Opportunities and threats: A security assessment of state e-government websites

被引:72
|
作者
Zhao, Jensen J. [1 ]
Zhao, Sherry Y. [2 ]
机构
[1] Ball State Univ, Miller Coll Business ISOM, Muncie, IN 47306 USA
[2] Int Comp Sci Inst, Berkeley, CA 94704 USA
关键词
E-government; Computer network systems; IP address; NAT; PAT; Port; 80/tcp; 443/tcp; Security; Vulnerability; Cyber intrusion; Hacker attack;
D O I
10.1016/j.giq.2009.07.004
中图分类号
G25 [图书馆学、图书馆事业]; G35 [情报学、情报工作];
学科分类号
1205 ; 120501 ;
摘要
This study assessed the security of the U.S. state e-government sites to identify opportunities for and threats to the sites and their users. The study used a combination of three methods - web content analysis, information security auditing, and computer network security mapping - for data collection and analysis. The findings indicate that most state e-government sites posted privacy and security policy statements; however, only less than half stated clearly what security measures were in action. Second, the information security audit revealed that 98% of the sites secured users' accounts with SSL encryption for data transmission, and the sites' search tools enable public users to search for public information only. Third, although the sites had most of their internet ports filtered or behind firewalls, all of them had their main IP addresses detected and their port 80/tcp open. The study discussed the threats and opportunities and suggested possible solutions for improving e-government security. (C) 2009 Elsevier Inc. All rights reserved.
引用
收藏
页码:49 / 56
页数:8
相关论文
共 50 条
  • [41] E-government services: Certification and security
    Talamo, M
    CERTIFICATION AND SECURITY IN E-SERVICES: FROM E-GOVERNMENT TO E-BUSINESS, 2003, 127 : 5 - 13
  • [42] Security aspects within e-Government
    Hof, S
    ELECTRONIC GOVENMENT, PROCEEDINGS, 2003, 2739 : 266 - 271
  • [43] E-government and network information security
    Center of Network, Hubei Administrative College, Wuhan 430022, China
    Zhongshan Daxue Xuebao, 2006, SUPPL. (156-159):
  • [44] The researches on public security in the e-Government
    Zang Yan-lin
    Liu Yan
    Chen Ge-lin
    Proceedings of 2006 International Conference on Public Administration, 2006, : 298 - 304
  • [45] An extended security framework for e-government
    Al-Ahmad, Walid
    Al-Kaabi, Reem
    ISI 2008: 2008 IEEE INTERNATIONAL CONFERENCE ON INTELLIGENCE AND SECURITY INFORMATICS, 2008, : 294 - +
  • [46] The State of e-Government Security in South Africa: Analysing the National Information Security Policy
    Ngoqo, Bukelwa
    Njenga, Kennedy
    E-INFRASTRUCTURE AND E-SERVICES FOR DEVELOPING COUNTRIES (AFRICOMM 2017), 2018, 250 : 29 - 46
  • [47] Assessment of e-Government effectiveness
    Balashova, E. M.
    VOPROSY GOSUDARSTVENNOGO I MUNITSIPALNOGO UPRAVLENIYA-PUBLIC ADMINISTRATION ISSUES, 2011, (02): : 205 - +
  • [48] Assessment of E-Government Portals
    Gkikas, Dimitris C.
    Tzavella, Georgia
    Tzioli, Melpomeni
    Vlachopoulou, Georgia
    Kondili, Isidora
    Magnisalis, Ioannis
    INTERNATIONAL JOURNAL OF INFORMATION SYSTEMS IN THE SERVICE SECTOR, 2022, 14 (01)
  • [49] Integrated Architecture Framework for e-Government: an Assessment of the e-Government Initiatives in Zimbabwe
    Ruhode, Ephias
    Owei, Vesper
    PROCEEDINGS OF 5TH INTERNATIONAL CONFERENCE ON E-GOVERNMENT, 2009, : 165 - 173
  • [50] E-government: E-state within a state
    Khan, Hameed Ullah
    Journal of Theoretical and Applied Information Technology, 2012, 41 (02) : 207 - 213