A Lightweight BYOD Cybersecurity Governance and Risk Assessment Framework for University Students
DOI:
https://doi.org/10.31098/quant.4555Keywords:
BYOD, Cybersecurity Governance, Risk Assessment, University Students, Information Security, NIST CSF, ISO/IEC 27001, Data ProtectionAbstract
The increasing use of personal laptops, smartphones, and tablets for academic activities has made Bring Your Own Device practices common in university environments. Although BYOD improves flexibility and accessibility, it also creates cybersecurity and data protection risks, including weak password practices, outdated devices, unsafe network usage, malware exposure, and limited user awareness. This study aims to develop a lightweight BYOD cybersecurity governance and risk assessment framework for university students. A quantitative survey-based method is used to collect data from university students regarding their BYOD usage and security practices. The collected responses are analyzed using descriptive statistics and a likelihood-impact risk scoring model. Based on the findings, the study proposes the Lightweight BYOD Governance and Risk Framework, which includes risk identification, risk assessment, governance, protection, education, and periodic review. The proposed framework provides practical guidance for universities to manage BYOD-related risks using simple and low-cost governance controls. The study contributes to cybersecurity governance by connecting student behavior, risk assessment, and policy-based security recommendations in a university context.

