The Effectiveness of Policies on ICT Resources and Passwords in Sri Lankan Universities
Chethana Ellepola, Roshan Ragel, Manjula Sandirigama, K.W.S.N. Kumari · 2022
All universities are bound by different policies to set guidelines as to how and in what capacity the universities need to operate. These policies could be introduced by the respective universities or by a higher governing body such as the University Grants Commission (UGC). This research was conducted with the expectation of evaluating two policies prepared by the UGC Standing Committee on Computing and introduced through the Commission Circular No.: 02/2013. These two policies, namely policy on passwords and policy on computing resources, have been prepared to regularise the passwords used by the university staff members and govern the use of computing resources in universities. The main objective of this research was to see to what extent the universities have implemented these policies, which were introduced in 2013. The study was conducted among staff members representing all national universities in Sri Lanka. The research consisted of two parts. The first stage evaluated the knowledge of university staff members and IT staff members regarding the above two policies. An online questionnaire was distributed among 5150 university academic and non-academic staff members of all local universities. Eight hundred fifty responses were received for this questionnaire which was beyond the expected sample size. The second questionnaire was sent to each university’s IT directors and other IT officers in a similar capacity. These surveys revealed that many staff members were not aware of these policies. 53.53% of staff members mentioned that they were unsure whether their own university had an IT policy. As the second stage of this research, the policy on passwords was cross-referenced with NIST 2020 guidelines for passwords to see how well the UGC policies are on par with the new guidelines. This revealed that the UGC policy on passwords needs to be updated according to the evolved techniques. The research makes some recommendations to improve the effectiveness of these policies, such as conducting periodic reviews and awareness sessions, carrying out surveys to check how well the university employees have understood and adhered to the guidelines, incorporating these policies into the university’s own IT policies, etc.