{"title":"埃塞俄比亚选定私人银行信息系统安全的成熟度","authors":"Tadele Shimels, Lemma F. Lessa","doi":"10.1109/ict4da53266.2021.9672221","DOIUrl":null,"url":null,"abstract":"Information system security is more critical than ever before because security threats are rapidly growing and the environment requires organizations to continuously adapt to changes. Before putting in place information systems security measures, organizations are required to determine the maturity level of their information security governance. Extant literature reveals that there is no recent study on information systems security maturity level of banks in Ethiopia. This study, thus, seeks to measure the existing maturity level and examine the security gaps in order to propose possible changes in Ethiopian private banking industry's information system security maturity indicators. Four private banks are selected as a representative sample. SSE-CMM (System Security Engineering Capability Maturity Model) is used as the maturity measurement criteria and the measurement was based on ISO/IEC 27001 information security control areas. The data for the study was gathered using a questionnaire. A total of 93 valid questionnaires were gathered from 110 participants in the study. Based on the SSE-CMM maturity model assessment criteria, the private banking industry's current maturity level is level 2 (repeatable but intuitive). Institutions have a pattern that is repeated when completing information security operations, but its existence was not thoroughly proven, and institutional inconsistency still exists. Recommendations are forwarded for management intervention in order to address the identified gaps.","PeriodicalId":371663,"journal":{"name":"2021 International Conference on Information and Communication Technology for Development for Africa (ICT4DA)","volume":"43 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2021-11-22","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":"{\"title\":\"Maturity of information systems security in selected private Banks in Ethiopia\",\"authors\":\"Tadele Shimels, Lemma F. Lessa\",\"doi\":\"10.1109/ict4da53266.2021.9672221\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"Information system security is more critical than ever before because security threats are rapidly growing and the environment requires organizations to continuously adapt to changes. Before putting in place information systems security measures, organizations are required to determine the maturity level of their information security governance. Extant literature reveals that there is no recent study on information systems security maturity level of banks in Ethiopia. This study, thus, seeks to measure the existing maturity level and examine the security gaps in order to propose possible changes in Ethiopian private banking industry's information system security maturity indicators. Four private banks are selected as a representative sample. SSE-CMM (System Security Engineering Capability Maturity Model) is used as the maturity measurement criteria and the measurement was based on ISO/IEC 27001 information security control areas. The data for the study was gathered using a questionnaire. A total of 93 valid questionnaires were gathered from 110 participants in the study. Based on the SSE-CMM maturity model assessment criteria, the private banking industry's current maturity level is level 2 (repeatable but intuitive). Institutions have a pattern that is repeated when completing information security operations, but its existence was not thoroughly proven, and institutional inconsistency still exists. Recommendations are forwarded for management intervention in order to address the identified gaps.\",\"PeriodicalId\":371663,\"journal\":{\"name\":\"2021 International Conference on Information and Communication Technology for Development for Africa (ICT4DA)\",\"volume\":\"43 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2021-11-22\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"0\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"2021 International Conference on Information and Communication Technology for Development for Africa (ICT4DA)\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/ict4da53266.2021.9672221\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"2021 International Conference on Information and Communication Technology for Development for Africa (ICT4DA)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ict4da53266.2021.9672221","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
Maturity of information systems security in selected private Banks in Ethiopia
Information system security is more critical than ever before because security threats are rapidly growing and the environment requires organizations to continuously adapt to changes. Before putting in place information systems security measures, organizations are required to determine the maturity level of their information security governance. Extant literature reveals that there is no recent study on information systems security maturity level of banks in Ethiopia. This study, thus, seeks to measure the existing maturity level and examine the security gaps in order to propose possible changes in Ethiopian private banking industry's information system security maturity indicators. Four private banks are selected as a representative sample. SSE-CMM (System Security Engineering Capability Maturity Model) is used as the maturity measurement criteria and the measurement was based on ISO/IEC 27001 information security control areas. The data for the study was gathered using a questionnaire. A total of 93 valid questionnaires were gathered from 110 participants in the study. Based on the SSE-CMM maturity model assessment criteria, the private banking industry's current maturity level is level 2 (repeatable but intuitive). Institutions have a pattern that is repeated when completing information security operations, but its existence was not thoroughly proven, and institutional inconsistency still exists. Recommendations are forwarded for management intervention in order to address the identified gaps.