A Fuzzy AHP-Based Framework for Assessing Cybersecurity Readiness in Smart Circular Economy Systems Aligned with ISO/IEC 27001
Abstract
1. Introduction
- RQ: How can a structured, ISO/IEC 27001:2022-aligned Fuzzy AHP framework be developed to systematically prioritize the factors determining cybersecurity readiness in smart circular-economy systems?
2. Conceptual Background: Mapping CE Digital Infrastructures to ISO/IEC 27001:2022 Readiness Criteria
3. Materials and Methods
3.1. Development of the Hierarchical Framework
3.2. Expert Panel and Selection Process
3.3. Fuzzy AHP and Computational Procedure
- reflects the comparative preference of criterion over criterion in fuzzy form.
- is its reciprocal, representing the inverse importance.
- indicates that each element is equally important with itself.
3.4. Reliability Assessment
3.4.1. Consistency Assessment
3.4.2. Sensitivity and Robustness Assessment
4. Results
4.1. Prioritization of Main Criteria
4.2. Prioritization of Sub-Criteria
4.2.1. Local Weight Ranking of Sub-Criteria
4.2.2. Global Weight Ranking of Sub-Criteria
4.3. Consistency Assessment and Sensitivity-Robustness Evaluation
5. Discussion and Implications
5.1. Governance and Regulatory Alignment as Foundational Determinants
5.2. Operational and Technological Controls as Mechanisms for Enacting Governance
5.3. Organizational, Human, and Physical Controls as Contextual Stabilizers
5.4. Integrated Perspective from the Global Ranking of Factors
5.5. Theoretical Implications for Cybersecurity Readiness in CE Systems
5.6. Practical and Managerial Implications for CE Cybersecurity Readiness
5.7. Limitations of the Study
6. Future Research Directions
7. Conclusions
Author Contributions
Funding
Institutional Review Board Statement
Informed Consent Statement
Data Availability Statement
Conflicts of Interest
References
- Ozturk, I.; Topuz, E. Quantification of Sustainability Index for the Wastewater Recovery Technologies: A Decision Support Approach for Circular City Adaptations. Int. J. Environ. Sci. Technol. 2023, 20, 9963–9980. [Google Scholar] [CrossRef]
- Noor, A.F.M.; Moghavvemi, S.; Tajudeen, F.P. Identifying Key Factors of Cybersecurity Readiness in Organizations: Insights from Malaysian Critical Infrastructure. Comput. Secur. 2025, 159, 104674. [Google Scholar] [CrossRef]
- Shah, M.H.; Muhammad, R.; Ameen, N. Cybersecurity Readiness of E-Tail Organisations: A Technical Perspective. In Responsible Design, Implementation and Use of Information and Communication Technology (I3E 2020); Lecture Notes in Computer Science; Hattingh, M., Matthee, M., Smuts, H., Pappas, I., Dwivedi, Y., Mäntymäki, M., Eds.; Springer: Cham, Switzerland, 2020; Volume 12066, pp. 153–160. [Google Scholar]
- Perozzo, H.; Zaghloul, F.; Ravarini, A. CyberSecurity Readiness: A Model for SMEs Based on the Socio-Technical Perspective. Complex Syst. Inform. Model. Q. 2022, 33, 53–66. [Google Scholar] [CrossRef]
- Folorunso, A.; Mohammed, V.; Wada, I.; Samuel, B. The Impact of ISO Security Standards on Enhancing Cybersecurity Posture in Organizations. World J. Adv. Res. Rev. 2024, 24, 2582–2595. [Google Scholar] [CrossRef]
- Malatji, M. Management of Enterprise Cyber Security: A Review of ISO/IEC 27001:2022. In Proceedings of the 2023 International Conference on Cyber Management and Engineering (CyMaEn); IEEE: New York, NY, USA, 2023; pp. 117–122. [Google Scholar]
- Tariq, M.I.; Tayyaba, S.; De-la-Hoz-Franco, E.; Ashraf, M.W.; Rad, D.V.; Butt, S.A.; Santarcangelo, V. Evaluation and Prioritization of Information Security Controls of ISO/IEC 27002:2013 for SMEs Through Fuzzy TOPSIS. In Advances in Intelligent Data Analysis and Applications; Springer: Singapore, 2022; pp. 271–289. [Google Scholar]
- Styoutomo, Y.A.; Ruldeviyani, Y. Information Security Awareness Raising Strategy Using Fuzzy AHP Method with HAIS-Q and ISO/IEC 27001:2013: A Case Study of XYZ Financial Institution. CommIT (Commun. Inf. Technol.) J. 2023, 17, 133–149. [Google Scholar] [CrossRef]
- Kahraman, C.; Cebeci, U.; Ulukan, Z. Multi-criteria Supplier Selection Using Fuzzy AHP. Logist. Inf. Manag. 2003, 16, 382–394. [Google Scholar] [CrossRef]
- Büyüközkan, G.; Göçer, F. Digital Supply Chain: Literature Review and a Proposed Framework for Future Research. Comput. Ind. 2018, 97, 157–177. [Google Scholar] [CrossRef]
- Chen, S.-J.; Hwang, C.-L. Fuzzy Multiple Attribute Decision Making Methods. In Fuzzy Multiple Attribute Decision Making; Lecture Notes in Economics and Mathematical Systems; Springer: Berlin/Heidelberg, Germany, 1992; pp. 289–486. [Google Scholar]
