International Journal For Multidisciplinary Research
E-ISSN: 2582-2160
•
Impact Factor: 9.24
A Widely Indexed Open Access Peer Reviewed Multidisciplinary Bi-monthly Scholarly International Journal
Home
Research Paper
Submit Research Paper
Publication Guidelines
Publication Charges
Upload Documents
Track Status / Pay Fees / Download Publication Certi.
Editors & Reviewers
View All
Join as a Reviewer
Get Membership Certificate
Current Issue
Publication Archive
Conference
Publishing Conf. with IJFMR
Upcoming Conference(s) ↓
Conferences Published ↓
DePaul-2026
IC-AIRCM-T3-2026
NSSFIGTMA-2025
SPHERE-2025
AIMAR-2025
SVGASCA-2025
ICCE-2025
Chinai-2023
PIPRDA-2023
ICMRS'23
Contact Us
Plagiarism is checked by the leading plagiarism checker
Call for Paper
Volume 8 Issue 4
July-August 2026
Indexing Partners
A Cybersecurity Controls Framework for Secure System and Network Access in the Hospitality Sector: A Case of Lake Victoria Hotel, Entebbe, Uganda
| Author(s) | Mr. Elijah Musosi, Dr. Ali Najib, Dr. David Kaketo, Mr. Anthony Bua |
|---|---|
| Country | Uganda |
| Abstract | Hotels across Uganda increasingly rely on networked systems for reservations, payments, and guest services, yet many still operate without a structured, risk-based approach for protections, a gap that leaves properties such as Lake Victoria Hotel (LVH) in Entebbe exposed, as cyber threats facing the hospitality sector continue to grow. This study set out to close that gap by designing Cybersecurity Controls Framework (LVH-CCF) for secure system and network access, tailored to LVH's operational and regulatory environment. This study was guided by three objectives: evaluating existing access control measures, including multi-factor authentication, role-based access control, privileged access management, and VLAN segmentation; developing an incident response and recovery plan aligned with NIST SP 800-61 Rev. 3; and finally, designing a controls framework anchored in NIST CSF 2.0, NIST SP 800-53 Rev. 5, Uganda's Data Protection and Privacy Act (DPPA) 2019, and the Computer Misuse (Amendment) Act (CMAA) 2022. The study is theoretically grounded in Systems Theory (Pigola et al., 2025), Protection Motivation Theory (Maalem Lahcen et al., 2020), and Compliance and Regulatory Theory. The study used a mixed-methods case study design, drawing on structured surveys, semi-structured interviews, OpenVAS-assisted technical audits, and expert panel assessments across five respondent groups management, IT personnel, staff, external experts, and guests (N = 72). Quantitative data were analysed in SPSS using Wilcoxon Signed-Rank and Spearman correlation tests, while qualitative data were analysed thematically. The findings painted a picture of a reactive, fragmented security posture. Basic perimeter defences were largely in place antivirus (100%), firewalls (86%), and backups (86%) but preventive and governance controls were almost entirely absent: no multi-factor authentication, a documented policy covering only 14% of respondents, network segmentation at just 14%, no staff training, and no incident response plan. Introducing a structured framework had a significant effect on secure system and network access (Wilcoxon W = 5.000, p = 0.0196), and access control measures showed a strong positive relationship with system security (Spearman ρ = 0.922, p < 0.001) a result consistent with Protection Motivation Theory's prediction that behavioural security gains in one domain carry over into adjacent ones. The link between incident response preparedness and business continuity could not be statistically confirmed, given the small management sample (n = 7), though qualitative and cross-group evidence supported it. The resulting LVH-CCF comprises 39 controls spanning the six NIST CSF 2.0 functions Govern (6), Identify (5), Protect (16), Detect (4), Respond (4), and Recover (4) sequenced across a five-phase roadmap. Implementing it would close LVH's most critical vulnerabilities, achieve verifiable DPPA 2019 compliance, and strengthen guest trust. |
| Keywords | Cybersecurity Controls Framework, NIST CSF 2.0, Access Control, Incident Response, Hospitality Industry, Data Protection and Privacy Act, Lake Victoria Hotel, Uganda. |
| Field | Computer > Network / Security |
| Published In | Volume 8, Issue 4, July-August 2026 |
| Published On | 2026-07-27 |
| DOI | https://doi.org/10.36948/ijfmr.2026.v08i04.84494 |
Share this

E-ISSN 2582-2160
CrossRef DOI prefix of IJFMR is 10.36948/ijfmr
All research papers published on this website are licensed under Creative Commons Attribution-ShareAlike 4.0 International License, and all rights belong to their respective authors/researchers.
Powered by Sky Research Publication and Journals