MePRiSIA: risk prevention methodology for academic information systems

被引:0
作者
Cristina Satizabal-Echavarria, Isabel [1 ]
Maria Acevedo-Quintana, Nancy [2 ]
机构
[1] Univ Antonio Narino, LACSER, Ave Bolivar 49,Norte 30, Armenia 630004, Colombia
[2] Univ Pamplona, LOGOS, Km 1 Via Bucaramanga, Pamplona 543050, Colombia
来源
REVISTA FACULTAD DE INGENIERIA-UNIVERSIDAD DE ANTIOQUIA | 2018年 / 89期
关键词
Educational information system; information management; information system evaluation; methodology; risk assessment;
D O I
10.17533/udea.redin.n89a11
中图分类号
T [工业技术];
学科分类号
08 ;
摘要
Information of academic systems can be stolen, modified or erased by attackers, causing losses to institutions. Applying a risk prevention methodology at educational institutions would help to avoid academic information misuse by users or attackers. MePRiSIA was designed as a risk prevention methodology to be simple and easy to understand while including the human factor in each step. This methodology has four steps to be considered in the process: setting the context, risk identification, risk analysis, and risk prevention. After being applied to the academic information system of Universidad de Pamplona (Colombia) called ACADEMUSOFT. MePRiSIA was evaluated by experts. In conclusion, after applying MePRiSIA to ACADEMUSOFT, the human factor was part of its most important assets and involved in the very high-level risks identified. According to the experts, implementation of MePRiSIA is hard when institution directors do not provide staff and financial resources for this purpose.
引用
收藏
页码:81 / 101
页数:21
相关论文
共 50 条
  • [21] Generalized risk assessment index for information systems auditing
    Peto, David
    ITI 2006: PROCEEDINGS OF THE 28TH INTERNATIONAL CONFERENCE ON INFORMATION TECHNOLOGY INTERFACES, 2006, : 97 - 102
  • [22] Security Risk Assessment of Information Systems in an Indeterminate Environment
    Basumatary, Basundhara
    Kumar, Chandan
    Yadav, Dilip Kumar
    2021 11TH INTERNATIONAL CONFERENCE ON CLOUD COMPUTING, DATA SCIENCE & ENGINEERING (CONFLUENCE 2021), 2021, : 82 - 87
  • [23] Towards a Privacy Risk Assessment Methodology for Location-Based Systems
    Friginal, Jesus
    Guiochet, Jeremie
    Killijian, Marc-Olivier
    MOBILE AND UBIQUITOUS SYSTEMS: COMPUTING, NETWORKING, AND SERVICES, 2014, 131 : 748 - 753
  • [25] An information-theoretic methodology for measuring the operational complexity of supplier-customer systems
    Sivadasan, S
    Efstathiou, J
    Frizelle, G
    Shirazi, R
    Calinescu, A
    INTERNATIONAL JOURNAL OF OPERATIONS & PRODUCTION MANAGEMENT, 2002, 22 (01) : 80 - 102
  • [26] A report on the use of action research to evaluate a manufacturing information systems development methodology in a company
    Grant, D
    Ngwenyama, O
    INFORMATION SYSTEMS JOURNAL, 2003, 13 (01) : 21 - 35
  • [27] An investigation on the information systems research in supply chain management: an analysis of research topic and methodology
    Younjung Kim
    Youngho Lee
    Kyung-Yong Chung
    Kang-Dae Lee
    Multimedia Tools and Applications, 2015, 74 : 8849 - 8860
  • [28] An investigation on the information systems research in supply chain management: an analysis of research topic and methodology
    Kim, Younjung
    Lee, Youngho
    Chung, Kyung-Yong
    Lee, Kang-Dae
    MULTIMEDIA TOOLS AND APPLICATIONS, 2015, 74 (20) : 8849 - 8860
  • [29] METHODOLOGY TO DETERMINE THE INSTALLED CAPACITY OF AN ACADEMIC PROGRAM
    Manyoma Velasquez, Pablo Cesar
    Orejuela Cabrera, Juan Pablo
    Gil Gonzalez, Cristiam Andres
    ESTUDIOS GERENCIALES, 2011, 27 (121) : 143 - 158
  • [30] A Quantitative CVSS-Based Cyber Security Risk Assessment Methodology For IT Systems
    Aksu, M. Ugur
    Dilek, M. Hadi
    Tatli, E. Islam
    Bicakci, Kemal
    Dirik, H. Ibrahim
    Demirezen, M. Umut
    Aykir, Tayfun
    2017 INTERNATIONAL CARNAHAN CONFERENCE ON SECURITY TECHNOLOGY (ICCST), 2017,