Enhancing security and privacy in credit transfer application systems: A proposed framework

Farah Farzana Abdul Aziz (1) , Raznida Isa , Noraliza Azizan , Noornajwa Md Amin , Noorshamshillah Kamarzaman , Siti Fajar Jalal
(1) Universiti Poly-Tech Malaysia, Malaysia

Abstract

Automated credit transfer systems in higher education offer substantial efficiency improvements but also introduce critical data security and confidentiality challenges. This paper addresses the current security vulnerabilities in the Universiti Poly-Tech Malaysia (UPTM) prototype of the Credit Transfer Application System (CTAS), which lacks essential security features such as user authentication, role-based authorization and encrypted data protection. To address these issues, this study proposes a secure academic data management framework incorporating secure user authentication, role-based access control, encrypted database storage and secure HTTPS communication protocols. The research methodology includes comprehensive security requirement analysis, detailed system architecture design, and the development of a validation plan comprising system simulation, penetration testing, performance evaluation, and compliance assessment to be conducted in future work. The proposed framework is expected to strengthen system access control, improve user accountability, enhance data privacy, and facilitate alignment with Malaysia’s Personal Data Protection Act (PDPA). This study presents a practical and scalable security solution that can guide future system enhancements and deployment, providing a strong foundation for safeguarding academic data and supporting potential cross-institutional credit transfer initiatives. Additionally, the framework contributes to improving institutional credibility, ensuring data protection best practices and promoting digital transformation in academic processes in higher education.

Full text article

Generated from XML file

References

Al-Slais, Y., & Ali, M. (2023). Robotic Process Automation and Intelligent Automation security challenges: A review. https://doi.org/10.1109/CyMaEn57228.2023.10050996

Alaattin Burak Bekmezci, Cigdem Eris, & Pinar Sarisaray Boluk. (2018). A multi-layered approach to securing enterprise applications by using TLS, two-factor authentication and single sign-on. https://doi.org/10.1109/siu.2018.8404773

Almakdi, S., & Alshehri, M. S. (2023). Developing an attack model for compromising privacy over secure connection protocols. 2023 IEEE 6th International Conference on Computer and Communication Engineering Technology (CCET), 43–47. https://doi.org/10.1109/ccet59170.2023.10335137

Ashwani Goyal. (2024). Blockchain for academic integrity preventing fraud and enhancing transparency in education. Advances in Nonlinear Variational Inequalities, *28*(3s), 109–124. https://doi.org/10.52783/anvi.v28.2853

Chandrasekaran, D., & Mago, V. (2022). Automating transfer credit assessment—A Natural Language Processing-Based approach. Computers, Materials & Continua, *73*(2), 2257–2274. https://doi.org/10.32604/cmc.2022.027236

Chordiya, A. R., Majumder, S., & Javaid, A. Y. (2018). Man-in-the-Middle (MITM) attack based hijacking of HTTP traffic using open source tools. 2018 IEEE International Conference on Electro/Information Technology (EIT). https://doi.org/10.1109/eit.2018.8500144

Destini, J. S., & Tony, T. (2024). Implementing hierarchical role-based access control for document administration in student organizations. Internet of Things and Artificial Intelligence Journal, *4*(4), 785–802. https://doi.org/10.31763/iota.v4i4.832

Dr. Pradeep Kumar Tiwari. (2025). Digital trust in education: Investigating the relationship between cybersecurity practices and student confidence in online learning. International Journal of Advanced Research in Science, Communication and Technology, 245–252. https://doi.org/10.48175/ijarsct-26432

Gharpure, N., & Rai, A. (2022). Vulnerabilities and threat management in relational database management systems. https://doi.org/10.1109/icast55766.2022.10039599

Halawi, L., & Makwana, A. (2023). The GDPR and UK GDPR and its impact on US academic institutions. Issues in Information Systems, *24*(2). https://doi.org/10.48009/2_iis_2023_120

Hamin, Z., Saslina Kamaruddin, Noh, M., Othman, M. B., & Mohamad, A. M. (2025). Recent reforms to the Personal Data Protection Act 2010 and its implications for business organisations in Malaysia. International Journal of Research and Innovation in Social Science, IX(IV), 410–422. https://doi.org/10.47772/IJRISS.2025.90400033

Impola, J. (2024). European credit transfer and accumulation system as a time-based predictor of student workload. Higher Education Research & Development, *44*(2), 417–430. https://doi.org/10.1080/07294360.2024.2406490

Ismail, S. (2024). Personal Data Protection Policy: Ensuring effective implementation of data privacy policies in private higher institutions. International Journal of Law, Government and Communication, *9*(35), 45–55. https://doi.org/10.35631/ijlgc.935005

Jones, K. M. L., & VanScoy, A. (2019). The syllabus as a student privacy document in an age of learning analytics. Journal of Documentation, *75*(6), 1333–1355. https://doi.org/10.1108/jd-12-2018-0202

