Monday, May 3, 2021

ISO/IEC 27001. Information Security Management System

 ISO/IEC 27001 is one of the world's most popular standards. It demonstrates a company can be trusted with information because it has sufficient controls in place to protect it. Many tech giants, financial institutions, health services providers, insurance companies, education institutions, manufacturing and service companies, large and small business around the world have this standard in place in order to have it as a proof of their capability to protect the confidentiality, integrity and availability of the information they process.

The management system requirements of ISO/IEC 27001 cover macro issues of 

  1. the context of the organization, 
  2. leadership, 
  3. information security policy and objectives, 
  4. information security risk assessment and treatment, 
  5. competence and awareness, 
  6. documented information, 
  7. operational planning and control, 
  8. internal audit, 
  9. management review, 
  10. nonconformity and corrective action 

Then there is these controls from Annex A of ISO/IEC 27001 - there are 114 information security controls. The topics include aspects such as: 
  1. Information security policies, 
  2. organization of information security, 
  3. mobile devices and teleworking, 
  4. security of human resources, 
  5. asset management, 
  6. classification of information, 
  7. media handling, 
  8. access control, 
  9. user responsibilities, 
  10. system and application access control, 
  11. cryptography, 
  12. physical and environmental security, 
  13. equipment security, 
  14. operations security, 
  15. protection from malware, 
  16. backup, 
  17. logging and monitoring, 
  18. control of operational software, 
  19. technical vulnerability management, 
  20. communications security, 
  21. network security management, 
  22. information transfer, 
  23. system acquisition, 
  24. development and maintenance, 
  25. security in development and support, 
  26. supplier relationships, 
  27. incident management, 
  28. information security as part of business continuity management, 
  29. redundancies and compliance.
Here are some links:
https://www.iso.org/isoiec-27001-information-security.html
https://www.iso.org/certification.html

Sunday, May 2, 2021

Self-regulated (Personalised) Learning During COVID-19

Overview

According to a recent report from UNESCO (2020), more than 1.9 billion students -children and youth- from 190 countries are forced to transfer their education from face-to-face to online form to fight the outbreak of COVID-19. This sudden shift created 

  1. crisis in terms of course design, evaluation tools and teaching strategies (Affouneh et al., 2020)
  2. a high level of stress, anxiety, and uncertainty among educators

However, several emerging technologies came to the rescue in higher education settings whether using these tools on campus, blended, or fully in online environments (Czerkawski & Lyman, 2016). These technologies reshaped student engagement for learning through new features that enable learners and instructors to communicate synchronously and asynchronously (Bergdahl et al., 2020; Khlaif & Farid, 2018).

There has been an abundance of research on online learning before the COVID-19 crisis to understand the factors influencing student’s engagement in online learning which could differ from the factors  influencing student’s engagement in online learning during a crisis like the COVID-19 pandemic.

  1. What are the factors that influence student personalised learning during an environment such as COVID-19 in developed countries?
  2. How do these factors influence the implementation and continuity of online classes in an emergency remote environment in developed countries? 

Teachers’ presence and quality of content were the major factors that influence student engagement and their learning normally. In online leaning, on the other hand, several factors such as infrastructure factors, cultural factors, digital inequality, and digital privacy influence student engagement in online leaning. 

Definition of Personalised Learning

Different definitions of student engagement have been proposed by many researchers.

Personalised learning has been variously defined and interpreted in practice. Larry Cuban provides a useful discussion of the range of personalised learning offerings, including examples from practice.

Personalised learning refers to the various educational programsmes, instructional methods, and academic support strategies to address the distinct learning needs of each individual student. The goal of personalised learning is to help each student achieve academic success by first understanding the learning needs, interests, and aspirations of individual students, and then providing customised learning. The foundation of personalised learning is for each and every student to become involved in making decisions about their education: what they would like to learn and how.

Personalisation of learning is conceptualised in a range of ways:

  1. Personalisation of content; students engaging with content, topics and areas that are of particular interest to them.
  2. Personalisation of pace and progress; students progressing through the content and curriculum levels at their own pace.
  3. Personalisation of process; instructional approaches and learning environments vary based on the students’ needs and interests.

Personalisation often includes the following tenets:

  • Learning is competency based, with students moving on once they have demonstrated mastery of a concept.
  • Learning is flexible, and is not restricted to traditional schooling structures or timetables
  • Students are encouraged to demonstrate agency and to take a level of ownership over their learning journey
  • Students’ interests, strengths and passions are incorporated into their learning

To summarise, Bond (2020) defines PL as "the energy and effort that students employ within their learning community, observable via any number of behavioural, cognitive or affective indicators across a continuum" . In addition, Dixson (2015) defines it as the effort that the learner makes to acquire knowledge and build his/her critical thinking skills through staying involved in the learning process. Moreover, Wong and Chong (2018) defined PL as a unique collection of comprised active and collaborative learning, participation in enriching learning activities, communication with teachers and among learners, involvement in educational experiences, and feeling supported.

-------------------------------------------------------------
Affouneh, S., Salha, S., & Khlaif, Z. N. (2020). Designing quality e-learning environments for emergency remote teaching in coronavirus crisis. Interdisciplinary Journal of Virtual Learning in Medical Sciences, 11(2), 135–137.

