Critical Analysis of Cybersecurity Frameworks and Zero Trust Adoption in Higher Education
Loading...
Date
Authors
Journal Title
Journal ISSN
Volume Title
Publisher
The British University in Dubai (BUiD)
Abstract
Higher education institutions continue to be increasingly targeted by cyber threats, yet still rely on frameworks designed for corporate and government environments rather than academic ones. This dissertation critically analyses how far NIST CSF, ISO/IEC 27001, and CIS Controls align with the organisational, cultural, and governance structures of higher education institutions, and where Zero Trust Architecture genuinely improves on them or introduces new challenges. The research adopts an interpretivist philosophy and inductive approach, it combines a PRISMA-guided systematic review of 46 sources from an initial pool of 259, with a documentary analysis of public governance documents from the University of Oxford and MIT. The central argument is that universities are dual natured organisations functioning both as enterprises managing HR, finance, procurement, and sometimes medical services, and as open academic communities built around teaching, research, and cross institutional collaboration. This duality is the fundamental reason why both traditional frameworks and Zero Trust Architecture falls short in higher education, as neither approach was designed to accommodate this dual identity. Thematic and documentary analysis together shows that Oxford and MIT already apply differentiated governance across different functional areas informally, even though no formal sector wide framework exists to codify this. In response, this dissertation proposes TRACE, the Tiered and Responsive Academic Cybersecurity Environment, organising security controls across three tiers: TRACE-E for enterprise functions, TRACE-A for academic and research functions, and TRACE-O for open access functions, each applying controls proportional to its actual risk profile within a federated governance structure.