<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta>
      <journal-title-group>
        <journal-title>F. Moses);</journal-title>
      </journal-title-group>
    </journal-meta>
    <article-meta>
      <title-group>
        <article-title>ISMS in small public sector organisations: requirements and design of a procedural approach</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Frank Moses</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Kurt Sandkuhl</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>University of Rostock</institution>
          ,
          <addr-line>Albert-Einstein-Str. 22, 18059 Rostock</addr-line>
          ,
          <country country="DE">Germany</country>
        </aff>
      </contrib-group>
      <pub-date>
        <year>2023</year>
      </pub-date>
      <volume>000</volume>
      <fpage>0</fpage>
      <lpage>0002</lpage>
      <abstract>
        <p>At a time when information technology is growing faster than ever before, information security management system (ISMS) assessment has become one of the most important aspects of most public sector organisations. The dependency on technology for almost every single process in an organisation has put ISMS at the top of the corporate agenda of public sector organisations. For public organisations in particular, the NIS 2 Directive describes abstract requirements for the development of an ISMS. On the other hand, only a few public administrations operate an ISMS. In this context, this paper analyses the requirements of the NIS-2 Directive and complements them with the obstacles and reasons for success in the introduction of ISMS in small public sector organisations (SPSO). At the same time, minimum requirements should be defined that help municipal administration set up an information security management system quickly and easily. This paper summarizes the different requirements and generates a foundation for a rough procedural model, for implementing the upcoming requirements of the NIS 2 Directive quickly and easily in local governments.</p>
      </abstract>
      <kwd-group>
        <kwd>eol&gt;Hindering Factors</kwd>
        <kwd>Requirements</kwd>
        <kwd>Information Security</kwd>
        <kwd>ISMS 1</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>1. Introduction</title>
      <p>The dependency on technology for almost every single process in an organization has put
information security management systems (ISMS) and their success factors at the top of the
agenda. The growing number of malicious cyber-attacks and their severity receive more and
more attention in the public discussion. The information belonging to sensitive and critical
organizations must be secured. Malicious cyber activities mainly take the form of business
disruption, data and property destruction, and theft of financial or sensitive data [1, p. 261]. Risks
and threats that can impact information security, in general, affect the confidentiality, availability,
and integrity of corporate resources, causing difficulties for both large and small companies, and
especially the public sector [2, p. 710], [3, p. 148].</p>
      <p>The focus of this paper is on ISMS for the public sector. The work presented is part of an
ongoing research project to develop procedural support for implementing information security
management in small organization units of the public sector (SPSO). Against this background, the
main obstacles to the implementation of an ISMS in SPSOs are gathered from the literature and a
foundation for the creation of a first approach of a procedural model is derived from this.</p>
      <p>
        In many centralized governmental structures, there are guidelines, recommendations, or even
mandatory standards for setting up and operating an ISMS. However, in small federal
governmental structures, this is often not the case[
        <xref ref-type="bibr" rid="ref4">4</xref>
        ] which establishes the responsibility for
ISMS on the individual organisation. Furthermore, these organizations are heterogeneous in size,
structure, administrative tasks, responsibilities, and resource availability. Due to this diversity,
many general approaches for ISMS are not applicable. This also coincides with the author's
experience after more than 25 years in a leading position in ministerial administration. The goal
of our research is to identify the specifics of small public sector units and develop an ISMS
approach tailored to their demands. The current requirements of the NIS-2 Directive [
        <xref ref-type="bibr" rid="ref5">5</xref>
        ]should
be considered.
      </p>
      <p>Chapter "2 Methodology" describes the phases of the Design Science approach, which are
progressed through step by step. Chapter "3 Identifying the requirements for an adoption and
diffusion of an ISMS" is divided into 3 subsections. First, the identification of the requirements
that can be derived for the SPSO from the NIS-2 guideline. Second, a summary of the results of the
literature review conducted. This provides an overview of the barriers, which is also the basis for
further research. Thirdly, these two results are compared. These results were structured in a
further step in order to develop and describe a rough process model based on them. In the fourth
chapter, a rough process model is derived from the requirements and described. This process
model has already been successfully tested in an artificial environment. Currently, the procedure
model is being tested in a real environment with different test subjects.</p>
    </sec>
    <sec id="sec-2">
      <title>2. Methodology</title>
      <p>
        This work is part of a research project aiming at methodical and technological support for
information security management in small public sector organization units. The project follows
the paradigm of design science research (DSR) [
        <xref ref-type="bibr" rid="ref6">6</xref>
        ]. DSR is a research paradigm aiming at
problemsolving in organizational settings with a focus on developing valid and reliable knowledge for
designing the required solutions. DSR research projects typically consist of several phases and
require the use of different research methods depending on the DSR phase and intended design
solution. This paper concerns the phase requirements definition and design and development of
the design solution, i.e., the core artefact. Table 1 provides an overview of the research activities
performed in the different phases of the DSR process, the research methods used for these
activities, the results achieved and the sections of this paper providing information about the
results.
      </p>
      <p>First, we have primarily considered the requirements of the NIS-2 Directive in this document.
At the same time, we have identified further important requirements through a literature review.
We merged both lists of requirements to create an overarching list of requirements as a
foundation for the development of a rough procedural model.
3. Identifying the requirements for an adoption and diffusion of an
isms</p>
      <sec id="sec-2-1">
        <title>3.1. Requirements from nis-2 directive</title>
        <p>
          The Network and Information Systems Directive 2 (NIS-2) is a European directive that aims to
improve cybersecurity in critical infrastructures and digital services. It significantly expands the
scope and obligations of the previous Directive and thus provides for various measures to achieve
the objective of improved resilience, including:[
          <xref ref-type="bibr" rid="ref7">7</xref>
          ]
• Mandatory security requirements: Operators of critical infrastructure and digital services
must implement appropriate safeguards to identify and prevent threats.
