Information Systems Control Framework for Enhancing ICT Incident Management in Tanzanian Public Institutions: A Case of Mwanza City Council
Abstract
Tanzanian public institutions depend heavily on information systems for service delivery, yet ICT incident management remains their weakest governance area, rated the lowest-performing domain nationally in the 2024/25 audit of information systems at 47% compliance across 133 institutions. This study examined the problem at Mwanza City Council and developed an Information Systems Control Framework to address it. A mixed-methods design was used: structured questionnaires collected quantitative data from 56 of 60 targeted staff across six departments, with a 93.3% response rate, while a semi-structured interview with the Head of ICT and a review of council and national policy documents added qualitative depth. Data were analysed descriptively, and the Relative Importance Index ranked eight factors weakening incident management, with the absence of documented and approved procedures ranking highest (RII = 0.88), followed by the lack of formal tracking and logging (0.86) and unclear roles and responsibilities (0.855). Guided by these findings, the study designed a four-component Information Systems Control Framework: a technical monitoring architecture for detection and alerting, a structured incident management process spanning detection to closure, an organisational governance layer built around a RACI responsibility matrix and escalation rules, and a measurement component for continuous improvement. The framework draws on ISO/IEC 27035 and ITIL 4 for its detection and lifecycle logic, while remaining anchored in Tanzania's e-Government Act No. 7 of 2019 and e-Government General Regulations 2020. A working prototype of the monitoring and incident-management components was tested against a live, publicly accessible Tanzanian government system, running continuously over a 12-hour window with zero failures and cutting mean time to detect from 1-3 hours to under 10 minutes. The results confirm that Mwanza City Council's weaknesses reflect a broader national pattern and that the proposed framework operationalises existing regulatory obligations rather than importing an unrelated standard.