A dependency-aware evaluation of IAM configuration strategies in maritime critical infrastructure using Fuzzy DEMATEL–ANP
International Journal of Critical Infrastructure Protection, cilt.55, 2026 (SCI-Expanded, Scopus)
- Yayın Türü: Makale / Tam Makale
- Cilt numarası: 55
- Basım Tarihi: 2026
- Doi Numarası: 10.1016/j.ijcip.2026.100904
- Dergi Adı: International Journal of Critical Infrastructure Protection
- Derginin Tarandığı İndeksler: Science Citation Index Expanded (SCI-EXPANDED), Scopus, Compendex, INSPEC
- Anahtar Kelimeler: Critical infrastructure protection, Cybersecurity governance, Fuzzy DEMATEL–ANP, Identity and Access Management (IAM), Maritime critical infrastructure, Zero trust architecture
- Van Yüzüncü Yıl Üniversitesi Adresli: Evet
Özet
This study proposes a dependency-aware framework for evaluating Identity and Access Management (IAM) configuration strategies in maritime critical infrastructure. An IAM configuration strategy is defined as a system-level combination of deployment model, trust model, identity governance structure, and policy-enforcement approach rather than a software architecture pattern. To capture interdependencies that independent-criteria approaches may overlook, the framework integrates Fuzzy Decision-Making Trial and Evaluation Laboratory (Fuzzy DEMATEL) and the Analytic Network Process (ANP) to model causal relationships and derive interdependent criterion weights. A representative maritime scenario involving Port Community Systems, Terminal Operating Systems, and multiple stakeholders contextualizes the analysis. Six IAM configuration strategies—locally centralized IAM, hybrid IAM, identity-as-a-service, decentralized identity, Zero Trust–oriented IAM, and policy-driven IAM—are evaluated against fourteen criteria covering regulatory alignment, security resilience, federated trust, lifecycle governance, and operational adaptability. The study focuses on human and organizational identity governance. Results show that governance-related criteria, particularly regulatory alignment, federated trust, and lifecycle flexibility, act as major drivers of IAM performance. Zero Trust–Oriented IAM and Policy-Driven IAM achieve the highest overall performance because of their support for continuous verification, fine-grained policy enforcement, and adaptability to dynamic trust environments. Score-level Monte Carlo analysis indicates that their exact ordering is moderately sensitive to performance-score uncertainty, while their overall dominance over the remaining strategies is comparatively robust. Locally Centralized IAM performs weakest, particularly in scalability, interoperability, and governance responsiveness.