Abstract
Modern enterprise environments are characterized by increasing technological complexity, including hybrid infrastructures, cloud comput-
ing, remote work models, and extensive supply-chain dependencies. At the same time, the cyber threat landscape evolves dynamically,
making it insufficient to assess security solely through formal compliance with security frameworks. Organizations increasingly require
verifiable methods to determine whether implemented security controls are effective in real operational conditions. This paper introduces
the Unified Security Validation Model (USVM), a structured approach for experimental validation of security controls in enterprise en-
vironments. The model shifts the focus from declarative compliance toward empirical verification of resilience through controlled attack
emulation, telemetry analysis, and measurement of detection and response capabilities. A key element of the model is the inclusion of de-
vice trust level, including hardware-rooted trust mechanisms, as an experimental variable influencing the effectiveness of security controls
and detection mechanisms within realistic attack scenarios.
References
European Union Agency for Cybersecurity (ENISA), ENISA Threat Landscape 2024. Dostępne online: https://securitydelta.nl/media/com_hsd/report/690/document/ENISA-Threat-Landscape-2024.pdf
Microsoft, Microsoft Digital Defense Report 2025. Dostępne online: https:// www.microsoft.com/en-us/cor-porate-responsibility/cybersecurity/ microsoft-digital-defense-report-2025/
Verizon, 2024 Data Breach Investigations Report (DBIR). Available on-line: https://www.verizon.com/business/resources/reports/2024-dbir-data-breach-investigations-re-port.pdf?msockid=19bd3de880e6605b1e6a2af581ae6123
NIST, Special Publication 800-137: Information Security Continuous Monitoring (ISCM) for Federal Information Systems and Organizations. Available online: https://csrc.nist.gov/pubs/sp/800/ 137/final [dostęp: 30.04.2025].
European Union, Directive (EU) 2022/2555 on measures for a high common level of cybersecurity across the Union (NIS2 Directive). Dostępne online: https://eur-lex.europa.eu/eli/dir/2022/2555/ oj
Y. Zhang et al., A Survey on Cyber Security Evaluation Methods. IEEE Access, 2020. Available online: https://ieeexplore.ieee.org/document/9140463
J. Peˇcˇarina et al., Security Control Effectiveness Measurement: A Systematic Literature Review. Computers & Security, 2021. Available online: https://www.sciencedirect.com/science/article/pii/ S0167404821001530
MITRE Corporation, MITRE ATT&CK® Enterprise Matrix. Dostępne online: https://attack. mi-tre.org/matrices/enterprise/ [dostęp: 30.04.2025].
MITRE Corporation, MITRE Caldera Documentation. Dostępne online: https://caldera. readthe-docs.io/en/latest/ [dostęp: 30.04.2025].
MITRE Corporation, ATT&CK® Evaluations – Enterprise 2025. Dostępne online: https://evals. mi-tre.org/enterprise/er7 [dostęp: 30.04.2025].
NIST, Special Publication 800-207: Zero Trust Architecture. Dostępne online: https://nvlpubs. nist.gov/nistpubs/specialpublications/NIST.SP.800-207.pdf [dostęp: 30.04.2025].
Cybersecurity and Infrastructure Security Agency (CISA), Best Practices for Event Logging and Threat Detection. Dostępne online: https://www.cisa.gov/resources-tools/resources/ best-practices-event-logging-and-threat-detection [dostęp: 30.04.2025].
Trusted Computing Group, Trusted Platform Module Library, Part 0: Introduction. Dostępne online: https://trustedcomputinggroup.org/wp-content/uploads/Trusted-Platform-Module-2.0-Library-Part-0-Version-184_pub.pdf [dostęp: 30.04.2025].
Microsoft, Windows Secure Boot Key Creation and Management Guidance. Dostępne online: https://learn.microsoft.com/en-us/windows-hardware/manufacture/desktop/ windows-secure-boot-key-crea-tion-and-management-guidance [dostęp: 30.04.2025].
S&P Global Market Intelligence, The Rise of Extended Detection and Response. Dostępne online: https://www.spglobal.com/content/dam/spglobal/mi/en/documents/general/ the-rise-of-extended-detection-and-response.pdf [dostęp: 30.04.2025].
NIST, Special Publication 800-55 Revision 1: Performance Measurement Guide for Information Security. Dostępne online: https://nvlpubs.nist.gov/nistpubs/legacy/sp/ nistspecialpublication800-55r1.pdf [dostęp: 30.04.2025].
NIST, Special Publication 800-61 Revision 3: Incident Response Recommendations and Considerations for Cybersecurity Risk Management. Dostępne online: https://csrc.nist.gov/pubs/sp/800/61/ r3/final [dostęp: 30.04.2025].
NIST, Special Publication 800-193: Platform Firmware Resiliency Guidelines. Dostępne online: https://csrc.nist.gov/pubs/sp/800/193/final [dostęp: 30.04.2025].
NIST, Special Publication 800-115: Technical Guide to Information Security Testing and Assessment. Do-stępne online: https://csrc.nist.gov/pubs/sp/800/115/final [dostęp: 30.04.2025].
Australian Cyber Security Centre, Best Practices for Event Logging and Threat Detection. Dostępne online: https://www.cyber.gov.au/sites/default/files/2024-08/ best-practices-for-event-logging-and-threat-detection.pdf [dostęp: 30.04.2025].
NIST, Special Publication 800-53A: Assessing Security and Privacy Controls in Information Systems and Organizations. Available online: https://csrc.nist.gov/pubs/sp/800/53/a/rev5/final
