Uganda Martyrs University Institutionalnal Repository (UMU-IR)
    • Login
    View Item 
    •   UMU Dissertations
    • Faculty of Science
    • Master of Science in ICT Management, Policy and Architectural Design
    • Master of Science in ICT Management, Policy and Architectural Design (Dissertations)
    • View Item
    •   UMU Dissertations
    • Faculty of Science
    • Master of Science in ICT Management, Policy and Architectural Design
    • Master of Science in ICT Management, Policy and Architectural Design (Dissertations)
    • View Item
    JavaScript is disabled for your browser. Some features of this site may not work without it.

    Towards a framework for mitigating information security insider threats in public institutions: case study office of the auditor general

    Thumbnail
    View/Open
    Abila_Martin_Charles_SCI_MSCICT_2015_SanyaRahman.pdf (10.82Mb)
    Date
    2015-10-01
    Author
    Abila, Martin Charles
    Metadata
    Show full item record
    Abstract
    Public institutions need to understand the vulnerabilities and risks associated with insider threats and implement sound information security practices to defend against them. It is important to note that effective management of insider threats requires a risk-based and organizational-wide approach that includes various stakeholders. The research revealed several information security weaknesses that insiders are likely to exploit in public institutions. The underlying cause of these weaknesses is public institution‟s failure to fully or effectively implement information security programs, which involve assessing and managing risk, implementing both technical and non-technical controls, developing and implementing security policies and procedures, promoting security awareness and training, monitoring the adequacy of security controls, and implementing appropriate remedial actions. The proposed framework is drawn from existing information security best practices and standards, as well as from the research findings to provide guidance for public institutions to improve their position against insider threats. The proposed framework provides an enterprise wide solution to insider threats. The proposed framework consists of four security layers: Information Security Governance, Insider Risk Management, Defense-in-depth strategy and Continuous Information Security Improvement. Public institutions should deploy and enforce controls at each layer to address the insider problem. The four layers do not operate independently of each other, rather, the implementation of controls across all four layers form the core of this approach
    URI
    http://dissertations.umu.ac.ug/xmlui/handle/123456789/1487
    Collections
    • Master of Science in ICT Management, Policy and Architectural Design (Dissertations) [29]

    UMU_DR copyright © 2022-2025  UMU_IR
    Contact Us | Send Feedback

    UMU_Library
     

     

    Browse

    All of DSpaceCommunities & CollectionsBy Issue DateAuthorsTitlesSubjectsThis CollectionBy Issue DateAuthorsTitlesSubjects

    My Account

    LoginRegister

    UMU_DR copyright © 2022-2025  UMU_IR
    Contact Us | Send Feedback

    UMU_Library