Local self-governments are recommended to exclude obsolete equipment from use, use licensed operating systems and new generation softwares, regularly update them and apply modern security equipment and procedures to protect information. One of the key recommendations is to improve the use of passwords and authentication within local self-governments, and to limit access for public officials to data that are not within their jurisdiction.
The recommendations were created within the framework of the project "Personal data protection and Information Security at the Local Level", implemented by the National Alliance for Local Economic Development (NALED) and the Office for Information Technologies and eGovernment, with the support of the eGovernment Union members - Asseco SEE, Comtrade, IBM, KPMG, SAGA, SBS and SAP.
"The goal of the project was to check the quality of citizens' data protection at the level of local self-governments, and besides the research, pen-tests of security of IT systems, websites and applications in eight cities and two municipalities were conducted. Kragujevac, Užice, Vranje, Pirot, Šabac, Požarevac, Sombor, Zrenjanin, Vrnjačka Banja and Pećinci are the first local self-governments in which information security experts, in cooperation with the competent authorities, simulated a controlled hacking attack!", said Jovanović at today's meeting on information security at the local level, held in the Palace of Serbia.
He added that this was all part of the training, which is supposed to ensure the protection of citizens' data during the time of digital transformation and public administration reform.
"Today, we gave recommendations to the mayors and presidents of municipalities on how to better protect the IT system from abuse in shortest time possible. The development of eGovernment is a major challenge for municipalities and cities in Serbia, and NALED and the eGovernment Union want to help them improve the sustainability and security of IT systems in order to be ready to provide e-services, but also to have awareness of responsible use and storage of data entrusted to them", said Dejan Đokić, president of the Executive Board of NALED and director of Asseco SEE.
The analysis, carried out within the project, also showed that out of 63 local self-governments in Serbia, almost half of them do not have adequate regulations on information security procedures. Although on average only 65 full-time employees in the local administration are hired from the IT profession, four out of five municipalities and cities do not organize trainings nor raise awareness on this topic. As many as 71% of respondents do not have mechanisms for controlling the outflow of information, while two thirds did not perform IT security assessment.
In addition to the IT system tests, workshops for municipal management and 119 civil servants in the IT sector were organized within the framework of the project in order to familiarize them with the obligations under the Personal Data Protection Act and the Law on Information Security and planned changes in regulations.