Assessment of Higher Education Information Security Risk Management Practices in Tanzania

Fatma Said Kombo, Peter Godwin Mwakalinga, Lazaro Inon Kumbo, Leticia Mihayo Edward, Neema Phillip Bhalalusesa
{"title":"Assessment of Higher Education Information Security Risk Management Practices in Tanzania","authors":"Fatma Said Kombo, Peter Godwin Mwakalinga, Lazaro Inon Kumbo, Leticia Mihayo Edward, Neema Phillip Bhalalusesa","doi":"10.46606/eajess2023v04i03.0294","DOIUrl":null,"url":null,"abstract":"This study assessed the information security risk management practices in in Tanzanian Higher Education Institutions (HEIs). It employed the sequential explanatory research design. Out of 51 HLIs in Tanzania, the study selected 10 HEIs from Dar es Salaam. The researchers computed the sample estimation through the Cochran’s formula for large population with a precision level of ±10 percentage and confidence level of 95%. The actual sample size was 96 ICT professionals in terms of ICT directors, network administrators, system administrators, ICT support staff and lecturers of ICT. The study used a closed-ended questionnaire, which had Yes/No questions and a structured interview, which collect qualitative data. Quantitative data analysis from the questionnaire was done through descriptive statistics using the SPSS whereas qualitative data from interviews was analyzed using the thematic analysis approach. The study uncovered a notable absence of risk management frameworks and inadequate integration of procedures within institutional strategies. While some HEIs demonstrated effective safeguarding of sensitive information, others required enhancements. The study recommend that HEIs should establish formal risk management frameworks and integrate them strategically into institutional plans. To bridge the implementation gap, HEIs should prioritize comprehensive training, require management support and tailor practices according to their specific contexts.","PeriodicalId":375627,"journal":{"name":"May to June 2023","volume":"46 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2023-06-30","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"May to June 2023","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.46606/eajess2023v04i03.0294","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0

Abstract

This study assessed the information security risk management practices in in Tanzanian Higher Education Institutions (HEIs). It employed the sequential explanatory research design. Out of 51 HLIs in Tanzania, the study selected 10 HEIs from Dar es Salaam. The researchers computed the sample estimation through the Cochran’s formula for large population with a precision level of ±10 percentage and confidence level of 95%. The actual sample size was 96 ICT professionals in terms of ICT directors, network administrators, system administrators, ICT support staff and lecturers of ICT. The study used a closed-ended questionnaire, which had Yes/No questions and a structured interview, which collect qualitative data. Quantitative data analysis from the questionnaire was done through descriptive statistics using the SPSS whereas qualitative data from interviews was analyzed using the thematic analysis approach. The study uncovered a notable absence of risk management frameworks and inadequate integration of procedures within institutional strategies. While some HEIs demonstrated effective safeguarding of sensitive information, others required enhancements. The study recommend that HEIs should establish formal risk management frameworks and integrate them strategically into institutional plans. To bridge the implementation gap, HEIs should prioritize comprehensive training, require management support and tailor practices according to their specific contexts.
坦桑尼亚高等教育信息安全风险管理实践评估
本研究评估了坦桑尼亚高等教育机构(HEIs)的信息安全风险管理实践。本研究采用序贯解释研究设计。在坦桑尼亚的51所高等教育机构中,该研究选择了来自达累斯萨拉姆的10所高等教育机构。研究人员通过Cochran公式计算了大量人口的样本估计,精度水平为±10%,置信度为95%。实际样本为96名资讯及通讯科技专业人士,包括资讯及通讯科技总监、网络管理员、系统管理员、资讯及通讯科技支援人员及资讯及通讯科技讲师。该研究使用了封闭式问卷,其中有是/否问题和结构化访谈,收集定性数据。问卷的定量数据分析是通过使用SPSS的描述性统计进行的,而访谈的定性数据是使用专题分析方法进行的。研究发现,风险管理框架明显缺乏,机构战略内的程序整合不足。虽然部分高等教育机构在保护敏感资料方面表现有效,但其他高等教育机构仍需加强。该研究建议高等教育机构建立正式的风险管理框架,并将其战略性地纳入机构计划。为了缩小实施差距,高等教育机构应优先考虑全面培训,需要管理支持,并根据具体情况量身定制实践。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信