conference-paper

Evaluating information security in academic management systems under the ISO/IEC 27001 standard

  • IET conference proceedings.
  • Institution of Engineering and Technology
Research footprint

At a glance

Citations
0
References
0
Comments
0
Paper overview

Abstract

An Academic Management System (AMS) is a technological tool used to manage academic processes in educational institutions. AMS helps optimise resources through data management, but it has information security challenges. Due to the need to inspect security in an AMS, this study aims to identify and evaluate risks and improve controls for AMS security. Adhering to international standards like ISO/IEC 27001:2013 is important for addressing cyber threats. The case study focuses on the AMS of the Technical University of Manabi, focusing on confidentiality, integrity, and availability of information. The methodology involves analysing AMS information security components using surveys conducted with the institution’s data centre personnel to determine the current system status. The results show that there are 48 active controls and 33 inactive ones, meaning that the AMS is partially protected according to the standard. Additionally, risks associated with likelihood and impact are identified, along with recommendations to strengthen AMS security management.

Record transparency

Publication details

DOI
10.1049/icp.2025.1237
OpenAlex
W4409671904
Document type
conference-paper
Language
EN
Source
IET conference proceedings.
Last metadata update
Community

Comments

Log in to join the discussion.

  1. No comments yet. Start the discussion.