140 likes | 248 Views
Findings from the eProcurement study. Arnd Weber Security of eGovernment , European Parliament, Brussels 2013. Public p rocurement in EU. 19% of GDP Prone to bid rigging , corruption. Source: Wikimedia. Electronic p rocurement. < 10% is e Procurement
E N D
Findings from the eProcurement study Arnd Weber Security of eGovernment, European Parliament, Brussels 2013
Public procurement in EU • 19% of GDP • Pronetobidrigging, corruption Source: Wikimedia Arnd Weber
Electronic procurement • <10% iseProcurement • Confidentialinformation, such as: • Prices • Content • Passwords Arnd Weber
Case study on securityofeProcurement • Will presenttwoover-archingissues • More available in report Arnd Weber
Issue 1: Vulnerabilityofcomputersystems • Attacks such as • Zero-dayattacks • Craftedattacks • Wekeeppatching • Reuters on Commissionreport: Spyware in Chinese hardware • Issue also in eHealth etc. = Not a solid foundationforeGovernment Arnd Weber
Issue 1: Vulnerabilityofcomputersystems Policy option: • Requirecomputersystemswithreliableisolation • Isolate sensitive ones • Isolate riskyapplications Arnd Weber
Issue 1: Vulnerabilityofcomputersystems Useofisolation: • Whatsecurityistechnicallyfeasible? • Whatisusable? • Whatiseconomic? • Howcanpolicy push forisolation? • Require exhaustive analysis? • Requireprovensystems? • Topic ofsession on „Protectingagainstattacks“ = A startof a debate on policies Arnd Weber
Issue 2: Varietyofsystems & tools FlorisAmpe, http://de.slideshare.net/Nicolas_Loozen/golden-book-presentation-challenges-and-opportunities Arnd Weber
Issue 2: Varietyofsystems & tools • Hundredsofplatforms • Varietyoftoolsusedforauthentication, encryption, non-repudiation • Reluctancetouseplatforms: 50% ofpublicauthoritiesrejectconceptofmandatoryeProcurement Arnd Weber
Issue 2: Varietyofsystems & tools • Policy option: European lead • Processes not efficient, go back to1990ies • Trans-borderprocessesneedtobeidentified, implemented, tested, theircost-efficiency estimated, androlled-out • Topic ofafternoonsession on thevariety in „27 Member States“ Arnd Weber
Thanks! Tointerviewedexperts Toco-author Christian Henrich of Forschungszentrum Informatik Arnd Weber
Backup Arnd Weber
DrafteProcurementDirective 896 Key content: • MakeeProcmandatory • Commissioncanimposetechnicalstandards Comments: • Considerthatbiddersubmitsdecryptionkey after submissiondeadline • Reliance on centralsystemsmayleadtorisksandcosts • Have upgrade pathifsignaturesgethacked Arnd Weber
Source: PEPPOL project Arnd Weber