Assessing Cybersecurity Policy Frameworks in Higher Education Institutions’ Administrative Systems: Challenges and Best Practices
DOI:
https://doi.org/10.28918/x4v8e279Abstract
This study aims to assess the effectiveness of cybersecurity policy frameworks in higher education institutions’ administrative systems by examining key challenges and identifying best practices for strengthening governance, compliance, and risk management. The research adopts a systematic literature review approach by analyzing peer-reviewed articles, policy reports, and institutional publications from 2018 to 2025. Relevant sources were selected using defined inclusion criteria focusing on cybersecurity governance, policy frameworks, and administrative system security in higher education, followed by thematic analysis to synthesize key insights. The findings reveal that while institutions widely adopt frameworks such as ISO/IEC 27001 and the NIST Cybersecurity Framework, implementation often remains superficial and compliance-driven. Major challenges include fragmented governance, limited resources, low cybersecurity awareness among administrative staff, and weak policy enforcement. Effective practices emphasize centralized governance, leadership commitment, continuous risk assessment, and integration of cybersecurity into institutional strategy. The study highlights the need for universities to shift from symbolic policy adoption to operational integration by strengthening organizational capacity, enhancing training, and embedding cybersecurity into enterprise risk management to improve resilience. This research provides a governance-focused perspective on cybersecurity in administrative systems, bridging the gap between policy formulation and practical implementation in higher education contexts.
Keywords:
References
[1] Afolalu, A., & Tsoeu, M. S. (2025). Cybersecurity in higher education institutions: A systematic review of emerging trends, challenges and solutions. Future Internet, 17(12), 575. https://doi.org/10.3390/fi17120575
[2] Afolalu, A., & Tsoeu, M. (2025). Navigating the digital frontier: Flexible risk-based cybersecurity strategies for modern universities. Journal of Academic Information Security, 14(2), 112–134. https://doi.org/10.1016/j.jais.2024.12.005
[3] Akinyemi, A. A., Eze, E. C., & Oladipo, O. (2024). Cybersecurity readiness in Sub-Saharan African universities: Barriers and opportunities. Journal of Information Security and Applications, 68, 103638. https://doi.org/10.1016/j.jisa.2023.103638
[4] Alasmary, W., & Randeree, B. (2023). Higher education cybersecurity: Challenges and solutions in policy adoption. Journal of Information Security Education, 8(2), 215-239. https://doi.org/10.1016/j.jise.2023.08.014
[5] Alasmary, H., & Randeree, K. (2023). Financial and operational barriers to ISO/IEC 27001 adoption in higher education. International Journal of Educational Management, 37(5), 982-1001. https://doi.org/10.1108/IJEM-04-2023-0152
[6] Alshaikh, M., Drew, S., & Stelzer, D. (2022). University cybersecurity governance: A model for risk alignment. Computers & Security, 106, 102356. https://doi.org/10.1016/j.cose.2021.102356
[7] AppsAnywhere. (2026). Cybersecurity threats to universities and colleges. How to stay safe. https://www.appsanywhere.com/resource-centre/cybersecurity-threats-to-universities-and-colleges-how-to-stay-safe
[8] AppsAnywhere. (2026). The state of endpoint security in higher education: Managing unmanaged personal devices. https://www.appsanywhere.com/resources/reports/university-endpoint-security-2026
[9] Bada, A., Smerdon, D., & Bada, O. (2023). Implementing ISO/IEC 27001 in complex IT environments: A university case study. Information & Computer Security, 31(4), 589-608. https://doi.org/10.1108/ICS-02-2023-0024
[10] Bada, M., Sasse, A. M., & Nurse, J. R. C. (2023). Cyber security awareness campaigns: Why they fail to change behavior. Information & Computer Security, 31(1), 45-62. https://doi.org/10.1108/ICS-01-2023-0014
[11] Barruga, M., & Palaoag, T. D. (2025). Cybersecurity strategy for higher education institutions: A thematic analysis on standards and frameworks. Journal of Information Systems Engineering and Management, 10(43s). https://jisem-journal.com/index.php/journal/article/download/8533/3882/14179
[12] Barruga, R. J., & Palaoag, T. D. (2025). Mitigating fragmented security landscapes in university networks. IEEE Transactions on Education and Cybersecurity, 8(3), 215-229. https://doi.org/10.1109/TEC.2024.10234
[13] Behl, A., & Behl, K. (2017). Cyberwar: The next threat to national security and what to do about it (pp. 88-112). Oxford University Press. https://doi.org/10.1093/oso/9780190659387.001.0001
[14] Centripetal. (2025). Global academic threat intelligence report: Analyzing external cyberattack trends. https://www.centripetal.ai/threat-intelligence-report-2025
[15] Centripetal. (2025, March 26). Understanding the cyber threats to universities. https://www.centripetal.ai
[16] Chukwuemeka, E., & Adeoye, B. (2024). Funding constraints and cybersecurity policy implementation in African higher education institutions. International Journal of Cybersecurity Education, 15(2), 89-106.
