Towards an information security maturity model for secure e-Government services: A stakeholders view
2011 (English) In: Proceedings of the 5th International Symposium on Human Aspects of Information Security and Assurance, HAISA 2011, 2011, p. 58-73Conference paper, Published paper (Refereed)
Abstract [en]
The paper proposes a comprehensive information security maturity model (ISMM) that addresses both technical and socio/non-technical security aspects. The model is intended for securing e-government services (implementation and service delivery) in an emerging and increasing security risk environment. The paper utilizes extensive literature review and survey study approaches. A total of eight existing ISMMs were selected and critically analyzed. Models were then categorized into security awareness, evaluation and management orientations. Based on the model's strengths-three models were selected to undergo further analyses and then synthesized. Each of the three selected models was either from the security awareness, evaluation or management orientations category. To affirm the findings-a survey study was conducted into six government organizations located in Tanzania. The study was structured to a large extent by the security controls adopted from the Security By Consensus (SBC) model. Finally, an ISMM with five critical maturity levels was proposed. The maturity levels were: undefined, defined, managed, controlled and optimized. The papers main contribution is the proposed model that addresses both technical and non-technical security services within the critical maturity levels. Additionally, the paper enhances awareness and understanding on the needs for security in e-government services to stakeholders.
Place, publisher, year, edition, pages 2011. p. 58-73
Keywords [en]
e-Government, Information Security, Maturity Model, Security services, Technical and Non-technical security, Government data processing, Information services, Mobile security, Surveys, Comprehensive information, E-government services, E-governments, Government organizations, Literature reviews, Technical security, Security of data
National Category
Information Systems
Identifiers URN: urn:nbn:se:kth:diva-308784 Scopus ID: 2-s2.0-84875546106 OAI: oai:DiVA.org:kth-308784 DiVA, id: diva2:1637257
Conference 5th International Symposium on Human Aspects of Information Security and Assurance, HAISA 2011, London, United Kingdom, July 7-8, 2011
Note QC 20220212
2022-02-122022-02-122022-06-25 Bibliographically approved