At a time when information technology is growing faster than ever before, information security management system (ISMS) assessment has become one of the most important aspects of most public sector organizations. In particular, the reliance on technology for almost every single process in an organization has put the issue of implementing an ISMS at the top of the agenda of public sector organizations. Public organizations must also meet requirements related to the development and operation of an ISMS. On the other hand, only a few public administrations operate an ISMS. Public organizations are hampered by many different factors such as lack of personnel, time, money, etc., which have a negative impact on the development of the ISMS. In this context, this paper briefly presents a procedural model that should help to overcome the implementation hurdles in the introduction of ISMS in small public sector organizations (SPSOs). This process model, which has already been presented elsewhere, will be evaluated in this paper. For this purpose, an evaluation strategy is developed based on evaluation methods described in the literature, the implementation of the evaluation is described based on evaluation activities over different episodes and the results are summarized.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Information Security in Small Public Sector Organizations: Design and Evaluation of Procedural Approach

  • Frank Moses,
  • Kurt Sandkuhl

摘要

At a time when information technology is growing faster than ever before, information security management system (ISMS) assessment has become one of the most important aspects of most public sector organizations. In particular, the reliance on technology for almost every single process in an organization has put the issue of implementing an ISMS at the top of the agenda of public sector organizations. Public organizations must also meet requirements related to the development and operation of an ISMS. On the other hand, only a few public administrations operate an ISMS. Public organizations are hampered by many different factors such as lack of personnel, time, money, etc., which have a negative impact on the development of the ISMS. In this context, this paper briefly presents a procedural model that should help to overcome the implementation hurdles in the introduction of ISMS in small public sector organizations (SPSOs). This process model, which has already been presented elsewhere, will be evaluated in this paper. For this purpose, an evaluation strategy is developed based on evaluation methods described in the literature, the implementation of the evaluation is described based on evaluation activities over different episodes and the results are summarized.