Content area

Abstract

Cybercriminals constantly seek new methods to infiltrate a company's defences, making cybersecurity investments essential. Enterprise architecture (EA) provides a systematic risk detection and mitigation process by emphasising the interdependencies between systems, data, processes, people, and other factors. This paper provides a comprehensive approach, also referred to as a process, based on EA to assist African universities in developing a comprehensive cybersecurity plan. The EA process comprises four pillars: business architecture, data architecture, application architecture, and technology architecture. African universities can develop a comprehensive cybersecurity strategy using an EA approach in cybersecurity to achieve institutional goals and objectives. The potential attack surface comprises isolated EA components and their interconnections. This article comprehensively examines various EA processes such as business, information, application, and technology architecture. These processes are carefully analysed to evaluate the organisational structures and uncover opportunities to enhance security protocols. Additionally, we delve deep into abstract security patterns, seeking to cultivate an environment of trustworthiness within complex systems. Our research findings underscore the significant potential within African higher education institutions. By embracing a model-based approach to risk analysis and mitigation, these institutions can fortify their cybersecurity defences and bolster their capabilities to ensure uninterrupted business operations and enhance overall resilience in the face of evolving security challenges. When we combine EA and information security (ICS), we uncover many vulnerabilities malicious actors might exploit. By embracing a holistic EA-based methodology, institutions can craft and implement robust security protocols to safeguard their components and connections. Leveraging EA, our proposed integrated approach aims to forge a comprehensive cybersecurity risk management strategy tailored to the African higher education sector. This strategy seeks to facilitate the identification of critical elements and their intricate interrelationships, thus formulating an effective defence strategy against potential cyber threats. The synergy between EA and cybersecurity within African universities promises to elevate cybersecurity practices, ensure uninterrupted business operations, and fortify the continent's resilience.

Details

Business indexing term
Title
Integrating Enterprise Architecture into Cybersecurity Risk Management in Higher Education
Author
Nkambule, Mafika 1 ; van Vuuren, Joey Jansen 1 ; Leenen, Louise 2 

 Tshwane University of Technology, Pretoria, South Africa 
 University of the Western Cape and CAIR, Cape Town, South Africa 
Pages
501-510
Publication year
2024
Publication date
Mar 2024
Publisher
Academic Conferences International Limited
Place of publication
Reading
Country of publication
United Kingdom
Publication subject
Source type
Conference Paper
Language of publication
English
Document type
Conference Proceedings
ProQuest document ID
3082337046
Document URL
https://www.proquest.com/conference-papers-proceedings/integrating-enterprise-architecture-into/docview/3082337046/se-2?accountid=208611
Copyright
Copyright Academic Conferences International Limited Mar 2024
Last updated
2025-11-14
Database
2 databases
  • ProQuest One Academic
  • ProQuest One Academic