Abstract
Abstract
The University of Northern Philippines (UNP) rely on critical infrastructure systems to promote innovation and efficiency in fulfilling its core mandate - deliver quality education. Like any environment, UNP’s cyber environment is vulnerable to security risks which dampen the privacy and safety of stakeholders, the security of assets, and the confidentiality of business proceedings. To proactively address these and other potential risks, this study reviewed existing risk management frameworks used across governments and selected one to be utilized for improving organizational cyber policies and risk mitigation procedures and practices – PRISM, a model to identify and implement cybersecurity risk management tailored towards the problems and needs of the university. Results showed that at least half of the risk areas have poor preparedness level, stemming from the lack of institutionalization of knowledge and solutions, assessing unusual behavior, and proactive and enterprise risk management. Most risk areas seemed to be prioritized, had allocated resources, and has reactive risk management in place. GAP Analysis was also conducted in conjunction with the results of PRISM assessment to better steer the university in the right direction. The study concluded that PRISM is a tool that aided the university in laying down a formalized groundwork for cybersecurity.
Reference26 articles.
1. Cybersecurity;Kemmerer,2003
2. Cybersecurity and critical infrastructure protection;Lewis,2006
Cited by
2 articles.
订阅此论文施引文献
订阅此论文施引文献,注册后可以免费订阅5篇论文的施引文献,订阅后可以查看论文全部施引文献