Information security risks management framework - A step towards mitigating security risks in university network

被引:39
|
作者
Joshi, Chanchala [1 ]
Singh, Umesh Kumar [2 ]
机构
[1] Vikram Univ Ujjain, Inst Comp Sci, Ujjain, Madhya Pradesh, India
[2] Vikram Univ Ujjain, Sch Engn & Technol, Ujjain, Madhya Pradesh, India
关键词
Security risk; Security threats; University campus network; Vulnerability;
D O I
10.1016/j.jisa.2017.06.006
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Information is one of the most prominent assets for Universities and must be protected from security breach. This paper analyzed the security threats specifically evolve in University's network, and with consideration of these issues, proposed information security framework for University network environment. The proposed framework reduces the risk of security breach by supporting three phase activities; the first phase assesses the threats and vulnerabilities in order to identify the weak point in educational environment, the second phase focuses on the highest risk and create actionable remediation plan, the third phase of risk assessment model recognizes the vulnerability management compliance requirement in order to improve University's security position. The proposed framework is applied on Vikram University Ujjain India's, computing environment and the evaluation result showed the proposed framework enhances the security level of University campus network. This model can be used by risk analyst and security manager of University to perform reliable and repeatable risk analysis in realistic and affordable manner. (C) 2017 Elsevier Ltd. All rights reserved.
引用
收藏
页码:128 / 137
页数:10
相关论文
共 50 条
  • [41] Risks in email security
    Levi, A
    Koç, ÇK
    [J]. COMMUNICATIONS OF THE ACM, 2001, 44 (08) : 112 - 112
  • [42] Managing Security Risks
    Abrahamson, Donald W.
    Sepeda, Adrian L.
    [J]. CHEMICAL ENGINEERING PROGRESS, 2009, 105 (07) : 41 - 47
  • [43] On the Security Risks of the Blockchain
    Zamani, Efpraxia
    He, Ying
    Phillips, Matthew
    [J]. JOURNAL OF COMPUTER INFORMATION SYSTEMS, 2020, 60 (06) : 495 - 506
  • [44] The risks of ecological security
    Benjaminsen, Tor A. A.
    [J]. NEW PERSPECTIVES, 2023, 31 (01): : 25 - 30
  • [45] Towards a Framework for Strategic Security Context in Information Security Governance
    Maynard, Sean B.
    Tan, Terrence
    Ahmad, Atif
    Ruighaver, Tobias
    [J]. PACIFIC ASIA JOURNAL OF THE ASSOCIATION FOR INFORMATION SYSTEMS, 2018, 10 (04): : 65 - 88
  • [46] Mitigating Hardware Cyber-Security Risks in Error Correcting Decoders
    Hemati, Saied
    [J]. 2016 9TH INTERNATIONAL SYMPOSIUM ON TURBO CODES AND ITERATIVE INFORMATION PROCESSING (ISTC), 2016, : 181 - 185
  • [47] Staying Secure and Unprepared: Understanding and Mitigating the Security Risks of Apple ZeroConf
    Bai, Xiaolong
    Xing, Luyi
    Zhang, Nan
    Wang, XiaoFeng
    Liao, Xiaojing
    Li, Tongxin
    Hu, Shi-Min
    [J]. 2016 IEEE SYMPOSIUM ON SECURITY AND PRIVACY (SP), 2016, : 655 - 674
  • [48] Mitigating Security Risks in Linux with KLAUS - A Method for Evaluating Patch Correctness -
    Wu, Yuhang
    Lin, Zhenpeng
    Chen, Yueqi
    Le, Dang K.
    Mu, Dongliang
    Xing, Xinyu
    [J]. PROCEEDINGS OF THE 32ND USENIX SECURITY SYMPOSIUM, 2023, : 4247 - 4264
  • [49] Cloud Strife: Mitigating the Security Risks of Domain-Validated Certificates
    Borgolte, Kevin
    Fiebig, Tobias
    Hao, Shuang
    Kruegel, Christopher
    Vigna, Giovanni
    [J]. PROCEEDINGS OF THE 2018 APPLIED NETWORKING RESEARCH WORKSHOP (ANRW '18), 2018, : 4 - 4
  • [50] Cloud Strife: Mitigating the Security Risks of Domain-Validated Certificates
    Borgolte, Kevin
    Fiebig, Tobias
    Hao, Shuang
    Kruegel, Christopher
    Vigna, Giovanni
    [J]. 25TH ANNUAL NETWORK AND DISTRIBUTED SYSTEM SECURITY SYMPOSIUM (NDSS 2018), 2018,