Dynamic Subdomain Risk Scoring and Mitigation Framework for Supply Chain Organizations
Main Article Content
Abstract
In the contemporary landscape of interconnected supply chains, organizations extensively depend on sophisticated digital infrastructures, where DNS subdomains play a pivotal role in facilitating operations, logistics, and data exchange. However, these subdomains frequently go unmonitored, rendering them attractive targets for cyber threats. This paper presents a proactive and automated method for subdomain security, utilizing the Scoring Framework for Subdomain Security (SCSS) while enhancing the Automated Subdomain Risk Scoring Framework to address vulnerabilities specific to supply chain environments. By incorporating real-time scanning, automation pipelines, and Governance, Risk, and Compliance (GRC) modules, this framework not only identifies risks but also optimizes mitigation processes, minimizing disruptions and fortifying security measures. Experimental results underscore the framework's efficacy in prioritizing vulnerabilities, optimizing resource deployment, and ensuring alignment with regulatory standards. This research offers a structured yet flexible solution to protect supply chain organizations from emerging DNS-based threats.


