Showing posts with label Information technology. Show all posts
Showing posts with label Information technology. Show all posts

Tuesday, March 6, 2012

Kenya's mobile revolution and the promise of mobile savings

Kenya has undergone a remarkable information and communications technology (ICT) revolution. At the close of the 1990s, less than 3 percent of Kenyan households owned a telephone, and fewer than 1 in 1,000 Kenyan adults had mobile phone service. By the end of 2011, 93 percent of Kenyan households owned a mobile phone.

A unique facet of the ICT phenomenon in Kenya has been the widespread proliferation of mobile money. Starting with the M-PESA system launched by Safaricom in 2007 and later joined by other systems, mobile money has become a fixture in the lives of Kenyans, extending a basic form of financial access to a wide population.

Mobile money platforms have evolved since inception and have entered a new phase with the advent of bank-integrated mobile savings products. The first such product, M-KESHO, was launched in March 2010 as a partnership between Safaricom and Equity Bank.

In this paper we examine the mobile savings phenomenon, using data collected in a survey during October and November of 2010. The concept of ―savings on mobile platforms is not well defined, and we begin by putting forward a classification of the existing innovations. We differentiate between ―basic mobile savings‖ and ―bank-integrated mobile savings. Basic mobile savings refers to the simple storage of credit using a mobile system such as M-PESA. Bank-integrated mobile savings refers to systems which include a fuller set of banking services such as interest payments on deposits or overdraft facilities. This is the first study that examines patterns of use of bank-integrated mobile savings in Kenya.

The paper is organized as follows. Section 2 presents findings on the overall prevalence of mobile phone and mobile money usage in Kenya based on the Afrobarometer survey conducted at the end of 2011. Section 3 reviews the existing literature on the broader mobile money phenomenon. Section 4 describes how mobile money works in Kenya and shows the growth of mobile money usage over time. Section 5 describes the data on mobile savings analyzed in this paper. Section 6 describes the concept and measurement of mobile savings. Section 7 presents
the core analysis. Section 8 discusses the future of mobile savings and concludes.

World Bank. Author:Demombynes, Gabriel; Thegeya,Aaron.Document Date: 2012/03/01. Document Type: Policy Research Working Paper. Report Number: WPS5988

Kenya's mobile revolution and the promise of mobile savings  x

Monday, November 14, 2011

Readying the Centers for Medicare and Medicaid Services' Information Technology Systems to Meet Emerging Needs

The mission of the Centers for Medicare and Medicaid Services (CMS) is shifting from one primarily concerned with claims payment to one centered on improving the efficiency, quality, safety, and equity of U.S. health care services.

CMS is also responsible for testing innovative care and payment models and overseeing and supporting the state-based insurance exchanges called for in the 2010 Patient Protection and Affordable Care Act. In light of these challenges, CMS asked the National Research Council to review the centers’ plans for modernizing and developing its information systems.

Committee on Future Information Architectures, Processes, and Strategies for the Centers for Medicare and Medicaid Services; National Research Council

http://books.nap.edu/catalog.php?record_id=13281#toc

Sunday, November 13, 2011

ISO/IEC TR 27008:2011, Information technology – Security techniques – Guidelines for auditors on information security controls

An ISO/IEC technical report (TR) providing technical controls and compliance guidelines for auditors can improve the effectiveness of an organization’s information security system.

ISO/IEC TR 27008:2011, Information technology – Security techniques – Guidelines for auditors on information security controls, aims to instill confidence in the controls underpinning an organization’s information security management system. The review applies to all parts of the organization, including business processes and its information systems environment.
“The business environment is constantly changing – along with threats to a company’s survival. Organizations need to be ahead of the game, and an excellent defence can be built around audit of the controls used to support the information security,” says Edward Humphreys, leader of the working group that developed the new document.
“ISO/IEC TR 27008:2011 supports a rigorous organizational security audit and review programme for information security controls, to enable the organization to have confidence that their controls have been appropriately implemented and operated and that their information security is ‘fit for purpose’.”
ISO/IEC 27008 provides guidance on reviewing the implementation and operation of controls, including technical compliance checking. The document is principally aimed at information security auditors who need to check the technical compliance of an organization’s information security controls against ISO/IEC 27002 and any other control standards used by the organization. ISO/IEC TR 27008 will help them to:
  • Identify and understand the extent of potential problems and shortfalls of information security controls
  • Identify and understand the potential organizational impacts of inadequately mitigated information security threats and vulnerabilities
  • Prioritize information security risk mitigation activities
  • Confirm that previously identified or emergent weaknesses or deficiencies have been adequately addressed
  • Support budgetary decisions within the investment process and other management decisions relating to improvement of organization’s information security management.
ISO/IEC 27008 will thus be of benefit to all types of organizations, including public and private companies, government entities, and not-for-profit organizations. It is the eight document available in a series of standards (ISO/IEC 27000) on information security management systems.
Edward Humphreys adds, “In every business model and organizational structure, every business sector and every business relationship, information is a key commodity and the ISO/IEC 27000 series of standards can be utilized to protect this important business commodity.”
ISO/IEC TR 27008:2011, Information technology – Security techniques Guidelines for auditors on information security controls, costs 136 Swiss francs and is available from ISO national member institutes (see the complete list with contact details) and from ISO Central Secretariat through the ISO Store or by contacting the Marketing & Communication department (see right-hand column)


Ref.:1485.2011-11-08
Mrs. Sonia Rosas FriotAssistant, Marketing Services
Marketing, Communication and Information
Tel. +41 22 749 03 36
Fax +41 22 749 09 47
E-mail
sales@iso.org