Study on Financial-sector Information Security Level Assessment and Improvement Anticipation Model

被引:0
|
作者
Park, Young-Rai [1 ]
Choy, Yoon-Chul [1 ]
Shon, Won-Sung [2 ]
机构
[1] Yonsei Univ, Dept Comp Sci, Seoul, South Korea
[2] Gyeongin Natl Univ Educ, Dept Comp Educ, Incheon, South Korea
关键词
information security; information security maturity level; assessment indices; information security management systems;
D O I
10.14257/ijsia.2014.8.6.14
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Infringement threats to the financial sector have become more sophisticated and intelligent. In order to more effectively respond to such threats, the financial sector faces the need to perform the assessment of information security maturity level on a voluntary basis in order to better understand organizational information security situation and improve own vulnerabilities to reinforce information security. The study, in reflection of financial industrial environmental characteristics, builds a comprehensive and systematic information security assessment indices specialized in the financial sector while presenting an information security maturity level assessment model based on the indices as well as an information security improvement anticipation model through vulnerability remedy. The quantification of vulnerability levels of the control item suggested herein and the improvement anticipation model based on vulnerability correction, in particular, supports an organization under the assessment to address its vulnerabilities to effectively enhance organizational information security. In the absence of such an information security assessment model, the financial sector has poorly performed in assessing own information security activities. With the models suggested herein being in place, the sector is expected to make an active use of it to facilitate information security assessment and improve the general information security maturity level of individual financial institutions and the financial industry as a whole
引用
收藏
页码:147 / 160
页数:14
相关论文
共 50 条
  • [31] An Analysis of and Perspective on the Information Security Maturity Model: a case study of a Public and a Private Sector Company
    Silva, Lucio
    Costa, Ana Paula
    Poleto, Thiago
    Moura, Jadielson
    [J]. AMCIS 2012 PROCEEDINGS, 2012,
  • [32] A policy driven, human oriented information security model: a case study in UAE banking sector
    Alhosani, Khalid Eisa Haidar Abdalla
    Khalid, Shamsul Kamal Ahmad
    Samsudin, Noor Azah
    Jamel, Sapiee
    bin Mohamad, Kamaruddin Malik
    [J]. 2019 IEEE CONFERENCE ON APPLICATION, INFORMATION AND NETWORK SECURITY (AINS), 2019, : 12 - 17
  • [33] AN ANALYTICAL STUDY OF INFORMATION SECURITY MANAGEMENT IN THE PUBLIC SECTOR OF ALBANIA
    Kuka, Elda
    [J]. CBU INTERNATIONAL CONFERENCE PROCEEDINGS 2018: INNOVATIONS IN SCIENCE AND EDUCATION, 2018, 6 : 277 - 281
  • [34] Risks Management relating to Information Systems Security. Assessment Methods for the Risk Level in Information Security
    Baicu, Floarea
    Baicu, Andrei Mihai
    [J]. QUALITY-ACCESS TO SUCCESS, 2012, 13 (129): : 112 - 115
  • [35] Enterprise Information Systems Security: A Case Study in the Banking Sector
    Chaudhry, Peggy E.
    Chaudhry, Sohail S.
    Clark, Kevin D.
    Jones, Darryl S.
    [J]. ENTERPRISE INFORMATION SYSTEMS OF THE FUTURE, 2013, 139 : 206 - 214
  • [37] Professional Competencies Level Assessment for Training of Masters in Information Security
    Miloslavskaya, Natalia
    Tolstoy, Alexander
    [J]. INFORMATION SECURITY EDUCATION ACROSS THE CURRICULUM, WISE 9, 2015, 453 : 135 - 145
  • [38] Information Security Culture Assessment: Case Study
    Al-Mayahi, Ibrahim
    Mansoor, Sa'ad P.
    [J]. 2013 INTERNATIONAL CONFERENCE ON INFORMATION SCIENCE AND TECHNOLOGY (ICIST), 2013, : 789 - 792
  • [39] Information security model using decision tree for Jordanian public sector
    Arabeyyat, Omar Suleiman
    [J]. INTERNATIONAL JOURNAL OF ELECTRONIC SECURITY AND DIGITAL FORENSICS, 2018, 10 (03) : 228 - 241
  • [40] A Study of Information Security Evaluation and Risk Assessment
    Li, Jingyi
    Chao, Shiwei
    Huo, Minxia
    [J]. 2015 FIFTH INTERNATIONAL CONFERENCE ON INSTRUMENTATION AND MEASUREMENT, COMPUTER, COMMUNICATION AND CONTROL (IMCCC), 2015, : 1909 - 1912