Graduate School, University of La Salette, Inc., Santiago City, Philippines.
Global Journal of Engineering and Technology Advances, 2026, 26(03), 244-256
Article DOI: 10.30574/gjeta.2026.26.3.0072
Received on 18 February 2026; revised on 26 March 2026; accepted on 28 March 2026
This study was conducted to assess the Information Security practices in Higher Education. The descriptive method was used with a questionnaire as the main tool in gathering data for the study. Statistical tools such as the weighted mean were used in analyzing and interpreting the data gathered. The research was conducted within all nine private higher education institutions located in the Santiago City. The study’s findings indicate that respondents perceive their institution as consistently implementing information security practices aligned with ISO/IEC 27001 standards across key domains, including risk assessment, security organization, asset management, human resource security, communications and operations management, access control, system development, incident management, and compliance. Nevertheless, the respondents also identified slight challenges in all nine areas. This suggests that although policies and procedures are in place, their operational maturity and consistency require further development to achieve full alignment with ISO 27001. Addressing these gaps is critical to enhancing the institution’s resilience, particularly in the context of evolving cybersecurity threats.
Information Security; Higher Education Institutions (HEIS); Digitalization; Cybersecurity; Data Protection and Information Systems Security
Preview Article PDF
Esli Joy N. Fernando. ISO 27001 Readiness: Information security practices and implementation challenges in higher education institutions. Global Journal of Engineering and Technology Advances, 2026, 26(03), 244-256. Article DOI: https://doi.org/10.30574/gjeta.2026.26.3.0072.





