For businesses to benefit from the many opportunities of cloud computing, they must first address a number of security challenges, such as the potential leakage of confidential data to unintended third parties. An inter-VM (where VM is virtual machine) attack, also known as cross-VM attack, is one threat through which cloud-hosted confidential data could be leaked to unintended third parties. An inter-VM attack exploits vulnerabilities between co-resident guest VMs that share the same cloud infrastructure. In an attempt to stop such an attack, this paper uses the principles of logical analysis to model a solution that provides physical separation of VMs belonging to conflicting tenants based on their levels of conflict. The derived mathematical model is founded on scientific principles and implemented using four conflict-aware VM placement algorithms. The resultant algorithms consider a tenant's risk appetite and cost implications. The model offers guidance to VM placement and is validated using a proof of concept. A cloud simulation tool was used to test and evaluate the effectiveness and efficiency of the model. The findings reflect that the introduction of the proposed model introduced a time lag in the time it took to place VM instances. On top of this, it was also discovered that the number and size of the VM instances has an effect on the VM placement performance. The findings further illustrate that the conflict tolerance level of a VM has a direct impact on the time it took to place.
Tropical Cyclone Idai ripped through Malawi, Madagascar, Mozambique and Zimbabwe in mid-March 2019. Hundreds of lives were lost and a lot more remain unaccounted for. This study investigates the extent to which Zimbabwe’s information and communication technology (ICT) is ready for disaster risk reduction (DRR) application and management. The focus was on Chimanimani District, where Cyclone Idai hit eastern Zimbabwe on 15 March 2019. This work further investigates the damage to ICT infrastructure and its resilience to the cyclone. Through the use of a questionnaire survey, interviews, document analysis and field observations, it emerged that Zimbabwe’s application of ICT in early warning systems remained low and ineffective due to the lack of appropriate equipment and expertise and unreliable electricity supply. In Chimanimani, some mobile network service providers’ base stations were flooded and communication was cut off completely, while mobile penetration at household level is near 100%. Grid electricity was also cut off for close to 1 month, with secondary impacts on charging mobile devices and signal coverage. Mobile phones and social media platforms such as WhatsApp were widely used at all DRR cycle stages, while radio provided the widest reach in terms of public announcements. From these findings, we recommend that authorities should invest heavily in modernising national weather forecasting ICT and promote the use of mobile phones as one of the platforms for DRR, especially in early warning. There is also the need to raise disaster awareness and preparedness among communities in Chimanimani.
As data breaches in mid-sized to large organizations become more frequent and more public, there is a need to focus less on technological solutions to information security management and more on sociological solutions. In this paper cost saving information security initiatives are identified and a framework is proposed for organizational and behavioral change in technical human resources, to better address information security concerns.
Introduction. Digital deception is a double-edged sword used by both blackhats and whitehats in cybersecurity. A status quo review of the reintroduction of digital deception can reveal challenges and initiatives and show how information behaviour expertise might inform cybersecurity research and vice versa. Aim. To use a status quo review of digital deception to reveal links between cybersecurity and information behaviour and to stimulate further research. Method. Critical review of digital deception in cybersecurity regarding whitehats and blackhats using an information behaviour lens. Findings. There is a need for research that tackles digital deception from both information behaviour and cybersecurity. There is also a need to bridge the gap between the two research fields and link cybersecurity concepts with information behaviour theories. Conclusions. The reintroduction of digital deception in cybersecurity highlights the challenges for the unreliability of defence-based detection systems. Although many solutions are available from cybersecurity, information behaviour might contribute to multidisciplinary research on digital deception and the future of defence technologies. Understanding the interplay between whitehats and blackhats in cybersecurity can help information behaviour practitioners to design models or frameworks for predicting changes in information-seeking behaviour.
