International Seminar on Mathematics, Science, and Computer Science Education 2016 | |
A Method for Evaluating Information Security Governance (ISG) Components in Banking Environment | |
数学;自然科学;计算机科学 | |
Ula, M.^1 ; Ula, M.^1 ; Fuadi, W.^1 | |
Informatics Engineering, Malikussaleh University, Jl. Cot Tengku Nie Reuleut, Aceh Utara, Indonesia^1 | |
关键词: Component importance; Computer technology; Critical component; Information security governance; Market interactions; Security breaches; Security professionals; Weighting coefficient; | |
Others : https://iopscience.iop.org/article/10.1088/1742-6596/812/1/012031/pdf DOI : 10.1088/1742-6596/812/1/012031 |
|
来源: IOP | |
【 摘 要 】
As modern banking increasingly relies on the internet and computer technologies to operate their businesses and market interactions, the threats and security breaches have highly increased in recent years. Insider and outsider attacks have caused global businesses lost trillions of Dollars a year. Therefore, that is a need for a proper framework to govern the information security in the banking system. The aim of this research is to propose and design an enhanced method to evaluate information security governance (ISG) implementation in banking environment. This research examines and compares the elements from the commonly used information security governance frameworks, standards and best practices. Their strength and weakness are considered in its approaches. The initial framework for governing the information security in banking system was constructed from document review. The framework was categorized into three levels which are Governance level, Managerial level, and technical level. The study further conducts an online survey for banking security professionals to get their professional judgment about the ISG most critical components and the importance for each ISG component that should be implemented in banking environment. Data from the survey was used to construct a mathematical model for ISG evaluation, component importance data used as weighting coefficient for the related component in the mathematical model. The research further develops a method for evaluating ISG implementation in banking based on the mathematical model. The proposed method was tested through real bank case study in an Indonesian local bank. The study evidently proves that the proposed method has sufficient coverage of ISG in banking environment and effectively evaluates the ISG implementation in banking environment.
【 预 览 】
Files | Size | Format | View |
---|---|---|---|
A Method for Evaluating Information Security Governance (ISG) Components in Banking Environment | 982KB | download |