- Tariq, M.I.; Ahmed, S.; Memon, N.A.; Tayyaba, S.; Ashraf, M.W.; Nazir, M.; Hussain, A.; Balas, V.E.; Balas, M.M. Prioritization of Information Security Controls through Fuzzy AHP for Cloud Computing Networks and Wireless Sensor Networks. Sensors 2020, 20, 1310. [Google Scholar] [CrossRef] [PubMed]
- Bhol, S.G.; Mohanty, J.R.; Pattnaik, P.K. Enhancing Cybersecurity Metrics Evaluation Through the Application of Fuzzy Ahp Methodology. In Intelligent Computing Systems and Applications (ICICSA 2023); Lecture Notes in Networks and Systems; Bandyopadhyay, S., Balas, V.E., Biswas, S.K., Saha, A.K., Thounaojam, D.M., Eds.; Springer: Singapore, 2024; Volume 1010, pp. 135–147. [Google Scholar]
- Mızrak, F. Premium E-Journal of Social Sciences. Prem. E-J. Soc. Sci. 2023, 7, 1272–1292. [Google Scholar] [CrossRef]
- Simjanović, D.; Ristić, L.; Milovanović, A.; Jovanović, A. The Fuzzy AHP Approach to Evaluation of Criteria Related to Active Cyber Attacks. In Proceedings of the BISEC 2024—15th International Conference on Business Information Security, Niš, Serbia, 28–29 November 2024; pp. 1–9. [Google Scholar]
- Magnusson, L.; Iqbal, S.; Elm, P.; Dalipi, F. Information Security Governance in the Public Sector: Investigations, Approaches, Measures, and Trends. Int. J. Inf. Secur. 2025, 24, 177. [Google Scholar] [CrossRef]
- Kekgathetse, M.; Lucas, B.; Sebapalo, M. A Systematic Review on Cyber Security Integration in Information Technology Governance. In Proceedings of the 2024 International Conference on Electrical and Computer Engineering Researches (ICECER); IEEE: Gaborone, Botswana, 2024; pp. 1–6. [Google Scholar]
- Brezavšček, A.; Baggia, A. Recent Trends in Information and Cyber Security Maturity Assessment: A Systematic Literature Review. Systems 2025, 13, 52. [Google Scholar] [CrossRef]
- Savaş, S.; Karataş, S. Cyber Governance Studies in Ensuring Cybersecurity: An Overview of Cybersecurity Governance. Int. Cybersecur. Law Rev. 2022, 3, 7–34. [Google Scholar] [CrossRef]
- Demircan, B.G.; Yetilmezsoy, K. A Hybrid Fuzzy AHP-TOPSIS Approach for Implementation of Smart Sustainable Waste Management Strategies. Sustainability 2023, 15, 6526. [Google Scholar] [CrossRef]
- Joshi, M.; Deole, P. Assessing Barriers to IoT Implementation in Circular Systems Using Spherical Fuzzy AHP Approach. J. Sci. Ind. Res. 2025, 84, 1088–1094. [Google Scholar] [CrossRef]
- Khoshand, A.; Rahimi, K.; Ehteshami, M.; Gharaei, S. Fuzzy AHP Approach for Prioritizing Electronic Waste Management Options: A Case Study of Tehran, Iran. Environ. Sci. Pollut. Res. 2019, 26, 9649–9660. [Google Scholar] [CrossRef] [PubMed]
- Turskis, Z.; Šniokienė, V. IoT-Driven Transformation of Circular Economy Efficiency: An Overview. Math. Comput. Appl. 2024, 29, 49. [Google Scholar] [CrossRef]
- Kristoffersen, E.; Blomsma, F.; Mikalef, P.; Li, J. The Smart Circular Economy: A Digital-Enabled Circular Strategies Framework for Manufacturing Companies. J. Bus. Res. 2020, 120, 241–261. [Google Scholar] [CrossRef]
- Morshedi, M.; Hargaden, V.; Papakostas, N.; Ghadimi, P. The Adoption of Digital Technologies in Circular Supply Chains: From Theoretical Developments to Practical Applications. Logistics 2026, 10, 18. [Google Scholar] [CrossRef]
- Handoyo, S.; Sueb, M. Integrating Digital Technologies Into the Circular Economy: A Systematic Literature Review of Trends, Challenges, and Opportunities. Circ. Econ. Sustain. 2026, 6, 111. [Google Scholar] [CrossRef]
- Trevisan, A.H.; Zacharias, I.S.; Liu, Q.; Yang, M.; Mascarenhas, J. Circular Economy and Digital Technologies: A Review of the Current Research Streams. Proc. Des. Soc. 2021, 1, 621–630. [Google Scholar] [CrossRef]
- GACERE. Circular Economy and Digitalization—Working Paper; GACERE: Nairobi, Kenya, 2025. [Google Scholar]
- Iruku, V.M. Smart Supply Chains for a Circular Future: AI and IoT for Greener Commerce for Sustainable Development. In Sustainable Development Through Machine Learning, AI and IoT (ICSD 2025); Communications in Computer and Information Science; Whig, P., Silva, N., Ahmad, A.E., Aneja, N., Sharma, P., Eds.; Springer: Cham, Switzerland, 2026; Volume 2888, pp. 128–139. [Google Scholar]
- ISO/IEC 27001:2022; Information Security, Cybersecurity and Privacy Protection—Information Security Management Systems—Requirements. International Organization for Standardization: Geneva, Switzerland, 2022.