• Security incident reporting: Operators must report security incidents to national
authorities and share information about these incidents to improve response capability.
• Establishment of CSIRTs: National authorities must establish Computer Security Incident
        </p>
        <p>Response Teams (CSIRTs) to respond to security incidents.
• Regular security audits: Operators must conduct regular security audits and review their
security measures to ensure they are adequate and in line with current threats.
• Cooperation between Member States: Member States need to work together and share
information to jointly combat threats and improve cybersecurity in Europe.</p>
        <p>
          These measures are intended to ensure that critical infrastructures and digital services in
Europe, including Germany, are safe and secure, and that they can respond to threats and prevent
attacks. In practice, the development and sustainable establishment of an information security
management system (ISMS) form an essential foundation for the implementation of the NIS 2
Directive, as an ISMS helps to ensure the security of critical infrastructures and digital services
and to respond quickly and effectively to threats.[
          <xref ref-type="bibr" rid="ref8">8</xref>
          ] In Art. 21 of the NIS-2 Directive, four core
requirements are formulated that must be met by an ISMS.[
          <xref ref-type="bibr" rid="ref7">7</xref>
          ] These include:
• Policies: Risk &amp; Information Security Policies
• Incident Management: Prevention, detection, and management of cyber incidents
• Business Continuity: Business Continuity Management, Crisis Management
• Supply Chain Management: Security in the supply chain — up to suppliers
• Procurement: Security in the procurement of IT and network systems
• Effectiveness: Requirements for measuring cyber and risk measures
• Training: Cyber Security Hygiene of employees
• Cryptography: Specifications for cryptography and, where possible, encryption
• Staff: Human Resources Security
• Physical access control
• Asset Management (ISMS)
• Authentication: Use of multi-factor authentication (MFA) and single sign-on (SSO)
• Communication: Use of secure voice, video, and text communication
• Emergency communication: Use of secure emergency communication systems
At this point, the NIS-2 Directive provides a simple framework. First and foremost, a strategy
must be formulated by the organisation. This is followed by the definition of requirements of the
context. The organisational and technical implementation of the requirements must be
coordinated by an appropriate organizational structure and flanked by appropriate guidelines.
However, descriptions of the concrete implementation of an ISMS remain open.[9, p. 824]
        </p>
      </sec>
      <sec id="sec-2-2">
        <title>3.2. The requirements from literature research</title>
        <p>
          To collect the relevant literature on the status quo of information security in the public sector and
especially in local government, a structured literature analysis based on Webster and Watson [
          <xref ref-type="bibr" rid="ref3">3</xref>
          ]
was carried out in the established electronic literature database SSOAR (administrative sciences),
EBSCO Econ Lit and WISO (public service) as well as Scopus (various disciplines). The literature
analysis was carried out based on a free-text search using the combination of the following terms:
"cybersecurity, public sector, information security, hindering factor, obstacles". In the first step,
the literature databases were searched with German search terms and then with English search
terms. The first search queries resulted in around 1,500 hits, whereby a search period of 15 years
was chosen. This search period was then successively restricted and ultimately limited to the
period from 2016. This reduced the number of hits to approx. 703 articles. After reviewing the
titles, 378 of the abstracts were read. This was followed by a full review of the text of 165 articles.
After assessing their relevance based on content, quality, and citation frequency, 92 articles were
filtered out of these, which were included in further analysis. The results of the search queries
can be summarized as follows (Table 2):
        </p>
        <p>
          Table 3 presents the results of a literature review. The publications identified with this
analysis were examined for factors inhibiting or supporting ISMS implementation. 60 inhibiting
factors or critical success factors were identified from the literature review. Behind each
hindering factor, the reference is listed in brackets citation (Table 3). On the one hand, this
summary serves as the basis of this paper in the sense of Design Science Research (DSR) an
overview of the disruptive factors of an ISMS. But also, at the same time as a foundation for further
research work. The determined requirements that are important for this paper are marked in
bold in Table 3.
10. Size of the Agency[
          <xref ref-type="bibr" rid="ref29">29</xref>
          ]
        </p>
        <p>
          Factor / Requirement
11. Disaster Recovery Planning [
          <xref ref-type="bibr" rid="ref12">12</xref>
          ]
13. Self-Interest [
          <xref ref-type="bibr" rid="ref20">20</xref>
          ]
15. Control Centre (SPoC) [
          <xref ref-type="bibr" rid="ref13">13</xref>
          ], [
          <xref ref-type="bibr" rid="ref31">31</xref>
          ]
17. Lack of qualified Employees [
          <xref ref-type="bibr" rid="ref19">19</xref>
          ], [
          <xref ref-type="bibr" rid="ref26">26</xref>
          ]
19. Definition of Measures and their
        </p>
        <p>
          implementation [32]
21. Financial Resources [
          <xref ref-type="bibr" rid="ref10">10</xref>
          ], [33], [
          <xref ref-type="bibr" rid="ref19">19</xref>
          ], [
          <xref ref-type="bibr" rid="ref26">26</xref>
          ],
        </p>
        <p>
          [
          <xref ref-type="bibr" rid="ref29">29</xref>
          ], [34]
23. Room for manoeuvre [
          <xref ref-type="bibr" rid="ref16">16</xref>
          ]
25. Outsourcing Quota [38]
27. Individual Attitude (Culture) [
