2023· International Journal of Multidisciplinary Research and Growth Evaluation· 0 citations
TL;DR
The study concludes that universities require a layered, integrated governance model rather than separate compliance silos, and recommends multidisciplinary oversight, harmonised control catalogues, precise data classification, Zero Trust access, privacy and security by design, recurring impact assessments, supplier accountability, and measurable assurance.
Abstract
This study examines how universities can govern cybersecurity, privacy, and healthcare information within increasingly interconnected digital environments. Its purpose is to clarify how ISO/IEC 27001, the General Data Protection Regulation, and the Health Insurance Portability and Accountability Act can be aligned without obscuring their distinct legal and operational requirements. A structured narrative review was undertaken using peer-reviewed literature, recognised standards, regulatory guidance, and relevant institutional studies published up to 2023. The analysis focused on smart campus architecture, data flows, cyber-risk exposure, information security management, privacy accountability, healthcare data protection, regulatory interoperability, governance barriers, and emerging technologies.
The findings indicate that ISO/IEC 27001 provides an effective institutional backbone for risk management, leadership accountability, control assurance, and continual improvement. However, GDPR introduces broader obligations relating to lawful processing, transparency, data-subject rights, and privacy by design, while HIPAA imposes specialised safeguards for protected health information within covered university healthcare functions. Significant convergence exists in access control, incident response, supplier oversight, documentation, workforce training, and continuous monitoring, yet divergence remains in legal scope, enforcement, individual rights, and breach obligations. The review further identifies fragmented authority, legacy infrastructure, shadow systems, cross-border processing, third-party dependence, and emerging technologies as major governance challenges.
The study concludes that universities require a layered, integrated governance model rather than separate compliance silos. It recommends multidisciplinary oversight, harmonised control catalogues, precise data classification, Zero Trust access, privacy and security by design, recurring impact assessments, supplier accountability, and measurable assurance. It also emphasises ethical governance of artificial intelligence, analytics, and connected infrastructure. Future research should empirically evaluate integrated models across jurisdictions, institutional types, and resource-constrained settings.
This review synthesizes peer-reviewed literature on governance structures, auditing methods, and resulting outcomes across key sectors including financial services, capital markets, healthcare, and critical infrastructure to reveal consistent emphasis on integrated governance approaches alongside persistent implementation tensions.
William Asare Yirenkyi, Apaflo Godson Teye, Matilda Konotey et al.· Magna Scientia Advanced Rese...· 0 citations
The increasing complexity of cyber threats, interconnected technologies, and data-intensive digital services has exposed limitations in security strategies that depend on isolated controls. This study develops a multi-level cybersecurity and privacy framework that integrates complementary controls across physical, network, endpoint, application, data, identity and access management, monitoring and incident response, and human and policy domains. The framework was developed through structured synthesis of the ten cybersecurity and privacy studies reviewed in the source manuscript and alignment with established cybersecurity guidance. The revised model treats monitoring and incident response as a cross-cutting capability and privacy and governance as cross-cutting concerns. It further introduces a measurable evaluation structure based on layer-specific security indicators and an overall Multi-Level Cybersecurity Resilience Index. The framework is mapped to NIST Cybersecurity Framework 2.0, ISO/IEC 27001:2022, and Zero Trust principles. The resulting architecture provides a practical basis for coordinating preventive, detective, responsive, recovery, governance, and privacy controls. Because the source studies did not include primary empirical testing, the present manuscript does not claim empirical effectiveness; instead, it specifies a validation protocol using expert assessment and/or controlled simulation. This study contributes an integrated architectural model and a measurable evaluation approach for organizations seeking adaptive and resilient cybersecurity.
The study concludes that trustworthy digital participation depends on the integration of technical safeguards, enforceable rights, organisational culture, and transparent governance, and recommends embedding security and privacy by design, strengthening incident preparedness, improving workforce competence, enhancing regulatory cooperation, and adopting measurable accountability mechanisms.
Bisola Akeju, Shalom Alugwe, Ayokunle Olamide Ijagbemi· International Journal of Mul...· 0 citations
The rapid expansion of digital technologies and cross-border data flows has fundamentally transformed the ways in which personal data are accessed, processed, and exchanged, creating new challenges for cyber regulation and individual data rights. In the Hashemite Kingdom of Jordan, the development of data protection regulations has not yet fully addressed the legal complexities associated with data access consent, technological transformation, and emerging forms of digital exploitation. This study aims to critically examine Jordan’s cyber regulatory framework governing personal data access and consent by evaluating its conceptual foundations, legislative coherence, enforcement capacity, and responsiveness to contemporary technological developments. The study employs a descriptive-analytical legal approach to examine statutory provisions, regulatory instruments, and relevant legal principles governing personal data, consent, privacy, intellectual property, and cybersecurity. A comparative approach is also employed selectively to identify regulatory practices from contemporary data protection frameworks that may inform legal reform in Jordan. The findings demonstrate a persistent regulatory gap between the pace of technological innovation and the capacity of existing legal mechanisms to provide effective and enforceable protection. Particular weaknesses emerge in the regulation of informed consent, personal data rights, data-related intellectual property interests, institutional enforcement, and cross-border data transfers. The study further finds that consent-based regulation can serve as a central mechanism for reconciling individual autonomy, data protection, and legitimate access to personal data, provided that consent is transparent, informed, specific, and effectively enforceable. Scientifically, this study contributes a reform-oriented framework for strengthening Jordan’s cyber regulatory architecture through legislative modernization, clearer institutional responsibilities, stronger cross-border cooperation, accountable data-consent platforms, technological safeguards, and enhanced public legal awareness. These reforms are essential for developing a rights-based and technologically responsive data governance regime in Jordan.
Mohammed Ali Khaled Al-Shurman, Wail Abouabaid, Hasan Jassam Ahmed et al.· Nusantara· 1 citation
: As cybersecurity regulations such as ISO/IEC 27001 and the NIS2 Directive continue to expand in scope and complexity, organizations face growing challenges in translating regulatory obligations into actionable security policies and audit-ready evidence. Conventional compliance approaches rely on manual interpretation of regulatory texts, fragmented documentation repositories, and ad hoc audit preparation, introducing operational bottlenecks and exposing organizations to non-compliance risks. This paper presents a compliance management platform that operationalizes regulatory requirements through structured, expert-guided control implementation. It combines NLP extraction with human-supervised annotation to convert regulatory texts into machine-readable frameworks, enabling multi-framework management (ISO/IEC 27001:2022 and NIS2), control mapping, evidence tracking, and role-based audit workflows. In a task-based usability study with twelve participants, the platform scored 83.3 on the System Usability Scale (SUS), rated “excellent,” indicating that embedded guidance can reduce expertise barriers in cybersecurity compliance management.
Mariana Andrade, João Rafael Almeida, J. Oliveira· International Conference on...· 0 citations
A novel, unified governance framework centred on digital trust is proposed that distinctly integrates the AI Trust Framework and Maturity Model (AI TMM), the Tiered Ethical Cybersecurity Model (TECM), and privacy preserving technologies such as federated learning to operationalize ethics by design.
Muhammad Faris bin Nordin, Muhammad Din bin Khalid, Normal Mat Jusoh· International journal of res...· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.