An Information Security Policy Development Process in Higher Education Institution: A Case Study Approach

Wan Basri Wan Ismail, Setyawan Widyarto, Krisna Adiyarta, Mohammad Syafrullah, Laili Mardziah Tajuddin · 2022

Higher Education Institutions (HEIs) are exposed to cybersecurity challenges due to the open campus cultures of information and computing resources. Moreover, universities need to ensure that data is always protected from potential corruption, destruction or theft. Therefore, many experts have agreed that the establishment and implementation of an information security policy (ISP) is one of the most crucial factors in the protection of an organization's information assets. The success of implementing information security policies does not only depend on the awareness, acceptance and employees' compliance toward security policies but also on the good design and functioning of the policy. However, security policies are not easy to develop, the policies may differ significantly in the way the policy and procedures are set forth because of different types of organizations, cultures, technology changes and users. In designing a security policy, the policy's clarity, comprehensiveness, and flexibility are important to enable users to comply with any security policies. This paper presents the information security development guidelines and the experiences on the development process of Information Security policies in the HEI. This study discovered three case studies at HEI based on a conceptual policy development model. There are 44 semi-structured questions were derived from six themes of the policy development process for interviews session with IT managers. The results of this study propose nine steps for the development process of ISP and the barriers during development and implementation, especially in HEI.

Read the paper · More papers on PaperTik