MePRiSIA: risk prevention methodology for academic information systems

被引:0
|
作者
Cristina Satizabal-Echavarria, Isabel [1 ]
Maria Acevedo-Quintana, Nancy [2 ]
机构
[1] Univ Antonio Narino, LACSER, Ave Bolivar 49,Norte 30, Armenia 630004, Colombia
[2] Univ Pamplona, LOGOS, Km 1 Via Bucaramanga, Pamplona 543050, Colombia
来源
REVISTA FACULTAD DE INGENIERIA-UNIVERSIDAD DE ANTIOQUIA | 2018年 / 89期
关键词
Educational information system; information management; information system evaluation; methodology; risk assessment;
D O I
10.17533/udea.redin.n89a11
中图分类号
T [工业技术];
学科分类号
08 ;
摘要
Information of academic systems can be stolen, modified or erased by attackers, causing losses to institutions. Applying a risk prevention methodology at educational institutions would help to avoid academic information misuse by users or attackers. MePRiSIA was designed as a risk prevention methodology to be simple and easy to understand while including the human factor in each step. This methodology has four steps to be considered in the process: setting the context, risk identification, risk analysis, and risk prevention. After being applied to the academic information system of Universidad de Pamplona (Colombia) called ACADEMUSOFT. MePRiSIA was evaluated by experts. In conclusion, after applying MePRiSIA to ACADEMUSOFT, the human factor was part of its most important assets and involved in the very high-level risks identified. According to the experts, implementation of MePRiSIA is hard when institution directors do not provide staff and financial resources for this purpose.
引用
收藏
页码:81 / 101
页数:21
相关论文
共 50 条
  • [1] APPLICATION OF THE INCREMENTAL METHODOLOGY IN THE DEVELOPMENT OF INFORMATION SYSTEMS
    Leon Yacelga, Andres Roberto
    Acosta Espinoza, Jorge Lenin
    Diaz Vasquez, Rita Azucena
    REVISTA UNIVERSIDAD Y SOCIEDAD, 2021, 13 (05): : 175 - 182
  • [3] A design science research methodology for Information Systems Research
    Peffers, Ken
    Tuunanen, Tuure
    Rothenberger, Marcus A.
    Chatterjee, Samir
    JOURNAL OF MANAGEMENT INFORMATION SYSTEMS, 2007, 24 (03) : 45 - 77
  • [4] Designing an appropriate information systems development methodology for different situations
    Avison, David
    Pries-Heje, Jan
    ICEIS 2007: PROCEEDINGS OF THE NINTH INTERNATIONAL CONFERENCE ON ENTERPRISE INFORMATION SYSTEMS: INFORMATION SYSTEMS ANALYSIS AND SPECIFICATION, 2007, : 63 - +
  • [5] A workflow-based methodology for developing hypermedia information systems
    Lee, H
    Suh, W
    JOURNAL OF ORGANIZATIONAL COMPUTING AND ELECTRONIC COMMERCE, 2001, 11 (02) : 77 - 106
  • [6] A Methodology for Context- Specific Information Systems Design Theorizing
    Atinaf, Muluneh
    Anteneh, Salehu
    Kifle, Mesfin
    AFRICAN JOURNAL OF INFORMATION SYSTEMS, 2023, 15 (02): : 63 - 91
  • [7] Risk Assessment Methodology For EMV Financial Transaction Systems
    Alqahtani, Mohammed
    van Moorsel, Aad
    ELECTRONIC NOTES IN THEORETICAL COMPUTER SCIENCE, 2018, 340 : 137 - 150
  • [8] EXTREME RISK ASSESSMENT METHODOLOGY (ERAM) IN AVIATION SYSTEMS
    Cioaca, Catalin
    Constantinescu, Cristian-George
    Boscoianu, Mircea
    Lile, Ramona
    ENVIRONMENTAL ENGINEERING AND MANAGEMENT JOURNAL, 2015, 14 (06): : 1399 - 1408
  • [9] Risk Assessment on Information Asset an academic Application Using ISO 27001
    Angraini
    Megawati
    Haris, Lukman
    2018 6TH INTERNATIONAL CONFERENCE ON CYBER AND IT SERVICE MANAGEMENT (CITSM), 2018, : 568 - 571
  • [10] A case study strategy as part of an information systems research methodology: a critique
    Irani, Z
    Ezingeard, JN
    Grieve, RJ
    Race, P
    INTERNATIONAL JOURNAL OF COMPUTER APPLICATIONS IN TECHNOLOGY, 1999, 12 (2-5) : 190 - 198