Research & Scholarship

Converged Security Publications and CSF Standards

Research papers, policy briefs, frameworks, and articles advancing converged security.

Official CSI Documents

Published Converged Security Institute Standards and Policies

Formal standards and policy documents published by the Converged Security Institute. Each document is authored by Prof. Dr. Vladimir Bunic and approved by the CSI Security Advisory Board.

Strategic Framework 2026

Converged Security Framework - Strategic Standards for Unified Risk Management and Organisational Resilience

This framework establishes strategic standards for unified risk management and organisational resilience. It integrates cybersecurity and physical security measures into a cohesive operational strategy, enabling organisations to address hybrid, systemic, and cascading risks through standardised processes, coordinated responses, governance, risk management, compliance, data dependency management, implementation strategies, incident response planning, stakeholder engagement, and training and awareness programmes.

Read Framework Version 2.0  ·  Published: June 2026  ·  Author: Prof. Dr. Vladimir Bunic  ·  Converged Security Institute
Main Standard 2025

ST-CSF.001 - Converged Security Framework

The foundational CSI standard defining best practices for implementing unified risk management through converged security frameworks. Covers 12 requirements domains including governance, risk management, technology integration, identity and access management, incident response, training, data protection, and compliance reporting. Aligned with ISO 31000:2018, ISO 27001:2022, ISO 22301:2019, NIS2, DORA, and GDPR. Includes six associated implementation documents (AD-CSF.001 to AD-CSF.006).

Read Standard Approved: September 2025  ·  Owner: Prof. Dr. Vladimir Bunic  ·  Version: ST-CSF.001-0
Training Standard 2025

ST-CSF.TRA.001 - Training and Awareness

A comprehensive framework for developing unified security competencies across cyber-physical domains. Defines requirements for Cross-functional Security Training Programs, Security Awareness Programs (95% coverage), specialised technology competency for ST-CSF.TIA.001 platforms, and tabletop exercises validating cross-domain incident response. Covers 9 requirements sections including governance, technology integration mastery, and a phased 18-month implementation roadmap. Aligned with NIS2, DORA, GDPR, Cyber Resilience Act, and AI Act. Includes five associated implementation documents (AD-CSF.TRA.001 to AD-CSF.TRA.005).

Read Standard Issued: 03 October 2025  ·  Owner: Prof. Dr. Vladimir Bunic  ·  Version: ST-CSF.TRA.001-01
Governance Standard 2025

ST-CSF.GLA.001 - Governance and Leadership Framework

This standard defines the mandatory requirements for establishing comprehensive governance and leadership structures that integrate Cybersecurity, physical security, and operational technology security domains under unified management frameworks. It aligns with the ST-CSF.001 Converged Security Framework, ST-CSF.TIA.001 Technology Integration and Architecture Standard, ST-CSF.IRBC.001 Incident Response and Business Continuity Framework, and the CSI Product-Oriented Endorsement & Readiness Framework. The standard applies to all organisational entities, subsidiaries, and business units under direct managerial control implementing the ST-CSF.001 Converged Security Framework.

Read Standard Issued: 12/2025  ·  Owner: Dr. Vladimir Bunic – Converged Security Institute  ·  Version: ST-CSF.GLA.001-01
Technology Standard 2025

ST-CSF.TIA.001 - Technology Integration and Architecture

This standard provides BEST practices for implementing unified Technology Integration and Architecture across cyber-physical security domains. It defines requirements for integrated SIEM and PSIM platforms, Cross-domain Integration, Zero Trust Architecture across IT and OT environments, artificial intelligence and machine learning capabilities for predictive threat analysis, documentation, governance, certification, assessment, monitoring, non-compliance enforcement, data protection, and governing law. The standard includes associated documents AD-CSF.TIA.001 Technology Integration Architecture Standards, AD-CSF.TIA.002 Implementation and Assessment Guide, and AD-CSF.TIA.003 Cross-Domain Incident Response Procedures.

