Management of digital information security projects in higher education institutions: traditional and agile approaches

Authors

  • Andrii A. Krasnik PhD in Technical Sciences, associate professor, department of intelligent systems and digital technologies, Academy of labor, social relations and tourism Kyiv 03188, Ukraine https://orcid.org/0009-0004-8737-5389

DOI:

https://doi.org/10.5281/zenodo.21875518

Keywords:

cyber resilience; compliance; risk portfolio; iterative planning; university infrastructure; digital maturity; continuous improvement; governance layer.

Abstract

Objective. The study aims to provide a theoretical justification and structural model for managing digital information security projects in higher education institutions through a comparison of traditional, agile, and hybrid approaches. Methods. The research uses systems analysis, comparative analysis, content analysis of scholarly publications and international standards, project classification, expert-analytical comparison of criteria, and modelling. Waterfall, Agile, Scrum, and Kanban were assessed according to regulatory compliance, threat adaptability, budget predictability, speed of value delivery, control transparency, stakeholder involvement, and suitability for resource-constrained environments. Results. Digital information security projects in universities are specified as socio-technical, cross-functional, and continuously changing systems. An extended project typology was developed, covering regulatory and compliance, infrastructure, identity and access management, monitoring, awareness and training, incident recovery, and research and innovation projects. Waterfall was found appropriate when requirements are stable and procedures are strictly regulated; Agile and Scrum are preferable under high uncertainty and when iterative improvement and frequent stakeholder feedback are essential; Kanban is effective for a continuous flow of operational security tasks. A hybrid model is proposed in which the strategic layer covers initiation, compliance, architecture design, and stage-gate control, whereas the adaptive layer relies on short iterations, risk backlog prioritisation, testing, retrospectives, and continuous adjustment of safeguards. Conclusions. Management effectiveness depends not on formally selecting a single methodology but on aligning the management mode with project type, cyber-risk level, institutional digital maturity, and available resources. The hybrid model reconciles regulatory discipline with operational adaptability, supports transparent allocation of responsibility, and can serve as an organisational framework for university practice and the education of cybersecurity professionals.

Published

2026-05-30

How to Cite

Krasnik, A. A. (2026). Management of digital information security projects in higher education institutions: traditional and agile approaches. Pedagogical Academy: Scientific Notes, (30). https://doi.org/10.5281/zenodo.21875518

Issue

Section

Theory and methodology of professional education