2.2 Identity Management, Access Policies, and Threat Mitigation
The operationalization of identity and access governance within local government unit (LGU) e-services requires an explicit division of administrative privileges and strict transactional boundaries. Integrating comprehensive cybersecurity dimensions into municipal electronic public service systems demands structured access management policies that limit unauthorized data exposure while sustaining service continuity (Alanezi et al., 2020). To operationalize these protections, the technical framework establishes least-privilege role assignments, mandatory multi-factor authentication for administrative personnel, and immutable transaction logging across local databases. These architectural controls directly prevent unauthorized data manipulation and ensure that transactional modifications within digital municipal records systems remain fully traceable and auditable. Furthermore, standardizing electronic records governance alongside role-based access controls provides a dependable operational baseline for public registries that manage sensitive citizen information (Calanasan Assessment Team, 2025). The criteria for deploying these protocols focus on eliminating single-point credential vulnerabilities, ensuring strict compliance with municipal privacy mandates, and preserving portal functionality under resource constraints (Alanezi et al., 2020; Calanasan Assessment Team, 2025). By establishing structured verification protocols before granting elevated credentials, local authorities mitigate identity spoofing risks and reinforce procedural transparency throughout service transactions. In practical application, institutionalizing these access controls isolates critical municipal databases from unauthorized external intrusions while systematically recording administrative workflows across citizen-facing service touchpoints.