- Hernandez Ramos, J.L.; Karopoulos, G.; Nai Fovino, I.; Spigolon, R.; Sportiello, L.; Steri, G.; Gorniak, S.; Magnabosco, P.; Atoui, R.; Crippa Martinez, C. Cyber Resilience Act Requirements Standards Mapping; Publication Office of the European Union: Luxembourg, 2024. [Google Scholar]
- Chou, Y.-C.; Sun, C.-C.; Yen, H.-Y. Evaluating the Criteria for Human Resource for Science and Technology (HRST) Based on an Integrated Fuzzy AHP and Fuzzy DEMATEL Approach. Appl. Soft Comput. 2012, 12, 64–71. [Google Scholar] [CrossRef]
- Buckley, J.J. Fuzzy Hierarchical Analysis. Fuzzy Sets Syst. 1985, 17, 233–247. [Google Scholar] [CrossRef]
- Saaty, R.W. The Analytic Hierarchy Process—What It Is and How It Is Used. Math. Model. 1987, 9, 161–176. [Google Scholar] [CrossRef]
- Saaty, T.L. Fundamentals of Decision Making and Priority Theory with the Analytic Hierarchy Process; RWS Publications: Pittsburgh, PA, USA, 1994; Volume 6. [Google Scholar]
- Alinezhad, A.; Amini, A.; Alinezhad, A. Sensitivity Analysis of Simple Additive Weighting Method (SAW): The Results of Change in the Weight of One Attribute on the Final Ranking of Alternatives. J. Ind. Eng. 2009, 4, 13–18. [Google Scholar]
- Banda, W. An Integrated Framework Comprising of AHP, Expert Questionnaire Survey and Sensitivity Analysis for Risk Assessment in Mining Projects. Int. J. Manag. Sci. Eng. Manag. 2019, 14, 180–192. [Google Scholar] [CrossRef]
- Spearman, C. The Proof and Measurement of Association between Two Things. Int. J. Epidemiol. 2010, 39, 1137–1150. [Google Scholar] [CrossRef]
- Selmi, M.; Kormi, T.; Ali, N.B.H. Comparing Multi-Criteria Decision Aid Methods through a Ranking Stability Index. In Proceedings of the 2013 5th International Conference on Modeling, Simulation and Applied Optimization (ICMSAO); IEEE: Hammamet, Tunisia, 2013; pp. 1–5. [Google Scholar]
- Kamil, Y.; Lund, S.; Islam, M.S. Information Security Objectives and the Output Legitimacy of ISO/IEC 27001: Stakeholders’ Perspective on Expectations in Private Organizations in Sweden. Inf. Syst. E-Bus. Manag. 2023, 21, 699–722. [Google Scholar] [CrossRef]
- Qudus, L. Cybersecurity Governance: Strengthening Policy Frameworks to Address Global Cybercrime and Data Privacy Challenges. Int. J. Sci. Res. Arch. 2025, 14, 1146–1163. [Google Scholar] [CrossRef]
- Chiara, P.G. Understanding the Regulatory Approach of the Cyber Resilience Act: Protection of Fundamental Rights in Disguise? Eur. J. Risk Regul. 2025, 16, 469–484. [Google Scholar] [CrossRef]
- Teichmann, F. The Cyber Resilience Act as a New Paradigm for Product Security: A Compliance Roadmap. Int. Cybersecur. Law Rev. 2026, 7, 1–17. [Google Scholar] [CrossRef]
- Arzt, S.; Gkoktsis, G.; Kreutzer, M.; Scheel, K.; Schreiber, L.; Simo Fhom, H. Cyber Resilience Act: Risk Management—Recommendations for the Implementation of Risk Management Under the CRA; National Research Center for Applied: Darmstadt, Germany, 2025. [Google Scholar]
- Chaudhary, S.; Gkioulos, V.; Katsikas, S. Developing Metrics to Assess the Effectiveness of Cybersecurity Awareness Program. J. Cybersecur. 2022, 8, tyac006. [Google Scholar] [CrossRef]
