International Journal of Industrial Engineering and Operations Management (Jun 2023)

Effectiveness of banking card security in the Ethiopian financial sector: PCI-DSS security standard as a lens

  • Lemma Lessa,
  • Daniel Gebrehawariat

DOI
https://doi.org/10.1108/IJIEOM-10-2021-0015
Journal volume & issue
Vol. 5, no. 2
pp. 135 – 147

Abstract

Read online

Purpose – This study is aimed at assessing the information security management practice with a focus on banking card security in selected financial institutions in Ethiopia, using an international information security standard as a benchmark. It is to identify the gaps and recommend best security practices to help financial institutions meet the required security compliance. Design/methodology/approach – Two financial sectors were purposively selected. A total of twenty-five respondents (IT executives and IT staff) were included in the study. Quantitative data was collected using the PCI-DSS (Payment Card Industry Data Security Standard) security standard questionnaire. In addition, observation and document analysis were made. Findings – The result shows that most of the essential security management activities in the financial sectors do not comply with the international security standard. Similarly, the level of most of the indispensable security requirements that should be in place is found to be below the acceptable level. The study also revealed major security factors that prohibit the financial sectors from PCI-DSS security standard compliance. Originality/value – This study assessed the information security management practice with a focus on banking card security and tried to figure out the limitations of security practices of the organizations surveyed based on the standard adopted. The topic has not been well explored especially in the Ethiopia context. Hence, the result can positively influence security policies, particularly in the banking sector.

Keywords