Infringement threats to the financial sector have become more sophisticated and intelligent. In order to more effectively respond to such threats, the financial sector faces the need to perform the assessment of information security maturity level on a voluntary basis in order to better understand organizational information security situation and improve own vulnerabilities to reinforce information security. The study, in reflection of financial industrial environmental characteristics, builds a comprehensive and systematic information security assessment indices specialized in the financial sector while presenting an information security maturity level assessment model based on the indices as well as an information security improvement anticipation model through vulnerability remedy. The quantification of vulnerability levels of the control item suggested herein and the improvement anticipation model based on vulnerability correction, in particular, supports an organization under the assessment to address its vulnerabilities to effectively enhance organizational information security. In the absence of such an information security assessment model, the financial sector has poorly performed in assessing own information security activities. With the models suggested herein being in place, the sector is expected to make an active use of it to facilitate information security assessment and improve the general information security maturity level of individual financial institutions and the financial industry as a whole
목차
Abstract 1. Introduction 2. Designing Financial-sector Information Security Assessment Indices 2.1. Structure of Financial-sector Information Security Assessment Indices 3. Designing of Information Security Maturity Level Assessment and Improvement Anticipation Model 3.1. Definition of Maturity Level Phases and Assessment Criteria 3.2. Method to Calculate Information Security Maturity Level 3.3. Method for Information Security Improvement Calculation based on Redressed vulnerability 4. Effectiveness Verification via Actual Case Application 4.1. A Results of Assessing the Financial Firm’s Information Security Maturity Level 4.2. A Results of Improvement after the Firm’s Vulnerability Redress 5. Conclusion Acknowledgement References
키워드
information securityinformation security maturity levelassessment indicesinformation security management systems
저자
Young-Rai Park [ Dept. of Computer Science, Yonsei University, Seoul, Korea ]
Yoon-Chul Choy [ Dept. of Computer Science, Yonsei University, Seoul, Korea ]
Won-Sung Shon [ Dept. of Computer Education, Gyeongin National University of Education, Incheon ]
보안공학연구지원센터(IJSIA) [Science & Engineering Research Support Center, Republic of Korea(IJSIA)]
설립연도
2006
분야
공학>컴퓨터학
소개
1. 보안공학에 대한 각종 조사 및 연구
2. 보안공학에 대한 응용기술 연구 및 발표
3. 보안공학에 관한 각종 학술 발표회 및 전시회 개최
4. 보안공학 기술의 상호 협조 및 정보교환
5. 보안공학에 관한 표준화 사업 및 규격의 제정
6. 보안공학에 관한 산학연 협동의 증진
7. 국제적 학술 교류 및 기술 협력
8. 보안공학에 관한 논문지 발간
9. 기타 본 회 목적 달성에 필요한 사업
간행물
간행물명
International Journal of Security and Its Applications
간기
격월간
pISSN
1738-9976
수록기간
2008~2016
등재여부
SCOPUS
십진분류
KDC 505DDC 605
이 권호 내 다른 논문 / International Journal of Security and Its Applications Vol.8 No.6