从成熟度模型到地面真相:调和网络安全能力框架与全球南方家庭层面的治理现实
From Maturity Models to Ground Truth: Reconciling Cybersecurity Capacity Frameworks with Household-Level Governance Realities in the Global South
浏览论文内容
中文总结 AI 辅助
本研究针对全球南方国家网络安全能力框架与家庭实际治理之间的“最后一英里”差距,提出四种机制及四个低成本指标,并给出分阶段采用路线图,以改善投资优先级的制定。
中文摘要 AI 辅助
国家网络安全和数字治理能力框架,最突出的是《国家网络安全能力成熟度模型》(CMM),影响着全球南方数十亿美元的捐助者资助的治理投资。然而,在国家层面的制度成熟度与终端用户实际经历的治理之间,仍然存在一个持续的、理论化不足的差距。我们将此称为“最后一英里治理差距”:即成熟度评估所能看到的——法律、机构、标准、意识宣传活动——与生活在正式架构之下的家庭所能获取、理解或执行的内容之间的结构性空间。通过结合CMM评估经验与对约旦智能家居隐私治理的同行评审实证实地调查的双重视角,并辅以肯尼亚和中国的研究佐证,我们识别出国家能力未能惠及家庭的四种机制:可读性、家庭内部权力分配、救济的可及性以及基础设施-可负担性约束。我们将这些机制明确映射到CMM的五个维度上,提出四个具体的、低成本的、可在现有CMM部署中试点的最后一英里指标,并概述了一个分阶段的采用路线图及对预期反对意见的回应。随着AI设备进入全球南方家庭的速度快于机构能力的适应速度,风险正在上升:这种动态有可能将可衡量的成熟度差距转变为无形的差距。最后,我们为GCSCC、国际电信联盟(ITU)、世界银行以及其他依赖成熟度评分来优先分配投资的组织提供了可操作的建议。
英文摘要
National cybersecurity and digital-governance capacity frameworks, most prominently the Cybersecurity Capacity Maturity Model for Nations (CMM), shape hundreds of millions of dollars in donor-funded governance investments across the Global South. Yet a persistent, under-theorised gap remains between state-level institutional maturity and the governance actually experienced by end-users. We term this the last-mile governance gap: the structural space between what a maturity assessment can see - laws, agencies, standards, awareness campaigns - and what a household living under that formal architecture can access, understand, or enforce. Drawing on a dual vantage point combining CMM assessment experience with peer-reviewed empirical fieldwork on smart-home privacy governance in Jordan, corroborated against studies from Kenya and China, we identify four mechanisms by which national capacity fails to reach the household: legibility, intra-household power distribution, accessibility of redress, and infrastructure-affordability constraints. We map these mechanisms explicitly onto the CMM's five dimensions, propose four concrete, low-cost last-mile indicators pilotable within existing CMM deployments, and outline a staged adoption roadmap with responses to anticipated objections. With AI-enabled devices entering homes across the Global South faster than institutional capacity can adapt, the stakes are rising: this dynamic risks converting a measurable maturity gap into an invisible one. We conclude with actionable implications for the GCSCC, the ITU, the World Bank, and other institutions relying on maturity scores to prioritize investment.
发表机构
- University of Oxford(牛津大学)
机构由 AI 辅助整理,请以论文原文为准。