An Investigation into Information Security Managerial Practices in Selected Public Sector Organizations.

The study aims to examine information security managerial practices in organisations. It was guided by three specific objectives: identification of information security practices critical to information assets management; establishment of implementation processes involved in the execution of structu...

Full description

Saved in:
Bibliographic Details
Main Authors: Ahimbisibwe, Benjamin K., Nabende, Peter, Musiimenta, Florence
Format: Article
Published: Kabale University 2023
Online Access:http://hdl.handle.net/20.500.12493/1278
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1800403073155203072
author Ahimbisibwe, Benjamin K.
Nabende, Peter
Musiimenta, Florence
author_facet Ahimbisibwe, Benjamin K.
Nabende, Peter
Musiimenta, Florence
author_sort Ahimbisibwe, Benjamin K.
collection KAB-DR
description The study aims to examine information security managerial practices in organisations. It was guided by three specific objectives: identification of information security practices critical to information assets management; establishment of implementation processes involved in the execution of structured information security governance; and evaluation of policies that influence information security best practices. In line with these objectives, security was acknowledged as a requisite element in protecting organizational information assets. The study covered two public sector organisations specifically, Uganda Wildlife Authority and National Forestry Authority. Focus was made on information security practices critical to managing information like human security, information classification, procedures for information labelling, compliance, standards, command and control techniques. These security practices were selected based on their importance in the protection of confidentiality, integrity and availability of information assets. Descriptive research design was adopted to describe the phenomenon under study. Being an in-depth inquiry, qualitative approach was used, survey questionnaires representing zero and one scores were designed to collect data. The respondents were purposively selected based on their knowledge in the subject area, cost-effectiveness and delivery of timely results. These respondents included information technology officers, administrative secretaries, data clerks and security guards. Findings from the field were analyzed and presented in meaningful tables. The research findings demonstrate that evaluation of users’ actions was hierarchical in nature; based on associations with tasks performed; information security practices are not aligned to guidelines set by National Information Technology Authority; there was need to establish appropriate measures to handle new information security risk in organizations. Based on these findings, recommendations that reflect the importance of examining information security managerial practices in organizations were made.
format Article
id oai:idr.kab.ac.ug:20.500.12493-1278
institution KAB-DR
publishDate 2023
publisher Kabale University
record_format dspace
spelling oai:idr.kab.ac.ug:20.500.12493-12782024-01-17T04:45:28Z An Investigation into Information Security Managerial Practices in Selected Public Sector Organizations. Ahimbisibwe, Benjamin K. Nabende, Peter Musiimenta, Florence The study aims to examine information security managerial practices in organisations. It was guided by three specific objectives: identification of information security practices critical to information assets management; establishment of implementation processes involved in the execution of structured information security governance; and evaluation of policies that influence information security best practices. In line with these objectives, security was acknowledged as a requisite element in protecting organizational information assets. The study covered two public sector organisations specifically, Uganda Wildlife Authority and National Forestry Authority. Focus was made on information security practices critical to managing information like human security, information classification, procedures for information labelling, compliance, standards, command and control techniques. These security practices were selected based on their importance in the protection of confidentiality, integrity and availability of information assets. Descriptive research design was adopted to describe the phenomenon under study. Being an in-depth inquiry, qualitative approach was used, survey questionnaires representing zero and one scores were designed to collect data. The respondents were purposively selected based on their knowledge in the subject area, cost-effectiveness and delivery of timely results. These respondents included information technology officers, administrative secretaries, data clerks and security guards. Findings from the field were analyzed and presented in meaningful tables. The research findings demonstrate that evaluation of users’ actions was hierarchical in nature; based on associations with tasks performed; information security practices are not aligned to guidelines set by National Information Technology Authority; there was need to establish appropriate measures to handle new information security risk in organizations. Based on these findings, recommendations that reflect the importance of examining information security managerial practices in organizations were made. 2023-07-04T13:19:50Z 2023-07-04T13:19:50Z 2023 Article Ahimbisibwe Benjamin K., Nabende Peter & Musiimenta Florence (2023). An Investigation into Information Security Managerial Practices in Selected Public Sector Organizations. Kabale: Kabale university. http://hdl.handle.net/20.500.12493/1278 application/pdf Kabale University
spellingShingle Ahimbisibwe, Benjamin K.
Nabende, Peter
Musiimenta, Florence
An Investigation into Information Security Managerial Practices in Selected Public Sector Organizations.
title An Investigation into Information Security Managerial Practices in Selected Public Sector Organizations.
title_full An Investigation into Information Security Managerial Practices in Selected Public Sector Organizations.
title_fullStr An Investigation into Information Security Managerial Practices in Selected Public Sector Organizations.
title_full_unstemmed An Investigation into Information Security Managerial Practices in Selected Public Sector Organizations.
title_short An Investigation into Information Security Managerial Practices in Selected Public Sector Organizations.
title_sort investigation into information security managerial practices in selected public sector organizations
url http://hdl.handle.net/20.500.12493/1278
work_keys_str_mv AT ahimbisibwebenjamink aninvestigationintoinformationsecuritymanagerialpracticesinselectedpublicsectororganizations
AT nabendepeter aninvestigationintoinformationsecuritymanagerialpracticesinselectedpublicsectororganizations
AT musiimentaflorence aninvestigationintoinformationsecuritymanagerialpracticesinselectedpublicsectororganizations
AT ahimbisibwebenjamink investigationintoinformationsecuritymanagerialpracticesinselectedpublicsectororganizations
AT nabendepeter investigationintoinformationsecuritymanagerialpracticesinselectedpublicsectororganizations
AT musiimentaflorence investigationintoinformationsecuritymanagerialpracticesinselectedpublicsectororganizations