earticle

논문검색

Compliance Risk Assessment Measures of Financial Information Security using System Dynamics

초록

영어

In this paper, we analyze relationships between EFT (Electronic Financial Transaction) Act of Korea and risk assessment standards and propose the map that helps financial institutions determine the priority of security control areas. It is a new method for financial information security risk identification and assessment through correlation analysis between the variety security standards and requirements. We attempt to integrate different information security standards and propose risk assessment measures specializing in financial companies based on the mixed methods of quantitative and qualitative methods to determine the priority through the calculation of weights. From the results of correlation analysis, three main security control areas are found to be more important than other areas and it can be utilized as a risk management measure about security countermeasures. In addition, financial companies should improve three main security control areas in an interval of at least 10 months. We expect that our result can be provided to security manager and IT auditor for establishment of risk mitigation strategies as basic data.

목차

Abstract
 1. Introduction
 2. Background and Approach
  2.1. IS (Information Security) Standards
  2.2. Risk Management
  2.3. System Dynamics
 3. Risk Assessment of Financial IS Compliance
  3.1. Compliance Risk Identification
  3.2. Compliance Risk Assessment
  3.3. Policy Assessment
 4. Conclusion and Future Work
 Acknowledgments
 References

저자정보

  • Ae Chan Kim Graduate School of Information Security, Korea University
  • Su Mi Lee Financial Security Agency, Korea
  • Dong Hoon Lee Graduate School of Information Security, Korea University

참고문헌

자료제공 : 네이버학술정보

    함께 이용한 논문

      ※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.

      0개의 논문이 장바구니에 담겼습니다.