          <xref ref-type="bibr" rid="ref16">16</xref>
          ], [
          <xref ref-type="bibr" rid="ref27">27</xref>
          ], [
          <xref ref-type="bibr" rid="ref31">31</xref>
          ]
29. Obtaining Information on Cyber Topics
        </p>
        <p>
          (OSINT) [41], [42], [
          <xref ref-type="bibr" rid="ref21">21</xref>
          ]
31. Communication [
          <xref ref-type="bibr" rid="ref10">10</xref>
          ]
33. Continuous Improvement [32], [39]
35. Cultural Context [
          <xref ref-type="bibr" rid="ref27">27</xref>
          ], [
          <xref ref-type="bibr" rid="ref31">31</xref>
          ]
37. Policies [
          <xref ref-type="bibr" rid="ref10">10</xref>
          ], [
          <xref ref-type="bibr" rid="ref11">11</xref>
          ], [
          <xref ref-type="bibr" rid="ref26">26</xref>
          ], [
          <xref ref-type="bibr" rid="ref28">28</xref>
          ], [32], [33], [43]–
        </p>
        <p>[45]
39. Integration of the Management into the</p>
        <p>
          Security Process [32], [
          <xref ref-type="bibr" rid="ref31">31</xref>
          ]
41. Human Factors [
          <xref ref-type="bibr" rid="ref11">11</xref>
          ], [
          <xref ref-type="bibr" rid="ref18">18</xref>
          ], [
          <xref ref-type="bibr" rid="ref27">27</xref>
          ], [39], [46]
43. Emergency Planning [37]
45. Process Management [
          <xref ref-type="bibr" rid="ref20">20</xref>
          ]
47. Project Management [43]
49. Legal Requirements [
          <xref ref-type="bibr" rid="ref4">4</xref>
          ], [
          <xref ref-type="bibr" rid="ref13">13</xref>
          ]
51. Risk Consciousness [
          <xref ref-type="bibr" rid="ref21">21</xref>
          ], [
          <xref ref-type="bibr" rid="ref26">26</xref>
          ]
53. Training Measures [
          <xref ref-type="bibr" rid="ref10">10</xref>
          ], [
          <xref ref-type="bibr" rid="ref23">23</xref>
          ], [33], [44], [45],
        </p>
        <p>
          [
          <xref ref-type="bibr" rid="ref24">24</xref>
          ]
55. Technical Equipment (Quality) [
          <xref ref-type="bibr" rid="ref12">12</xref>
          ], [
          <xref ref-type="bibr" rid="ref26">26</xref>
          ],
        </p>
        <p>
          [44]
57. Tools [
          <xref ref-type="bibr" rid="ref20">20</xref>
          ], [
          <xref ref-type="bibr" rid="ref23">23</xref>
          ], [
          <xref ref-type="bibr" rid="ref31">31</xref>
          ]
59. Certification as Proof [
          <xref ref-type="bibr" rid="ref19">19</xref>
          ]
        </p>
        <p>
          Factor / Requirement
12. Document Revision [
          <xref ref-type="bibr" rid="ref17">17</xref>
          ]
14. Achieved Level of Protection [
          <xref ref-type="bibr" rid="ref30">30</xref>
          ]
16. Misjudgement of the Management Level
        </p>
        <p>
          [
          <xref ref-type="bibr" rid="ref19">19</xref>
          ]
18. Definition of Roles / Responsibilities
        </p>
        <p>
          and Communication [32], [
          <xref ref-type="bibr" rid="ref10">10</xref>
          ], [
          <xref ref-type="bibr" rid="ref21">21</xref>
          ]
20. Sanctions [
          <xref ref-type="bibr" rid="ref11">11</xref>
          ], [
          <xref ref-type="bibr" rid="ref16">16</xref>
          ] [
          <xref ref-type="bibr" rid="ref26">26</xref>
          ]
22. Funding (Government) [35], [36]
24. Business Continuity [37]
26. Improvement process [39]
28. Information Exchange regarding Security
        </p>
        <p>
          Vulnerabilities [32], [
          <xref ref-type="bibr" rid="ref13">13</xref>
          ], [
          <xref ref-type="bibr" rid="ref30">30</xref>
          ], [40] and
        </p>
        <p>
          Networking [
          <xref ref-type="bibr" rid="ref13">13</xref>
          ], [
          <xref ref-type="bibr" rid="ref31">31</xref>
          ]
30. Government Interest [
          <xref ref-type="bibr" rid="ref4">4</xref>
          ]
32. Concrete Measures of Security Strategies
        </p>
        <p>
          [
          <xref ref-type="bibr" rid="ref30">30</xref>
          ]
34. Loss of control [38], [36]
36. Leadership [
          <xref ref-type="bibr" rid="ref20">20</xref>
          ]
38. Management attention [
          <xref ref-type="bibr" rid="ref20">20</xref>
          ], [
          <xref ref-type="bibr" rid="ref28">28</xref>
          ]
40. Measurements [
          <xref ref-type="bibr" rid="ref20">20</xref>
          ]
42. Level of the Critical Infrastructures [
          <xref ref-type="bibr" rid="ref30">30</xref>
          ]
44. Organizational Perspective [37]
46. Productivity Loss due to cyberloafing
        </p>
        <p>
          [
          <xref ref-type="bibr" rid="ref16">16</xref>
          ]
48. Qualified Employees [
          <xref ref-type="bibr" rid="ref18">18</xref>
          ], [
          <xref ref-type="bibr" rid="ref19">19</xref>
          ], [
          <xref ref-type="bibr" rid="ref26">26</xref>
          ], [
          <xref ref-type="bibr" rid="ref29">29</xref>
          ],
        </p>
        <p>[33]
50. Review of the Implementation of</p>
        <p>
          Measures [32]
52. Collaboration [
          <xref ref-type="bibr" rid="ref10">10</xref>
          ]
54. Security Culture [
          <xref ref-type="bibr" rid="ref11">11</xref>
          ], [
          <xref ref-type="bibr" rid="ref16">16</xref>
          ]
56. Technical Security Controls [
          <xref ref-type="bibr" rid="ref11">11</xref>
          ]
58. Behavioural Controls [
          <xref ref-type="bibr" rid="ref11">11</xref>
          ]
60. Maturity Models [47]
3.3. Merge of requirements from literature review and nis-2 directive
Various requirements for the development of an ISMS can be derived from the NIS-2 guidelines
as well as from the literature. The literature research carried out provides the following
overarching requirements: Management Attention, Strategy Requirements, Compliance and
Legal Requirements, Financial Requirements, Organisational Requirements, Effective Procedural
Approach, Personnel and Financial Resources.