Czerkawski, B. & Lyman, B. (2016). An Instructional Design Framework for Fostering Student Engagement in Online Learning Environments. Tech Trends 60, 532–539 (2016). https://doi.org/10.1007/s11528-016-0110-z


Monday, April 26, 2021

Real-time Learning Analytics

Real-time Learning Analytics (RLA) visualizes and analyses the data as it appears in the computing system which is a Learning Management System (LMS). It is the use of data and the related resources for analysis as soon as it becomes available in the LMS. The term real-time always refers to computer responsiveness and is associated with streaming data architectures which enable real-time operational decisions automatically through process automation and/or policy enforcement.

Real-time analytics helps us with the following:

  1. Forming just-in time teaching decisions and applying them to learning activities -- including day-to-day teaching/learning processes and transactions -- on an ongoing basis.
  2. Viewing dashboard displays in real-time with constantly updated transactional data sets.
  3. Utilizing existing prescriptive and predictive analytics
  4. Reporting historical and current data simultaneously.
Real-time Learning Analytics (RLA) ensures that data analysis is done as close to the data's origin as possible. In addition to edge computing, other technologies that support RLA include:

  1. Processing in memory -- a chip architecture in which the processor is integrated into a memory chip to reduce latency. 
  2. In-database analytics -- a technology that allows data processing to be conducted within the database by building analytic logic into the database itself. 
  3. Data warehouse appliances -- a combination of hardware and software products designed specifically for analytical processing. An appliance allows the purchaser to deploy a high-performance data warehouse right out of the box. 
  4. In-memory analytics -- an approach to querying data when it resides in random access memory, as opposed to querying data that is stored on physical disks.
  5. Massively parallel programming -- the coordinated processing of a program by multiple processors that work on different parts of the program, with each processor using its own operating system and memory.
In order for the real-time data to be useful, the RLA applications being used should have high availability and low response times. These applications should also feasibly manage large amounts of data, over time up to terabytes. This should all be done while returning answers to queries within seconds.

The term real-time also includes managing changing data sources -- something that LMSs may have as third-party tools. As a result, the real-time analytics applications should be able to handle big data. The adoption of real-time big data analytics can maximize institutional returns, reduce operational costs and introduce an era where machines can interact over the internet of things using real-time information to make decisions on their own.

Real-time Learning Analytics (RLA) enables educators to react without delay, quickly detect and respond to patterns in learner behaviour, take advantage of opportunities that could otherwise be missed and prevent problems before they arise.

Institutions that utilize real-time analytics greatly reduce at-risk students throughout their teaching tenure since the system uses data to predict outcomes and suggest alternatives rather than relying on the collection of speculations based on past events or recent scans -- as is the case with historical data analytics. Real-time analytics provides insights into what is going on in the moment. The way forward.

Sunday, May 3, 2020

Phishing

Phishing is dangerous because the stakes are high when it comes to email phishing security. It is deadly because certain links are hyperlinked within email text deceptively and it becomes hard to distinguish as dubious by an untrained eye.



Phishing normally have two types of people as its targets:

  1. Spear phishing. In this an email is designed to look like it was sent from a user's manager within an organization. Spear-phishing attacks target a particular person or group of people, usually low-level to mid-level employees.Unsuspecting targets may be fooled by name recognition of trusted names or brands.
  2. Whale phishing. The term whaling is used to describe the size of the attack. Whaling targets are larger authorities within the organization like high-level company executives, like CFOs or CEOs. Employees in high-level positions have the most access to this critical data, which makes them natural targets in this type of phishing attack. Whale phishing creates email messages that look like they are from a trusted brand or client to manipulate the victim into enacting wire or data transfers to the attacker, for example. These email messages are branded with personal or professional information pertinent to the target -- such as job title, name or other details -- gleaned from a variety of sources via social engineering. The level of personalization provides the victim with a false sense of security.

It takes only one click to affect or even compromise the whole network. This is complicated by the fact that many types of phishing scams are not easily eliminated by software alone. It takes a combination of threat detection systems, security awareness training and a vigilant security team to create a solid defense against phishing threats.

Monday, December 3, 2012

Three Dimentions of a Form-Teacher


Form Teacher is vital to the efficient running of the school.The Form Teacher should be the first person to whom a student will turn to for help or advice, although it may sometimes be necessary to refer the matter to the Year Head, Head of School, Deputy Head or, through them, even to an outside agency. It is through regular daily contact that unobtrusive care is exercised.
  1. COMMUNICATION: 
    1. Roll is marked accurately and daily. Reasons for absence will be collected and recorded on the weekly basis. Patterns of lateness and absence are recognised and action is taken to remedy problems relating to lateness and absence.
    2. Ensure that letters to parents are distributed and recorded in student planners.  Returns should be collected and disseminated or passed on. Matters arising from any returns from parents are discussed with Year Head and action is taken on problems and queries. Register notices give essential last minute messages and along with messages from staff briefing should be read out or passed on to the tutor group. 
    3. Ensure that all students have access to the same quality of pastoral care and supports HODs with constructive criticism.This is to take an active role in initiating new developments or shouldering responsibility for maintenance of whole year tasks.
    4. Play the vital role of checking daily the progress students are making and praising and supporting students and arrange to meet parents over matters of concern and in appropriate cases attends meetings of external agencies and to report back and helps whole pastoral team (Head, Dep., Head of School, Year Head) in decision making process.
  2. ASSESSMENT
    1. Gather information from students and other parties which does not appear on formal reports / and develop a thorough knowledge of all students in the form.  In depth picture of both their academic abilities and out of school activities and interests and give advice to students in constructing personal targets and portfolio of achievements.
  3. ETHOS
    1. Student protocol at general assemblies
    2. Maintain the standards of discipline and uniform
    3. Check student diaries