- Glöckler, J.; Sedlmeir, J.; Frank, M.; Fridgen, G. A Systematic Review of Identity and Access Management Requirements in Enterprises and Potential Contributions of Self-Sovereign Identity. Bus. Inf. Syst. Eng. 2024, 66, 421–440. [Google Scholar] [CrossRef]
- Tariq, U.; Ahmed, I.; Bashir, A.K.; Shaukat, K. A Critical Cybersecurity Analysis and Future Research Directions for the Internet of Things: A Comprehensive Review. Sensors 2023, 23, 4117. [Google Scholar] [CrossRef]
- Sobb, T.; Turnbull, B.; Moustafa, N. A Holistic Review of Cyber–Physical–Social Systems: New Directions and Opportunities. Sensors 2023, 23, 7391. [Google Scholar] [CrossRef]
- Alluqmani, K.; Karrar, A.E.; Alhaidari, M.; Alharbi, R.; Alharbi, S. Assessing the Efficacy of Security Awareness Training in Mitigating Phishing Attacks: A Review. Int. J. Adv. Trends Comput. Sci. Eng. 2025, 14, 177–184. [Google Scholar] [CrossRef]
- Mudau, P.; Mpekoa, N.; Gcaza, N. Identifying Gaps in the Evaluation of Security Education, Training and Awareness (SETA) Programs: A Systematic Literature Review. In Advancing Innovative Cybersecurity Solutions and Approaches to Protect Digital Ecosystems (IFIP-UNIVEN-CSIR ICC 2025); IFIP Advances in Information and Communication Technology; Mtsweni, J., Kanyane, M., Phahlamohlaka, J., Munyoka, W., Thomson, K.-L., Futcher, L., van Vuuren, J.J., Eds.; Springer: Cham, Switzerland, 2026; Volume 777, pp. 141–153. [Google Scholar]
- Fitzgerald, J.; Morisset, C. Can We Develop Holistic Approaches to Delivering Cyber-Physical Systems Security? Res. Dir. Cyber-Phys. Syst. 2024, 2, e2. [Google Scholar] [CrossRef]
- Choudhury, A.; Kaushik, K.; Kumar, V.; Singh, B.K. Cyber-Physical Systems Security, 1st ed.; Springer: Singapore, 2025; Volume 154. [Google Scholar]
- Shaffique, M.R. Cyber Resilience Act 2022: A Silver Bullet for Cybersecurity of IoT Devices or a Shot in the Dark? Comput. Law Secur. Rev. 2024, 54, 106009. [Google Scholar] [CrossRef]
- Teichmann, F. Cybersecurity of Critical Infrastructure in Europe: The NIS2 Directive in Focus. Int. Cybersecur. Law Rev. 2025, 6, 207–220. [Google Scholar] [CrossRef]
- Cao, M.; Ye, M.; Zino, L. Control of Networked Cyber–Physical–Human Systems. Nat. Rev. Electr. Eng. 2025, 3, 32–45. [Google Scholar] [CrossRef]
- Liu, C.; Tan, R.; Wu, Y.; Feng, Y.; Jin, Z.; Zhang, F.; Liu, Y.; Liu, Q. Dissecting Zero Trust: Research Landscape and Its Implementation in IoT. Cybersecurity 2024, 7, 20. [Google Scholar] [CrossRef]
- Pöhn, D.; Hommel, W. New Directions and Challenges within Identity and Access Management. IEEE Commun. Stand. Mag. 2023, 7, 84–90. [Google Scholar] [CrossRef]
- Larrucea, X.; Santamaria, I. Towards the Analysis of Software Supply Chain and EU Regulations. In Systems, Software and Services Process Improvement (EuroSPI 2025); Communications in Computer and Information Science; Yilmaz, M., Clarke, P., Riel, A., Messnarz, R., Zelmenis, M., Buce, I.A., Eds.; Springer: Cham, Switzerland, 2026; Volume 2658, pp. 170–183. [Google Scholar]
- Mahmood, S.; Chadhar, M.; Firmin, S. Addressing Cybersecurity Challenges in Times of Crisis: Extending the Sociotechnical Systems Perspective. Appl. Sci. 2024, 14, 11610. [Google Scholar] [CrossRef]
