Show simple item record

dc.contributor.advisorSkotnes, Ruth Østgaard
dc.contributor.authorSundfær, Christian
dc.contributor.authorHaagensen, Hans Tore
dc.date.accessioned2022-10-04T15:51:22Z
dc.date.available2022-10-04T15:51:22Z
dc.date.issued2022
dc.identifierno.uis:inspera:106583770:68633782
dc.identifier.urihttps://hdl.handle.net/11250/3023683
dc.description.abstractThis thesis has looked at “how Norwegian municipalities work with the risk of cyber attacks via suppliers' ICT services” and, by extension, what requirements they place on the supply chain, both through internal processes, as a client and what is within the regulations for public procurement. Finally, the thesis has also looked at how the municipalities experience the authorities' work in the area. We as authors chose early on to split the theory chapter into several parts. Risk, information security, cybersecurity, and procurement. This division is made to cover the necessary spectrum to answer the broad research question. As we have used the question form "how" in this research and have had a desire to study individual events, go in depth, shed light on small details and give informants freedom to express themselves, qualitative research method with interviews is used. In total, the thesis has 14 informants spread over several municipalities, an inter-municipal cooperation, Kommune-CSIRT and Orange Cyberdefence. Our main finding in this thesis shows that the municipalities are partly aware of the risk of cyber attacks via the supply chains and are actively working to reduce it. As of today, the municipalities in this thesis, are in the lower tier of maturity when it comes to risk, but based on long-term plans, they are in the process of implementing a better management system with common definitions, methodology and understanding of how to work with the subject area. Furthermore, through this thesis we have found findings that indicate that the municipalities could with advantage integrate a better set of standard requirements for cyber and information security in their procurements. Finally, we want to highlight the thesis' findings where the municipalities experience that there are too many government actors within the subject area, who by extension use different approaches so that it becomes confusing for the municipalities to identify recommended best practice.
dc.description.abstract
dc.languagenob
dc.publisheruis
dc.titleNorwegian municipalities risk management of cyber-attacks through suppliers ICT systems
dc.typeMaster thesis


Files in this item

Thumbnail

This item appears in the following Collection(s)

  • Studentoppgaver (TN-ISØP) [1412]
    Master- og bacheloroppgaver i Byutvikling og urban design / Offshore technology : risk management / Risikostyring / Teknologi/Sivilingeniør : industriell økonomi / Teknologi/Sivilingeniør : risikostyring / Teknologi/Sivilingeniør : samfunnssikkerhet

Show simple item record