The Classification of Information Assets and Risk Assessment: An Exploratory Study using the Case of C-Bank

被引:4
|
作者
Chen, Patrick S. [1 ]
Yen, David C. [2 ]
Lin, Shu-Chiung [3 ]
机构
[1] Tatung Univ, Dept Informat Management, Informat Secur, Taipei 104, Taiwan
[2] SUNY Coll Oneonta, Sch Business & Econ, MIS, Oneonta, NY USA
[3] Tatung Univ, Dept Informat Management, Taipei 104, Taiwan
关键词
Assets Classification; Information Assets; Information Security; Risks Assessment; QUALITATIVE RESEARCH; SECURITY; MANAGEMENT; HAZARDS; DELPHI; MODEL;
D O I
10.4018/JGIM.2015100102
中图分类号
G25 [图书馆学、图书馆事业]; G35 [情报学、情报工作];
学科分类号
1205 ; 120501 ;
摘要
Many information systems' incidents result from inadequate protection of information assets. Assets classification and risks assessment procedures will no doubt help to identify the associated risks related to information systems for a better security control. In the banking industry, prior research and studies are rather lacking due to the nature of maintaining confidentiality. The purpose of this study is to develop an approach to classify information assets of financial institutions and also assess their corresponding risks. Delphi method was adopted and questionnaires based on the guidelines of the well-recognized standard of ISO/IEC 27001 were developed subsequently. A total of 99 information assets subject to security breaches are chosen for risks assessment and a panel of seven experts is invited to complete questionnaires. Consequently, a model for calculating the risk index is proposed according to an exponential scale ranging over 9 grades. The results reveal that three types of information assets exposed to a high level of risk warrant special protection. The experts also make some security enhancement suggestions for the assets with a risk grade >= 6. Aiming to enrich research literature on the risks assessment of information assets in the banking industry, the results of this study can provide a valuable reference for both academia and security practitioners.
引用
收藏
页码:26 / 54
页数:29
相关论文
共 50 条
  • [1] A Study of Risk Assessment of Information Assets in Banking Industry-A Case of the Taiwan's Bank
    Chen, Patrick S.
    Lin, Shu-Chiung
    Li, S. H.
    Shi, Perry
    WMSCI 2008: 12TH WORLD MULTI-CONFERENCE ON SYSTEMICS, CYBERNETICS AND INFORMATICS, VOL VI, PROCEEDINGS, 2008, : 79 - 84
  • [2] Significance of genetic information in risk assessment and individual classification using silicosis as a case model
    McCanlies, E
    Landsittel, DP
    Yucesoy, B
    Vallyathan, V
    Luster, ML
    Sharp, DS
    ANNALS OF OCCUPATIONAL HYGIENE, 2002, 46 (04): : 375 - 381
  • [3] A Case Study for Assessment of High Risk Earthing on Distribution Assets The Tasmanian Experience
    Goodger, James
    Carleton, Gary
    Tocher, Bill
    2016 DOWN TO EARTH CONFERENCE (DTEC), 2016,
  • [4] NON-PERFORMING ASSETS: A CASE STUDY OF SYNDICATE BANK
    Shiralashetti, A. S.
    Poojari, Lata N.
    PACIFIC BUSINESS REVIEW INTERNATIONAL, 2016, 8 (10): : 87 - 92
  • [5] A Proposed Taxonomy of Assets for Information Security Risk Assessment (ISRA)
    Shamala, Palaniappan
    Ahmad, Rabiah
    2014 4TH WORLD CONGRESS ON INFORMATION AND COMMUNICATION TECHNOLOGIES (WICT), 2014, : 29 - 33
  • [6] Erosion risk assessment: A case study of the Langat River bank in Malaysia
    Abidin, Roslan Zainal
    Sulaiman, Mohd Sofiyan
    Yusoff, Naimah
    INTERNATIONAL SOIL AND WATER CONSERVATION RESEARCH, 2017, 5 (01) : 26 - 35
  • [7] Vietnamese Bank Liquidity Risk Study Using the Risk Assessment Model of Systemic Institutions
    Thanh Duong
    Duc Pham-Hi
    Phuong Phan
    MODELLING, COMPUTATION AND OPTIMIZATION IN INFORMATION SYSTEMS AND MANAGEMENT SCIENCES - MCO 2015 - PT II, 2015, 360 : 401 - 412
  • [8] Generic Taxonomy of Assets Identification for Information Security Risk Assessment (ISRA)
    Shamala, Palaniappan
    Ahmad, Rabiah
    bin Sahib, Shahrin
    JOURNAL OF INFORMATION ASSURANCE AND SECURITY, 2015, 10 (06): : 260 - 268
  • [9] The Information Privacy Concerns at the Organizational Level: An Exploratory Study in the Bank Sector
    Montesdioca, Gustavo Zimmermann
    Hino, Marcia Cassitas
    Gastaud Macada, Antonio Carlos
    AMCIS 2015 PROCEEDINGS, 2015,
  • [10] Risk control of bank loans in the case of asymmetric information
    Ai, Xiaolian
    PROCEEDINGS OF THE FOURTH INTERNATIONAL CONFERENCE OF MODELLING AND SIMULATION (ICMS2011), VOL 1, 2011, : 265 - 269