Information Security Regulations: Explaining Compliance and Non-Compliance

Dr. Tommy Tranvik

NRCCL, University of Oslo

I will present findings from a research project that has studied (i) what (if anything) 18 municipal authorities have done (and are currently doing) in order to implement the information security regulations of the Norwegian Data Protection Act, and (ii) what the most important national information security actors, particularly the Norwegian Data Inspectorate, have done (and are currently doing) in order to secure local government compliance. Two main questions will be addressed. First, to what extent and in what way do local governments comply with the information security regulations? Second, what strategies and tools does the Norwegian Data Inspectorate employ in order to secure municipal compliance? This means that the research project gives a bottom-up (a municipal) and a top-down (a national) view of and approach to practical information security work.