A CONCEPTUAL MODEL FOR INFORMATION SECURITY ASSESSMENT IN JUDICIAL INFORMATION SYSTEMS BASED ON RISK AND REGULATORY REQUIREMENTS

Authors

  • Nikolay Koev University of Library Studies and Information Technologies, Sofia, Bulgaria
  • George Dimitrov Faculty of Information Sciences, Computer Sciences Department, University of Library Studies and Information Technologies, Sofia, Bulgaria
  • Daniela Pavlova Faculty of Information Sciences, Computer Sciences Department, University of Library Studies and Information Technologies, Sofia, Bulgaria
  • Nikolay Penev University of Library Studies and Information Technologies, Sofia, Bulgaria

DOI:

https://doi.org/10.68302/std2026.vol3.120

Keywords:

information security, judicial information systems, regulatory requirements, risk assessment

Abstract

The increasing digitalization of the judicial sector requires the implementation of complex information systems that ensure high levels of information security, especially when processing sensitive and classified data. However, the application of security requirements in such environments is often fragmented due to the complexity of regulatory frameworks and the lack of structured approaches for risk assessment. This paper proposes a conceptual model for information security assessment in judicial information systems based on risk and regulatory requirements. The model integrates fundamental principles of information security, including confidentiality, integrity, and availability, with applicable legal and organizational constraints. It provides a structured approach for identifying assets, assessing risks, ensuring compliance with regulatory standards, and selecting appropriate security measures. The proposed model is designed to support decision-making processes and improve the effectiveness of security implementation during the deployment of complex information systems in the judicial sector. The results demonstrate that the model enhances the consistency and traceability of security-related decisions and facilitates alignment with established security standards and legal requirements.

Downloads

Download data is not yet available.

References

[1] A. Maralbaeva, "Evolution of e-Justice Platforms: from ICT in Courts Towards 'Digital Justice' Portal in Kyrgyzstan," International Journal for Court Administration, vol. 15, no. 1, art. 6, 2024, https://doi.org/10.36745/ijca.582.

[2] M. Fabri, "Will COVID-19 Accelerate Implementation of ICT in Courts?," International Journal for Court Administration, vol. 12, no. 2, art. 2, 2021, https://doi.org/10.36745/ijca.384.

[3] J. Björkdahl and C. Kronblad, "Getting on track for digital work: Digital transformation in an administrative court before and during COVID-19," Journal of Professions and Organization, vol. 8, no. 3, pp. 374-393, 2021, https://doi.org/10.1093/jpo/joab015.

[4] C. Kronblad and J. E. Pregmark, "When digitalization hit the court: Strategizing to turn turbulence into opportunities," Journal of Professions and Organization, vol. 12, no. 1, art. joae007, 2025, https://doi.org/10.1093/jpo/joae007.

[5] O. Oktal, O. Alpu, and B. Yazici, "Measurement of internal user satisfaction and acceptance of the e-justice system in Turkey," Aslib Journal of Information Management, vol. 68, no. 6, pp. 716-735, 2016, https://doi.org/10.1108/AJIM-04-2016-0048.

[6] M. Schmidt, "Information security risk management terminology and key concepts," Risk Management, vol. 25, art. 2, 2023, https://doi.org/10.1057/s41283-022-00108-8.

[7] M. Brunner, C. Sauerwein, M. Felderer, and R. Breu, "Risk management practices in information security: Exploring the status quo in the DACH region," Computers & Security, vol. 92, art. 101776, 2020, https://doi.org/10.1016/j.cose.2020.101776.

[8] National Institute of Standards and Technology, Managing Information Security Risk: Organization, Mission, and Information System View, NIST SP 800-39, 2011, https://doi.org/10.6028/NIST.SP.800-39.

[9] National Institute of Standards and Technology, Guide for Conducting Risk Assessments, NIST SP 800-30 Rev. 1, 2012, https://doi.org/10.6028/NIST.SP.800-30r1.

[10] ISO/IEC 27001:2022, Information security, cybersecurity and privacy protection - Information security management systems - Requirements, 2022.

