24
R. Dette
Table 2.2 Risk mitigation for humanitarian ICT uses: why and what
1. Study the context before
choosing tools
The information and technology ecosystems determine whether a
new tool or approach can have a positive impact in the long term.
Hotlines, for example, only work where locals have and use
phones. Satellite images only make sense when skies are clear and
smartphones should only be used in culturally appropriate ways
Be very clear about the information you need to gather or spread.
Assess closely what type of information and knowledge travels via
which channels in your context. Understand who influences and
spreads information and can impact it
2. Involve all users actively Any tool or technology is only as effective as those meant to use it
understand - and use - it. This involves all: programme staff,
supervisors, data collectors, local communities, those processing
the data and those making decisions based on it
Work with representatives of the different user groups when
inventing, designing and testing the tools. Focus groups or
interviews and, as much as possible, collaboration can help assure
that ICT is usable and appropriate in all ways, including handling,
pricing, language, etc.
3. Establish informed
consent practices
Achieving informed consent is especially difficult when aid actors
themselves do not know all the risks involved with technologies
and digitization. Because there is currently little best practice, aid
actors need to handle recipients’ data carefully
Agree on mechanisms and standards by which to explain the risks
involved with handling survey responses or phone requests
digitally. Do this well before disaster hits
4. Provide back-up
channels and alternatives
Technology-based efforts need to be prepared for the worst cases
including energy outages, network disruption, theft of devices,
software jams and other complications
Have analogue alternatives in place to turn to when the new tool
does not work. Also, assure that every online function has an
offline option. And do carry extra batteries
5. Use security-conscious,
free and open source
software
With technology, intuition and observation are not enough to know
who can gain access to information, as calls and electronically
submitted data can be intercepted, often unnoticeably. The
responsibility to safeguard personal data and keep it away from
third parties lies with the aid organizations, so the choice of
technology matters
Use only those tools that independent security experts can review.
Such ‘free and open source software’ (or FOSS) options exist for
moth relevant ICT tools
6. Minimize and self-limit
data
Even with the best tools, ensuring digital security is extremely
difficult, also for experts. It is safe to assume that every data point
that has been digitized can be copied or stolen. Even seemingly
harmless datasets can reveal people when combined with other data
Collect only on a ‘need to know’ basis. Be clear which information
gaps you are trying to fill and identify which data points you need
to collect. Similarly, define access levels clearly. Who needs to see
individual records and where do aggregate numbers suffice?
(continued)
R. Dette
Table 2.2 Risk mitigation for humanitarian ICT uses: why and what
1. Study the context before
choosing tools
The information and technology ecosystems determine whether a
new tool or approach can have a positive impact in the long term.
Hotlines, for example, only work where locals have and use
phones. Satellite images only make sense when skies are clear and
smartphones should only be used in culturally appropriate ways
Be very clear about the information you need to gather or spread.
Assess closely what type of information and knowledge travels via
which channels in your context. Understand who influences and
spreads information and can impact it
2. Involve all users actively Any tool or technology is only as effective as those meant to use it
understand - and use - it. This involves all: programme staff,
supervisors, data collectors, local communities, those processing
the data and those making decisions based on it
Work with representatives of the different user groups when
inventing, designing and testing the tools. Focus groups or
interviews and, as much as possible, collaboration can help assure
that ICT is usable and appropriate in all ways, including handling,
pricing, language, etc.
3. Establish informed
consent practices
Achieving informed consent is especially difficult when aid actors
themselves do not know all the risks involved with technologies
and digitization. Because there is currently little best practice, aid
actors need to handle recipients’ data carefully
Agree on mechanisms and standards by which to explain the risks
involved with handling survey responses or phone requests
digitally. Do this well before disaster hits
4. Provide back-up
channels and alternatives
Technology-based efforts need to be prepared for the worst cases
including energy outages, network disruption, theft of devices,
software jams and other complications
Have analogue alternatives in place to turn to when the new tool
does not work. Also, assure that every online function has an
offline option. And do carry extra batteries
5. Use security-conscious,
free and open source
software
With technology, intuition and observation are not enough to know
who can gain access to information, as calls and electronically
submitted data can be intercepted, often unnoticeably. The
responsibility to safeguard personal data and keep it away from
third parties lies with the aid organizations, so the choice of
technology matters
Use only those tools that independent security experts can review.
Such ‘free and open source software’ (or FOSS) options exist for
moth relevant ICT tools
6. Minimize and self-limit
data
Even with the best tools, ensuring digital security is extremely
difficult, also for experts. It is safe to assume that every data point
that has been digitized can be copied or stolen. Even seemingly
harmless datasets can reveal people when combined with other data
Collect only on a ‘need to know’ basis. Be clear which information
gaps you are trying to fill and identify which data points you need
to collect. Similarly, define access levels clearly. Who needs to see
individual records and where do aggregate numbers suffice?
(continued)
