The Classification of Information Assets and Risk Assessment: An Exploratory Study using the Case of C-Bank

被引:4
|
作者
Chen, Patrick S. [1 ]
Yen, David C. [2 ]
Lin, Shu-Chiung [3 ]
机构
[1] Tatung Univ, Dept Informat Management, Informat Secur, Taipei 104, Taiwan
[2] SUNY Coll Oneonta, Sch Business & Econ, MIS, Oneonta, NY USA
[3] Tatung Univ, Dept Informat Management, Taipei 104, Taiwan
关键词
Assets Classification; Information Assets; Information Security; Risks Assessment; QUALITATIVE RESEARCH; SECURITY; MANAGEMENT; HAZARDS; DELPHI; MODEL;
D O I
10.4018/JGIM.2015100102
中图分类号
G25 [图书馆学、图书馆事业]; G35 [情报学、情报工作];
学科分类号
1205 ; 120501 ;
摘要
Many information systems' incidents result from inadequate protection of information assets. Assets classification and risks assessment procedures will no doubt help to identify the associated risks related to information systems for a better security control. In the banking industry, prior research and studies are rather lacking due to the nature of maintaining confidentiality. The purpose of this study is to develop an approach to classify information assets of financial institutions and also assess their corresponding risks. Delphi method was adopted and questionnaires based on the guidelines of the well-recognized standard of ISO/IEC 27001 were developed subsequently. A total of 99 information assets subject to security breaches are chosen for risks assessment and a panel of seven experts is invited to complete questionnaires. Consequently, a model for calculating the risk index is proposed according to an exponential scale ranging over 9 grades. The results reveal that three types of information assets exposed to a high level of risk warrant special protection. The experts also make some security enhancement suggestions for the assets with a risk grade >= 6. Aiming to enrich research literature on the risks assessment of information assets in the banking industry, the results of this study can provide a valuable reference for both academia and security practitioners.
引用
收藏
页码:26 / 54
页数:29
相关论文
共 50 条
  • [21] ITERATION AND INTERACTION IN COMPUTER DATA BANK ANALYSIS - CASE STUDY IN PHYSIOLOGIC CLASSIFICATION AND ASSESSMENT OF CRITICALLY ILL
    GOLDWYN, RM
    FRIEDMAN, HP
    SIEGEL, JH
    COMPUTERS AND BIOMEDICAL RESEARCH, 1971, 4 (06): : 607 - &
  • [22] Risk Assessment for the Logistics of Shipping Companies: An Exploratory Study
    Liu, Yutong
    Cui, Li
    JOURNAL OF COASTAL RESEARCH, 2020, : 463 - 467
  • [23] Risk Assessment Using Information Entropy
    Franklin, Paul
    2023 ANNUAL RELIABILITY AND MAINTAINABILITY SYMPOSIUM, RAMS, 2023,
  • [24] A Proposed Framework for Ranking Critical Information Assets in Information Security Risk Assessment Using the OCTAVE Allegro Method with Decision Support System Methods
    Prajanti, Anisa Dewi
    Ramli, Kalamullah
    2019 34TH INTERNATIONAL TECHNICAL CONFERENCE ON CIRCUITS/SYSTEMS, COMPUTERS AND COMMUNICATIONS (ITC-CSCC 2019), 2019, : 567 - 570
  • [25] The Role of Information Management in the Assessment of Grammar in L2 Academic Writing: An Exploratory Case Study
    Neumann, Heike
    WRITING & PEDAGOGY, 2015, 7 (2-3): : 329 - 354
  • [26] Affect assessment in crisis negotiation:: An exploratory case study using two distinct indicators
    Bilsky, W
    Müller, J
    Voss, A
    Von Groote, E
    PSYCHOLOGY CRIME & LAW, 2005, 11 (03) : 275 - 287
  • [27] Study on Commercial Bank Credit Risk Based on Information Asymmetry
    Shi, Chenghua
    Zhang, Kui
    2009 INTERNATIONAL CONFERENCE ON BUSINESS INTELLIGENCE AND FINANCIAL ENGINEERING, PROCEEDINGS, 2009, : 758 - 761
  • [28] Formative Assessment in EFL Writing: An Exploratory Case Study
    Lee, Icy
    CHANGING ENGLISH-STUDIES IN CULTURE AND EDUCATION, 2011, 18 (01): : 99 - 111
  • [29] An information system risk assessment model: a case study in online banking system
    Shokouhyar, Sajjad
    Panahifar, Farhad
    Karimisefat, Azadeh
    Nezafatbakhsh, Maryam
    INTERNATIONAL JOURNAL OF ELECTRONIC SECURITY AND DIGITAL FORENSICS, 2018, 10 (01) : 39 - 60
  • [30] Risk recognition and risk classification diagnosis of bank outlets based on information entropy and BP neural network
    Xu, Moli
    Xiong, Deping
    Yang, Mengyuan
    JOURNAL OF INTELLIGENT & FUZZY SYSTEMS, 2020, 38 (02) : 1531 - 1538