Management of digital information security projects in higher education institutions: traditional and agile approaches
DOI:
https://doi.org/10.5281/zenodo.21875518Keywords:
cyber resilience; compliance; risk portfolio; iterative planning; university infrastructure; digital maturity; continuous improvement; governance layer.Abstract
Objective. The study aims to provide a theoretical justification and structural model for managing digital information security projects in higher education institutions through a comparison of traditional, agile, and hybrid approaches. Methods. The research uses systems analysis, comparative analysis, content analysis of scholarly publications and international standards, project classification, expert-analytical comparison of criteria, and modelling. Waterfall, Agile, Scrum, and Kanban were assessed according to regulatory compliance, threat adaptability, budget predictability, speed of value delivery, control transparency, stakeholder involvement, and suitability for resource-constrained environments. Results. Digital information security projects in universities are specified as socio-technical, cross-functional, and continuously changing systems. An extended project typology was developed, covering regulatory and compliance, infrastructure, identity and access management, monitoring, awareness and training, incident recovery, and research and innovation projects. Waterfall was found appropriate when requirements are stable and procedures are strictly regulated; Agile and Scrum are preferable under high uncertainty and when iterative improvement and frequent stakeholder feedback are essential; Kanban is effective for a continuous flow of operational security tasks. A hybrid model is proposed in which the strategic layer covers initiation, compliance, architecture design, and stage-gate control, whereas the adaptive layer relies on short iterations, risk backlog prioritisation, testing, retrospectives, and continuous adjustment of safeguards. Conclusions. Management effectiveness depends not on formally selecting a single methodology but on aligning the management mode with project type, cyber-risk level, institutional digital maturity, and available resources. The hybrid model reconciles regulatory discipline with operational adaptability, supports transparent allocation of responsibility, and can serve as an organisational framework for university practice and the education of cybersecurity professionals.
Downloads
Published
How to Cite
Issue
Section
License
Copyright (c) 2026 Андрій Анатолійович Краснік

This work is licensed under a Creative Commons Attribution 4.0 International License.