INFORMATION SECURITY AND CYBER SECURITY MANAGEMENT IN HIGHER EDUCATION INSTITUTIONS

Andriy Ivanusa, Rostyslav Tkachuk, Nataliya Maslova, Valentyna Yashchuk, A. M. Tkachenko · Bulletin of Lviv State University of Life Safety · 2025

Research problem. In the current conditions of rapid digitalization of education, the issues of information security and cybersecurity in higher education institutions are becoming extremely relevant. Educational institutions store a significant amount of confidential data, including personal information of students, employees, research results or intellectual property. Unauthorized access to such data can cause significant reputational and financial damage. In this context, the implementation of an effective information security policy is a key element of the risk management strategy. It allows you to regulate the procedure for processing, storing, and transmitting information, preventing leaks and misuse. Constantly evolving cyber threats demand a systematic approach to the formation of protective mechanisms. A cybersecurity policy promotes the implementation of procedures for detecting, responding to, and eliminating security incidents. It also ensures compliance with legal and regulatory requirements, particularly with regard to personal dataprotection. Implementation of this policy raises awareness of information security among participants in the educational process. Thus, the development and implementation of information security and cybersecurity policies in higher education institutions is a prerequisite for the stable and secure functioning of the educational environment.Aim. The aim of the work is to improve the working tools for managing information security and cybersecurity in higher education institutions by identifying threats, analyzing network infrastructure vulnerabilities, and developing information security policies based on risk assessment, according to modern international and national standards in the field of information security.Research methods. The study uses system analysis, observation, modeling, comparison, expert evaluation, ranking, normalization, probability theory, decision-making theory, and information security theory.Results. The study examines the process of information security management and its relationship with the continuity of operational processes. It has been found that the lack of effective information security measures and policies can jeopardize the continuity of the daily activities of the higher education institution. Particular attention is paid to discretion in managing information security processes, which is a key aspect of protecting information assets. Using the example of Lviv State University of Life Safety, the author analyzes the means of information protection and network infrastructure, identifies shortcomings, and proposes organizational, software, and technical measures to improve the level of information security. The proposed adaptive methodology for analyzing technical software is suitable for use by business entities regardless of their financial capabilities.

Read the paper · More papers on PaperTik