- Prabaswari, R.; Ali, Y.; Gultom, R.A.G.; Simbolon, L.; Gunawan, A.A.N. A Novel Socio-Technical Framework for Enhancing Cyber Crisis Management Capabilities. Int. J. Saf. Secur. Eng. 2024, 14, 1181–1193. [Google Scholar] [CrossRef]
- Huang, Y.; Lu, X. Editorial: Security, Governance, and Challenges of the New Generation of Cyber-Physical-Social Systems. Front. Phys. 2024, 12, 1464919. [Google Scholar] [CrossRef]
- Al Qurashi, M. Decentralized Identity Management for Industrial Internet of Things Utilizing Blockchain-Enhanced Multi-Factor Authentication. Int. J. Comput. Netw. Appl. 2024, 11, 519–526. [Google Scholar] [CrossRef]
- Jazairy, A.; Brho, M.; Manuj, I.; Goldsby, T.J. Cyber Risk Management Strategies and Integration: Toward Supply Chain Cyber Resilience and Robustness. Int. J. Phys. Distrib. Logist. Manag. 2024, 54, 1–29. [Google Scholar] [CrossRef]
- Bahmanova, A.; Lace, N. Modelling Cyber Resilience in SMEs as a Socio-Technical System: A Systemic Approach to Adaptive Digital Risk Management. Systems 2026, 14, 151. [Google Scholar] [CrossRef]
- Van Zomeren, M.; Deane, F.; Joiner, K.F.; Qiao, L.; Horne, R.; Suprun, E. Regulating Cyberworthiness: Governance Frameworks for Safety-Critical Cyber-Physical Systems. Systems 2025, 13, 862. [Google Scholar] [CrossRef]
- Huang, J.; Li, L.; Jiang, P.; Zhang, S. DEMATEL-Based ANP Model for Identifying Critical Indicators in Sustainable Emergency Material Reserve Systems. Sustainability 2024, 16, 5263. [Google Scholar] [CrossRef]
- Shi, Y.; Yu, S.; Mei, J. Strategic Decision-Making Enhancement through Graph-Optimized DEMATEL-AHP with Pruning. Group Decis. Negot. 2025, 34, 105–133. [Google Scholar] [CrossRef]
- Androutsopoulou, M.; Carayannis, E.G.; Askounis, D.; Zotas, N. Towards AI-Enabled Cyber-Physical Infrastructures—Challenges, Opportunities, and Implications for a Data-Driven EGovernment Theory, Policy, and Practice. J. Knowl. Econ. 2025, 1–38. [Google Scholar] [CrossRef]
- Mukherjee, K. A Note on Limitations of FAHP. In Supplier Selection; Studies in Systems, Decision and Control; Springer: New Delhi, India, 2017; Volume 88, pp. 101–111. [Google Scholar]
- Bhol, S.G. Applications of Multi Criteria Decision Making Methods in Cyber Security. In Cyber-Physical Systems Security; Studies in Big Data; Choudhury, A., Kaushik, K., Kumar, V., Singh, B.K., Eds.; Springer: Singapore, 2025; Volume 154, pp. 233–258. [Google Scholar]
- Madanchian, M.; Taherdoost, H. Applications of Multi-Criteria Decision Making in Information Systems for Strategic and Operational Decisions. Computers 2025, 14, 208. [Google Scholar] [CrossRef]
- Scholtysik, M.; Rasor, A.; Petzke, L.; Koldewey, C.; Dumitrescu, R. An Integrative Perspective on Digital Technologies and Circular Economy: A Systematic Literature Review. Proc. Des. Soc. 2025, 5, 541–550. [Google Scholar] [CrossRef]
- Teixeira, N. Circular Economy Perspectives: Challenges, Innovations, and Sustainable Futures. Discov. Sustain. 2025, 6, 738. [Google Scholar] [CrossRef]
