Cyberworthiness extends the concept of cybersecurity by evaluating whether systems and networks can perform their intended functions securely while maintaining protection against cyber threats. In corporate environments, cyberworthiness aims to ensure security, operational resilience, and trustworthiness across interconnected business processes and digital infrastructures. Modern organisations increasingly rely on complex cyber–physical and information systems, where vulnerabilities in software, networks, and devices can introduce significant operational and security risks. Cyberworthiness, therefore, encompasses security controls, risk management practices, and compliance with recognised cybersecurity standards and governance frameworks. It supports the assessment of information technology components and their exposure to both known and emerging cyber attacks, enabling organisations to evaluate system robustness and operational continuity. While cyberworthiness has historical foundations in system assurance and dependability, it also provides a conceptual basis for contemporary cyber resilience strategies. This paper discusses the concept of cyberworthiness in corporate organisations and identifies potential pathways for its practical implementation. It analyses existing cybersecurity standards and governance frameworks to support structured cyberworthiness assessment. This study presents a structured comparative review of fifteen cyberworthiness-relevant standards, supported by a Source Quality Appraisal Framework, a Framework Selection Guide specifying when each standard should be preferred and where conflicts arise, and a five-dimensional Cyberworthiness Assessment Readiness Model (CARM), a directional self-assessment instrument. The Efficient Automatic Safety and Security Assurance (EASSA) concept is proposed as a direction for future research, not a validated deployed system. Ensuring cyberworthiness remains challenging due to automation limitations in all reviewed standards, evolving threat landscapes, and governance complexity, requiring organisations to adopt integrated and measurable approaches to safeguard their digital assets and operational systems.
Almarri et al. (Fri,) studied this question.