index can be restored to tolerance using admissible actions while the profile remains fixed. Only when this problem is infeasible does the second stage generate a minimum-burden candidate profile for assessment and reauthorization. The model defines an authorization envelope, preserves mandatory requirements, distinguishes candidate from authorized states, and treats any structural profile revision as a reauthorization event. In a 365-day synthetic critical-infrastructure benchmark with 100 paired Monte Carlo replicates, the proposed strategy averaged 0.27 days above the benchmark risk tolerance and 1.43 risk-driven profile revisions, compared with 0 days and 9.06 revisions for direct event-driven reoptimization. Ablation and sensitivity analyses support the role of the remediation-first boundary while identifying assumed control effectiveness as the main source of model uncertainty. The results support frequent reassessment but selective, explainable profile revision. This study is a computational proof of concept and does not replace legal authorization or empirical cyber-range validation.
Keywords: 
;  ;  ;  ;  ;  ;  
Copyright: This open access article is published under a Creative Commons CC BY 4.0 license, which permit the free download, distribution, and reuse, provided that the author and preprint are cited in any reuse.