About the Journal
Aims and Scope. Journal of Security Governance and Cyber Risk provides a focused venue for research on risk assessment, controls, security governance, resilience planning, compliance engineering. The journal prioritizes technically substantive, internationally relevant work in which the principal novelty lies inside the stated computing scope rather than only in the application domain.
Core topics in scope include:
- risk assessment
- controls
- security governance
- resilience planning
- compliance engineering
- security metrics
- cyber risk
- organizational security
- assurance
Evidence and methodological expectations. Security papers must state an explicit threat, attacker, or trust model; use ethically obtained data; compare against credible defenses or attacks; report false-positive/false-negative and robustness characteristics where relevant; and follow responsible disclosure for exploitable vulnerabilities. Reproducible artifacts must not enable harmful misuse.
Normally outside scope. Generic security awareness surveys, vulnerability scans without scientific analysis, offensive demonstrations lacking defensive value or ethical safeguards, and claims of security based solely on obscurity or encryption use are normally outside scope.
Research integrity and reproducibility. Authors should disclose datasets, software, model or system configurations, experimental protocols, statistical procedures, ethical approvals where applicable, competing interests, funding, and any material use of generative AI. Data and code should be shared when legally and ethically possible, or the restriction must be explained.