IDEAS home Printed from https://ideas.repec.org/a/pop/procee/v10y2022p129-136.html
   My bibliography  Save this article

Creation of a distinct culture for the overall system Compliance, IT security and Data protection in municipalities in Germany

Author

Listed:
  • Christian SCHACHTNER

    (IU University of Applied Sciences, Bad Reichenhall, Germany)

Abstract

Public administrations in Germany today are increasingly exposed to attacks from the digital space. Threats to their IT systems or organizations in the physical world require security strategies. The Objectives of the work are the conviction of government leaders to enable themselves to control the implementation of data protection and IT security in their organizations with priority and resources. This also includes compliance as part ofinformation security management systems in order to better anchor compliance in the overall organization, especially at the operational level. The Prior work shows that only a few protective measures are implemented in municipalities in Germany, although models for IT-Governance are available. One reason could be the scope and abstractness of the management systems, which lead to avoiding the introduction phase. To close the gap between awareness of the relevance of the topic and the actual taking action of measures, clear vision of practical implementation must be conveyed in order to protect the organization sufficiently and permanently. The Approach is based on a combination of technology, strategy and people. A bipolar approach is to be chosen in this thesis: Government leaders are to be simulated by a game-based learning approach knowledge around the topics of IT security, data protection and compliance through serious games scenarios. At the operational level of the security officers, building blocks such as Building information security, Compliance processes and applications and Risk management are to be developed collaboratively as predefined building blocks and meaningful process models are to be visualized at a uniform level of abstraction. The first Results lead to the realization that technical and organizational measures for institutional protection can be developed independently, so that no external consultants are required. Authority management can increasingly assume their responsibility in this area as soon as a basic understanding of sufficient resources has been established and their own roles in the overall system of compliance, IT security and data protection are assigned. The Implications include enabling government leaders to initiate and manage compliance in their organizations. The operationally responsible employees must be enabled to implement compliance in practice in cooperation with experts from thematic departments. In the long term, this is intended to create a distinct compliance culture in an organization. The Value of the work lies in getting compliance directly linked to the working level in order to anchor it directly in the organization. Government leaders are tasked with building a security- and risk- based culture. The thesis focuses in particular on adapting the mindset of employees and operational managers with regard to security risks and their consequences. Prioritization in preventive measures must therefore be shown in order to take up decisions on activities against cyber attacks and other incidents.

Suggested Citation

  • Christian SCHACHTNER, 2022. "Creation of a distinct culture for the overall system Compliance, IT security and Data protection in municipalities in Germany," Smart Cities International Conference (SCIC) Proceedings, Smart-EDU Hub, vol. 10, pages 129-136, November.
  • Handle: RePEc:pop:procee:v:10:y:2022:p:129-136
    as

    Download full text from publisher

    File URL: https://scrd.eu/index.php/scic/article/view/428/388
    Download Restriction: no

    File URL: https://scrd.eu/index.php/scic/article/view/428
    Download Restriction: no
    ---><---

    More about this item

    JEL classification:

    • O35 - Economic Development, Innovation, Technological Change, and Growth - - Innovation; Research and Development; Technological Change; Intellectual Property Rights - - - Social Innovation

    Statistics

    Access and download statistics

    Corrections

    All material on this site has been provided by the respective publishers and authors. You can help correct errors and omissions. When requesting a correction, please mention this item's handle: RePEc:pop:procee:v:10:y:2022:p:129-136. See general information about how to correct material in RePEc.

    If you have authored this item and are not yet registered with RePEc, we encourage you to do it here. This allows to link your profile to this item. It also allows you to accept potential citations to this item that we are uncertain about.

    We have no bibliographic references for this item. You can help adding them by using this form .

    If you know of missing items citing this one, you can help us creating those links by adding the relevant references in the same way as above, for each refering item. If you are a registered author of this item, you may also want to check the "citations" tab in your RePEc Author Service profile, as there may be some citations waiting for confirmation.

    For technical questions regarding this item, or to correct its authors, title, abstract, bibliographic or download information, contact: Catalin Vrabie (email available below). General contact details of provider: https://edirc.repec.org/data/fasnsro.html .

    Please note that corrections may take a couple of weeks to filter through the various RePEc services.

    IDEAS is a RePEc service. RePEc uses bibliographic data supplied by the respective publishers.