        </p>
        <p>In addition to these overarching requirements, the requirements from the NIS-2 Directive can
be combined with the requirements from the literature research. Table 4 provides an overview
of the requirements (Table 4) from the NIS-2 Directive and the literature review.
4. From requirements to a first approach of a procedural model
These requirements have been summarised as follows. At the top hierarchical level, the
requirements from the area of compliance must be met by an ISMS to be established. This is only
possible if there are appropriate financial conditions in the organization. Within the framework
of the organizational requirements, the prerequisites for management attention, organizational
structure and guidelines must be created. The sub-items Business Continuity, Continuous
Improvement and Audits are subsumed under the heading Strategy. In the area of human
requirements, training measures are essential to be implemented. This is followed by the largest
block of requirements. The technical requirements for application security, infrastructure, and
the associated implementation of measures. Risk management examines all requirements
individually or comprehensively to determine dependencies between the individual
requirements. Figure 1 summarises the results from Sections 3.1 and 3.2.</p>
        <p>What are the requirements of the NIS 2 Directive on the one hand and what are the obstacles
on the other hand and how can they be implemented quickly and easily through a rough process
model in small and medium-sized municipal administrations?
Government
Interest
Legal
Requirements
Self Interest</p>
        <p>Financial
Ressources
Funding</p>
        <p>Policies
Management
Attention
Stakeholder
Management
Organization
Structure
Team-Building
Document
Control</p>
        <p>Management
System
Business
Continuity
Ousourcing
Continuous
Improvement
Audits</p>
        <p>Skills &amp; Expertise</p>
        <p>Riskmanagement
Awareness
Risk
Consciousness
Training
Measures</p>
        <p>Technical
Application
Security
Infrastructure
Security
Servicemanagement
Implementation
of Measures...</p>
        <p>Policies and ATwraairneinnegs,s,
Objectives Competence</p>
        <p>Team- Documentation Service- Risk- GAP
Building Tasks Management Modelling Management Analysis
Planning &amp;
Realisation</p>
        <p>Internal
Audit</p>
        <p>Revision
legend
Part of Approach</p>
        <p>Basic
Requirements</p>
        <p>In a further development step, these requirements for an ISMS were transferred into a
procedural model. The procedural model is supported by an appropriate software prototype. The
procedural model and the software support (Figure 2) with the help of 12 steps the requirements
of an ISMS and help fulfill the requirements of the NIS-2-Directive.</p>
      </sec>
    </sec>
    <sec id="sec-3">
      <title>5. Summary and next steps</title>
      <p>The requirements of the NIS-2 Directive are very abstract framework. Currently, there is a lack of
corresponding architectural concepts.[9, p. 824] Below this architecture, an ISMS must be
established and operated sustainably. At the same time, the listed requirements from the NIS-2
Directive meet in practice the obstacles to the introduction of an ISMS. Through a clear
identification of the requirements of the NIS-2 Directive, but also of the obstacles described from
Sections 3.1 and 3.2 an summarized in Figure 1, the foundations have been laid to create an
appropriate framework for the implementation of ISMS in SPSO. The current research project
focuses on the development of such a framework. The framework conditions listed above must
be considered in the development of a process model. Currently, there is a first framework
concept with the help of which the requirements are tested prototypically in practice. As part of
the research work, the presented procedural model was integrated into a software prototype
(Figure 2) and the usability was checked in an artificial environment and in the field test [48].
Since we follow the guidelines of the Design Science Research Approach (DSR) as an overarching
research design, the overall architecture (procedural model and software prototype) will be
evaluated in a further step within the framework of the ongoing research project. To this end, the
specifications of Hevner and Chatterjee [49] are to be implemented with the help of the
Framework for Evaluation Design Science (FEDS) [50].
Systems and Computing. Singapore: Springer, 2021, pp. 371–381.
[32] R. Tatiara, A. N. Fajar, B. Siregar, and W. Gunawan, ‘Analysis of factors that inhibiting
implementation of Information Security Management System (ISMS) based on ISO 27001’, J.</p>
      <p>Phys. Conf. Ser., vol. 978, no. 1, p. 012039, Mar. 2018.
[33] P. Cooke, ‘“Digital tech” and the public sector: what new role after public funding?’, Eur. Plan.</p>
      <p>Stud., vol. 25, no. 5, pp. 739–754, May 2017, doi: 10.1080/09654313.2017.1282067.
[34] K. Zheng, L. A. Albert, J. R. Luedtke, and E. Towle, ‘A budgeted maximum multiple coverage
model for cybersecurity planning and management’, IISE Trans., vol. 51, no. 12.
[35] K. M. N. De Abrew and R. Wickramarachchi, ‘Organizational Factors Affecting the ISMS</p>
      <p>Effectiveness in Sri Lankan IT Organizations: A Systematic Review’, 2021.
[36] E. Koza, Eine empirische Kontentanalyse zur Ermittlung von praxisorientierten
Optimierungsfeldern zur Resilienz-Erhöhung der IT-Systeme im Sinne der ganzheitlichen
Betrachtung der Informationssicherheit. Gesellschaft für Informatik, Bonn, 2021.
[37] M. S. Jalali, B. Russell, S. Razak, and W. J. Gordon, ‘EARS to cyber incidents in health care’, J.</p>
      <p>Am. Med. Inform. Assoc., vol. 26, no. 1, pp. 81–90, Jan. 2019, doi: 10.1093/jamia/ocy148.
[38] B. Farrand and H. Carrapico, ‘Digital sovereignty and taking back control: from regulatory
capitalism to regulatory mercantilism in EU cybersecurity’, Eur. Secur., vol. 31, no. 3, 2022.
