Information security risk management in small-scale organisations: A case study of secondary schools computerised information systems

M. Moyo, Hanifa Abdullah, R. C. Nienaber
{"title":"Information security risk management in small-scale organisations: A case study of secondary schools computerised information systems","authors":"M. Moyo, Hanifa Abdullah, R. C. Nienaber","doi":"10.1109/ISSA.2013.6641062","DOIUrl":null,"url":null,"abstract":"The use of computerised information systems has become an integral part of South African secondary schools, bringing about a host of information security challenges that schools have to deal with in addition to their core business of teaching and learning. Schools handle large volumes of sensitive information pertaining to educators, learners, creditors and financial records, which they are obliged to secure. Unfortunately, school management and users are not aware of the risks to their information assets and the repercussions of a compromise thereof. Computerised information systems are susceptible to both internal and external threats but ease of access is likely to manifest in security breaches, thereby undermining information security. One way of enlightening schools about the risks to their computerised information systems is through a risk management programme. Schools may not have the full capacity to perform information security risk management exercises due to the unavailability of risk management experts and scarce financial resources. Therefore, the objective of this paper is to educate secondary schools' management and users on how to perform a risk management exercise for their computerised information systems in order to reduce or mitigate information security risks within their information systems and protect vital information assets. This study uses the Operationally Critical Threat, Asset, and Vulnerability Evaluation for small organisations (OCTAVE-Small) risk management methodology to address these information security risks in two selected secondary schools.","PeriodicalId":300864,"journal":{"name":"2013 Information Security for South Africa","volume":"37 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2013-10-21","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"12","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2013 Information Security for South Africa","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ISSA.2013.6641062","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 12

Abstract

The use of computerised information systems has become an integral part of South African secondary schools, bringing about a host of information security challenges that schools have to deal with in addition to their core business of teaching and learning. Schools handle large volumes of sensitive information pertaining to educators, learners, creditors and financial records, which they are obliged to secure. Unfortunately, school management and users are not aware of the risks to their information assets and the repercussions of a compromise thereof. Computerised information systems are susceptible to both internal and external threats but ease of access is likely to manifest in security breaches, thereby undermining information security. One way of enlightening schools about the risks to their computerised information systems is through a risk management programme. Schools may not have the full capacity to perform information security risk management exercises due to the unavailability of risk management experts and scarce financial resources. Therefore, the objective of this paper is to educate secondary schools' management and users on how to perform a risk management exercise for their computerised information systems in order to reduce or mitigate information security risks within their information systems and protect vital information assets. This study uses the Operationally Critical Threat, Asset, and Vulnerability Evaluation for small organisations (OCTAVE-Small) risk management methodology to address these information security risks in two selected secondary schools.
小型机构的资讯保安风险管理:中学电脑化资讯系统个案研究
计算机化信息系统的使用已成为南非中学的一个组成部分,除了教与学的核心业务外,还带来了许多学校必须应对的信息安全挑战。学校处理大量与教育工作者、学习者、债权人和财务记录有关的敏感信息,他们有义务保护这些信息。不幸的是,学校管理层和用户并没有意识到他们的信息资产所面临的风险以及泄露信息资产的后果。电脑化的资讯系统容易受到内部和外部的威胁,但容易进入的资讯系统很可能出现保安漏洞,从而破坏资讯保安。让学校了解其计算机化信息系统面临的风险的一种方法是开展风险管理项目。由于缺乏风险管理专家和缺乏财政资源,学校可能没有充分的能力进行信息安全风险管理练习。因此,本文的目的是教育中学的管理层和使用者如何为其电脑化资讯系统进行风险管理,以减少或减轻其资讯系统内的资讯保安风险,并保护重要的资讯资产。本研究采用针对小型组织的关键威胁、资产和脆弱性评估(OCTAVE-Small)风险管理方法,在两所选定的中学解决这些信息安全风险。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信