Main factors and good practices for managing BYOD and IoT risks in a K-12 environment
Shaun Aghili, Oluwaseun Akeju, Sergey Butakov · International Journal of Internet of Things and Cyber-Assurance · 2018
The presented research looks into information security and privacy risk related to using mobile and embedded devices for learning in the K-12 environment.Bring Your Own Device (BYOD) program and Internet of Things (IoT) for learning are the two focus areas discussed in this paper.The NIST privacy risk management framework (NIST-8062) template was used to illustrate the privacy impact factors K-12 ecosystem participants should consider while developing BYOD/IoT programs.The key factors involved in the decisions include reputation costs, direct business costs and non-compliance costs.Key security issues and risks such as network access, server and end-user device malware, application risks, and privacy risks were identified.The analysis of the risks suggested to recommend some good practices derived from various documents suggested by ISACA, IIA, SANS, and NIST.The proposed good practices were subsequently incorporated into BYOD guide for the K-12 system in two Canadian provinces (Alberta and Manitoba) in an attempt to increase its effectiveness in terms of addressing relevant risks.Although the good practices compiled in this research are proposed to be incorporated into the Alberta and Manitoba's BYOD guide for K-12 schools, the same process is applicable to any similar K-12 environment.