A Holistic Approach for Managing ICT Security in Non-Commercial Organisations A Case Study in a Developing Country

نویسنده

  • Jabiri Kuwe Bakari
چکیده

The use and development of Information and Communication Technology (ICT) has improvedthe efficiency and flexibility in providing services. While computerisation is taking place at afast speed, the security of critical ICT assets is a growing concern for management. This isbecause the potential for financial damage is intensified and may result in the loss of strategicinformation and property, in service interruption and liability claims. If these risks are not takencare of, the objectives of organisations might be negatively affected as well. The research reported here is about improvement of the ICT security management process innon-commercial organisations in order to reduce possible financial damage, taking intoconsideration the realities found in developing countries. The research took place in adeveloping country—Tanzania, where five organisations were involved. The data gatheringinstruments employed were questionnaires with multiple choice questions, open-endedquestions, and face-to-face interviews with some selected respondents. Also, onsite observation(participatory) and documentary review was used. The respondents were mainly seniormanagement, Operational managers, IT Managers and system administrators, and general andtechnical staff.This thesis presents the empirical investigations and analyses carried out in the organisations.The study is organised into seven papers covering: the state of ICT security management in theorganisations; prerequisites when utilising the existing ICT security management approaches inattaining a solution for managing ICT security in the organisations; issues and challenges ofmanaging ICT security; important aspects to be taken into consideration in order to successfullymanage ICT security; and how the management of ICT security in non-commercialorganisations could be improved. Among others, the research was motivated by the observedneed for bridging the perception gap between the management and technicians when dealingwith the ICT security problem, and consequently extending to a common understanding by thestaff in the various departments and specialities within and between the departments.The thesis contributes to increased empirical knowledge on the importance of the holistic ICTsecurity management process. Particularly, our main contribution is the proposed holisticapproach for managing ICT security in non-commercial organisations, organised in the form ofguidelines with two main phases: the initialisation phase which involved the introduction of theICT security management process in the organisation; and the internalised and continuousphase. The research confirmed that the backing of general management and staff is important forthe success of the ICT security management process in the organisation. This implies that themanagement allows the organisation through its own acquired knowledge and confidence, tointernalise the ICT security management practices, thus enabling people to act confidently at alllevels. Knowing about the ICT risks and their consequences for the core service operations ofthe organisation, the management and staff at all levels and from all departments or specialitiesare more likely to offer their support to ICT security endeavours.

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Outsourcing ICT Security to MSSP: Issues and Challenges for The Developing World

The overall use and development of ICT in developing countries has been faced with a wide range of constraints and challenges. These constraints may concern culture, infrastructure and education, and involve social, legal, political or economic issues. Numerous problems related to each of these issues have been observed. The problems may include, for example the absence of ICT policies, impleme...

متن کامل

The Study of Differences between E-commerce Impacts on Developed Countries and Developing Countries, Case Study: USA and Iran

This study determines the impact of E-commerce (EC) on some of important economic criteria including total factor productivity( TFP) of Iran country as a developing country in comparison with US standard as a developed country through analyzing and calculating interrelated issues. The model is based on both econometrics and growth accounting approach to fill the gaps of previous studies. On the...

متن کامل

Localization of Determinants of Fertility through Measurement Adaptations in Developing-Country Settings: The Case of Iran; Comment on “Analysis of Economic Determinants of Fertility in Iran: A Multilevel Approach”

Studies investigating fertility decline in developing countries often adopt measures of determinants of fertility behavior developed based on observations from developed countries, without adapting them to the realities of the study setting. As a result, their findings are usually invalid, anomalous or statistically non-significant. This commentary draws on the research article by Moeeni and co...

متن کامل

An approach to enhance the security of ICT infrastructure through legal, regulatory influences

As information systems and networks (ICTs) are increasingly used by governments, different organisations, businesses and end-users worldwide, there has been a common interest in promoting the security of such systems through a variety of methods and approaches. This interest is important to address the challenges posed by the potential harm from security failures of the systems to national econ...

متن کامل

The effect of developing the dynamics of library software system on information security management (Case study: Libraries of Islamic Azad universities of the country)

Background and Objective: Information security is of vital importance in most organizations. This is especially central in academic libraries due to the specific type of visitors, exchange and transfer of information to the users. Thus, the purpose   is to investigate the relationship of the development of library software and information security management in the libraries of Islamic Azad Uni...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2007