DocumentCode :
1804478
Title :
Information security risk management in small-scale organisations: A case study of secondary schools computerised information systems
Author :
Moyo, Moses ; Abdullah, Hanim ; Nienaber, Rita C.
Author_Institution :
Sch. of Comput. Sci., UNISA, Pretoria, South Africa
fYear :
2013
fDate :
14-16 Aug. 2013
Firstpage :
1
Lastpage :
6
Abstract :
The use of computerised information systems has become an integral part of South African secondary schools, bringing about a host of information security challenges that schools have to deal with in addition to their core business of teaching and learning. Schools handle large volumes of sensitive information pertaining to educators, learners, creditors and financial records, which they are obliged to secure. Unfortunately, school management and users are not aware of the risks to their information assets and the repercussions of a compromise thereof. Computerised information systems are susceptible to both internal and external threats but ease of access is likely to manifest in security breaches, thereby undermining information security. One way of enlightening schools about the risks to their computerised information systems is through a risk management programme. Schools may not have the full capacity to perform information security risk management exercises due to the unavailability of risk management experts and scarce financial resources. Therefore, the objective of this paper is to educate secondary schools´ management and users on how to perform a risk management exercise for their computerised information systems in order to reduce or mitigate information security risks within their information systems and protect vital information assets. This study uses the Operationally Critical Threat, Asset, and Vulnerability Evaluation for small organisations (OCTAVE-Small) risk management methodology to address these information security risks in two selected secondary schools.
Keywords :
educational administrative data processing; information systems; risk management; security of data; teaching; OCTAVE-Small risk management methodology; South African secondary schools; ease of access; external threats; financial resources; information assets; information security risk management; internal threats; learning business; operationally critical threat-asset-vulnerability evaluation for small organisations; risk management experts; risk management programme; school management; secondary school computerised information systems; small-scale organisations; teaching business; Collaboration; Educational institutions; Information security; Personnel; Risk management; computerised information systems; exposure; information security; risk; risk analysis; risk assessment; risk management; threats; vulnerability;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Information Security for South Africa, 2013
Conference_Location :
Johannesburg
Type :
conf
DOI :
10.1109/ISSA.2013.6641062
Filename :
6641062
Link To Document :
بازگشت