Cybersecurity Risk Assessment Approach for Malaysian Organizations: Malaysian Universities as Case Study

Abdulaziz Aborujilah, AbdulAleem Al-Othmani, Nur Syahela Hussien, S. A. Mokhtar, Zalizah Awang Long, M. Nizam
{"title":"Cybersecurity Risk Assessment Approach for Malaysian Organizations: Malaysian Universities as Case Study","authors":"Abdulaziz Aborujilah, AbdulAleem Al-Othmani, Nur Syahela Hussien, S. A. Mokhtar, Zalizah Awang Long, M. Nizam","doi":"10.1109/ICEEE55327.2022.9772546","DOIUrl":null,"url":null,"abstract":"Malaysian organizations are following different methods for cybersecurity risk assessment such as Control Objectives for Information and Related Technologies (COBIT) and International Organization for Standardization (ISO) 27001. The higher education institutions in Malaysia are facing the same difficulties as different standards and approaches are used to evaluate the cybersecurity risk of their institutions. So, there is a lack of a cybersecurity risk assessment approach that takes Malaysian and international standards into consideration. This paper aims to develop a cybersecurity risk assessment approach for higher education institutions in Malaysia. The methodology of conducting this research is qualitative research using a case study. The framework has considered international cybersecurity standards such as the Holistic cybersecurity maturity assessment framework (HCYMAF) and local cybersecurity standards such as National Cyber Security Agency (NACSA) and the Malaysia Cyber Security Strategy (MCSS). In addition, a measurable instrument to assess cybersecurity risk has been proposed. The subject-matter expert can apply this approach to assess their organization's cybersecurity maturity and risk. The findings of this study shall be useful in overcoming the drawbacks of employing non-standard procedures in such evaluations, resulting in more accurate and reliable evaluation outcomes.","PeriodicalId":375340,"journal":{"name":"2022 9th International Conference on Electrical and Electronics Engineering (ICEEE)","volume":"22 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2022-03-29","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"4","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2022 9th International Conference on Electrical and Electronics Engineering (ICEEE)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ICEEE55327.2022.9772546","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 4

Abstract

Malaysian organizations are following different methods for cybersecurity risk assessment such as Control Objectives for Information and Related Technologies (COBIT) and International Organization for Standardization (ISO) 27001. The higher education institutions in Malaysia are facing the same difficulties as different standards and approaches are used to evaluate the cybersecurity risk of their institutions. So, there is a lack of a cybersecurity risk assessment approach that takes Malaysian and international standards into consideration. This paper aims to develop a cybersecurity risk assessment approach for higher education institutions in Malaysia. The methodology of conducting this research is qualitative research using a case study. The framework has considered international cybersecurity standards such as the Holistic cybersecurity maturity assessment framework (HCYMAF) and local cybersecurity standards such as National Cyber Security Agency (NACSA) and the Malaysia Cyber Security Strategy (MCSS). In addition, a measurable instrument to assess cybersecurity risk has been proposed. The subject-matter expert can apply this approach to assess their organization's cybersecurity maturity and risk. The findings of this study shall be useful in overcoming the drawbacks of employing non-standard procedures in such evaluations, resulting in more accurate and reliable evaluation outcomes.
马来西亚组织的网络安全风险评估方法:以马来西亚大学为例研究
马来西亚组织正在遵循不同的网络安全风险评估方法,例如信息及相关技术控制目标(COBIT)和国际标准化组织(ISO) 27001。马来西亚的高等教育机构也面临着同样的困难,因为他们使用不同的标准和方法来评估机构的网络安全风险。因此,缺乏将马来西亚和国际标准考虑在内的网络安全风险评估方法。本文旨在为马来西亚高等教育机构开发网络安全风险评估方法。进行这项研究的方法是使用案例研究的定性研究。该框架考虑了国际网络安全标准,如整体网络安全成熟度评估框架(HCYMAF)和当地网络安全标准,如国家网络安全局(NACSA)和马来西亚网络安全战略(MCSS)。此外,还提出了一种可测量的网络安全风险评估工具。主题专家可以应用此方法来评估其组织的网络安全成熟度和风险。本研究结果将有助于克服此类评估中采用非标准程序的弊端,从而获得更准确可靠的评估结果。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信