This research addresses the limitations of educational institutions in defining the cybersecurity capabilities needed to protect, respond, and recover from the main cybercrime scenarios in the sector. To date, there is evidence of an increase in cyberattacks targeting educational institutions, and there are no models to define the capabilities to reduce risk, so we focused on creating a cybersecurity target profile model based on NIST based on the reality of the education sector. This model will allow the institution to implement a cybersecurity program autonomously, reduce costs, and prioritize critical capabilities for the institution. In this sense, the model has been confirmed through a case study in which the current cybersecurity posture of the institution was calculated and, based on the gaps identified with the proposed target profile, initiatives to improve it were set up. The results show that the implementation of the model improved critical cybersecurity capabilities in educational institutions by 30%, moving capabilities from a low maturity level (Initial) to a defined level. In addition, a 60% reduction in the cost of implementing the cybersecurity program was shown. Thus, the proposed model allows institutions to find gaps and opportunities for improvement, strengthening their cybersecurity management and maturity in this area. It also helps the implementation of a cybersecurity program by reducing costs and providing autonomy to educational institutions.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Target Profile Model to Improve Cybersecurity Capabilities of Educational Institutions Against Cyber-Attacks

  • Jeremy Cruz,
  • Andrés La Rosa Toro,
  • Juan Mansilla Lopez,
  • Christian Cipriano Portugal

摘要

This research addresses the limitations of educational institutions in defining the cybersecurity capabilities needed to protect, respond, and recover from the main cybercrime scenarios in the sector. To date, there is evidence of an increase in cyberattacks targeting educational institutions, and there are no models to define the capabilities to reduce risk, so we focused on creating a cybersecurity target profile model based on NIST based on the reality of the education sector. This model will allow the institution to implement a cybersecurity program autonomously, reduce costs, and prioritize critical capabilities for the institution. In this sense, the model has been confirmed through a case study in which the current cybersecurity posture of the institution was calculated and, based on the gaps identified with the proposed target profile, initiatives to improve it were set up. The results show that the implementation of the model improved critical cybersecurity capabilities in educational institutions by 30%, moving capabilities from a low maturity level (Initial) to a defined level. In addition, a 60% reduction in the cost of implementing the cybersecurity program was shown. Thus, the proposed model allows institutions to find gaps and opportunities for improvement, strengthening their cybersecurity management and maturity in this area. It also helps the implementation of a cybersecurity program by reducing costs and providing autonomy to educational institutions.