A Security-Evaluation Framework for Mobile Cross-Border e-Government Solutions

被引:1
|
作者
Zefferer, Thomas [1 ]
Pruenster, Bernd [1 ]
Kollmann, Christian [1 ]
Corici, Andreea Ancuta [2 ]
Alber, Lukas [3 ,4 ]
Czerny, Roland [3 ,4 ]
Podgorelec, Blaz [3 ,4 ]
机构
[1] A SIT Plus GmbH, Vienna, Austria
[2] Fraunhofer FOKUS Inst, Berlin, Germany
[3] Graz Univ Technol, Inst Appl Informat Proc & Commun IAIK, Graz, Austria
[4] Secure Informat Technol Ctr Austria A SIT, Graz, Austria
关键词
Security evaluation; Risk analysis; Risk evaluation; Security; e-Government;
D O I
10.1145/3598469.3598529
中图分类号
TP39 [计算机的应用];
学科分类号
081203 ; 0835 ;
摘要
Security evaluation is crucial for any security-critical system. In this context, a system can mean technical systems, organizations, or any other entity with certain security requirements. The major challenge in doing risk analysis is the trade-off between completeness and complexity. When done on a more abstract level, certain risks are potentially overlooked. When done on a very detailed level, risk analyses quickly become complex and exceed available resources. To tackle this challenge, various norms and standards propose different security evaluation methodologies. These methodologies vary depending on their target scope. Also, these standards typically remain on a rather abstract level to ensure broad applicability to different systems. In practice, this often complicates the application of these standards to concrete technical systems. In this paper, we tackle this issue by proposing a customized security-evaluation framework tailored to the special characteristics of cross-border e-government services. The proposed framework does not re-invent the wheel but combines aspects and approaches of established norms and standards to cherry-pick from each standard those aspects most beneficial for the given context. We evaluated the proposed framework by applying it to a set of software building blocks, which have been developed in the Horizon-2020 project mGov4EU and leverage mobile cross-border e-government services in Europe. The conducted evaluation shows that the proposed framework facilitates the practical application of security evaluations in the targeted domain and supports evaluators in handling the trade-off between completeness and complexity.
引用
收藏
页码:536 / 543
页数:8
相关论文
共 50 条
  • [1] Towards a Transdisciplinary Evaluation Framework for Mobile Cross-Border Government Services
    Eibl, Gregor
    Temple, Lucy
    Sellung, Rachelle
    Dedovic, Stefan
    Alishani, Art
    Schmidt, Carsten
    ELECTRONIC GOVERNMENT, EGOV 2022, 2022, 13391 : 543 - 562
  • [2] Blockchain Performance Analysis for Supporting Cross-Border E-Government Services
    Geneiatakis, Dimitris
    Soupionis, Yannis
    Steri, Gary
    Kounelis, Ioannis
    Neisse, Ricardo
    Nai-Fovino, Igor
    IEEE TRANSACTIONS ON ENGINEERING MANAGEMENT, 2020, 67 (04) : 1310 - 1322
  • [3] Solving Semantic Interoperability Conflicts in Cross-Border E-Government Services
    Mocan, Adrian
    Facca, Federico M.
    Loutas, Nikolaos
    Peristeras, Vassilios
    Goudos, Sotirios K.
    Tarabanis, Konstantinos
    INTERNATIONAL JOURNAL ON SEMANTIC WEB AND INFORMATION SYSTEMS, 2009, 5 (01) : 1 - 47
  • [4] An extended security framework for e-government
    Al-Ahmad, Walid
    Al-Kaabi, Reem
    ISI 2008: 2008 IEEE INTERNATIONAL CONFERENCE ON INTELLIGENCE AND SECURITY INFORMATICS, 2008, : 294 - +
  • [5] Designing a large cross-border secured eID service for e-government and e-business
    Blazic, Borka Jerman
    2014 INTERNATIONAL CONFERENCE ON MULTIMEDIA COMPUTING AND SYSTEMS (ICMCS), 2014, : 663 - 668
  • [6] PASSPORT - A novel architectural model for the provision of seamless cross-border e-government services
    Gouscos, D
    Mentzas, G
    Georgiadis, P
    12TH INTERNATIONAL WORKSHOP ON DATABASE AND EXPERT SYSTEMS APPLICATIONS, PROCEEDINGS, 2001, : 318 - 322
  • [7] AN EVALUATION FRAMEWORK FOR E-GOVERNMENT SYSTEM
    Na, Wang
    Lu, Liu
    Rui, Miao
    PROCEEDINGS OF THE 38TH INTERNATIONAL CONFERENCE ON COMPUTERS AND INDUSTRIAL ENGINEERING, VOLS 1-3, 2008, : 1406 - 1411
  • [8] Information security evaluation of e-government systems
    Cheng, Xiaorong
    Li, Mei
    Zhao, Huilan
    DCABES 2007 Proceedings, Vols I and II, 2007, : 532 - 535
  • [9] A Canonical Evidence-based Approach for Semantic Interoperability in Cross-border and Cross-domain e-Government Services
    Karunaratne, Thashmee
    Kontopoulos, Efstratios
    Konstantinidis, Ioannis
    Guzman Carbonell, Ana Rosa
    PROCEEDINGS OF THE 15TH INTERNATIONAL CONFERENCE ON THEORY AND PRACTICE OF ELECTRONIC GOVERNANCE, ICEGOV 2022, 2022, : 131 - 139
  • [10] E-government evaluation: A framework and case study
    Gupta, MP
    Jana, D
    GOVERNMENT INFORMATION QUARTERLY, 2003, 20 (04) : 365 - 387