Study on Financial-sector Information Security Level Assessment and Improvement Anticipation Model

被引:0
|
作者
Park, Young-Rai [1 ]
Choy, Yoon-Chul [1 ]
Shon, Won-Sung [2 ]
机构
[1] Yonsei Univ, Dept Comp Sci, Seoul, South Korea
[2] Gyeongin Natl Univ Educ, Dept Comp Educ, Incheon, South Korea
关键词
information security; information security maturity level; assessment indices; information security management systems;
D O I
10.14257/ijsia.2014.8.6.14
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Infringement threats to the financial sector have become more sophisticated and intelligent. In order to more effectively respond to such threats, the financial sector faces the need to perform the assessment of information security maturity level on a voluntary basis in order to better understand organizational information security situation and improve own vulnerabilities to reinforce information security. The study, in reflection of financial industrial environmental characteristics, builds a comprehensive and systematic information security assessment indices specialized in the financial sector while presenting an information security maturity level assessment model based on the indices as well as an information security improvement anticipation model through vulnerability remedy. The quantification of vulnerability levels of the control item suggested herein and the improvement anticipation model based on vulnerability correction, in particular, supports an organization under the assessment to address its vulnerabilities to effectively enhance organizational information security. In the absence of such an information security assessment model, the financial sector has poorly performed in assessing own information security activities. With the models suggested herein being in place, the sector is expected to make an active use of it to facilitate information security assessment and improve the general information security maturity level of individual financial institutions and the financial industry as a whole
引用
收藏
页码:147 / 160
页数:14
相关论文
共 50 条
  • [1] Development of Information Security Management Assessment Model for the Financial Sector
    Oh, Eun
    Kim, Tae-Sung
    Cho, Tae-Hee
    [J]. INFORMATION SECURITY APPLICATIONS, WISA 2016, 2017, 10144 : 186 - 197
  • [2] Financial-sector shocks in a credit-view model
    Abrams, Burton A.
    [J]. ECONOMICS LETTERS, 2011, 112 (03) : 256 - 258
  • [3] The Study on Risk Assessment System of Information Security in Financial Transaction
    Lu, Dan
    [J]. INFORMATION TECHNOLOGY APPLICATIONS IN INDUSTRY II, PTS 1-4, 2013, 411-414 : 2191 - 2194
  • [4] ASSESSMENT OF THE FINANCIAL SECURITY LEVEL OF UKRAINE
    Kalinichenko, O., V
    Lesyuk, V. S.
    [J]. SCIENCE AND INNOVATION, 2021, 17 (06): : 3 - 12
  • [5] Dynamic financial and monetary security risk assessment based on information service security assessment model and blockchain
    Jia Li
    [J]. Scientific Reports, 13
  • [6] Dynamic financial and monetary security risk assessment based on information service security assessment model and blockchain
    Li, Jia
    [J]. SCIENTIFIC REPORTS, 2023, 13 (01)
  • [7] AN ASSESSMENT OF THE FINANCIAL AND ECONOMIC SECURITY OF THE AGRICULTURAL SECTOR IN UKRAINE
    Sirenko, N.
    Lunkina, T.
    Burkovskaya, A.
    Mikulyak, K.
    [J]. FINANCIAL AND CREDIT ACTIVITY-PROBLEMS OF THEORY AND PRACTICE, 2021, 4 (39): : 241 - 250
  • [8] A study on the optimal model for information security management level
    Cho, Kyong Ho
    Lee, Dong Hwi
    Kim, Jeom-Goo
    Lee, Cheol-Won
    Seo, Hyung-Jun
    Kim, Kuinam J.
    [J]. ICISS 2008: INTERNATIONAL CONFERENCE ON INFORMATION SCIENCE AND SECURITY, PROCEEDINGS, 2008, : 238 - +
  • [9] Enterprise risk management and information technology security in the financial sector
    Kwateng, Kwame Owusu
    Amanor, Christopher
    Tetteh, Francis Kamewor
    [J]. INFORMATION AND COMPUTER SECURITY, 2022, 30 (03) : 422 - 451
  • [10] Rethinking FS-ISAC: An IT Security Information Sharing Network Model for the Financial Services Sector
    Liu, Charles Z.
    Zafar, Humayun
    Au, Yoris A.
    [J]. COMMUNICATIONS OF THE ASSOCIATION FOR INFORMATION SYSTEMS, 2014, 34 : 15 - 36