Read Standard Issued: 03 October 2025  ·  Owner: Prof. Dr. Vladimir Bunic – Converged Security Institute (CSI)  ·  Version: ST-CSF.TIA.001-01
Incident Response Standard 2025

ST-CSF.IRBC.001 - Incident Response and Business Continuity Framework

This standard provides BEST practices for implementing unified Incident Response and Business Continuity capabilities across cyber-physical security domains. It defines the requirements for establishing coordinated response teams, automatic escalation procedures, and integrated business continuity planning that supports the ST-CSF.001 Converged Security Framework approach to unified risk management. It addresses Hybrid Risks, Systemic Risks, and Cascading Risks, with associated guidance for incident response integration standards, technology integration, unified incident response procedures, training and certification requirements, implementation checklists, role-specific response matrices, regulatory compliance mapping, business case analysis, and performance monitoring dashboards.

Read Standard Issued: 10/2025  ·  Owner: Prof. Dr. Vladimir Bunic and Hannah Beck – Converged Security Institute  ·  Version: ST-CSF.IRBC.001-001
Identity Standard 2025

ST-CSF.IAM.001 - Identity and Access Management Standard

This standard provides requirements for unified Identity and Access Management across cybersecurity, physical security, and operational technology domains. It covers unified identity governance, identity lifecycle management, authentication standards and requirements, authorization and access control, Privileged Access Management, identity federation and integration, monitoring and audit requirements, risk management and threat response, technology standards and architecture, data protection and privacy requirements, implementation timeline and milestones, and review and update procedures. It includes Technical Implementation Standards and Supporting Technical Documentation for identity platform architecture, advanced identity analytics, identity lifecycle management, identity risk assessment methodology, cross-domain identity integration, performance metrics, business continuity, and vendor management.

Read Standard Issued: 09/2025  ·  Owner: Prof. Dr. Vladimir Bunic and Hannah Beck – Converged Security Institute  ·  Version: ST-CSF.IAM.001-01
Data Protection Standard 2025

ST-CSF.DPP.001 - Data Protection and Privacy Standard for Converged Security Framework

This standard provides BEST practices for implementing unified Data Protection and Privacy across cyber-physical security domains. It defines requirements for deploying integrated Privacy Impact Assessment and Data Governance platforms supporting ST-CSF.001 unified privacy risk management, Cross-domain Privacy Integration capabilities, data protection governance controls, Privacy by Design Architecture, Data Loss Prevention Systems, data subject rights, incident response and breach notification, audit and compliance monitoring, third-party data processing, and technical and organisational measures.

Read Standard Issued: 11/2025  ·  Owner: Vladimir Bunic - Converged Security Institute  ·  Version: ST-CSF.DPP.001-01
Risk Management Standard 2025

ST-CSF.RMA.001 - Converged Security Risk Management and Assessment Standard

This standard establishes mandatory industry-leading converged security risk management protocols, strategic assessment methodologies, and unified governance frameworks that organizations must implement to achieve measurable operational superiority and competitive advantage across all security domains. It provides specific requirements for implementing unified risk assessment, comprehensive threat analysis, integrated compliance management, risk-to-response coordination, identity-related risk management, CCSO authority structures, board-level oversight, and automated response integration within the ST-CSF.001 Converged Security Framework mandatory governance structures.

Read Standard Issued: 11/2025  ·  Owner: Prof. Dr. Vladimir Bunic – Converged Security Institute (CSI)  ·  Version: ST-RMA.001-0
Domain Policy 2025

Chief Converged Security Officer (CCSO) Policy

Organisational and Leadership Standard

Establishes unified governance framework for the CCSO role with executive authority across cyber, physical, and operational technology domains. Covers governance structure, risk management, IAM, incident response, compliance, and 21 policy sections across 4 parts.