[11] ISO/IEC 27005:2022, Information security, cybersecurity and privacy protection - Guidance on managing information security risks, 2022.

[12] ISO 31000:2018, Risk management - Guidelines, 2018.

[13] Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (General Data Protection Regulation), OJ L 119, 4 May 2016.

[14] Directive (EU) 2022/2555 of the European Parliament and of the Council of 14 December 2022 on measures for a high common level of cybersecurity across the Union (NIS2), OJ L 333, 27 December 2022.

[15] Regulation (EU) No 910/2014 of the European Parliament and of the Council of 23 July 2014 on electronic identification and trust services for electronic transactions in the internal market (eIDAS), OJ L 257, 28 August 2014.

[16] Regulation (EU) 2023/2844 of the European Parliament and of the Council of 13 December 2023 on the digitalisation of judicial cooperation and access to justice in cross-border civil, commercial and criminal matters, OJ L, 27 December 2023.

[17] Cybersecurity Act, promulgated in State Gazette No. 94 of 13 November 2018, amended and supplemented in State Gazette No. 17 of 13 February 2026. [In Bulgarian].

[18] Classified Information Protection Act, promulgated in State Gazette No. 45 of 30 April 2002. [In Bulgarian].

[19] Ordinance on the Security of Communication and Information Systems, adopted by Council of Ministers Decree No. 28 of 24 February 2020, promulgated in State Gazette No. 18 of 28 February 2020. [In Bulgarian].

[20] Ordinance No. 1 of 8 January 2008 on Automated Information Systems in the Judiciary. [In Bulgarian].

[21] Rules on the Internal Procedure for the Use of Electronic Signatures and Electronic Identification by the Authorities of the Judiciary, adopted by the Plenum of the Supreme Judicial Council under item 39 of Protocol No. 10/16 March 2017, promulgated in State Gazette No. 32 of 21 April 2017. [In Bulgarian].

[22] Ordinance No. 6 of 3 August 2017 on the Performance of Procedural Actions and Certifying Statements in Electronic Form, promulgated in State Gazette No. 67 of 18 August 2017, amended and supplemented in State Gazette No. 53 of 1 July 2025. [In Bulgarian].

[23] National Institute of Standards and Technology, The NIST Cybersecurity Framework (CSF) 2.0, NIST CSWP 29, 2024, https://doi.org/10.6028/NIST.CSWP.29.

[24] A. Nelson, S. Rekhi, M. Souppaya, and K. Scarfone, Incident Response Recommendations and Considerations for Cybersecurity Risk Management: A CSF 2.0 Community Profile, NIST SP 800-61 Rev. 3, 2025, https://doi.org/10.6028/NIST.SP.800-61r3.

[25] R. S. Alves, J. P. B. da Silva, L. A. Ribeiro Junior, and R. R. Nunes, "Enhancing cybersecurity in the judiciary: Integrating additional controls into the CIS framework," Computers & Security, vol. 157, art. 104584, 2025, https://doi.org/10.1016/j.cose.2025.104584.

[26] I. V. Țicovan and G. Sebestyen, "Solutions for enhancing the protection of digital evidence in judicial information systems," Romanian Journal of Information Technology and Automatic Control, vol. 35, no. 2, pp. 19-32, 2025, https://doi.org/10.33436/v35i2y202502.

[27] M. Ramos-Maqueda and D. L. Chen, "The data revolution in justice," World Development, vol. 186, art. 106834, 2025, https://doi.org/10.1016/j.worlddev.2024.106834.

Downloads

Published

17.09.2026

How to Cite

[1]
N. Koev, G. Dimitrov, D. Pavlova, and N. Penev, “A CONCEPTUAL MODEL FOR INFORMATION SECURITY ASSESSMENT IN JUDICIAL INFORMATION SYSTEMS BASED ON RISK AND REGULATORY REQUIREMENTS”, SysTechDev, vol. 3, pp. 127–132, Sep. 2026, doi: 10.68302/std2026.vol3.120.