- Seyi- Lande, O.B.; Layode, O.; Naiho, H.N.N.; Adeleke, G.S.; Udeh, E.O.; Labake, T.T.; Johnson, E. Circular Economy and Cybersecurity: Safeguarding Information and Resources in Sustainable Business Models. Financ. Account. Res. J. 2024, 6, 953–977. [Google Scholar] [CrossRef]
- Nemilentseva, M.; Tariq, A.; Tariq, W.; Aghajani, D.; Torkkeli, M. A Review of Digital Platform and Circular Economy. In Human Perspectives of Industry 4.0 Organizations: Reviewing Sustainable Performance; CRC Press: New York, NY, USA, 2024; pp. 38–67. [Google Scholar]






| Study | Application Context | Criteria Source | Scope of Analysis | Key Contributions | Limitations (Relative to Readiness Assessment) |
|---|---|---|---|---|---|
| Tariq et al. [12] | Cloud computing and wireless sensor networks | ISO/IEC 27002:2013 | Technical information-security controls | Provides prioritization of security controls for cloud and WSN environments | Focuses only on technical controls; based on ISO 27002:2013; no governance, operational, or regulatory integration |
| Styoutomo & Ruldeviyani [8] | Financial institution (WFH conditions) | HAIS-Q + ISO/IEC 27001:2013 | Human attitudes, knowledge, behavior, and awareness | Identifies weak areas in employee security awareness and provides improvement recommendations | Limited to people-centric factors; no technological, operational, or compliance components |
| Bhol et al. [13] | Enterprise cybersecurity metrics | Literature + security-metric hierarchies | Cybersecurity performance indicators | Proposes hierarchical evaluation of cybersecurity metrics | Not linked to ISO 27001 structure; not designed for organizational readiness; no Circular Economy or regulatory context |
| Mızrak [14] | International organizations | Literature-derived strategic criteria | High-level cybersecurity strategy development | Supports strategic prioritization of cybersecurity criteria for international organizations | Strategic focus only; lacks ISMS reference models; no operational or domain-specific (e.g., Circular Economy) application |
| Simjanović et al. [15] | Active cyber-attack landscape | Attack-type characteristics (frequency, impact, complexity) | Threat and attack prioritization | Ranks social engineering and masquerade attacks as most critical | Focuses on attack types rather than readiness; no ISMS linkage; no organizational governance or regulatory dimension |
| Linguistic Terms | TFNs |
|---|---|
| Equally important | (1,1,1) |
| Moderately important | (2,3,4) |
| Important | (4,5,6) |
| Very important | (6,7,8) |
| Extremely important | (8,9,10) |
| Intermediate | (1,2,3), (3,4,5), (5,6,7), (7,8,9) |
| Criterion | Fuzzy Geometric Mean | Fuzzy Weight | Crisp Weight | Normalized Weight | Rank |
|---|---|---|---|---|---|
| C1 | (2.0830, 2.5221, 2.9487) | (0.2078, 0.2941, 0.4163) | 0.3061 | 0.2941 | 1 |
| C2 | (1.2514, 1.5152, 1.7715) | (0.1248, 0.1767, 0.2501) | 0.1839 | 0.1767 | 3 |
| C3 | (0.6883, 0.8333, 0.9743) | (0.0687, 0.0972, 0.1376) | 0.1011 | 0.0972 | 5 |
| C4 | (0.4143, 0.5016, 0.5865) | (0.0413, 0.0585, 0.0828) | 0.0609 | 0.0585 | 6 |
| C5 | (0.2762, 0.3342, 0.3908) | (0.0276, 0.0390, 0.0552) | 0.0406 | 0.0390 | 7 |
| C6 | (0.8327, 1.0083, 1.1788) | (0.0831, 0.1176, 0.1664) | 0.1224 | 0.1176 | 4 |
