信息安全
业务
互联网隐私
计算机安全
计算机科学
作者
Diogo Ribeiro,Victor Fonte,Luis Felipe Ramos,João Marco C. Silva
标识
DOI:10.1016/j.giq.2025.102031
摘要
The fast global expansion of online public services has transformed how governments interact with citizens, offering convenience and efficiency. However, this digital transformation also introduces significant security risks, as sensitive data exchanged between users and service providers over public networks are exposed to cyber threats. Thus, ensuring the security and trustworthiness of these services is critical to the success of Electronic Government (EGOV) initiatives. This study evaluates the information security posture of 3068 public service platforms across all 193 UN Member States through non-intrusive assessments conducted in 2023 and 2024. The evaluation focuses on three key dimensions: (i) the adoption of secure end-to-end communication protocols, (ii) the trustworthiness of digital certificate chains, and (iii) the exposure of hosting servers to known vulnerabilities. The findings reveal that while some progress has been made in securing online public services, substantial gaps remain in the implementation of international security standards and best practices. Many platforms continue to rely on outdated cryptographic protocols, misconfigured certificates, and unpatched vulnerabilities, leaving citizens and services vulnerable to cyber threats due to weaknesses that malicious actors can easily and inconspicuously identify. These insights emphasize the need for effective implementation of more comprehensive cybersecurity policies, proactive security assessments, and improved regulatory compliance checks. Additionally, this work provides actionable guidance for governments and system administrators to enhance the security of EGOV infrastructures by addressing persistent vulnerabilities and adopting robust cybersecurity practices. • This study reveals progress and persistent security gaps of EGOV services. • The identified issues pose risks to providers and citizens alike. • Common issues found include certificate trustworthiness and vulnerability exposure. • The impact of issues is presented, including a set of recommendations on how to fix them. • The recommendations provided enhance resilience to threats and minimize risk exposure.
科研通智能强力驱动
Strongly Powered by AbleSci AI