Implementing ISO 27001 Security Measures in Educational Open-Source ERP Systems
Saima Bibi, Farooque Azam, Muhammad Waseem Anwar · 2024
This paper explores the applicability of security standards ISO 27001 to Open-source Enterprise Resource Plan-ning (ERP) software for educational institutes. The gap in existing security measures, particularly in the implementation of ISO 27001 concerning data privacy, integrity and availability, are identified for Odoo ERP system that aims to establish a benchmark for similar systems for ensuring data privacy, integrity, and availability. Mixed-methods approach proposed in this paper integrates expert analysis and quantitative survey methodology for effective compliance with ISO 27001 controls for the EPR system of educational institutes. The findings of this paper contribute to enhancing security measures for ERP systems in educational institutes by applying ISO 27001 standards. The expert analysis provides the standardization of industrial best practices for ERP system and current state of security measures are evaluated using quantitative surveys for educational ERP systems.