Developing the Cloud ERP Cybersecurity Assessment Framework (CECAF) for Evidence-Based Cybersecurity Capability Assessment in Cloud ERP Platforms

Authors

  • Staš Heric
  • Samo Bobek

Keywords:

Cloud ERP, Cybersecurity, Cybersecurity assessment framework, Cybersecurity capability assessment, Evidence-based assessment, Capability maturity

Abstract

The purpose of this study is to develop the Cloud ERP Cybersecurity Assessment Framework (CECAF) to systematically evaluate cybersecurity capabilities in cloud ERP platforms. The framework was developed through the synthesis of academic literature, internationally recognised cybersecurity standards, cybersecurity capability maturity assessment principles, and cloud ERP-specific cybersecurity requirements, and demonstrated through an evidence-based assessment of Infor CloudSuite using publicly available official technical documentation. The findings demonstrate that CECAF enables a structured, transparent, and reproducible evaluation of cybersecurity capabilities across multiple assessment domains. The study contributes by introducing an analytical assessment framework tailored to cloud ERP platforms and by highlighting the methodological importance of documented technical evidence for objective cybersecurity capability assessment. The framework provides practical guidance for cybersecurity evaluation and comparative assessment of cloud ERP platforms.

Downloads

Download data is not yet available.

References

Almorsy, M., Grundy, J., & Müller, I. (2016). An analysis of the cloud computing security problem. Journal of Cloud Computing, 5(1), 38. https://doi.org/10.1186/s13677-016-0066-2

Anica-Popa, L.-E., Vrîncianu, M., Pugna, I.-B., & Boldeanu, D.-M. (2024). Addressing cybersecurity issues in ERP systems: Emerging trends and challenges. Proceedings of the International Conference on Business Excellence, 18(1), 1306–1323. https://doi.org/10.2478/picbe-2024-0108

Becker, J., Knackstedt, R., & Pöppelbuß, J. (2009). Developing maturity models for IT management: A procedure model and its application. Business & Information Systems Engineering, 1(3), 213–222. https://doi.org/10.1007/s12599-009-0044-5

Bertino, E. (2021). Zero Trust Architecture: Does It Help? IEEE Security & Privacy, 19(6), 95–99. https://doi.org/10.1109/MSEC.2021.3091195

Brezavšček, A., & Baggia, A. (2025). Recent trends in information and cyber security maturity assessment: A systematic literature review. Systems, 13(1), 52. https://doi.org/10.3390/systems13010052

Cloud Security Alliance. (2024). Cloud Controls Matrix (CCM). Retrieved from https://cloudsecurityalliance.org/research/cloud-controls-matrix

Demi, S., & Haddara, M. (2018). Do cloud ERP systems retire? An ERP lifecycle perspective. Procedia Computer Science, 138, 587–594. https://doi.org/10.1016/j.procs.2018.10.079

Dwivedi, Y. K., Hughes, L., Coombs, C., et al. (2021). Artificial Intelligence (AI): Multidisciplinary perspectives on emerging challenges, opportunities, and agenda for research, practice and policy. International Journal of Information Management, 57, 101994. https://doi.org/10.1016/j.ijinfomgt.2019.08.002

Infor. (2020). Infor Business Continuity Plan Overview. Retrieved from https://webassets.infor.com/images/Infor-Business-Continuity-Plan-Overview-April-2020.pdf

Infor. (2023). Information Security Plan (Software as a Service). Retrieved from https://dam.infor.com/api/public/content/94cc4621111741dfb603ed08dbb0f254

Infor. (2024). Data Privacy. Retrieved from https://www.infor.com/about/data-privacy

Infor. (n.d.). Audit Logging Documentation. Retrieved June 10, 2026, from https://docs.infor.com/

Infor. (n.d.). Federated Security. Retrieved June 9, 2026, from https://docs.infor.com/inforos/

Infor. (n.d.). Infor ION API Administration Guide. Retrieved June 10, 2026, from https://docs.infor.com/ionapi/

Infor. (n.d.). Infor OS API Gateway Administration Guide. Retrieved June 8, 2026, from https://docs.infor.com/inforos/

Infor. (n.d.). Infor OS Security Administration Guide. Retrieved June 10, 2026, from https://docs.infor.com/inforos/

Infor. (n.d.). Infor OS User Administration Guide. Retrieved June 9, 2026, from https://docs.infor.com/inforos/