Kebande, V. R., Karie, N. M., & Ikuesan, R. A. (2020). Real-time monitoring as a supplementary security component of vigilantism in modern network environments. International Journal of Information Technology, *13*(1), 5–17. https://link.springer.com/article/10.1007/s41870-020-00585-8

Krishnarajan S, & A. Rengarajan. (2024). Surveying authentication and authorization mechanisms in today's web technology landscape. International Journal of Innovative Research in Computer and Communication Engineering, *12*(05), 6337–6340. https://doi.org/10.15680/ijircce.2024.1205198

Llanten-Lucio, Y.-I., Amador-Donado, S., & Marc eles-Villalba, K. (2022). Validation of cybersecurity framework for threat mitigation. Revista Facultad de Ingeniería, *31*(62), e14840. https://doi.org/10.19053/01211129.v31.n62.2022.14840

Mehra, T. (2024). The critical role of role-based access control (RBAC) in securing backup, recovery, and storage systems. International Journal of Science and Research Archive, *13*(1), 1192–1194. https://doi.org/10.30574/ijsra.2024.13.1.1733

Muhammad Adil Inam, Chen, Y., Goyal, A., Liu, J., Mink, J., Michael, N., ... Wajih Ul Hassan. (2023). SoK: History is a vast early warning system: Auditing the provenance of system intrusions. https://doi.org/10.1109/sp46215.2023.10179405

Neeli, S. S. S. (2025). A hands-on guide to data integrity and privacy for database administrators. International Journal of Scientific Research in Engineering and Management, *09*(01), 1–6. https://doi.org/10.55041/ijsrem16443

Pollard, E., Hadjivassiliou, K., & Swift, S. (2017). Credit transfer in higher education: A review of the literature. Institute for Employment Studies. https://dera.ioe.ac.uk/id/eprint/28446/1/Credit_transfer_in_Higher_Education.pdf

Ramim, M., & Levy, Y. (2006). Securing e-learning systems. Journal of Cases on Information Technology, *8*(4), 24–34. https://doi.org/10.4018/jcit.2006100103

Shah, M. H., & Panchal, M. (2022). Theoretical evaluation of securing modules for educational chatbot. https://doi.org/10.1109/ICICCS53718.2022.9788120

Shah, R., & Correia, S. (2021). Encryption of data over HTTP/HTTPS requests for secure data transfers over the Internet. 2021 International Conference on Recent Trends on Electronics, Information, Communication & Technology (RTEICT). https://doi.org/10.1109/rteict52294.2021.9573978

Simha.R, K., H K, R., Prabhu, A., & Joshi, P. (2024). Beyond passwords: A multi-factor authentication approach for robust digital security. Internet Technology Letters, *8*(2). https://doi.org/10.1002/itl2.555

Singh, S., Kumar, M., & Das, S. (2013). An efficient model for securing identity access in scalable system. International Journal of Computer Applications, *70*(5), 26–30. https://doi.org/10.5120/11959-7793

Strack, H., Gollnick, M., Karius, S., Lips, M., Wefel, S., Altschaffel, R., ... Arn Waßmann. (2022). Digitization of (higher) education processes: Innovations, security and standards. EPiC Series in Computing, *86*, 22–29. https://doi.org/10.29007/rrg4

Tarchila, P. (2021). Protection of personal data for individuals on the territory of the Union of Europe. International Journal of Legal and Social Order, *1*(1). https://doi.org/10.55516/ijlso.v1i1.41

Trofymenko, O., Loginova, N., Serhii, M., & Dubovoil, Y. (2022). Cyberthreats in higher education. Cybersecurity: Education, Science, Technique, *4*(16), 76–84. https://doi.org/10.28925/2663-4023.2022.16.7684

Tyshyk, I. (2024). Implementation of database security based on Oracle Audit Vault and Database Firewall. Cybersecurity: Education, Science, Technique, *2*(26), 56–70. https://doi.org/10.28925/2663-4023.2024.26.666

Authors

Farah Farzana Abdul Aziz
farah_aziz@uptm.edu.my (Primary Contact)
Raznida Isa
Noraliza Azizan
Noornajwa Md Amin
Noorshamshillah Kamarzaman
Siti Fajar Jalal
Abdul Aziz, F. F., Isa, R., Azizan, N., Md Amin, N., Kamarzaman, N., & Jalal, S. F. (2025). Enhancing security and privacy in credit transfer application systems: A proposed framework. The Asian Journal of Professional & Business Studies, 6(2), 73–85. https://doi.org/10.61688/ajpbs.v6i2.422

Article Details

Similar Articles

1 2 > >> 

You may also start an advanced similarity search for this article.

Facial recognition smart security door

Muhamad Zul Afiq Zulkifli, Airuddin Ahmad, Norreha Othman, Nor Hafiza Abd Samad
Abstract View : 405
Download :260