| C7 | (1.5367, 1.8606, 2.1754) | (0.1533, 0.2170, 0.3071) | 0.2258 | 0.2170 | 2 |
| Sub-Criterion | Fuzzy Geometric Mean | Fuzzy Weight | Crisp Weight | Normalized Weight | Rank |
|---|---|---|---|---|---|
| C1.1 | (2.1500, 2.8000, 3.4000) | (0.2200, 0.2800, 0.3500) | 0.2833 | 0.2950 | 2 |
| C1.2 | (1.8500, 2.4500, 3.0500) | (0.1900, 0.2500, 0.3100) | 0.2517 | 0.2620 | 3 |
| C1.3 | (2.3500, 3.0500, 3.7000) | (0.2400, 0.3000, 0.3700) | 0.3033 | 0.3160 | 1 |
| C1.4 | (1.6500, 2.1500, 2.7500) | (0.1700, 0.2100, 0.2700) | 0.2130 | 0.2220 | 4 |
| C2.1 | (1.2000, 1.5500, 1.9000) | (0.1200, 0.1600, 0.1900) | 0.1550 | 0.1580 | 2 |
| C2.2 | (1.3500, 1.7500, 2.1500) | (0.1300, 0.1700, 0.2100) | 0.1700 | 0.1730 | 1 |
| C2.3 | (0.9500, 1.2500, 1.5500) | (0.0900, 0.1200, 0.1500) | 0.1187 | 0.1210 | 3 |
| C3.1 | (0.6500, 0.8500, 1.0500) | (0.0700, 0.0900, 0.1100) | 0.0933 | 0.0960 | 3 |
| C3.2 | (0.8000, 1.0500, 1.3000) | (0.0800, 0.1000, 0.1300) | 0.1030 | 0.1060 | 2 |
| C3.3 | (0.5500, 0.7000, 0.8500) | (0.0500, 0.0700, 0.0900) | 0.0707 | 0.0720 | 7 |
| C3.4 | (0.9000, 1.1500, 1.4000) | (0.0900, 0.1100, 0.1400) | 0.1133 | 0.1160 | 1 |
| C3.5 | (0.5000, 0.6500, 0.8000) | (0.0500, 0.0600, 0.0800) | 0.0633 | 0.0650 | 8 |
| C3.6 | (0.6000, 0.7500, 0.9000) | (0.0600, 0.0800, 0.0900) | 0.0733 | 0.0750 | 6 |
| C3.7 | (0.7000, 0.9000, 1.1000) | (0.0600, 0.0900, 0.1100) | 0.0867 | 0.0890 | 4 |
| C3.8 | (0.6500, 0.8500, 1.0500) | (0.0600, 0.0800, 0.1000) | 0.0867 | 0.0890 | 5 |
| C4.1 | (0.4000, 0.5000, 0.6000) | (0.0400, 0.0500, 0.0600) | 0.0500 | 0.0510 | 2 |
| C4.2 | (0.4500, 0.5500, 0.6500) | (0.0400, 0.0500, 0.0600) | 0.0533 | 0.0540 | 1 |
| C4.3 | (0.3500, 0.4500, 0.5500) | (0.0300, 0.0400, 0.0500) | 0.0433 | 0.0440 | 4 |
| C4.4 | (0.3000, 0.4000, 0.5000) | (0.0300, 0.0400, 0.0500) | 0.0400 | 0.0410 | 5 |
| C4.5 | (0.4000, 0.5000, 0.6000) | (0.0400, 0.0500, 0.0600) | 0.0500 | 0.0510 | 3 |
| C5.1 | (0.2762, 0.3342, 0.3908) | (0.0276, 0.0390, 0.0552) | 0.0406 | 0.0410 | 2 |
| C5.2 | (0.3000, 0.3600, 0.4200) | (0.0300, 0.0400, 0.0500) | 0.0400 | 0.0410 | 1 |
| C5.3 | (0.2500, 0.3000, 0.3500) | (0.0250, 0.0300, 0.0400) | 0.0317 | 0.0320 | 5 |
| C5.4 | (0.2700, 0.3300, 0.3900) | (0.0270, 0.0330, 0.0390) | 0.0337 | 0.0340 | 3 |
| C5.5 | (0.2600, 0.3200, 0.3800) | (0.0260, 0.0320, 0.0380) | 0.0320 | 0.0330 | 4 |
| C6.1 | (0.8327, 1.0083, 1.1788) | (0.0831, 0.1176, 0.1664) | 0.1224 | 0.1240 | 2 |
| C6.2 | (0.9000, 1.1000, 1.3000) | (0.0900, 0.1200, 0.1500) | 0.1200 | 0.1220 | 1 |
| C6.3 | (0.8500, 1.0200, 1.1900) | (0.0850, 0.1020, 0.1190) | 0.1020 | 0.1040 | 3 |
| C6.4 | (0.8000, 0.9500, 1.1000) | (0.0800, 0.0950, 0.1100) | 0.0950 | 0.0970 | 4 |
| C6.5 | (0.7600, 0.9000, 1.0400) | (0.0760, 0.0900, 0.1040) | 0.0900 | 0.0920 | 5 |
| C6.6 | (0.7000, 0.8400, 0.9800) | (0.0700, 0.0840, 0.0980) | 0.0840 | 0.0860 | 6 |
| C6.7 | (0.6500, 0.7800, 0.9100) | (0.0650, 0.0780, 0.0910) | 0.0780 | 0.0800 | 7 |
| C6.8 | (0.6000, 0.7200, 0.8400) | (0.0600, 0.0720, 0.0840) | 0.0720 | 0.0740 | 8 |
| C6.9 | (0.5500, 0.6600, 0.7700) | (0.0550, 0.0660, 0.0770) | 0.0660 | 0.0680 | 9 |
| C6.10 | (0.5000, 0.6000, 0.7000) | (0.0500, 0.0600, 0.0700) | 0.0600 | 0.0620 | 10 |
