Uma Proposta de Plataforma para Avaliação Contínua de Maturidade em Governança de Cibersegurança no Setor Público

  • João G. I. Braga UFC
  • Francisco J. S. Sousa UFC
  • Paola S. Pereira UFC
  • Tales P. Nogueira UNILAB / UFC
  • Antonia M. A. da Silva UFC
  • Emanuel Bezerra Rodrigues UFC
  • Alexandre S. Cialdini Seplag-CE
  • Rossana M. C. Andrade UFC

Resumo


This paper proposes a web-based platform to support continuous cybersecurity maturity assessment in the public sector, aligned with the Information Privacy and Security Program (PPSI). Motivated by limitations of unstructured assessment practices, such as spreadsheet-based monitoring, the proposed solution centralizes sensitive information, supports evidence management, and improves traceability through role-based access and audit mechanisms. The platform operationalizes PPSI guidelines through structured forms, data analysis, dashboards, and action plans, enabling organizations to assess maturity levels, identify gaps, prioritize corrective measures, and monitor progress over successive evaluation cycles. By integrating governance, monitoring, and improvement activities, the solution will contribute to greater transparency, accountability, and consistency in cybersecurity management for public entities.

Referências

BRASIL. PPSI 1.0: Programa de Privacidade e Segurança da Informação. 2023. Disponível em: [link]. Acesso em: 26 maio 2026.

BRASIL. PPSI 2.0: Programa de Privacidade e Segurança da Informação. 2025. Disponível em: [link]. Acesso em: 26 maio 2026.

DRIVAS, George; CHATZOPOULOU, Argyro; MAGLARAS, Leandros; LAMBRINOUDAKIS, Costas; COOK, Allan; JANICKE, Helge. A NIS Directive Compliant Cybersecurity Maturity Assessment Framework. In: 2020 IEEE 44th Annual Computers, Software, and Applications Conference (COMPSAC). [S. l.]: IEEE, 2020. p. 1641–1646. DOI: 10.1109/COMPSAC48688.2020.00-20.

HAMID, Supardi; HUDA, Mohammad Nurul. Mapping the landscape of government data breaches: A bibliometric analysis of literature from 2006 to 2023. Social Sciences & Humanities Open, Elsevier, v. 11, p. 101234, 2025.

HOSSAIN, Sk Tahsin; YIGITCANLAR, Tan; NGUYEN, Kien; XU, Yue. Cybersecurity in local governments: A systematic review and framework of key challenges. Urban Governance, Elsevier, v. 5, n. 1, p. 1–19, 2025.

LIMA, João C. C. et al. Análise de Severidade e Explorabilidade de Vulnerabilidades de Segurança no Setor Público. In: ANAIS Estendidos do Simpósio Brasileiro de Cibersegurança (SBSeg). [S. l.]: SBC, 2025. p. 409–416. DOI: 10.5753/sbseg_estendido.2025.12672.

MAGNUSSON, L.; IQBAL, S.; ELM, P.; DALIPI, F. Information Security Governance in the Public Sector: Investigations, Approaches, Measures, and Trends. International Journal of Information Security, Springer, v. 24, n. 4, p. 177, 2025.

SARAIVA, Juliana; SOUZA, Cleidson de; SOARES, Sérgio. MMAI-LGPD: A Maturity Model for Governance and Data Compliance in Information Systems Institutions. In: ANAIS do Simpósio Brasileiro de Sistemas de Informação (SBSI). [S. l.]: SBC, 2025. p. 788–797. DOI: 10.5753/sbsi.2025.246644.

SOUSA, M.; SILVA, D.; SOARES, H. Prioritization Strategy for Measures in the Brazilian Security Framework. In: ANAIS do XIII Latin American Symposium on Digital Government. Maceió/AL: SBC, 2025. p. 261–272. DOI: 10.5753/lasdigov.2025.9349.

SPÓSITO, Stefano Luppi; MOREIRA, Fernando Rocha; CANEDO, Edna Dias. Designing a Training Journey for Privacy and Information Security Practitioners in the Federal Public Administration. In: ANAIS do Simpósio Brasileiro de Sistemas de Informação (SBSI). [S. l.]: SBC, 2025. p. 95–104. DOI: 10.5753/sbsi.2025.246040.
Publicado
01/09/2026
BRAGA, João G. I.; SOUSA, Francisco J. S.; PEREIRA, Paola S.; NOGUEIRA, Tales P.; SILVA, Antonia M. A. da; RODRIGUES, Emanuel Bezerra; CIALDINI, Alexandre S.; ANDRADE, Rossana M. C.. Uma Proposta de Plataforma para Avaliação Contínua de Maturidade em Governança de Cibersegurança no Setor Público. In: TRILHA DE INTERAÇÃO COM A INDÚSTRIA E DE INOVAÇÃO - SIMPÓSIO BRASILEIRO DE CIBERSEGURANÇA (SBSEG), 26. , 2026, Armação dos Búzios/RJ. Anais [...]. Porto Alegre: Sociedade Brasileira de Computação, 2026 . p. 961-967. DOI: https://doi.org/10.5753/sbseg_estendido.2026.29388.

Artigos mais lidos do(s) mesmo(s) autor(es)

1 2 3 4 5 6 > >>