[39] F. Moses, K. Sandkuhl, and T. Kemmerich, ‘Empirical Study on the State of Practice of
Information Securty Maturity Management in Local Government.’, in Human Centred
Intelligent Systems 2022 - Proceeding of the 15th International Conference on Human Centred
Intelligent Systems (KES-HCIS-22). Smart Innovation, Systems and Technologies., A.</p>
      <p>Zimmermann, Ed., Springer. Accepted for publication. To appear June 2022., 2022.
[40] A. Sengupta, ‘A Stakeholder-Centric Approach for Defining Metrics for Information Security
Management Systems’, in Risks and Security of Internet and Systems, B. Luo, M. Mosbah, F.
Cuppens, L. Ben Othmane, N. Cuppens, and S. Kallel, Eds., in Lecture Notes in Computer
Science. Cham: Springer International Publishing, 2022, pp. 57–73.
[41] S. P. Chainey and A. Alonso Berbotto, ‘A structured methodical process for populating a crime
script of organized crime activity using OSINT’, Trends Organ. Crime, vol. 25, no. 3, pp. 272–
300, Sep. 2022.
[42] D. O. Potter and J. S. Hurley, ‘The new role of the “Next generation” CFO’, presented at the</p>
      <p>Proceedings of the 15th International Conference on Cyber Warfare and Security, 2022.
[43] H. Hui-Lin and W. Kuei-Min, ‘The critical success factors assessment of ISO 27001
certification in computer organization by test-retest reliability’, Afr. J. Bus. Manag., vol. 8, no.
17, pp. 705–716, Sep. 2014.
[44] F. Alkhudhayr, S. Alfarraj, B. Aljameeli, and S. Elkhdiri, ‘Information Security:A Review of
Information Security Issues and Techniques’, in 2019 2nd International Conference on
Computer Applications &amp; Information Security (ICCAIS), May 2019, pp. 1–6.
[45] S. Schmitz-Berndt and P. G. Chiara, ‘One step ahead: mapping the Italian and German
cybersecurity laws against the proposal for a NIS2 directive’, Int. Cybersecurity Law Rev., vol.
3, no. 2, pp. 289–311, Dec. 2022.
[46] J. Kävrestad, S. Furnell, and M. Nohlberg, ‘What Parts of Usable Security Are Most Important
to Users?’, in Information Security Education for Cyber Resilience, L. Drevin, N. Miloslavskaya,
W. S. Leung, and S. von Solms, Eds., in IFIP Advances in Information and Communication
Technology. Cham: Springer International Publishing, 2021, pp. 126–139.
[47] H. J. Clemith and D. C. Sicker, ‘Maturity and Process Capability Models and Their Use in
Measuring Resilience in Critical Infrastructure Protection Sectors’, Int. J. Strateg. Inf. Technol.</p>
      <p>Appl. IJSITA, vol. 5, no. 2, pp. 44–63, Apr. 2014.
[48] F. Moses and K. Sandkuhl, ‘Mit CISIS12 ein ISMS aufbauen’, Datenschutz Datensicherheit .
[49] A. Hevner and S. Chatterjee, ‘Design Science Research in Information Systems’, in Design
Research in Information Systems: Theory and Practice, A. Hevner and S. Chatterjee, Eds., in
Integrated Series in Information Systems. Boston, MA: Springer US, 2010, pp. 9–22.
[50] J. Venable, J. Pries-Heje, and R. Baskerville, ‘FEDS: a Framework for Evaluation in Design
Science Research’, Eur. J. Inf. Syst., vol. 25, no. 1, pp. 77–89, Jan. 2016.</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          [1]
          <string-name>
            <given-names>M.</given-names>
            <surname>Riek</surname>
          </string-name>
          ,
          <string-name>
            <given-names>R.</given-names>
            <surname>Bohme</surname>
          </string-name>
          , and T. Moore, '
          <article-title>Measuring the Influence of Perceived Cybercrime Risk on Online Service Avoidance'</article-title>
          ,
          <source>IEEE Trans. Dependable Secure Comput.</source>
          , vol.
          <volume>13</volume>
          , no. 2.
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          [2] 'Raising Awareness of Cybersecurity', ENISA,
          <year>2022</year>
          . https://www.enisa.europa.eu/publications/raising
          <article-title>-awareness-of-cybersecurity (accessed Dec</article-title>
          .
          <volume>14</volume>
          ,
          <year>2022</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          [3]
          <string-name>
            <given-names>R. T.</given-names>
            <surname>Watson</surname>
          </string-name>
          and
          <string-name>
            <given-names>J.</given-names>
            <surname>Webster</surname>
          </string-name>
          , '
          <article-title>Analysing the past to prepare for the future: Writing a literature review a roadmap for release 2</article-title>
          .0',
          <string-name>
            <surname>J. Decis. Syst.</surname>
          </string-name>
          , vol.
          <volume>29</volume>
          , no.
          <issue>3</issue>
          , pp.
          <fpage>129</fpage>
          -
          <lpage>147</lpage>
          , Jul.
          <year>2020</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          [4]
          <string-name>
            <given-names>F.</given-names>
            <surname>Moses</surname>
          </string-name>
          ,
          <string-name>
            <given-names>K.</given-names>
            <surname>Sandkuhl</surname>
          </string-name>
          , and T. Kemmerich, '
          <article-title>Information security management in German local government'</article-title>
          ,
          <source>presented at the 17th Conference on Computer Science and Intelligence</source>
          ,
          <year>2022</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          [5]
          <string-name>
            <surname>Richtlinie</surname>
          </string-name>
          (EU)
          <year>2022</year>
          /
          <article-title>2555 des Europäischen Parlaments und des Rates über Maßnahmen für ein hohes gemeinsames Cybersicherheitsniveau in der Union, zur Änderung der Verordnung (EU) Nr. 910/2014 und der Richtlinie (EU) 2018/1972 sowie zur Aufhebung der Richtlinie (EU)</article-title>
          <year>2016</year>
          /1148 (NIS-2-Richtlinie), vol.
