New Approach for Information Security Evaluation and Management of IT Systems in Educational Institutions

被引:0
|
作者
Wang M. [1 ]
Wang Y. [2 ]
Wang T. [2 ]
Hou L. [2 ]
Li M. [2 ]
机构
[1] Information Center of Shanghai Municipal Education Commission, Shanghai
[2] University of Michigan — Shanghai Jiao Tong University Joint Institute, Shanghai Jiao Tong University, Shanghai
来源
关键词
A; analytic hierarchy process (AHP); educational institution; information security management; information technology (IT) systems; TP; 302.7;
D O I
10.1007/s12204-020-2231-y
中图分类号
学科分类号
摘要
Security evaluation and management has become increasingly important for Web-based information technology (IT) systems, especially for educational institutions. For the security evaluation and management of IT systems in educational institutions, determining the security level for a single IT system has been well developed. However, it is still difficult to evaluate the information security level of the entire educational institution considering multiple IT systems, because there might be too many different IT systems in one institution, educational institutions can be very different, and there is no standard model or method to provide a justifiable information security evaluation among different educational institutions considering their differences. In light of these difficulties, a security evaluation model of educational institutions’ IT systems (SEMEIS) is proposed in this work to facilitate the information security management for the educational institutions. Firstly, a simplified educational industry information system security level protection rating (EIISSLPR) with a new weight redistribution strategy for a single IT system is proposed by choosing important evaluation questions from EIISSLPR and redistributing the weights of these questions. Then for the entire educational institution, analytic hierarchy process (AHP) is used to redistribute the weights of multiple IT systems at different security levels. Considering the risk of possible network security vulnerabilities, a risk index is formulated by weighting different factors, normalized by a utility function, and calculated with the real data collected from the institutions under the evaluation. Finally, the information security performance of educational institutions is obtained as the final score from SEMEIS. The results show that SEMEIS can evaluate the security level of the education institutions practically and provide an efficient and effective management tool for the information security management. © 2020, Shanghai Jiao Tong University and Springer-Verlag GmbH Germany, part of Springer Nature.
引用
收藏
页码:689 / 699
页数:10
相关论文
共 50 条
  • [1] Information security issues in educational institutions
    Imbaquingo Esparza, Daisy Elizabeth
    Javier Diaz, Francisco
    Saltos Echeverria, Tatyana Katherine
    Arciniega Hidrobo, Silvia Rosario
    Leon Villavicencio, Diego Andres
    Robayo Ordonez, Adrian
    [J]. 2020 15TH IBERIAN CONFERENCE ON INFORMATION SYSTEMS AND TECHNOLOGIES (CISTI'2020), 2020,
  • [2] SYSTEM OF MEASURES RELATED TO ENSURING INFORMATION SECURITY IN THE MANAGEMENT OF EDUCATIONAL INSTITUTIONS
    Davud, Ulviyya Hajiyeva
    Mammad, Mirvari Gasimova
    Gizi, Gunay Aliyeva Dilgam
    Khaleddin, Yegana Iskenderova
    [J]. REVISTA UNIVERSIDAD Y SOCIEDAD, 2024, 16 (03): : 523 - 528
  • [3] A New Evaluation Model for Information Security Risk Management of SCADA Systems
    Lin, Kuo-Sui
    [J]. 2019 IEEE INTERNATIONAL CONFERENCE ON INDUSTRIAL CYBER PHYSICAL SYSTEMS (ICPS 2019), 2019, : 757 - 762
  • [4] New Approach in Information System Security Evaluation
    Breier, Jakub
    Hudec, Ladislav
    [J]. 2012 IEEE FIRST AESS EUROPEAN CONFERENCE ON SATELLITE TELECOMMUNICATIONS (ESTEL), 2012,
  • [5] Approach to the Evaluation of the Efficiency of Information Security in Control Systems
    Zegzhda, P. D.
    Anisimov, V. G.
    Sem'yanov, P., V
    Suprun, A. F.
    Anisimov, E. G.
    Saurenko, T. N.
    Los, V. P.
    [J]. AUTOMATIC CONTROL AND COMPUTER SCIENCES, 2020, 54 (08) : 864 - 870
  • [6] Approach to the Evaluation of the Efficiency of Information Security in Control Systems
    P. D. Zegzhda
    V. G. Anisimov
    P. V. Sem’yanov
    A. F. Suprun
    E. G. Anisimov
    T. N. Saurenko
    V. P. Los’
    [J]. Automatic Control and Computer Sciences, 2020, 54 : 864 - 870
  • [7] A security evaluation approach for information systems in telecommunication enterprises
    Yan, Qiang
    [J]. ENTERPRISE INFORMATION SYSTEMS, 2008, 2 (03) : 309 - 324
  • [8] A new approach to security evaluation of operating systems
    Zegzhda, Peter D.
    Zegzhda, Dmitry P.
    Kalinin, Maxim O.
    [J]. COMPUTER NETWORK SECURITY, PROCEEDINGS, 2007, 1 : 254 - +
  • [9] Information Security Problems in Educational Institutions in Conditions of Network Interaction
    Kozlov, Oleg A.
    Rodionov, Dmitriy G.
    Guzikova, Liudmilaa A.
    [J]. 2018 32ND INTERNATIONAL CONFERENCE ON INFORMATION NETWORKING (ICOIN), 2018, : 267 - 269
  • [10] Evaluation of Security Information and Event Management Systems for Custom Security Visualization Generation
    Sonmez, Ferda Ozdemir
    Gunel, Banu
    [J]. 2018 INTERNATIONAL CONGRESS ON BIG DATA, DEEP LEARNING AND FIGHTING CYBER TERRORISM (IBIGDELFT), 2018, : 38 - 44