Cybersecurity Posture of Higher Learning Institutions in Tanzania

Authors

  • Baraka Mtakati Department of ICT, Arusha Technical College
  • Frank Sengati Manager, Department of Information Technology Services, Institute of Accountancy Arusha

DOI:

https://doi.org/10.59645/tji.v1i1.1

Keywords:

Cybersecurity Posture, Cybersecurity Preparedness, Higher Learning Institutions, Cybersecurity Framework

Abstract

In a bid to become a middle-income country by 2025, the Government of the United Republic of Tanzania promoted the productive use of ICT for rapid development, which is why Higher Learning Institutions (HLIs) adopted information systems to handle admission matters. Urgent response to directives without enforcing credible cybersecurity measures is a massive security vulnerability that cyber attackers can exploit. This study assessed the cybersecurity preparedness of HLIs in protection, detection, and response to cyber-attacks using the NIST cybersecurity framework. To achieve this objective, a qualitative method and an interpretive research approach were adopted. The target population was four (4) Higher Learning Institutions located in Arusha Municipality. A purposive sampling technique was used due to an inadequate number of cybersecurity experts in the population. Empirical data were collected using semistructured, face-to-face interviews, documentary reviews, observation, penetration testing and analyzed using content analysis. Despite implementing minimal countermeasures, the study discovered that Higher Learning Institutions are vulnerable to cyber-attacks. Higher Learning Institutions must be vigilant by; addressing identified weaknesses, providing cybersecurity training to all staff, and continuously monitoring information systems. The study recommends a need to explore the factors affecting cybersecurity preparedness in Higher Learning Institutions.

Downloads

Download data is not yet available.

References

Adams, Y. (2017) Computer Security Technology Planning Study. Retrieved 21 08, 2020, from National Institute of Standards and Technology, Information Technology Laboratory: http://csrc.nist.gov/publications/history/ande72.pdf

AT&T Cybersecurity (2020) Establishing Baseline Network Behavior. [Online] Available at https://cybersecurity.att.com/documentation/usm-appliance/getting-started/baseline-behavior.htm [Accessed 10 May 2020]

Anderson, E. (2017) Blog: How to Comply with the 5 Functions of the NIST Cybersecurity Framework. [Online] Available at: https://www.secmatters.com/blog/how-to-comply-with-the-5-functions-ofthe-nist-cybersecurity-framework [Accessed 15 May 2020].

Australian Securities and Investments Commission (2015) Cyber resilience: Health check. [Online] Available at: https://download.asic.gov.au/media/3062900/rep429-published-19-march-20151.pdf [Accessed 15 June 2020].

Baino, T. (2016) Evaluation of Security Risks Associated with Networked Information Systems. Melbourne: Royal Melbourne Institute of Technology University.

Blum D. (2020) Institute Resilience Through Detection, Response, and Recovery. In: Rational Cybersecurity for Business. Apress, Berkeley, CA. https://doi.org/10.1007/978-1-4842-5952-8_9

Brink H. I. L. (1993) Validity and Reliability in qualitative research. Paper delivered at SA Society of Nurse Researchers" Workshop-RAU, UNISA: Department of Nursing Science Vol 16, No 2. Retrieved March, 16th 2020, from https://www.curationis.org.za/index.php/curationis/ article/ download/1396/1350.

CISCO Report (2015) what-is-cybersecurity.aspx. Retrieved from

http://www.itgovernance.co.uk:http://www.itgovernance.co.uk/whatiscybersecurity.aspx

Edith Cowan University (2019) ECU | Cyber-attacks cause data breach costs to soar: News: News. Available at: https://www.ecu.edu.au/news/latest-news/2019/08/cyber-attacks-cause-data-breachcosts-to-soar (Accessed: 7 March 2020).

Engebretson, A. (2011) The Basics of Hacking and Penetration Testing. Waltham, Elsevier Inc

Heidi W.M. (2017) Countering Social Engineering through Social Media: An Enterprise Security Perspective. Australia: Charles Sturt University.

International Telecommunication Union (2016) New Security Threats Invade Africa in 2016. Retrieved 21 08, 2020, from IT News Africa: http://www.itnewsafrica.com/

International Telecommunication Union (2018) Measuring the Information Society Report 2018 - Volume 1. Geneva, Switzerland., ITU Publications. Available at: https://www.itu.int/en/ITUD/Statistics/Documents/publications/misr2018/MISR-2018-Vol-1-E.pdf.

International Telecommunication Union (2018) Global Cybersecurity Index (GCI), ITU Report. DOI: 10.1111/j.1745-4514.2008.00161. x.

Kerravala, Z. (2016) Broadband Wan: The Importance of Setting Network Baselines. [Online] Available at: http://blog.silver-peak.com/the-importance-of-setting-network-baselines [Accessed 10 May 2020].

Kreicberga, G. (2017) Internal Threat to Information Security-Countermeasures and human factor within SME. Kiruna: Lulea University of Technology.

Kumar, D. A. (2017). A Study on ISO 9001 Quality Management System: Reason behind the failure of ISO Certified Organizations. Global Journal of Management and Business Research, Vol. XI (XI), 43-50.

