Integrated Security Management of Public and Private Sector for Critical Infrastructures - Problem Investigation

被引:0
|
作者
Rehbohm, Thomas [1 ]
Sandkuhl, Kurt [1 ,4 ]
Cap, Clemens H. [1 ]
Kemmerich, Thomas [2 ,3 ]
机构
[1] Univ Rostock, Inst Comp Sci, Rostock, Germany
[2] Univ Bremen, Technol Zentrum Informat & Informationstechn, Bremen, Germany
[3] Norwegian Univ Sci & Technol, Trondheim, Norway
[4] Jonkoping Univ, Jonkoping, Sweden
关键词
Cybersecurity; Security management; Services of general interest; GOVERNANCE; ORGANIZATIONS;
D O I
10.1007/978-3-031-04216-4_26
中图分类号
F [经济];
学科分类号
02 ;
摘要
The interaction between security management in public and private organisations includes complex challenges. In particular in critical infrastructure sectors, there is a need for instruments that enable the holistic and overarching management of private and public providers. Cross-organisational structures and processes should be defined, but are difficult to establish in federal governmental structures due to different legislative levels and scopes. The paper investigates this challenge using Germany and the Free Hanseatic City of Bremen as example. The study proposes the development of an "Enterprise Architecture Framework" integrating and overarching the organizational structurers for both, a federal state, its municipalities and the (private) critical infrastructure providers in these municipalities. The main contributions of this paper are based on the results of an interview study. The interview partners were representatives of enterprises and public bodies covered by the federal IT security regulations. The contribution of the paper is the identification of security management challenges for services of general interest and how to increase the resilience of public service providers. Cybersecurity management in the context of public institutions is in focus.
引用
收藏
页码:291 / 303
页数:13
相关论文
共 50 条