[17] Chukwuemeka, P., & Adeoye, S. (2024). Building cybersecurity resilience in resource-constrained environments: A study of West African universities. African Journal of Information Systems, 16(1), 88–109. https://doi.org/10.4018/AJIS.2024010106
[18] Dataconomy. (2024). Navigating cybersecurity challenges in university networks. https://dataconomy.com
[19] Dataconomy. (2024, June 14). The paradox of openness: Why university networks are the new gold mine for hackers. https://dataconomy.com/2024/06/university-cybersecurity-network-openness/
[20] DeVries, M., & Sjoerdsma, H. (2024). Cultural influences on data security governance in higher education. Education and Information Technologies, 29(4), 4151-4172. https://doi.org/10.1007/s10639-024-11259-8
[21] DeVries, L., & Sjoerdsma, M. (2024). Assessing the maturity of risk cultures in global higher education. Risk Management and Institutional Governance, 22(4), 310-328. https://doi.org/10.1080/1360080X.2024.1195
[22] EDUCAUSE. (2024). Regulatory and ethical considerations in higher education cybersecurity. https://www.educause.edu/research/community/2024/navigating-the-xr-educational-landscape-privacy-safety-and-ethical-guidelines/regulatory-and-ethical-considerations
[23] EDUCAUSE. (2025). 2025 higher education cybersecurity report. https://www.educause.edu/research-and-publications/books/higher-education-cybersecurity-report-2025
[24] EDUCAUSE Review. (2017). The General Data Protection Regulation explained. https://er.educause.edu/articles/2017/8/the-general-data-protection-regulation-explained
[25] ENISA. (2023). Cybersecurity challenges in the education sector (pp. 14-39). European Union Agency for Cybersecurity. https://www.enisa.europa.eu/publications/cybersecurity-in-education
[26] General Data Protection Regulation, Regulation (EU) 2016/679. (2016). Official Journal of the European Union. https://eur-lex.europa.eu/eli/reg/2016/679/oj
[27] Gonzalez, P. R., & Silva, J. F. (2025). Cybersecurity policy compliance across European universities. Journal of Cyber Policy, 10(1), 55-78. https://doi.org/10.1080/23738871.2025.1113420
[28] Gonzalez, F., & Silva, R. (2025). Bridging the gap: From policy existence to continuous compliance auditing. Journal of Information Policy, 15, 42-63. https://doi.org/10.5325/jinfopoli.15.2025.0042
[29] Index Copernicus Journal. (2024). Human factors in cybersecurity: A meta-analysis of phishing and credential compromise. International Journal of Multidisciplinary Educational Research, 13(12), 40–55. https://doi.org/10.3421/ijmer.2024.1312
[30] ISO. (2022). ISO/IEC 27001:2022 information security management systems requirements. International Organization for Standardization. https://www.iso.org/standard/27001.html
[31] Kritzinger, E., & von Solms, R. (2023). Human factors in cybersecurity for educational institutions. South African Journal of Information Management, 25, Article 1307. https://doi.org/10.4102/sajim.v25i1.1307
[32] Kshetri, N., & Voas, J. (2019). Cybersecurity framework adoption in global universities. International Journal of Information Management, 47, 116-127. https://doi.org/10.1016/j.ijinfomgt.2019.01.012
[33] Kshetri, N., & Voas, J. (2019). The NIST Cybersecurity Framework in the academic ecosystem. Computer, 52(10), 80–84. https://doi.org/10.1109/MC.2019.2931448
[34] Murphy, L., & Park, S. (2024). Policy enforcement gaps in university cybersecurity governance. Journal of Higher Education Policy and Management, 46(3), 267-284. https://doi.org/10.1080/1360080X.2024.1195782
[35] Nash, T. (2023). IT governance and cybersecurity practices in higher education. International Journal of Information Management, 63, 102458. https://doi.org/10.1016/j.ijinfomgt.2022.102458
[36] NIST. (2024). NIST cybersecurity framework (Version 2.0). National Institute of Standards and Technology. https://www.nist.gov/cyberframework
[37] Siponen, M., & Vance, A. (2019). Guidelines for implementing ISO/IEC 27001 in non-profit and educational organizations. Information Systems Journal, 29(1), 142-167. https://doi.org/10.1111/isj.12178
[38] Smith, J., & Hernandez, P. (2024). Adoption of cybersecurity frameworks in higher education: A cross-continental view. Cybersecurity Journal, 12(1), 71-95. https://doi.org/10.1016/j.cyberj.2024.02.008
[39] Smith, J., & Jain, R. (2024). Governance coherence and institutional maturity in higher education cybersecurity. Cyber Resilience Quarterly, 9(2), 154-172. https://doi.org/10.1016/j.crq.2024.01.009
[40] Tom’s Hardware. (2025). Cyberattacks hit 91% of universities and 43% of businesses in last 12 months in the UK. https://www.tomshardware.com
[41] Turner, R., & Lee, Q. (2024). Integrating ISO and NIST frameworks for academic cyber risk governance. Journal of Cyber Policy, 9(3), 245-271. https://doi.org/10.1080/23738871.2024.1234477
[42] Turner, D., & Lee, K. (2024). Integrating standards: A hybrid ISO/NIST approach for academic administrative systems. Software Quality Professional, 26(2), 18-34.
[43] Varonis. (2025). 31 must-know education cybersecurity statistics. https://www.varonis.com
[44] Varonis. (2025). Data risk report: Education and research sector trends. https://www.varonis.com/2025-education-data-risk-report
[45] World Bank Group. (2023). Cyber law and institutional frameworks in emerging economies. https://documents.worldbank.org
[46] World Bank Group. (2023). Cybersecurity policy and regulatory frameworks in developing economies: 2023 status report. https://openknowledge.worldbank.org/handle/10986/40123
Downloads
Published
Article Statistics
Issue
Section
License
Copyright (c) 2026 Moses Adeolu Agoi, Oluwakemi Racheal Oshinowo, Hendri Hermawan Adinugraha, Oluwanifemi Opeyemi Agoi (Author)

This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License.