          <volume>333</volume>
          .
          <year>2022</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          [6]
          <string-name>
            <given-names>P.</given-names>
            <surname>Johannesson</surname>
          </string-name>
          and
          <string-name>
            <given-names>E.</given-names>
            <surname>Perjons</surname>
          </string-name>
          , An Introduction to Design Science.
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          [7]
          <string-name>
            <given-names>P.</given-names>
            <surname>Weissmann</surname>
          </string-name>
          , '
          <article-title>Die neue EU NIS 2 Direktive für Cyber Security in KRITIS'</article-title>
          ,
          <year>2023</year>
          . https://www.openkritis.de/it-sicherheitsgesetz/eu-nis-2
          <string-name>
            <surname>-</surname>
          </string-name>
          direktive-kritis.html.
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          [8]
          <string-name>
            <given-names>P.</given-names>
            <surname>Eckhardt</surname>
          </string-name>
          and
          <string-name>
            <given-names>A.</given-names>
            <surname>Kotovskaia</surname>
          </string-name>
          , '
          <article-title>The EU's cybersecurity framework: the interplay between the Cyber Resilience Act and the NIS 2 Directive'</article-title>
          ,
          <source>Int. Cybersecurity Law Rev.</source>
          , vol.
          <volume>4</volume>
          , no.
          <issue>2</issue>
          ,
          <year>2023</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          [9]
          <string-name>
            <given-names>C.</given-names>
            <surname>Werner</surname>
          </string-name>
          ,
          <string-name>
            <given-names>N.</given-names>
            <surname>Brinker</surname>
          </string-name>
          , and
          <string-name>
            <given-names>O.</given-names>
            <surname>Raabe</surname>
          </string-name>
          , '
          <article-title>Grundlagen für ein gesetzliches ITSicherheitsrisikomanagement - Ansätze zur Vereinheitlichung von Rollenmodellen, Risikomanagement für das IT-Sicherheitsrecht'</article-title>
          ,
          <source>Comput. Recht</source>
          , vol.
          <volume>38</volume>
          ,
          <year>2023</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          [10]
          <string-name>
            <given-names>P.</given-names>
            <surname>Choejey</surname>
          </string-name>
          ,
          <string-name>
            <given-names>D.</given-names>
            <surname>Murray</surname>
          </string-name>
          , and
          <string-name>
            <given-names>C.</given-names>
            <surname>Che Fung</surname>
          </string-name>
          , '
          <article-title>Exploring Critical Success Factors for Cybersecurity in Bhutan's Government Organizations'</article-title>
          ,
          <source>in Computer Science &amp; Information Technology ( CS &amp; IT )</source>
          ,
          <source>Academy &amp; Industry Research Collaboration Center (AIRCC)</source>
          ,
          <year>Dec</year>
          .
          <year>2016</year>
          , pp.
          <fpage>49</fpage>
          -
          <lpage>61</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          [11]
          <string-name>
            <given-names>H. W.</given-names>
            <surname>Glaspie</surname>
          </string-name>
          and
          <string-name>
            <given-names>W.</given-names>
            <surname>Karwowski</surname>
          </string-name>
          , '
          <article-title>Human Factors in Information Security Culture: A Literature Review'</article-title>
          , in Advances in Human Factors in Cybersecurity, D. Nicholson, Ed.,
          <source>in Advances in Intelligent Systems and Computing.</source>
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          [12]
          <string-name>
            <given-names>E. B. S.</given-names>
            <surname>Çubuk</surname>
          </string-name>
          ,
          <string-name>
            <given-names>H. E.</given-names>
            <surname>Zeren</surname>
          </string-name>
          , and
          <string-name>
            <given-names>B.</given-names>
            <surname>Demirdöven</surname>
          </string-name>
          , '
          <article-title>The Role of Data Governance in Cybersecurity for E-Municipal Services: Implications From the Case of Turkey', in Handbook of Research on Cybersecurity Issues and Challenges for Business and FinTech Applications</article-title>
          , IGI Global,
          <year>2022</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref13">
        <mixed-citation>
          [13]
          <string-name>
            <given-names>T.</given-names>
            <surname>Rehbohm</surname>
          </string-name>
          ,
          <string-name>
            <given-names>K.</given-names>
            <surname>Sandkuhl</surname>
          </string-name>
          ,
          <string-name>
            <given-names>C. H.</given-names>
            <surname>Cap</surname>
          </string-name>
          , and T. Kemmerich, '
          <article-title>Integrated Security Management of Public and Private Sector for Critical Infrastructures - Problem Investigation'</article-title>
          , in Business Information Systems Workshops, W. Abramowicz,
          <string-name>
            <given-names>S.</given-names>
            <surname>Auer</surname>
          </string-name>
          , and M. Stróżyna, Eds.,
          <year>2022</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref14">
        <mixed-citation>
          [14]
          <string-name>
            <given-names>M.</given-names>
            <surname>Taddeo</surname>
          </string-name>
          , 'Is Cybersecurity a Public Good?',
          <string-name>
            <given-names>Minds</given-names>
            <surname>Mach</surname>
          </string-name>
          ., vol.
          <volume>29</volume>
          , no.
          <issue>3</issue>
          , pp.
          <fpage>349</fpage>
          -
          <lpage>354</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref15">
        <mixed-citation>
          [15]
          <string-name>
            <given-names>S.</given-names>
            <surname>Nather</surname>
          </string-name>
          , '
          <article-title>Improving Information Security Through Risk Management and Enterprise Architecture Integration'</article-title>
          ,
          <source>in International Conference on Cyber Warfare and Security</source>
          , Academic Conferences International Limited, Jan.
          <year>2018</year>
          , p.
