The key information security challenges facing universities are creating a security culture in a dynamic environment with changing risks, protecting high value research from internal and external threats during international collaboration, and managing risks from commodity and advanced hackers. To address these, the document proposes adopting the PDCA (Plan-Do-Check-Act) approach from ISO27001 to continuously identify, assess, treat, review, and adapt controls for the university's information assets and risks. This includes planning by identifying assets and risks, implementing controls, checking effectiveness, and acting to improve based on lessons learned.
Related topics: