Abstract
AI-enabled learning depends on trustworthy data. Yet, education systems often run security controls as isolated tasks, with weak governance links and few integrity metrics. This study proposes AI-Ready ICT Security for Education, a holistic framework that connects governance maturity, access-control maturity, and risk-management practice to data-integrity outcomes in Malaysia’s MOE data centre. The work is grounded in ISO/IEC 27001:2022 (ISMS and control baselines), ISO 31000/31073 (risk concepts), and the Govern function of NIST CSF 2.0 (policy, roles, accountability, and measurement). Using Design Science Research, we develop three artefacts: a policy-to-control-to-metric traceability map, an integrity indicator dictionary (e.g., MFA coverage, orphan-account rate, mean time to revoke privileged access, detect-to-correct time, checksum mismatch rate), and an implementation roadmap. Expert review and a bounded pilot evaluation support feasibility and clarity. Novelty is the integrity-centred measurement layer that operationalises international standards for an education data-centre context, enabling auditable progress towards safe, inclusive AI-supported e-learning.
Metadata
| Item Type: | Article |
|---|---|
| Creators: | Creators Email / ID Num. Ramli, Azlin UNSPECIFIED Darus, Mohamad Yusof UNSPECIFIED |
| Subjects: | L Education > LB Theory and practice of education > Educational technology Q Science > QA Mathematics > Instruments and machines > Electronic Computers. Computer Science > Cryptography. Access control. Computer security |
| Divisions: | Universiti Teknologi MARA, Shah Alam > Institute Of Continuing Education & Professional Studies (iCEPS) |
| Journal or Publication Title: | International Journal on E-Learning and Higher Education (IJELHE) |
| UiTM Journal Collections: | UiTM Journals > International Journal of e-Learning and Higher Education (IJELHE) |
| ISSN: | eISSN: 3030-6663 |
| Volume: | 21 |
| Number: | 1 |
| Page Range: | pp. 121-139 |
| Keywords: | Access control, Data integrity, ISO/IEC 27001, NISTCybersecurity Framework 2.0, Risk management |
| Date: | January 2026 |
| URI: | https://ir.uitm.edu.my/id/eprint/131054 |
