This thesis explores various aspects of cybersecurity during the development of information systems within the public administration of the Republic of Slovenia. It emphasizes that information systems are essential components of modern public administration, and their security is increasingly critical given the growing cyber threats that can compromise national stability and safety.
It begins by clarifying the fundamental concepts of information systems and cybersecurity, followed by an examination of the relevant cybersecurity regulation in both the European Union and Slovenia. It presents modern approaches to integrating security into the development processes of information systems, such as the implementation of static and dynamic code analysis, the use of the DevSecOps approach, the automation of security testing, and advanced data protection techniques, including encryption, anonymization, and pseudonymization. It also covers network protection measures, securing containerized environments, and the use of artificial intelligence and automation in responding to security incidents.
Special attention is given to the analysis of security requirements in public procurement documentation for the development of public sector information systems. Four concrete cases are examined from the areas of justice, healthcare, social welfare, and inspection oversight. Based on the analysis, improvement proposals are made, including the early execution of security reviews, centralized identity and access management, and regular penetration testing. The thesis also emphasizes the necessity of systematically incorporating cybersecurity into all phases of information system development, adhering strictly to legislative requirements, and using modern security technologies and practices to ensure a high level of information security in public administration.
|