Information security assessment in public administration

被引:28
作者
Szczepaniuk, Edyta Karolina [1 ]
Szczepaniuk, Hubert [2 ]
Rokicki, Tomasz [2 ]
Klepacki, Bogdan [2 ]
机构
[1] Polish Air Force Univ, Dywizjonu 303 35 ST, PL-08521 Deblin, Poland
[2] WULS, SGGW, Nowoursynowska 166 ST, PL-02787 Warsaw, Poland
关键词
Information security; Cybersecurity; Public administration; Information security assessment; Information security management; SYSTEMS;
D O I
10.1016/j.cose.2019.101709
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The aim of the article is to characterise and assess information security management in units of public administration and to define recommended solutions facilitating an increase in the level of information security. The article is considered a theoretical-empirical research paper. The aim of theoretical research is to explain the basic terms related to information security management and to define conditions for the implementation of Information Security Management System (ISMS). Within the scope of theoretical considerations, source literature, legislation and reports are being referred to. In the years 2016-2019, empirical research has been conducted, which aim was to assess the efficiency of information security management in public administration offices. The evaluation of results of surveys was accompanied by an analysis of statistical relations between the researched variables, which enabled to define effects of European Union regulations on the delivery of information security in public administration. Results of the empirical data show that in the years 2016-2017, in public administration offices, certain problem areas in the aspect of information security management were present, which include, among others: lack of ISMS organisation, incomplete or outdated ISMS documentation, lack of regular risk analysis, lack of reviews, audits or controls, limited use of physical and technological protection measures, lack of training or professional development. In the years 2018-2019, European Union solutions, i.e. the GDPR Regulation and the NIS Directive, have affected the increase in the security level of information in public administration and have a significantly limited occurrence of identified irregularities. Results of the research enable to assume that the delivery of information security in public administration requires a systemic approach arising from the need for permanent improvement. (C) 2020 The Authors. Published by Elsevier Ltd.
引用
收藏
页数:11
相关论文
共 43 条
[1]   Furanoic Lipid F-6, A Novel Anti-Cancer Compound that Kills Cancer Cells by Suppressing Proliferation and Inducing Apoptosis [J].
Al-Hassan, Jassim M. ;
Liu, Yuan Fang ;
Khan, Meraj A. ;
Yang, Peiying ;
Guan, Rui ;
Wen, Xiao-Yan ;
Afzal, Mohammad ;
Oommen, Sosamma ;
Paul, Bincy M. ;
Nair, Divya ;
Palaniyar, Nades ;
Pace-Asciak, Cecil .
CANCERS, 2019, 11 (07)
[2]  
Alberts C.J., 2003, MANAGING INFORM SECU
[3]  
[Anonymous], 2006, INT J NETWORK SECURI
[4]  
[Anonymous], 2016, The Global Information Technology Report 2016
[5]  
[Anonymous], 2018, The ISO 27001 standard provides requirements for an information security management system
[6]  
[Anonymous], 2018, 27005 ISOIEC
[7]  
Barczak A., 2003, BEZPIECZENSTWO SYSTE
[8]  
Brewer D., 2010, INSIGHTS ISO IEC 270
[9]   What is security: Definition through knowledge categorization [J].
Brooks, David J. .
SECURITY JOURNAL, 2010, 23 (03) :225-239
[10]  
Cornel C.C. Jude., 2015, International Journal of Scientific and Research Publications, V5, P1