Cybersecurity maturity assessment framework for higher education institutions in Saudi Arabia

被引:14
|
作者
Almomani, Iman [1 ,2 ]
Ahmed, Mohanned [1 ]
Maglaras, Leandros [3 ]
机构
[1] Prince Sultan Univ, Secur Engn Lab, Riyadh, Saudi Arabia
[2] Univ Jordan, Comp Sci Dept, Amman, Jordan
[3] De Montfort Univ Leicester, Sch Comp Sci & Informat, Leicester, Leics, England
关键词
Saudi Arabia; Cybersecurity; Maturity assessment; Audit tool; ISO27001; CITC; NCA; ECC; CRF; GDPR; COVID-19; Higher education;
D O I
10.7717/peerj-cs.703
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
The Saudi Arabia government has proposed different frameworks such as the CITC's Cybersecurity Regulatory Framework (CRF) and the NCA's Essential Cybersecurity Controls (ECC) to ensure data and infrastructure security in all IT-based systems. However, these frameworks lack a practical, published mechanism that continuously assesses the organizations' security level, especially in HEI (Higher Education Institutions) systems. This paper proposes a Cybersecurity Maturity Assessment Framework (SCMAF) for HEIs in Saudi Arabia. SCMAF is a comprehensive, customized security maturity assessment framework for Saudi organizations aligned with local and international security standards. The framework can be used as a self-assessment method to establish the security level and highlight the weaknesses and mitigation plans that need to be implemented. SCMAF is a mapping and codification model for all regulations that the Saudi organizations must comply with. The framework uses different levels of maturity against which the security performance of each organization can be measured. SCMAF is implemented as a lightweight assessment tool that could be provided online through a web-based service or offline by downloading the tool to ensure the organizations' data privacy. Organizations that apply this framework can assess the security level of their systems, conduct a gap analysis and create a mitigation plan. The assessment results are communicated to the organization using visual score charts per security requirement per level attached with an evaluation report.
引用
收藏
页数:26
相关论文
共 50 条
  • [1] A Holistic Cybersecurity Maturity Assessment Framework for Higher Education Institutions in the United Kingdom
    Aliyu, Aliyu
    Maglaras, Leandros
    He, Ying
    Yevseyeva, Iryna
    Boiten, Eerke
    Cook, Allan
    Janicke, Helge
    [J]. APPLIED SCIENCES-BASEL, 2020, 10 (10):
  • [2] Sustainability Assessment of Higher Education Institutions in Saudi Arabia
    Alshuwaikhat, Habib M.
    Adenle, Yusuf A.
    Saghir, Bilal
    [J]. SUSTAINABILITY, 2016, 8 (08):
  • [3] A Conceptual Framework for Facility Management in Higher Education Institutions in Saudi Arabia
    Alsayyari, Abdulaziz
    Alblawi, Adel
    Nawab, Mohammad
    Alosaimi, Ahmed
    [J]. TEM JOURNAL-TECHNOLOGY EDUCATION MANAGEMENT INFORMATICS, 2019, 8 (01): : 157 - 164
  • [4] Digital Maturity Framework for Higher Education Institutions
    Durek, Valentina
    Redep, Nina Begicevic
    Divjak, Blazenka
    [J]. CENTRAL EUROPEAN CONFERENCE ON INFORMATION AND INTELLIGENT SYSTEMS: PROCEEDINGS ARCHIVE 2017, 2017, : 99 - 106
  • [5] A Hybrid Cloud Computing Model for Higher Education Institutions in Saudi Arabia
    Khan, Muhammad Asif
    [J]. CLOUD COMPUTING (CLOUDCOMP 2015), 2016, 167 : 255 - 259
  • [6] Current state of female leadership in higher education institutions in Saudi Arabia
    Dahlan, Dina Abdullah
    [J]. COGENT BUSINESS & MANAGEMENT, 2023, 10 (03):
  • [7] Cybersecurity Policy Framework in Saudi Arabia: Literature Review
    Alhalafi, Nawaf
    Veeraraghavan, Prakash
    [J]. FRONTIERS IN COMPUTER SCIENCE, 2021, 3
  • [8] Developing a Framework for Cost-Benefit Analysis of Cloud Computing Adoption by Higher Education Institutions in Saudi Arabia
    Aldahwan, Nouf S.
    Saleh, Mohamed S.
    [J]. 2018 INTERNATIONAL CONFERENCE ON SMART COMPUTING AND ELECTRONIC ENTERPRISE (ICSCEE), 2018,
  • [9] Cybersecurity Risk Assessment: Modeling Factors Associated with Higher Education Institutions
    Ganesen, Rachel
    Abu Bakar, Asmidar
    Ramli, Ramona
    Rahim, Fiza Abdul
    Zawawi, Nabil Ahmad
    [J]. INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2022, 13 (08) : 355 - 362
  • [10] Impediments of Activating E-Learning in Higher Education Institutions in Saudi Arabia
    Gawad, Ashraf M. H. Abdel
    Al-Masaud, Khalefah A. K.
    [J]. INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2014, 5 (04) : 12 - 18