The importance of Treasury management, within a commercial bank has increased significantly over the last couple of years. After the 2008 financial crisis the role and responsibility of a Treasury department has changed in terms of scope and strategic importance, evolving from a transactional cash manager to the guardian of the balance sheet. In order tomeet this broader strategicmandate, Treasurers must therefore consider ways to become more effective and streamlined, while reducing time-consuming operational activities. Digitalisation can address many of the traditional Treasury challenges and provide a number of commercial and competitive benefits as well. However, to successfully adopt digital technologies and related digital innovations, Treasury requires a well-defined digital transformation plan. The Smart Digital TreasuryModel (SDTM)was developed to provide a comprehensive roadmap to assist a Treasury’s digital transition towards a next generation ‘smart’ Treasury department. This paper explores a key building block of the SDTM, which addresses the risks and threats that can arise from the adoption of new digital technology. The reason for focusing on this aspect is that many of the digital risks have no direct reference points with conventional banking activity or security measures. The result of this research is an approach that articulates Treasury specific digital risks and threats, as well as describes a risk management process that can be deployed as part of the digital transformation. The digital landscape is evolving the whole time; therefore, digital risk management activity in Treasury can’t be seen as a once-off exercise, but needs to evolve in line with market developments.
People with disabilities may still be excluded from some of the learning opportunities at tertiary institutions because of their disabilities. To create a society which respects all people irrespective of their abilities, digital and social divides should be discouraged. This exploratory study investigates the role of usability when people with specific disabilities interact with e-learning environments. The objective is making informed decisions regarding the support presented by this institution's e-learning websites. If disability policies at higher education institutions fully address the needs of students with disabilities and are implemented accordingly, all students will be able to access and utilise all the learning opportunities and graduate competitively. The disability policies for students at tertiary institutions should address all their needs, including accessibility and usability of e-learning websites. The University of South Africa (Unisa) is the largest Open Distance electronic Learning (ODeL) institution in South African. In order to determine how students with disabilities interact with the e-learning website of Unisa, students were observed in the controlled usability laboratory. Students with mobility (limited hand function), visual and auditory disabilities were requested to attempt specific tasks using the Unisa websites. A total of twenty students, fifteen with above mentioned disabilities and five without disabilities, participated in this study to determine the usability of the Unisa's website. The results of this study are reported in this paper.
It is currently almost impossible for students enrolled at an open distance learning institution to obtain their study materials, communicate with lecturers or engage in any other teaching and learning processes without the use of computers and the Internet. This paper investigates and reports on the time taken and level of difficulty experienced by students with disabilities and students without disabilities in completing a number of set tasks involving the main website and the learning management system (LMS) of the University of South Africa (Unisa). The findings of the study indicate that students with disabilities take considerably longer than students without disabilities to finish such tasks, and in some cases experience greater difficulty in doing so. The study determined the importance of well-developed e-learning platforms at this institution for ensuring efficient and effective use by both students with and students without disabilities. The study indicates the advisability of including all LMS stakeholders, particularly the users of the LMS, in the development of e-learning websites in order to ensure that accessibility and usability design principles, guidelines and standards are properly adhered to so as to reduce both digital and social divides and the marginalisation of students. This becomes even more significant when the target user groups are students with disabilities.
The paper presents a validated socio-technical information security (STInfoSec) framework for the development of online information security (InfoSec) applications. The framework addresses both social and technical aspects of InfoSec design. The preliminary framework was developed using a mixed methods research design that collected data from 540 surveys by online banking users and six interviews with online banking personnel. The preliminary framework was presented in another publication and it is beyond the scope of this paper. The scope of this paper is limited to the validation findings of the evaluation process that involves seven evaluators. In the socio-technical context, the STInfoSec framework facilitates acceptance and usability of online applications based on online banking as a case study. The authors argue that usability of online InfoSec applications such as online banking significantly affects the adoption and continued use of such applications. As such, the paper investigates design principles for usable security and proposes a validated STInfoSec framework that consists of 12 usable security design principles. The design principles have been validated through heuristic evaluation by seven field experts for inclusion in the final STInfoSec framework. The development of InfoSec applications can be improved by applying these design principles.
