Systematic Literature Review of Cybersecurity Risk Assessment and Management Frameworks in Higher Education Institutions

Beatrice Akoth Owino, Collins Oduor, Gerald Chege · The University Journal · 2025

Cybersecurity threats continue to pose significant risks to higher education institutions (HEIs), which increasingly depend on digital infrastructure for academic, administrative, and research activities. However, the effectiveness of cybersecurity risk assessment and management (CSRA&M) frameworks in addressing these threats within university contexts remains unclear. This study presents a systematic literature review to identify, analyze, and synthesize existing CSRA&M models relevant to HEIs. The review followed the PRISMA methodology to ensure transparency and rigor in article selection and analysis. Peer-reviewed journal articles and academic conference papers were sourced from databases including IEEE Xplore, Scopus, and ScienceDirect. Inclusion criteria focused on studies that applied, evaluated, or discussed CSRA&M frameworks in the context of universities or higher education environments. Findings indicate that frameworks such as ISO 27001, ISO/IEC 27005, OCTAVE, and COBIT are frequently referenced. However, many are not fully tailored to universities’ socio-technical and governance structures, particularly in developing regions. The review highlights a need for hybrid, context-sensitive approaches that combine technical controls with strategic planning, stakeholder engagement, and regulatory alignment. This study contributes to the cybersecurity literature by providing a consolidated understanding of how existing frameworks address risk in HEIs and identifying key gaps for future research and model development. It offers insights for academic policymakers, IT leaders, and researchers seeking to strengthen cybersecurity resilience in university settings.

Read the paper · More papers on PaperTik