Information security risks management framework - A step towards mitigating security risks in university network

被引:39
|
作者
Joshi, Chanchala [1 ]
Singh, Umesh Kumar [2 ]
机构
[1] Vikram Univ Ujjain, Inst Comp Sci, Ujjain, Madhya Pradesh, India
[2] Vikram Univ Ujjain, Sch Engn & Technol, Ujjain, Madhya Pradesh, India
关键词
Security risk; Security threats; University campus network; Vulnerability;
D O I
10.1016/j.jisa.2017.06.006
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Information is one of the most prominent assets for Universities and must be protected from security breach. This paper analyzed the security threats specifically evolve in University's network, and with consideration of these issues, proposed information security framework for University network environment. The proposed framework reduces the risk of security breach by supporting three phase activities; the first phase assesses the threats and vulnerabilities in order to identify the weak point in educational environment, the second phase focuses on the highest risk and create actionable remediation plan, the third phase of risk assessment model recognizes the vulnerability management compliance requirement in order to improve University's security position. The proposed framework is applied on Vikram University Ujjain India's, computing environment and the evaluation result showed the proposed framework enhances the security level of University campus network. This model can be used by risk analyst and security manager of University to perform reliable and repeatable risk analysis in realistic and affordable manner. (C) 2017 Elsevier Ltd. All rights reserved.
引用
收藏
页码:128 / 137
页数:10
相关论文
共 50 条
  • [31] Reputation Risks through Information Security Incidents
    Eduardovich, Dorokhov Vitaliy
    Vladimirovich, Yankevskiy Alexey
    [J]. PROCEEDINGS OF THE 2016 IEEE NORTH WEST RUSSIA SECTION YOUNG RESEARCHERS IN ELECTRICAL AND ELECTRONIC ENGINEERING CONFERENCE (ELCONRUSNW), 2016, : 194 - 198
  • [32] Modeling of Information Security Risks in the Digital Economy
    Minzov, A. S.
    Nevsky, A. Yu
    Osipov, P. A.
    Bolshakov, B. Ye
    [J]. INTERNATIONAL CONFERENCE ON NUMERICAL ANALYSIS AND APPLIED MATHEMATICS (ICNAAM-2018), 2019, 2116
  • [33] IoT Network Security: Threats, Risks, and a Data-Driven Defense Framework
    Wheelus, Charles
    Zhu, Xingquan
    [J]. IOT, 2020, 1 (02): : 259 - 285
  • [34] A FRAMEWORK FOR INFORMATION SECURITY MANAGEMENT
    Angheluta, Dragos-Ionut
    Lupu, Luminita-Mihaela
    [J]. FROM MANAGEMENT OF CRISIS TO MANAGEMENT IN A TIME OF CRISIS, 2016, : 2 - 16
  • [35] Risks Management relating to Information Systems Security. Vulnerabilities and Threats in Information Systems
    Baicu, Floarea
    Baicu, Andrei Mihai
    [J]. QUALITY-ACCESS TO SUCCESS, 2012, 13 (128): : 112 - 116
  • [36] A framework for the management of information security
    Leiwo, J
    Zheng, YL
    [J]. INFORMATION SECURITY, 1998, 1396 : 232 - 245
  • [37] COMMUNICATIONS MANAGEMENT SYSTEM TO ASSESS SECURITY RISKS
    Toro Flores, Yury A.
    Rivas Almonte, Fancy U.
    Turpo Gebera, Osbaldo
    Cuadros Paz, Luis
    Fernandez Gambarini, Walter
    Valderrama Chauca, Enrique
    [J]. REVISTA UNIVERSIDAD Y SOCIEDAD, 2019, 11 (01): : 86 - 92
  • [38] Including technical and security risks in the management of information systems: A programmatic risk management model
    Dillon, Robin L.
    Paté-Cornell, M. Elisabeth
    [J]. Systems Engineering, 2005, 8 (01) : 15 - 28
  • [39] Energy security through a framework of country risks and vulnerabilities
    Krishnan, R.
    [J]. ENERGY SOURCES PART B-ECONOMICS PLANNING AND POLICY, 2016, 11 (01) : 32 - 37
  • [40] Governance and Management of Organizations with Cloud Supported Services Recommendations for Risks of Information Security
    Silva, Elcelina
    Soares, Bruno Horta
    [J]. 2018 13TH IBERIAN CONFERENCE ON INFORMATION SYSTEMS AND TECHNOLOGIES (CISTI), 2018,