          <fpage>420</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref16">
        <mixed-citation>
          [16]
          <string-name>
            <given-names>L.</given-names>
            <surname>Khansa</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.</given-names>
            <surname>Kuem</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Siponen</surname>
          </string-name>
          , and
          <string-name>
            <given-names>S. S.</given-names>
            <surname>Kim</surname>
          </string-name>
          , 'To Cyberloaf or Not to Cyberloaf:
          <article-title>The Impact of the Announcement of Formal Organizational Controls'</article-title>
          ,
          <string-name>
            <surname>J. Manag. Inf. Syst.</surname>
          </string-name>
          , vol.
          <volume>34</volume>
          , no. 1.
        </mixed-citation>
      </ref>
      <ref id="ref17">
        <mixed-citation>
          [17]
          <string-name>
            <given-names>V.</given-names>
            <surname>Susukailo</surname>
          </string-name>
          ,
          <string-name>
            <surname>I. Opirsky</surname>
          </string-name>
          , and
          <string-name>
            <given-names>O.</given-names>
            <surname>Yaremko</surname>
          </string-name>
          , '
          <article-title>Methodology of ISMS Establishment Against Modern Cybersecurity Threats'</article-title>
          , in
          <string-name>
            <surname>Future</surname>
          </string-name>
          Intent-Based
          <string-name>
            <surname>Networking</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          <string-name>
            <surname>Klymash</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          <string-name>
            <surname>Beshley</surname>
          </string-name>
          ,
          <article-title>and</article-title>
          <string-name>
            <surname>A</surname>
          </string-name>
          . Luntovskyy, Eds., in Lecture Notes in Electrical Engineering.
        </mixed-citation>
      </ref>
      <ref id="ref18">
        <mixed-citation>
          [18]
          <string-name>
            <given-names>N.</given-names>
            <surname>Poehlmann</surname>
          </string-name>
          ,
          <string-name>
            <surname>K. M. Caramancion</surname>
            , I. Tatar,
            <given-names>Y.</given-names>
          </string-name>
          <string-name>
            <surname>Li</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          <string-name>
            <surname>Barati</surname>
          </string-name>
          , and T. Merz, '
          <article-title>The Organizational Cybersecurity Success Factors: An Exhaustive Literature Review'</article-title>
          , in Advances in Security, Networks, and Internet of Things, K. Daimi,
          <string-name>
            <given-names>H. R.</given-names>
            <surname>Arabnia</surname>
          </string-name>
          ,
          <string-name>
            <given-names>L.</given-names>
            <surname>Deligiannidis</surname>
          </string-name>
          , M.-
          <string-name>
            <given-names>S.</given-names>
            <surname>Hwang</surname>
          </string-name>
          , and
          <string-name>
            <given-names>F. G.</given-names>
            <surname>Tinetti</surname>
          </string-name>
          , Eds.,
          <source>in Transactions on Computational Science and Computational Intelligence.</source>
        </mixed-citation>
      </ref>
      <ref id="ref19">
        <mixed-citation>
          [19]
          <string-name>
            <given-names>B.</given-names>
            <surname>Preis</surname>
          </string-name>
          and
          <string-name>
            <given-names>L.</given-names>
            <surname>Susskind</surname>
          </string-name>
          , 'Municipal Cybersecurity: More Work Needs to be Done',
          <source>Urban Aff. Rev.</source>
          , vol.
          <volume>58</volume>
          , no.
          <issue>2</issue>
          , pp.
          <fpage>614</fpage>
          -
          <lpage>629</lpage>
          , Mar.
          <year>2022</year>
          , doi: 10.1177/1078087420973760.
        </mixed-citation>
      </ref>
      <ref id="ref20">
        <mixed-citation>
          [20]
          <string-name>
            <given-names>F.</given-names>
            <surname>Moses</surname>
          </string-name>
          ,
          <string-name>
            <given-names>K.</given-names>
            <surname>Sandkuhl</surname>
          </string-name>
          , and T. Kemmerich, '
          <article-title>Empirical Study on the State of Practice of Information Security Management in Local Government', in Human Centred Intelligent Systems, A</article-title>
          . Zimmermann,
          <string-name>
            <given-names>R. J.</given-names>
            <surname>Howlett</surname>
          </string-name>
          , and L. C. Jain, Eds., in Smart Innovation, Systems and Technologies. Singapore: Springer Nature,
          <year>2022</year>
          , pp.
          <fpage>13</fpage>
          -
          <lpage>25</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref21">
        <mixed-citation>
          [21]
          <string-name>
            <given-names>K.</given-names>
            <surname>Gedris</surname>
          </string-name>
          et al., '
          <article-title>Simulating municipal cybersecurity incidents: Recommendations from expert interviews'</article-title>
          ,
          <source>presented at the Proceedings of the Annual Hawaii International Conference on System Sciences</source>
          ,
          <year>2021</year>
          , pp.
          <fpage>2036</fpage>
          -
          <lpage>2045</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref22">
        <mixed-citation>
          [22]
          <string-name>
            <given-names>F.</given-names>
            <surname>Kitsios</surname>
          </string-name>
          , E. Chatzidimitriou, and
          <string-name>
            <given-names>M.</given-names>
            <surname>Kamariotou</surname>
          </string-name>
          , '
          <article-title>Developing a Risk Analysis Strategy Framework for Impact Assessment in Information Security Management Systems: A Case Study in IT Consulting Industry'</article-title>
          ,
          <source>Sustainability</source>
          , vol.
          <volume>14</volume>
          , no.
          <issue>3</issue>
          ,
          <string-name>
            <surname>Art</surname>
          </string-name>
          . no.
          <issue>3</issue>
          ,
          <string-name>
            <surname>Jan</surname>
          </string-name>
          .
          <year>2022</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref23">
        <mixed-citation>
          [23]
          <string-name>
            <surname>I. Nikolova</surname>
          </string-name>
          , '
          <article-title>Best Practice for Cybersecurity Capacity Building in Bulgaria's Public Sector'</article-title>
          ,
          <source>Inf. Secur. Int. J.</source>
          , vol.
