Asee peer logo

Institutional Review Panel for Cybersecurity Research and Education

Download Paper |

Conference

2022 ASEE Annual Conference & Exposition

Location

Minneapolis, MN

Publication Date

August 23, 2022

Start Date

June 26, 2022

End Date

June 29, 2022

Conference Session

CIT Division Technical Session #2

Page Count

21

DOI

10.18260/1-2--40437

Permanent URL

https://peer.asee.org/40437

Download Count

199

Paper Authors

biography

James Nelson Texas A&M University

visit author page

Associate Vice Chancellor in the Texas A&M University System and Director of the RELLIS Academic Alliance.

visit author page

author page

Brent Donham Texas A&M University - Commerce

Download Paper |

Abstract

Cybersecurity is an emerging field with significant implications as the use of interconnected devices increases. We are now at a point where the number of connected devices significantly exceeds the world population. [1]. Each of these devices represents a potential entry point for individuals with malicious intentions. As such, many contend that cybersecurity is national security extending across multiple governmental, industry, and consumer sectors.

To mitigate new and current threats as cybersecurity evolves into the future, considerable education and research is needed on both the operational technology and network sides of the industry. This research and education, by its nature, involves vulnerability testing, intentional network intrusion, virus testing and ethical hacking. The conduct of these activities has associated internal and external risk, as well as ethical considerations. Typically, these tasks require exceptions to the policies and controls in place to protect information. To manage the risk and ensure ethical conduct, a policy requiring review and approval of such activities is necessary. Such a policy, although different in focus, is similar in concept to policies for research and education involving humans and animals.

Presented in this paper is the development of the Cybersecurity Institutional Review Policy and associated Cybersecurity Institutional Review Panel (CIRP) implemented in the [Academic Unit] on the [System Name] University System. An associated review form is expected to be submitted and approved prior to all research and education activities involving cybersecurity. This includes class projects, independent research and study, and faculty research. The CIRP reviews all requests and evaluates if the compensating controls are acceptable. If predetermined risk levels are not exceeded, the policy includes provisions for an expedited or shortened review. The rationale for the provisions in the policy, the levels of review and the makeup of the review panel are discussed. The implemented policy and required review form are included as appendices.

Nelson, J., & Donham, B. (2022, August), Institutional Review Panel for Cybersecurity Research and Education Paper presented at 2022 ASEE Annual Conference & Exposition, Minneapolis, MN. 10.18260/1-2--40437

ASEE holds the copyright on this document. It may be read by the public free of charge. Authors may archive their work on personal websites or in institutional repositories with the following citation: © 2022 American Society for Engineering Education. Other scholars may excerpt or quote from these materials with the same citation. When excerpting or quoting from Conference Proceedings, authors should, in addition to noting the ASEE copyright, list all the original authors and their institutions and name the host city of the conference. - Last updated April 1, 2015