Read Policy Version 1.0  ·  November 2025  ·  CSI Policy

Research & Books

Published Works

Research papers and books authored by Prof. Dr. Vladimir Bunic on converged security systems, governance, and EU legislative frameworks.

Research Paper 2025

Digital Strategies for Enterprise Converged Security Systems

This dissertation looks into how digital strategies can boost both the integration and overall performance of enterprise converged security systems. It sets out to tackle the challenge of creating a flexible framework that works across various organisational settings. The research takes a mixed-methods approach, gathering a blend of qualitative insights and numerical data on everyday security practices, technology uptake, and what different stakeholders have to say. One clear takeaway is that customised digital strategies tend to enhance communication across departments, cut down incident response times, and generally build a sturdier system. The findings highlight how a comprehensive digital plan that balances both tech solutions and human touch is crucial - particularly within healthcare, where keeping patient data safe and operations running smoothly is absolutely key. The study hints that the benefits extend beyond immediate gains for an organisation; it offers practical, actionable ideas that could inform future policy and strategic planning in the wider field of healthcare security. By stressing the need for organisations to standardise their digital security schemes, this work aims to nurture a culture of continuous improvement and fresh innovation in the sector, ultimately encouraging a safer, more trustworthy approach to healthcare delivery.

View Publication
Research Paper 2025

Challenges in the Governance of Converged Security Systems in Enterprises within the European Union (EU)

The research aims to investigate the complexities and obstacles faced by enterprises in the EU when implementing governance frameworks for converged security systems. Key focuses include understanding regulatory discrepancies, technological integration issues, and organisational culture impacts on effective governance. Qualitative data from case studies, interviews, and surveys with security professionals and compliance officers were utilised.

View Publication
Research Paper 2025

EU Legislative Frameworks of Converged Security Systems

This research investigates how laws work for security systems in companies in the European Union. It pays attention to the problem of too many different rules and what that means for security. Using a mix of methods, like talking to people and checking case studies, the study finds big gaps in how companies follow rules and the problems they face because laws are not the same everywhere. The results show that this messiness stops good risk management and smart use of resources, which can hurt how safe a company is - especially in healthcare where keeping data safe is important. The study points out that there is a real need for better and more equal laws to help security practices work better across countries, leading to stronger operations. This research also talks about how lawmakers should think about different problems within sectors and changing security threats in healthcare. By giving useful suggestions, it hopes to help create better laws that support strong security systems, making businesses safer in the European Union overall.

View Publication
Research Paper 2026

Risk Convergence in Critical Infrastructure Governance in the European Union: A Qualitative Framework for Integrated Multi Domain Risk Oversight

The critical infrastructure sectors of the European Union face growing cross-functional cyber, physical, operational, and human-factor threats. With the increased pace of digitalisation, the effects of such risks spread across organisations, creating systemic vulnerabilities that challenge conventional governance models. This paper analyses the causes and effects of risk convergence and proposes an organised governance model to support integrated multi-domain control. The study adopts a qualitative conceptual methodology based on academic literature, EU regulatory frameworks, industry reports, and documented incidents. Thematic analysis was used to identify recurring themes of risk convergence, supported by cross-document comparison. Regulatory triangulation ensured alignment with NIS2, CER, GDPR, DORA, and the Cyber Resilience Act. Five patterns of risk convergence were identified: cyber-physical interdependencies, operational-cyber propagation, human-factor amplification, regulatory-risk misalignment, and organisational fragmentation. The paper proposes a hybrid governance system comprising structural, operational, and assurance layers - one of the earliest governance-focused models tailored to converged risk environments in EU critical infrastructure. Published in the International Journal of Public Administration, Management and Economic Development, Vol. 11, No. 1 (2026), pp. 34–46.

View Publication
Book

Converged Security for Manufacture's Security

This book helps you to understand Converged Security Systems and their function, and gives you in detail technology solutions with a description of implementation within various manufacturing environments. It also provides operational best practices in converged security systems.

View on Amazon