Cybersecurity Risk Assessment of the University of Northern Philippines using PRISM Approach
Bryan Irvin J. Lamarca · IOP Conference Series Materials Science and Engineering · 2020
Abstract The University of Northern Philippines (UNP) rely on critical infrastructure systems to promote innovation and efficiency in fulfilling its core mandate - deliver quality education. Like any environment, UNP’s cyber environment is vulnerable to security risks which dampen the privacy and safety of stakeholders, the security of assets, and the confidentiality of business proceedings. To proactively address these and other potential risks, this study reviewed existing risk management frameworks used across governments and selected one to be utilized for improving organizational cyber policies and risk mitigation procedures and practices – PRISM, a model to identify and implement cybersecurity risk management tailored towards the problems and needs of the university. Results showed that at least half of the risk areas have poor preparedness level, stemming from the lack of institutionalization of knowledge and solutions, assessing unusual behavior, and proactive and enterprise risk management. Most risk areas seemed to be prioritized, had allocated resources, and has reactive risk management in place. GAP Analysis was also conducted in conjunction with the results of PRISM assessment to better steer the university in the right direction. The study concluded that PRISM is a tool that aided the university in laying down a formalized groundwork for cybersecurity.