| C6.11 | (0.4800, 0.5700, 0.6600) | (0.0480, 0.0570, 0.0660) | 0.0550 | 0.0560 | 11 |
| C7.1 | (1.5367, 1.8606, 2.1754) | (0.1533, 0.2170, 0.3071) | 0.2258 | 0.2169 | 1 |
| C7.2 | (1.2000, 1.5000, 1.8000) | (0.1200, 0.1500, 0.1800) | 0.1500 | 0.1445 | 3 |
| C7.3 | (1.0000, 1.2500, 1.5000) | (0.1000, 0.1250, 0.1500) | 0.1250 | 0.1204 | 2 |
| Criterion | DP (%) | Spearman ρ | RSI |
|---|---|---|---|
| C1 | 105.70 | 1.00 | 1.00 |
| C2 | 23.60 | 1.00 | 1.00 |
| C3 | 32.00 | 1.00 | 1.00 |
| C4 | 59.00 | 1.00 | 1.00 |
| C5 | 72.70 | 1.00 | 1.00 |
| C6 | 17.70 | 1.00 | 1.00 |
| C7 | 51.90 | 1.00 | 1.00 |
| Overall | |||
| MDP (%) | 105.7 | — | — |
| CST (%) | — | — | 21 |
| Criterion | DP (%) | Spearman ρ | RSI |
|---|---|---|---|
| C1.1 | 376.50 | 1.00 | 1.00 |
| C1.2 | 323.10 | 1.00 | 1.00 |
| C1.3 | 410.40 | 1.00 | 1.00 |
| C1.4 | 258.70 | 1.00 | 1.00 |
| C2.1 | 53.20 | 1.00 | 1.00 |
| C2.2 | 68.10 | 1.00 | 1.00 |
| C2.3 | 17.40 | 1.00 | 1.00 |
| C3.1 | 48.90 | 1.00 | 1.00 |
| C3.2 | 43.50 | 1.00 | 1.00 |
| C3.3 | 61.40 | 1.00 | 1.00 |
| C3.4 | 38.00 | 1.00 | 1.00 |
| C3.5 | 65.30 | 1.00 | 1.00 |
| C3.6 | 59.80 | 1.00 | 1.00 |
| C3.7 | 52.40 | 1.00 | 1.00 |
| C3.8 | 52.40 | 1.00 | 1.00 |
| C4.1 | 83.60 | 1.00 | 1.00 |
| C4.2 | 82.80 | 1.00 | 1.00 |
| C4.3 | 86.00 | 1.00 | 1.00 |
| C4.4 | 86.70 | 1.00 | 1.00 |
| C4.5 | 83.60 | 1.00 | 1.00 |
| C5.1 | 91.00 | 1.00 | 1.00 |
| C5.2 | 91.00 | 1.00 | 1.00 |
| C5.3 | 93.00 | 1.00 | 1.00 |
| C5.4 | 92.60 | 1.00 | 1.00 |
| C5.5 | 93.00 | 1.00 | 1.00 |
| C6.1 | 20.10 | 1.00 | 1.00 |
| C6.2 | 21.20 | 1.00 | 1.00 |
| C6.3 | 32.90 | 1.00 | 1.00 |
| C6.4 | 37.20 | 1.00 | 1.00 |
| C6.5 | 40.70 | 1.00 | 1.00 |
| C6.6 | 44.60 | 1.00 | 1.00 |
| C6.7 | 48.10 | 1.00 | 1.00 |
| C6.8 | 52.00 | 1.00 | 1.00 |
| C6.9 | 55.90 | 1.00 | 1.00 |
| C6.10 | 59.80 | 1.00 | 1.00 |
| C6.11 | 63.70 | 1.00 | 1.00 |
| C7.1 | 158.50 | 1.00 | 1.00 |
| C7.2 | 72.30 | 1.00 | 1.00 |
| C7.3 | 43.50 | 1.00 | 1.00 |
| Overall | |||
| MDP (%) | 410.40 | — | — |
| CST (%) | — | — | >10 |
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content. |
© 2026 by the authors. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license.
Share and Cite
Alavi-Borazjani, S.A.; Shafique, M.N. A Fuzzy AHP-Based Framework for Assessing Cybersecurity Readiness in Smart Circular Economy Systems Aligned with ISO/IEC 27001. Information 2026, 17, 429. https://doi.org/10.3390/info17050429
Alavi-Borazjani SA, Shafique MN. A Fuzzy AHP-Based Framework for Assessing Cybersecurity Readiness in Smart Circular Economy Systems Aligned with ISO/IEC 27001. Information. 2026; 17(5):429. https://doi.org/10.3390/info17050429
Chicago/Turabian StyleAlavi-Borazjani, Seyedeh Azadeh, and Muhammad Noman Shafique. 2026. "A Fuzzy AHP-Based Framework for Assessing Cybersecurity Readiness in Smart Circular Economy Systems Aligned with ISO/IEC 27001" Information 17, no. 5: 429. https://doi.org/10.3390/info17050429
APA StyleAlavi-Borazjani, S. A., & Shafique, M. N. (2026). A Fuzzy AHP-Based Framework for Assessing Cybersecurity Readiness in Smart Circular Economy Systems Aligned with ISO/IEC 27001. Information, 17(5), 429. https://doi.org/10.3390/info17050429