Kumar & Ranjit (2005) Research Methodology a Step – by – Step Guide for Beginners, (2nd Edition), Singapore, Pearson Education.

Kundy, E. D & Lyimo, B. J. (2019) Cyber Security Threats in Higher Learning Institutions in Tanzania, A Case of University of Arusha and Tumaini University Makumira. Olva Academy – School of Researchers, Vol. 2, Issue 3.

Leder, F. (2016) Proactive Botnet Countermeasures an Offensive Approach. Bonn: Institute of Computer Science IV, Germany, University of Bonn

Lillis, D. et al. (2016) 'Current Challenges and Future Research Areas for Digital Forensic Investigation', in The 11th ADFSL Conference on Digital Forensics, Security and Law (CDFSL 2016), Daytona Beach, Florida, USA, May 2016. Available at: http://arxiv.org/abs/1604.03850 (Accessed: 6 October 2020).

Lubua, E., and Pretorius, P. (2019) 'Cyber-security Policy Framework and Procedural Compliance in Public Organizations', Proceedings of the International Conference on Industrial Engineering and Operations Management Pilsen, Czech Republic, July 23-26, 2019

Makumbi et al. (2018) An Analysis of Information Technology (IT) Security Practices: A Case Study of Kenyan Small and Medium Enterprises (SMEs) in the Financial Sector, Nairobi, University of Nairobi

Matandiko, K. (2017) ‘Wahalifu wa kimtandao wavamia tovuti ya Chuo Kikuu Huria’, Daily Nation, 24 October.

Mugenda.O.M & Mugenda. A.G (2003) "Research Methods: Quantitative & Qualitative Approaches"; Nairobi, African Centre for Technology Studies (ACTS)

Myers, M. D. (2013) Qualitative Research in Business and Management, 2nd ed., London, Sage Publications.

Ministry of Works Transport & Communication (2016) 'National Information and Communications Technology Policy', National Information and Communications Technology Policy, (May).

Naden, C. (2019) Stronger data protection with updated guidelines on assessing information security controls. Available at: https://www.iso.org/news/ref2367.html (Accessed: 5 March 2020).

National Audit Office of Tanzania (2020) General Audit Reports | National Audit office of Tanzania (NAOT). [Online]Available at https://www.nao.go.tz/index.php/reports/category/general-auditreports (Accessed: 23 September 2020).

NIS (2018) Framework for Improving Critical Infrastructure Cybersecurity. [Online] Available at: https://nvpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf [Accessed 10 March 2020].

Njiru, N. (2016) A Framework to Guide Information Security Initiatives for Banking Information Systems, Nairobi, Kenyan Banking Sector Case Study

Nyamongo, V. (2015) Information Systems Security Management a Case Study of Private Chartered Universities in Kenya, Nairobi, Strathmore University

O'Neill, P. F. (2016) Building Resilience Through Risk Analysis. In: Resilience and Risk: Methods and Application in Environment, Cyber, and Social Domains Azores: Springer, pp.451-468.

Sithole, T. (2019) Assessing Cybersecurity Preparedness of Public Sector Information Systems. Pretoria.

[Online] Available at

https://repository.up.ac.za/bitstream/handle/2263/72687/Sithole_Assessing_2019.pdf?sequence= 1 > [Accessed: 5 March 2020].

Tenable Network Security (2013) Continuous Network Monitoring: Eliminate periodic assessment processes that expose security and compliance programs to failure, Available at < https://docplayer.net/8634178-Continuous-network-monitoring.html > [Accessed: 5 March 2020]

Tanzania Communications Regulatory Authority (2020) Publications & Statistics › Research Papers, available at < https://www.tcra.go.tz/publication-and-statistics/studies-research-papers > [Accessed 21 April 2020]

Tanzania Commission for Universities (2020) Universities Information Management System, Available at: <http://uims.tcu.go.tz/> [Accessed: 14 March 2020].

Tanzania Commission for Universities (2018) Higher education student’s admission, enrolment and graduation statistics 2012/13 - 2017/18, Available at: <https://www.tcu.go.tz/sites/default/files/Admission and Graduation Statistics.pdf > [Accessed: 6 March 2020].

Tanzania Computer Emergency Response Team (2020) Reports – Tanzania Computer Emergency Response Team, Available at: https://www.tzcert.go.tz/resources-2/reports/ [Accessed: 16 October 2020].

Zegers, N. (2016) A Methodology for Improving Information Security Incident Identification and Response, Rotterdam, Erasmus Universiteit Rotterdam.

Zwilling, Lesjak, D., Natek, S., Phusavat, K., & Anussornnitisarn, P., M. (2019) 'How to Deal with the Awareness of Cyber Hazards and Security in (Higher) Education?', International Conference on Innovation and Management, (August), pp. 433–439.

Downloads

Published

2021-03-31

How to Cite

Mtakati, B. ., & Sengati, F. (2021). Cybersecurity Posture of Higher Learning Institutions in Tanzania. The Journal of Informatics, 1(1). https://doi.org/10.59645/tji.v1i1.1

Issue

Section

Articles