In this research, the critical task of enhancing information security within a higher education institution is addressed through the implementation of a methodology grounded in the ISO/IEC 27,001 and 27,002 standards. The current context, characterized by increasing digitalization, underscores the urgent need to protect data and information against cyber threats. The research employs a quasi-experimental approach, combined with precise diagnostic tools, to identify initial vulnerabilities in information security. Subsequently, a strategic risk management plan is developed and implemented, tailored to the institution's needs and specificities. The outcomes are significant, demonstrating an increase in compliance with ISO standards, resulting in a substantial improvement in information security. This progress not only reflects the effectiveness of the adopted methodology but also highlights the importance of systematic and well-structured risk management in the educational sector. This study not only provides a valuable framework for future initiatives in similar institutions but also encourages constructive dialogue on cybersecurity practices in the educational sector at an international level.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Application of ISO/IEC 27,001 in Higher Education Technological Institutes: Case-Control Study

  • Flavio López-Vasco,
  • Mishell Angulo-Alvarez,
  • David Ismael Sosa Zuñiga,
  • Edwin Puente Moromenacho,
  • Nury Ortiz

摘要

In this research, the critical task of enhancing information security within a higher education institution is addressed through the implementation of a methodology grounded in the ISO/IEC 27,001 and 27,002 standards. The current context, characterized by increasing digitalization, underscores the urgent need to protect data and information against cyber threats. The research employs a quasi-experimental approach, combined with precise diagnostic tools, to identify initial vulnerabilities in information security. Subsequently, a strategic risk management plan is developed and implemented, tailored to the institution's needs and specificities. The outcomes are significant, demonstrating an increase in compliance with ISO standards, resulting in a substantial improvement in information security. This progress not only reflects the effectiveness of the adopted methodology but also highlights the importance of systematic and well-structured risk management in the educational sector. This study not only provides a valuable framework for future initiatives in similar institutions but also encourages constructive dialogue on cybersecurity practices in the educational sector at an international level.