基于学习管理系统分析实例的信息安全风险评估方法

С.А. Абдыманапов, А.Б. Барлыбаев, Б.А. Алтынбек
{"title":"基于学习管理系统分析实例的信息安全风险评估方法","authors":"С.А. Абдыманапов, А.Б. Барлыбаев, Б.А. Алтынбек","doi":"10.31489/2022ped3/84-95","DOIUrl":null,"url":null,"abstract":"The active development and application of new digital technologies in education, on the one hand, has opened up new opportunities for improving the efficiency of the university’s business process management. On the other hand, this has led to a significant increase in security threats and the vulnerability of educational institutions to cyber criminals. The recent rapid growth of various incidents regarding cybercrimes shows the insufficiency of traditional approaches to information security. Consequently, information security risk assessment has become an important task for most educational institutions. Several models have been proposed to help educational institutions solve problems with building information security. This article proposes a new hierarchical structured model for assessing information security risks in educational institutions using fuzzy logic. A new method for assessing information security risks is also described using the example of automated control systems or ERP systems (for example, training management systems). The proposed risk assessment of the university was modeled using fuzzy logic in the form of 15 fuzzy machines. In the course of a number of experiments, we carefully studied the assessment of information security risks of various software products used in universities. The proposed method should solve the problem of flexible risk assessment.","PeriodicalId":336594,"journal":{"name":"Bulletin of the Karaganda University. Pedagogy series","volume":"39 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2022-09-29","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":"{\"title\":\"InfoSec Risk Assessment Methodology based on the example of Learning Management Systems Analysis\",\"authors\":\"С.А. Абдыманапов, А.Б. Барлыбаев, Б.А. Алтынбек\",\"doi\":\"10.31489/2022ped3/84-95\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"The active development and application of new digital technologies in education, on the one hand, has opened up new opportunities for improving the efficiency of the university’s business process management. On the other hand, this has led to a significant increase in security threats and the vulnerability of educational institutions to cyber criminals. The recent rapid growth of various incidents regarding cybercrimes shows the insufficiency of traditional approaches to information security. Consequently, information security risk assessment has become an important task for most educational institutions. Several models have been proposed to help educational institutions solve problems with building information security. This article proposes a new hierarchical structured model for assessing information security risks in educational institutions using fuzzy logic. A new method for assessing information security risks is also described using the example of automated control systems or ERP systems (for example, training management systems). The proposed risk assessment of the university was modeled using fuzzy logic in the form of 15 fuzzy machines. In the course of a number of experiments, we carefully studied the assessment of information security risks of various software products used in universities. The proposed method should solve the problem of flexible risk assessment.\",\"PeriodicalId\":336594,\"journal\":{\"name\":\"Bulletin of the Karaganda University. Pedagogy series\",\"volume\":\"39 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2022-09-29\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"0\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"Bulletin of the Karaganda University. Pedagogy series\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.31489/2022ped3/84-95\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"Bulletin of the Karaganda University. Pedagogy series","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.31489/2022ped3/84-95","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0

摘要

新的数字技术在教育中的积极发展和应用,一方面为提高大学业务流程管理的效率开辟了新的机遇。另一方面,这导致安全威胁显著增加,教育机构容易受到网络罪犯的攻击。近年来,各种网络犯罪事件的快速增长表明了传统信息安全方法的不足。因此,信息安全风险评估已成为大多数教育机构的一项重要任务。人们提出了几种模式来帮助教育机构解决建筑信息安全问题。本文利用模糊逻辑提出了一种新的教育机构信息安全风险评估层次结构模型。本文还以自动化控制系统或ERP系统(例如培训管理系统)为例,描述了一种评估信息安全风险的新方法。采用模糊逻辑,以15个模糊机的形式对所提出的大学风险评估进行建模。在多次实验的过程中,我们认真研究了高校使用的各种软件产品的信息安全风险评估。所提出的方法应解决风险评估的灵活性问题。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
InfoSec Risk Assessment Methodology based on the example of Learning Management Systems Analysis
The active development and application of new digital technologies in education, on the one hand, has opened up new opportunities for improving the efficiency of the university’s business process management. On the other hand, this has led to a significant increase in security threats and the vulnerability of educational institutions to cyber criminals. The recent rapid growth of various incidents regarding cybercrimes shows the insufficiency of traditional approaches to information security. Consequently, information security risk assessment has become an important task for most educational institutions. Several models have been proposed to help educational institutions solve problems with building information security. This article proposes a new hierarchical structured model for assessing information security risks in educational institutions using fuzzy logic. A new method for assessing information security risks is also described using the example of automated control systems or ERP systems (for example, training management systems). The proposed risk assessment of the university was modeled using fuzzy logic in the form of 15 fuzzy machines. In the course of a number of experiments, we carefully studied the assessment of information security risks of various software products used in universities. The proposed method should solve the problem of flexible risk assessment.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
自引率
0.00%
发文量
0
期刊最新文献
Эффективность применения таксономии Б. Блума при обучении студентов русскому языку как неродному Development of soft skills of high school students as an opportunity to implement the requirements of modern education Реализация конструктивистского подхода к обучению при разработке приложений виртуальной и дополненной реальности Профессиональная ориентация обучающихся в Казахстане в фокусе инклюзивности Оқушылардың жоғары деңгейдегі ойлау дағдыларын сұрақ қою әдісі арқылы қалыптастыру жолдары
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1