Infor. (n.d.). Infor Trust Center. Retrieved June 10, 2026, from https://trust.infor.com/

International Organization for Standardization. (2022). ISO/IEC 27001:2022 Information security, cybersecurity and privacy protection—Information security management systems—Requirements. https://www.iso.org/standard/27001.html

Ivanović, T., & Marić, M. (2021). Cloud ERP systems in digital transformation: Opportunities and challenges. Strategic Management, 26(4), 28–40. https://doi.org/10.5937/StraMan2104028I

Khan, M. Y., Ab-Rahim, R., & Yeng, S. (2025). A conceptual overview of Enterprise Resource Planning systems. International Journal of Academic Research in Business and Social Sciences, 15(5). https://doi.org/10.6007/IJARBSS/v15-i5/25490

Khokrale, R. (2025). Cybersecurity in ERP-integrated supply chains: Risks and mitigation strategies. The Eastasouth Journal of Information System and Computer Science, 3(2). https://doi.org/10.58812/esiscs.v3i02.869

Klaus, H., Rosemann, M., & Gable, G. G. (2000). What is ERP? Information Systems Frontiers, 2(2), 141–162. https://doi.org/10.1023/A:1026543906354

Lee, Y., Lee, J., & Kim, S. (2024). Cybersecurity challenges and strategies in cloud ERP environments: A systematic literature review. Journal of Enterprise Information Management, 37(3), 742–768. https://doi.org/10.1108/JEIM-07-2023-0283

Liyanage, L., Arachchilage, N. A. G., & Russello, G. (2024). SoK: Identifying limitations and bridging gaps of cybersecurity capability maturity models (CCMMs). arXiv. https://doi.org/10.48550/arXiv.2408.16140

Llivisaca-Villazhañay, J., Paredes-Gualtor, J., Paredes-Valverde, M. A., & Ortiz-Crespo, A. (2025). Cloud ERP adoption and digital transformation in organisations: A systematic literature review. Information Systems Frontiers. Advance online publication. https://doi.org/10.1007/s10796-025-10625-5

Mushtaq, S., Mohsin, M., & Mushtaq, M. M. (2025). A systematic literature review on the implementation and challenges of Zero Trust Architecture across domains. Sensors, 25(19), 6118. https://doi.org/10.3390/s25196118

National Institute of Standards and Technology. (2024). The NIST Cybersecurity Framework (CSF) 2.0. U.S. Department of Commerce. https://www.nist.gov/cyberframework

Paulk, M. C., Curtis, B., Chrissis, M. B., & Weber, C. V. (1993). Capability Maturity Model, Version 1.1. IEEE Software, 10(4), 18–27. https://doi.org/10.1109/52.219617

Qazi, A., Khorram-Manesh, A., Vaziri, S., & Dimitrov, D. (2026). Cybersecurity capability assessment in cloud ERP systems: A maturity model approach. Computers & Security, 142, Article 103821. https://doi.org/10.1016/j.cose.2025.103821

Rose, S., Borchert, O., Mitchell, S., & Connelly, S. (2020). Zero trust architecture (NIST Special Publication 800-207). https://doi.org/10.6028/NIST.SP.800-207

Singh, U. K., & Sharma, A. (2021). Cloud computing security framework based on shared responsibility models: Cloud computing. In Cyber-Physical, IoT, and Autonomous Systems in Industry 4.0 (pp. 39-55). CRC Press.

Sternad Zabukovšek, S., & Bobek, S. (2025). Using the technology acceptance model for factors influencing acceptance of enterprise resource planning solutions. In Encyclopedia of Information Science and Technology, Sixth Edition (pp. 1-28). IGI Global Scientific Publishing.

Sunyaev, A. (2020). Internet computing: Principles of distributed systems and emerging internet-based technologies (2nd ed.). Springer. https://doi.org/10.1007/978-3-030-34957-8

Yin, R. K. (2018). Case study research and applications: Design and methods (6th ed.). SAGE Publications.

Downloads

Published

28.09.2026

Data Availability Statement

Findings in this paper are based on publicly available technical documentation of Infor CSI (Infor, n.d.).

How to Cite

Heric, S., & Bobek, S. (2026). Developing the Cloud ERP Cybersecurity Assessment Framework (CECAF) for Evidence-Based Cybersecurity Capability Assessment in Cloud ERP Platforms. Naše Gospodarstvo Our Economy, 72(3), 90-112. https://journals.um.si/index.php/oe/article/view/6388