          <volume>38</volume>
          , pp.
          <fpage>79</fpage>
          -
          <lpage>92</lpage>
          ,
          <year>2017</year>
          , doi: 10.11610/isij.3806.
        </mixed-citation>
      </ref>
      <ref id="ref24">
        <mixed-citation>
          [24]
          <string-name>
            <surname>T. van Steen</surname>
          </string-name>
          and
          <string-name>
            <given-names>J. R. A.</given-names>
            <surname>Deeleman</surname>
          </string-name>
          , 'Successful Gamification of Cybersecurity Training',
          <source>Cyberpsychology Behav. Soc. Netw.</source>
          , vol.
          <volume>24</volume>
          , no.
          <issue>9</issue>
          , pp.
          <fpage>593</fpage>
          -
          <lpage>598</lpage>
          , Sep.
          <year>2021</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref25">
        <mixed-citation>
          [25]
          <string-name>
            <given-names>E.</given-names>
            <surname>Koza</surname>
          </string-name>
          ,
          <article-title>Eine empirische Kontentanalyse zur Ermittlung von praxisorientierten Optimierungsfeldern zur Resilienz-Erhöhung der IT-Systeme im Sinne der ganzheitlichen Betrachtung der Informationssicherheit</article-title>
          . Gesellschaft für Informatik, Bonn,
          <year>2021</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref26">
        <mixed-citation>
          [26]
          <string-name>
            <given-names>A.</given-names>
            <surname>CHODAKOWSKA</surname>
          </string-name>
          ,
          <string-name>
            <surname>S. KAŃDUŁA</surname>
          </string-name>
          , and
          <string-name>
            <surname>J. PRZYBYLSKA</surname>
          </string-name>
          , '
          <article-title>Cybersecurity in the Local Government Sector in Poland: More Work Needs to be Done'</article-title>
          ,
          <string-name>
            <surname>Lex Localis - J. Local</surname>
          </string-name>
          Self-Gov., vol. Vol.
          <volume>20</volume>
          , No. 1,
          <string-name>
            <surname>Jan</surname>
          </string-name>
          .
          <year>2022</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref27">
        <mixed-citation>
          [27]
          <string-name>
            <given-names>V.</given-names>
            <surname>Benson</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.</given-names>
            <surname>McAlaney</surname>
          </string-name>
          , and
          <string-name>
            <given-names>L. A.</given-names>
            <surname>Frumkin</surname>
          </string-name>
          , '
          <article-title>Emerging Threats for the Human Element and Countermeasures in Current Cyber Security Landscape'</article-title>
          ,
          <source>Cyber Law Priv. Secur. Concepts Methodol</source>
          .
          <source>Tools Appl.</source>
          , pp.
          <fpage>1264</fpage>
          -
          <lpage>1269</lpage>
          ,
          <year>2019</year>
          , doi: 10.4018/978-1-
          <fpage>5225</fpage>
          -8897-9.
          <year>ch062</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref28">
        <mixed-citation>
          [28]
          <string-name>
            <given-names>K.</given-names>
            <surname>Arbanas</surname>
          </string-name>
          and
          <string-name>
            <given-names>N. Žajdela</given-names>
            <surname>Hrustek</surname>
          </string-name>
          , '
          <article-title>Key Success Factors of Information Systems Security'</article-title>
          ,
          <string-name>
            <given-names>J.</given-names>
            <surname>Inf</surname>
          </string-name>
          . Organ. Sci., vol.
          <volume>43</volume>
          , no.
          <issue>2</issue>
          , pp.
          <fpage>131</fpage>
          -
          <lpage>144</lpage>
          , Dec.
          <year>2019</year>
          , doi: 10.31341/jios.43.
          <issue>2</issue>
          .1.
        </mixed-citation>
      </ref>
      <ref id="ref29">
        <mixed-citation>
          [29]
          <string-name>
            <given-names>J.</given-names>
            <surname>Forrester</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M. L.</given-names>
            <surname>Lopez</surname>
          </string-name>
          , and
          <string-name>
            <given-names>M. D.</given-names>
            <surname>Valentina</surname>
          </string-name>
          , '
          <article-title>Marketing a cybersecurity Awareness Solution in LPA Contexts'</article-title>
          , in Cybersecurity Awareness,
          <string-name>
            <given-names>J.</given-names>
            <surname>Andriessen</surname>
          </string-name>
          ,
          <string-name>
            <given-names>T.</given-names>
            <surname>Schaberreiter</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Papanikolaou</surname>
          </string-name>
          , and J. Röning, Eds., in Advances in Information Security.
        </mixed-citation>
      </ref>
      <ref id="ref30">
        <mixed-citation>
          [30]
          <string-name>
            <given-names>J. H.</given-names>
            <surname>Awan</surname>
          </string-name>
          , '
          <article-title>Security strategies to overcome cyber measures, factors</article-title>
          and barriers',
          <source>Eng. Sci. Technol. Int. Res. J.</source>
          , vol. Vol.
          <volume>1</volume>
          , No. 1,
          <string-name>
            <surname>Apr</surname>
          </string-name>
          .
          <year>2017</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref31">
        <mixed-citation>
          [31]
          <string-name>
            <given-names>S. B. M.</given-names>
            <surname>Sabtu and K. M. Mohamad</surname>
          </string-name>
          , '
          <article-title>Critical Information Infrastructure Protection Requirement for the Malaysian Public Sector'</article-title>
          ,
          <source>in Advances on Smart and Soft Computing</source>
          ,
          <string-name>
            <given-names>F.</given-names>
            <surname>Saeed</surname>
          </string-name>
          ,
          <string-name>
            <given-names>T.</given-names>
            <surname>Al-Hadhrami</surname>
          </string-name>
          ,
          <string-name>
            <given-names>F.</given-names>
            <surname>Mohammed</surname>
          </string-name>
          , and E. Mohammed, Eds., in Advances in Intelligent
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>