The Internet and ultimately websites should be accessible and usable so that they can provide timely and accurate information in an effective, efficient and satisfactory way. Accessible and usable websites will help with academic activities, such as accessing study material or contacting lecturers and other teaching and learning processes, that are challenging to accomplish at an ODeL (open distance learning) institution. This paper examines and reports on the average time taken by groups of students with and without disabilities to complete certain tasks, using the University of South Africa (Unisa) website and myUnisa, the e-learning website of Unisa. The people for whom a website is intended, in this case, students with disabilities, have to be involved in the development of the websites, that is the e-learning websites. In this qualitative study, quantitative data analysis is used to support qualitative data analysis. The findings of this study show that groups of participants or students with disabilities are having problems working on this e-learning website. The study endorses that well-developed e-learning platforms must be efficiently, effectively and satisfactorily used by all students, including those with disabilities. The study recommends that it is significant for all the applicable stakeholders to be part of the development of websites to guarantee that accessibility and usability are appropriately adhered to. The intention is to reduce marginalisation, as well as digital and social divides of students with disabilities. In order to obtain improved learning accomplishments, technologies such as the Internet should be used.
To allow access to educational information for all people, including those with disabilities, the Internet and websites should be accessible and usable. Websites should provide timely and precise information effectively, efficiently and satisfactorily. Accessible and usable websites will create the necessary platforms for students to learn at open distance e-learning (ODeL) institutions without hindrances. Academic activities, such as accessing study material or contacting lecturers and other teaching and learning processes, are difficult to perform at an open distance learning institution without the use of computers and the Internet. This article investigates and reports on usability principles not satisfied based on time taken by students with disabilities to complete certain tasks, using the University of South Africa (Unisa) website and myUnisa, its e-learning website. The findings of the study indicate that not all usability principles for participants or students with disabilities are satisfied by this institution's e-learning websites. The study con-firms that well-developed e-learning platforms must guarantee efficient, effective and satisfactory use by all students, including those with disabilities. The study suggests that it is important for all the relevant stakeholders to be involved in the development of websites to ensure that accessibility and usability are properly adhered to. The aim is to reduce digital and social divides and the marginalisation of students, specifically when the target user groups have disabilities or limited capabilities.
The main objective of this paper is to report on perceptions of online banking custodians with regard to the development of secure and usable online banking applications. The paper also reports on the impact of online banking users' behaviour in fostering a secure online environment. Using an exploratory study, the paper discuss findings based on empirical interview data from six participants. The results identified information security as the main risk and financial institutions are using multiple initiatives in assisting users to enhance their protection from online information security threats. The awareness initiatives need to be complemented with a more holistic approach into the design and development of information systems that is user-centred. One such approach is finding a balance between protecting information assets and providing users with information systems that are easy to use.
Online banking is a critical service offered by financial institutions to their clientele to facilitate easier and faster access to financial services and transactions. Banks currently spend huge amounts of money on development and maintenance of websites and backend systems that offer online banking facilities to clients. Here we address the effect of moderating factors on online banking usability assessment in South Africa. Using statistical analysis techniques that included t-tests, ANOVA and correlation, we investigated whether there are statistically significant mean differences in system usability scale (SUS) scores based on a variety of moderating factors in South Africa. Findings based on a sample of 540 respondents show that SUS scores differ significantly based on factors such as age, experience and income, whereas factors such as gender, use frequency and employment did not affect the mean SUS scores. Given the individual SUS scores for a variety of users based on different demographics, the financial institutions might improve service usability to target specific user groups and realise their return on investment in digital banking channels. Therefore improving service usability might go a long way in encouraging online banking adoption in South Africa. Significance: The overall assessment of online banking service by users based on a SUS measurement tool was investigated. The effect of moderating variables on the mean SUS scores of different user groups was established. An insight into areas of improvement with regard to usability based on demographic information of users is provided.
This paper examines the way in which blockchain technology can be used to improve the integrity of the chain of evidence in digital forensics. A particular scalable method of verifying point-in-time existence of a piece of digital evidence, using the OpenTimestamps (OTS) service, is described, and tests are carried out to independently validate the claims made by the service. The results demonstrate that the OTS service is highly reliable, but not suitable for time-sensitive digital times-
The main objective of this paper is to present a preliminary socio-technical information security (STInfoSec) framework for the development of online information security applications that addresses both social and technical aspects of information security design. The paper looks at theoretical aspects related to a view of information security as a socio-technical system in the context of online banking. The STInfoSec framework investigates usability and security requirements for an improved online banking system that seeks to improve the adoption and continued use of the service. The STInfoSec framework proposes 12 usable security design principles that assist in addressing security and usability requirements in online applications such as online banking. The framework seeks to influence the behaviour of designers of online information security applications by incorporating principles that consider the end user behaviour of such applications. The validation of the framework is beyond the scope of this paper.
