The article provides for the task of assessing the risks of Information Security (IS) of information and educational systems of educational institutions. It is shown that the existing methods and models of JSC risk management mainly consider the object of corporate and critical information systems. These models do not fully take into account the specifics of the educational environment. A probabilistic model for assessing the risks of JSC based on the Bayesian network apparatus is proposed, which allows formalizing causal relationships between information assets, threats, vulnerabilities and user behavior characteristics. The model provides integration of statistical and expert data and allows specialists of an educational institution to calculate the back probability of implementing threats in the presence of a partial Aparat about the state of the system. The human factor is included in the model as an observable random variable that characterizes the level of awareness of users, compliance with information security requirements and features of their behavior. Based on the posterior probability of implementing threats, the expected damage and the integral level of risk are determined. The performance of the proposed approach is checked by a computational experiment on the data of the educational institution. Model information assets and threats specific to the educational environment, including unauthorized access, malicious software and phishing attacks, were considered. The performance of the presented model is confirmed by a computational experiment in the data of the educational institution. The experiment analyzed the effect of the human factor on the expected harm and the integral risk of white blood cells. The results showed the sensitivity of the presented model to changes in behavioral parameters and confirmed its practical application to justify managerial decisions in the field of Information Protection of educational institutions.
ALMUKHANOVA A.K.
Doctoral student, Satbayev University, Almaty, Kazakhstan
Е-mail: almuhanova_aak@mail.ru, https://orcid.org/0009-0005-7858-9016
YUBUZOVA H.I.
PhD, associate professor, Satbayev University, Almaty, Kazakhstan
E-mail: k. yubuzova@satbayev.university, https://orcid.org/0000-0001-8892-6745
ALIMSEITOVA ZH.K.
PhD, associate professor, Satbayev University, Almaty, Kazakhstan
E-mail: zh.alimseitova@satbayev.university, https://orcid.org/0000-0002-1907-8997
LAKHNO V.A.
Doctor of technical sciences, professor, National university of life and environmental sciences, Kyiv, Ukraine
Е-mail: lva964@gmail.com, https://orcid.org/0000-0001-9695-4543
- Merchan-Lima J., Astudillo-Salinas F., Tello-Oquendo L., Sanchez F., Lopez-Fonseca G., Quiroz, D. Information security management frameworks and strategies in higher education institutions: a systematic review. // Annals of Telecommunications. – 2021. – Vol. 76, no. 3–4. – P. 255–270. – DOI: 10.1007/s12243-020-00783-2.
- Hina S., Dominic P.D.D. Information security policies’ compliance: a perspective for higher education institutions. / Journal of Computer Information Systems. – 2020. – Vol. 60, no. 3. – P. 201–211. – DOI: 10.1080/08874417.2018.1432996.
- Esparza D.E.I., Diaz F.J., Echeverria T.K.S., Hidrobo S.R.A., Villavicencio D.A.L., Ordonez A.R. Information security issues in educational institutions. // 2020 15th Iberian Conference on Information Systems and Technologies (CISTI). – IEEE, 2020. – P. 1–7. – DOI: 10.23919/CISTI49556.2020.9141014.
- Cheung S.K. Information security management for higher education institutions. // Intelligent Data Analysis and Its Applications: Proceedings of the First Euro-China Conference on Intelligent Data Analysis and Applications, Shenzhen, China, June 13–15, 2014. – Cham : Springer International Publishing, 2014. – Vol. 297. – P. 11–19. – DOI: 10.1007/978-3-319-07776-5_2.
- Joshi C., Singh U.K. Information security risks management framework – a step towards mitigating security risks in university network. // Journal of Information Security and Applications. – 2017. – Vol. 35. – P. 128–137. – DOI: 10.1016/j.jisa.2017.06.006.
- Lallie H.S., Thompson A., Titis E., Stephens P. Understanding cyber threats against the universities, colleges, and schools. arXiv:2307.07755. DOI: 10.48550/arXiv.2307.07755.
- Ulinnuha Y.K.P., Ayu I.K., Yasmin N.A. Risk assessment maturity level of academic information system using ISO 27001 System Security Engineering–Capability Maturity Model. / Journal of Applied Engineering and Technological Science. – 2024. – Vol. 5, no. 2. – P. 941–954. – DOI: 10.37385/jaets.v5i2.2971.
- Абдыманапов С.А. Методика оценки рисков информационной безопасности на примере анализа Learning Management Systems. // Вестник Карагандинского университета. Серия «Педагогика». – 2022. – Т. 107, № 3. – С. 84–95. – DOI: 10.31489/2022ped3/84-95.
- Al-Mudaires F., Al-Samawi A., Aljughaiman A., Nissirat L. Information security risk management framework for a governmental educational institute. // Journal of Information and Knowledge Management. – 2023. – Vol. 13, no. 1. – P. 36–54. – DOI: 10.24191/jikm.v13i1.4714.
- Мулик Д.И., Замотайлова Д.А. Информационная безопасность в учебных заведениях. // Информационное общество: современное состояние и перспективы развития : материалы международного форума. – Краснодар : КубГАУ, 2019. – С. 95–98.
- Воронин Е.А., Козлов С.В., Кубанков А.Н. Выявление угроз на основе ограниченного набора данных при оценке систем обеспечения безопасности и мероприятий по их реализации. // Наукоемкие технологии в космических исследованиях Земли. – 2022. – Т. 14, № 3. – С. 41–48.
- Атаманов А. Н. Динамическая итеративная оценка рисков информационной безопасности в автоматизированных системах : дис. ... канд. техн. наук : 05.13.19 / Москва, 2012. – 147 с.
- Голубинский А.Н., Алехин И.В. О математических моделях ущербов и рисков возникновения угроз в информационно-технических системах. // Охрана, безопасность, связь. – 2016. – № 1–3. – С. 109–115.
