The Classification of Information Assets and Risk Assessment: An Exploratory Study using the Case of C-Bank

被引:4
|
作者
Chen, Patrick S. [1 ]
Yen, David C. [2 ]
Lin, Shu-Chiung [3 ]
机构
[1] Tatung Univ, Dept Informat Management, Informat Secur, Taipei 104, Taiwan
[2] SUNY Coll Oneonta, Sch Business & Econ, MIS, Oneonta, NY USA
[3] Tatung Univ, Dept Informat Management, Taipei 104, Taiwan
关键词
Assets Classification; Information Assets; Information Security; Risks Assessment; QUALITATIVE RESEARCH; SECURITY; MANAGEMENT; HAZARDS; DELPHI; MODEL;
D O I
10.4018/JGIM.2015100102
中图分类号
G25 [图书馆学、图书馆事业]; G35 [情报学、情报工作];
学科分类号
1205 ; 120501 ;
摘要
Many information systems' incidents result from inadequate protection of information assets. Assets classification and risks assessment procedures will no doubt help to identify the associated risks related to information systems for a better security control. In the banking industry, prior research and studies are rather lacking due to the nature of maintaining confidentiality. The purpose of this study is to develop an approach to classify information assets of financial institutions and also assess their corresponding risks. Delphi method was adopted and questionnaires based on the guidelines of the well-recognized standard of ISO/IEC 27001 were developed subsequently. A total of 99 information assets subject to security breaches are chosen for risks assessment and a panel of seven experts is invited to complete questionnaires. Consequently, a model for calculating the risk index is proposed according to an exponential scale ranging over 9 grades. The results reveal that three types of information assets exposed to a high level of risk warrant special protection. The experts also make some security enhancement suggestions for the assets with a risk grade >= 6. Aiming to enrich research literature on the risks assessment of information assets in the banking industry, the results of this study can provide a valuable reference for both academia and security practitioners.
引用
收藏
页码:26 / 54
页数:29
相关论文
共 50 条
  • [41] Outcomes Assessment in Psychiatric Postgraduate Medical Education: An Exploratory Study Using Clinical Case Vignettes
    Huffman, Jeff C.
    Petersen, Tim
    Baer, Lee
    Romeo, Sarah
    Sutton-Skinner, Kelly
    Fromson, John A.
    Birnbaum, Robert J.
    ACADEMIC PSYCHIATRY, 2010, 34 (06) : 445 - 448
  • [42] Outcomes Assessment in Psychiatric Postgraduate Medical Education: An Exploratory Study Using Clinical Case Vignettes
    Jeff C. Huffman
    Tim Petersen
    Lee Baer
    Sarah Romeo
    Kelly Sutton-Skinner
    John A. Fromson
    Robert J. Birnbaum
    Academic Psychiatry, 2010, 34 : 445 - 448
  • [43] Using information technology to improve health information literacy in singapore -An exploratory study
    Mokhtar, Intan Azura
    Majid, Shaheen
    Foo, Schubert
    INFORMATION PROCESSING IN THE SERVICE OF MANKIND AND HEALTH, 2006, : 59 - +
  • [44] Classification of hundreds of classes: A case study in a bank internal control department
    Duman, Ekrem
    JOURNAL OF INTELLIGENT & FUZZY SYSTEMS, 2023, 45 (01) : 649 - 658
  • [45] Impact of environmental cost information on reducing bank risk: an applied study
    Al-Shaabaney, Salih Ibrahim Younis
    International Journal of Technology, Policy and Management, 2022, 22 (03) : 159 - 177
  • [46] A Study of Information Security Evaluation and Risk Assessment
    Li, Jingyi
    Chao, Shiwei
    Huo, Minxia
    2015 FIFTH INTERNATIONAL CONFERENCE ON INSTRUMENTATION AND MEASUREMENT, COMPUTER, COMMUNICATION AND CONTROL (IMCCC), 2015, : 1909 - 1912
  • [47] Table Classification Using Both Structure and Content Information: A Case Study of Financial Documents
    Li, Quanzhi
    Shah, Sameena
    Fang, Rui
    2016 IEEE INTERNATIONAL CONFERENCE ON BIG DATA (BIG DATA), 2016, : 1778 - 1783
  • [48] Assessment of risk to terrestrial receptors using uncertain analysis - A case study
    Hope, BK
    HUMAN AND ECOLOGICAL RISK ASSESSMENT, 1999, 5 (01): : 145 - 170
  • [49] Using body mapping as part of the risk assessment process - a case study
    Thomas, David
    Hare, Billy
    Cameron, Iain
    POLICY AND PRACTICE IN HEALTH AND SAFETY, 2018, 16 (02) : 224 - 240
  • [50] Risk assessment of oil fields using proxy models: A case study
    Risso, F. V. A.
    Risso, V. F.
    Schiozer, D. J.
    JOURNAL OF CANADIAN PETROLEUM TECHNOLOGY, 2008, 47 (08): : 9 - 14