EP Journals Group logo
EP Journals GroupAcademic Publishing Organisation
Submit Paper
HomeAboutJournalsArticlesIndexingAuthor GuidelinesPublication ProcessEditorial BoardPoliciesContact

Global Journal of Engineering and Technology Research (GJETR)

The Compliance Gap: Why Audit-Based Cybersecurity Models Fail Critical Infrastructure and the Case for Continuous Control

Amadi, Chukwunenye

10 September 2026 · Vol. 2, Issue 9, pp. 536-562

DOI: 10.65150/EP-gjetr/V2E9/2026-12

Abstract

Critical infrastructure (CI) sectors, including energy, water, transportation, healthcare, telecommunications, and finance, continue to anchor their cybersecurity assurance in periodic, audit-based compliance: scheduled assessments that certify, at a point in time, that mandated controls exist and are documented. This conceptual review argues that this model is structurally incapable of guaranteeing security in modern CI environments and develops the case for a transition to continuous monitoring and continuous control. Drawing on standards literature, empirical studies of operational technology (OT) security, documented attacks on industrial systems, and the continuous auditing tradition in accounting information systems, the paper synthesizes five interlocking failure modes of periodic compliance: (a) the static-snapshot problem, in which audit findings describe a past state rather than the present one; (b) the error-proneness and limited depth of manual, checklist-driven assessment; (c) configuration drift, through which compliant systems silently degrade between audits; (d) the asymmetry between adversary operational tempo and annual or multi-year audit cycles; and (e) an audit-centric organizational culture that substitutes evidence production for risk reduction. The analysis situates these failures against a threat landscape defined by IT/OT convergence, industrial Internet of Things expansion, deep infrastructure interdependencies, nation-state pre-positioning, and ransomware economics. The paper then traces the intellectual and regulatory lineage of the alternative (continuous auditing, information security continuous monitoring, continuous diagnostics and mitigation, zero trust architecture, and emerging continuous control validation) and discusses implications for regulators, operators, and researchers. The compliance gap, it concludes, is not a maturity deficit but a design flaw requiring an architectural response. As a conceptual review the paper offers an analytic framework rather than an effect estimate: it presents no new data and does not establish that continuous regimes reduce realized risk relative to periodic ones, a limitation stated in full in Section 7.

Keywords: critical infrastructure, audit-based compliance, continuous monitoring, configuration drift, NIST Cybersecurity Framework, operational technology security

Read the full text on Global Journal of Engineering and Technology Research →The full peer-reviewed article and PDF are hosted on the journal's site (the version of record).

Cite this article

APA
Amadi, & Chukwunenye (2026). The Compliance Gap: Why Audit-Based Cybersecurity Models Fail Critical Infrastructure and the Case for Continuous Control. Global Journal of Engineering and Technology Research, 2(9), 536-562. https://doi.org/10.65150/EP-gjetr/V2E9/2026-12
BibTeX
@article{Amadi2026,
  title   = {The Compliance Gap: Why Audit-Based Cybersecurity Models Fail Critical Infrastructure and the Case for Continuous Control},
  author  = {Amadi and Chukwunenye},
  journal = {Global Journal of Engineering and Technology Research},
  year    = {2026},
  volume  = {2},
  number  = {9},
  pages   = {536-562},
  doi     = {10.65150/EP-gjetr/V2E9/2026-12},
  url     = {https://doi.org/10.65150/EP-gjetr/V2E9/2026-12}
}

Related articles in GJETR

  • Climate-Resilient Foundation Design for Coastal Infrastructure Under Rising Groundwater Conditions: A Review

    Olukoju, John Ayomide, Oladosu, Micheal Abimbola · Sept 2026

  • Edge-Optimized YOLO Architectures for Real-Time Autonomous Vehicle Perception: A Hardware-Aware Co-Design Framework

    Christian Sankara, Harouna Wendpanga Yann, Oyesiji, Serif Oyindamola, Aalaj, Emmanuel Eniola, Nwakamma, Stanley · Sept 2026

  • A Hardware-In-The-Loop CI/CD Validation Framework for IoT and Vehicle Embedded Systems Using C# and Azure Devops

    Ndupu, Kingsley Chinazaekpere, Ajala, Emmanuel Eniola, Oyesiji, Serif Oyindamola, Nwakamma, Stanley · Sept 2026

  • Predictive Maintenance Metrics in the Minimisation of Non-Routine Flaring from Rotating Machinery Failure: A Review of Condition Monitoring, Prognostics and the Conditional Chain from Early Detection to Avoided Emergency Pressure Relief

    Ekelemu, Oghenekaro, Akano, Oluwaseyi Ayotunde, Adikwu, Friday Emmanuel, Amarahobu, Chibuzor · Sept 2026

  • Design and Implementation of a Smart Energy Management System for Solar-Powered Buildings Using Predictive Energy Control: A Case Study of University of Delta, Agbor, Delta State

    Nelson, Obonyano Kingdom, Solomon, Onyemelife Ezeh, Mene, Joseph, Sylvester, Ihieabiaobini · Sept 2026

← Back to all articles

Publisher

EP Journals Group

Publisher of peer-reviewed scholarly journals operating under a documented governance framework. Editorial decisions are based on scholarly merit and peer review, and the portfolio is published on a monthly frequency.

Country / jurisdiction: Published and administered internationally

Journals

  • Journals list (publisher site)

Policies

  • Publication Ethics
  • Peer Review Process
  • Editorial Policies
  • Corrections & Retractions
  • Open Access
  • Complete policy index

Administration

Official contact email:
editor@ep-journals.org

Administrative note: Correspondence is logged for governance and audit purposes. Editorial enquiries answered within 24 hours. Editorial decisions typically within 1–2 weeks.

Compliance disclaimer: Indexing claims and database listings are subject to verification by the respective agencies.

© 2026 EP Journals Group. All rights reserved.

AboutJournalsArticlesFor AuthorsTemplatesEditorial BoardJoin the BoardIndexingSubmitPublishPoliciesEthicsPeer ReviewContact

EP Journals Group operates under a documented policy framework. Editorial decisions are independent and are grounded in peer review and scholarly assessment. All journals are peer-reviewed, open-access, and published monthly. Indexing claims are subject to verification by the respective agencies.

Last site update: April 2026