Adoption of Cybersecurity Capability Maturity Models in Municipal Governments
Walter Miron · 2015
Cyberattacks are increasing in diversity and volume placing information and communications technology (ICT) as well as physical assets at risk.Municipal governments operating as the provider of an interdependent network of e-government services, Information and Communications Technology, and Critical Infrastructure (CI) have a requirement to quickly, easily, and inexpensively secure their ICT systems and physical assets.In addition to other sources, this study sampled data from Canadian municipal government CIO's using expert interviews followed by a web-based survey in the winter of 2015 to help inform both the development of a Cybersecurity Capability Maturity Model for Canadian municipalities and to provide recommendations pertaining to the adoption of such a model. The study confirmed the low level of recognition by Canadian municipalities regardingCybersecurity Capability Maturity Models (CCMM) and identified a need to improve their observability in this sector in order to foster adoption.Simplicity of the CCMM and its Trialability in municipal CI networks emerged as key factors influencing its adoption and these factors are considered in the development of the CCMM.Compatibility of the CCMM did not emerge as a factor in adoption as they are new to municipal CI protection.A model combining controls from ISO 27000 and maturity scoring based on SEI-CMMI maturity levels is developed to simplify cybersecurity readiness maturity assessment, and a model for diffusing the CCMM in Canadian municipalities is provided.