基于学习管理系统分析实例的信息安全风险评估方法

С.А. Абдыманапов, А.Б. Барлыбаев, Б.А. Алтынбек
{"title":"基于学习管理系统分析实例的信息安全风险评估方法","authors":"С.А. Абдыманапов, А.Б. Барлыбаев, Б.А. Алтынбек","doi":"10.31489/2022ped3/84-95","DOIUrl":null,"url":null,"abstract":"The active development and application of new digital technologies in education, on the one hand, has opened up new opportunities for improving the efficiency of the university’s business process management. On the other hand, this has led to a significant increase in security threats and the vulnerability of educational institutions to cyber criminals. The recent rapid growth of various incidents regarding cybercrimes shows the insufficiency of traditional approaches to information security. Consequently, information security risk assessment has become an important task for most educational institutions. Several models have been proposed to help educational institutions solve problems with building information security. This article proposes a new hierarchical structured model for assessing information security risks in educational institutions using fuzzy logic. A new method for assessing information security risks is also described using the example of automated control systems or ERP systems (for example, training management systems). The proposed risk assessment of the university was modeled using fuzzy logic in the form of 15 fuzzy machines. In the course of a number of experiments, we carefully studied the assessment of information security risks of various software products used in universities. The proposed method should solve the problem of flexible risk assessment.","PeriodicalId":336594,"journal":{"name":"Bulletin of the Karaganda University. Pedagogy series","volume":"39 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2022-09-29","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":"{\"title\":\"InfoSec Risk Assessment Methodology based on the example of Learning Management Systems Analysis\",\"authors\":\"С.А. Абдыманапов, А.Б. Барлыбаев, Б.А. Алтынбек\",\"doi\":\"10.31489/2022ped3/84-95\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"The active development and application of new digital technologies in education, on the one hand, has opened up new opportunities for improving the efficiency of the university’s business process management. On the other hand, this has led to a significant increase in security threats and the vulnerability of educational institutions to cyber criminals. The recent rapid growth of various incidents regarding cybercrimes shows the insufficiency of traditional approaches to information security. Consequently, information security risk assessment has become an important task for most educational institutions. Several models have been proposed to help educational institutions solve problems with building information security. This article proposes a new hierarchical structured model for assessing information security risks in educational institutions using fuzzy logic. A new method for assessing information security risks is also described using the example of automated control systems or ERP systems (for example, training management systems). The proposed risk assessment of the university was modeled using fuzzy logic in the form of 15 fuzzy machines. In the course of a number of experiments, we carefully studied the assessment of information security risks of various software products used in universities. The proposed method should solve the problem of flexible risk assessment.\",\"PeriodicalId\":336594,\"journal\":{\"name\":\"Bulletin of the Karaganda University. Pedagogy series\",\"volume\":\"39 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2022-09-29\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"0\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"Bulletin of the Karaganda University. Pedagogy series\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.31489/2022ped3/84-95\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"Bulletin of the Karaganda University. Pedagogy series","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.31489/2022ped3/84-95","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0

摘要

新的数字技术在教育中的积极发展和应用,一方面为提高大学业务流程管理的效率开辟了新的机遇。另一方面,这导致安全威胁显著增加,教育机构容易受到网络罪犯的攻击。近年来,各种网络犯罪事件的快速增长表明了传统信息安全方法的不足。因此,信息安全风险评估已成为大多数教育机构的一项重要任务。人们提出了几种模式来帮助教育机构解决建筑信息安全问题。本文利用模糊逻辑提出了一种新的教育机构信息安全风险评估层次结构模型。本文还以自动化控制系统或ERP系统(例如培训管理系统)为例,描述了一种评估信息安全风险的新方法。采用模糊逻辑,以15个模糊机的形式对所提出的大学风险评估进行建模。在多次实验的过程中,我们认真研究了高校使用的各种软件产品的信息安全风险评估。所提出的方法应解决风险评估的灵活性问题。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
InfoSec Risk Assessment Methodology based on the example of Learning Management Systems Analysis
The active development and application of new digital technologies in education, on the one hand, has opened up new opportunities for improving the efficiency of the university’s business process management. On the other hand, this has led to a significant increase in security threats and the vulnerability of educational institutions to cyber criminals. The recent rapid growth of various incidents regarding cybercrimes shows the insufficiency of traditional approaches to information security. Consequently, information security risk assessment has become an important task for most educational institutions. Several models have been proposed to help educational institutions solve problems with building information security. This article proposes a new hierarchical structured model for assessing information security risks in educational institutions using fuzzy logic. A new method for assessing information security risks is also described using the example of automated control systems or ERP systems (for example, training management systems). The proposed risk assessment of the university was modeled using fuzzy logic in the form of 15 fuzzy machines. In the course of a number of experiments, we carefully studied the assessment of information security risks of various software products used in universities. The proposed method should solve the problem of flexible risk assessment.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信