Intrusion detection systems (IDSs) are an important component of information security. The challenge with current versions has be en the high numb er of fa lse positive and f alse negative alerts they generate. The aim of this paper is the analysis of current intrusion detection systems and the Common Intrusion Detection Framework (CIDF) model for any weaknesses through a detailed literature review. The result is a proposed model which addresses these weaknesses. The weaknesses are ad dressed through the inclusion of data r eduction algorithms in e very component which is seen as key to reducing the amount of data being processed or analysed by the proposed IDS model, thereby increasing the processing speed. The introduction of a parallel analysis process which employs misuse-, anomaly — and specification-based detection approaches may also e nhance the detection accuracy of the proposed model. The paper concludes with a call to the IDS develo pment community to try out the proposed model.
Data protection and management of personal information has become an integral aspect for organisations and individuals in conducting business in the modern era. It has also become a major issue for legislators, regulators and consumers worldwide due to the widespread repercussions when personal information is negligently or maliciously used. Despite increased attention on personal information and the existence of data protection legislation internationally, data breaches remain a common occurrence. It has become crucial now, more than ever, for organisations to manage and safeguard personal information. As a nation, South Africa has addressed the need for increased protection - the Protection of Personal Information (PoPI) Act was signed into law in November 2013. This paper presents a comparison between the South African PoPI Act and other international data protection laws in order to highlight similarities and differences. These privacy legislations will be compared based on the principles set out by the PoPI Act. Other areas to be considered include data protection officers, enforcement, electronic marketing, online privacy and the year enacted. Data protection compliance is not straightforward and having the correct measurements and procedures in place is of utmost importance. These findings can be applied in future work to examine where South Africans can make use of already established international best practices to best enforce their privacy regulation.
The main objective of this paper is to investigate the factors that influence users' adoption and acceptance of online banking in South Africa, based on 324 respondents' current perceptions of the service. This paper reports empirical findings of an exploratory study in South Africa. The findings confirm security risk as main concern, while convenience ranks as the main benefit for using online banking. Financial institutions need to find ways to mitigate security problems and enhance their communication strategies to encourage the uptake of online banking service. Given the ever-improving internet penetration rate in South Africa and considering that a huge number of adult banked South Africans already having internet access, it is important to investigate why these banked adults are not adopting online banking.
Data breaches remain a common occurrence affecting both companies and individuals alike, despite promulgated data protection legislation worldwide. It is unlikely that factors causing data breaches such as incorrect device configuration or negligence will stop unless effective enforcement of relevant legislation is applied. While several information privacy regulators exist, the dominant norm is to respond reactively on reported incidents. Reactive response is useful for cleaning up detected breaches but does not provide a clear indication of the level of personal information available on the internet since only reported incidents are taken into account. The possibility of pro-active automated breach detection has previously been discussed as a capability augmentation for existing privacy regulators. By pro-actively detecting leaked information, detection times can potentially be reduced to limit the exposure time of Personal Identifiable Information (PII) on publicly accessible networks. At present the average time for data breach detection is in excess of three months internationally and breach discovery it most often not by the data owner but an external third party increasing exposure of leaked information. The duration of time that data is exposed on the internet has severe negative implications since a significant portion of information disclosed in data breaches have been proven to be used for cybercrime activities. It could then be argued that any reduction of data breach exposure time should directly reduce the opportunity for associated cyber-crime. While pro-active breach detection has been proven as potentially viable in previous work, numerous aspects of such a system remain in question. Aspects such as legality, detection accuracy and communication with affected parties and alignment with privacy regulator operating procedures are all unexplored. The research presented in this paper considers the results obtained from two iterations of such an experimental system that was conducted on the South African. co.za domain. The first iteration conducted in early 2014 was used as a baseline for the second iteration that was conducted one year later in 2015. While the experiment was conducted on the South African cyber domain, the concepts are applicable to the international environment.