Application of ISO/IEC 27,001 in Higher Education Technological Institutes: Case-Control Study
摘要
In this research, the critical task of enhancing information security within a higher education institution is addressed through the implementation of a methodology grounded in the ISO/IEC 27,001 and 27,002 standards. The current context, characterized by increasing digitalization, underscores the urgent need to protect data and information against cyber threats. The research employs a quasi-experimental approach, combined with precise diagnostic tools, to identify initial vulnerabilities in information security. Subsequently, a strategic risk management plan is developed and implemented, tailored to the institution's needs and specificities. The outcomes are significant, demonstrating an increase in compliance with ISO standards, resulting in a substantial improvement in information security. This progress not only reflects the effectiveness of the adopted methodology but also highlights the importance of systematic and well-structured risk management in the educational sector. This study not only provides a valuable framework for future initiatives in similar institutions but also encourages constructive dialogue on cybersecurity practices in the educational sector at an international level.