Browse > Article
http://dx.doi.org/10.13089/JKIISC.2016.26.6.1605

Improvements of Information Security Level in Electronic Financial Infrastructure(By Analyzing Information Security Management Level)  

Park, Keun-dug (KSEL)
Youm, Heung-youl (Soonchunhyang University)
Abstract
In recent years, security incidents - such as personal information leakage, homepage hacking, DDoS and etc. - targeting finance companies(banks, securities companies, credit card companies, insurance companies and etc.) have increased steadily. In this paper, we analyze problems of information security management level in the existing electronic financial infrastructure from perspective of compliance and information security certification system and propose improvements to enable sustainable high level of information security activities under a comprehensive management system for the financial sector characteristics using ISMS, SECU-STAR and CNIVAM system.
Keywords
Electronic Financial Infrastructure; Information Security; ISMS(Information Security Management System); SECU-STAR(SECUriTy Assessment for Readiness); CNIVAM(Critical Network Infrastructure Vulnerability Analysis.Measurement);
Citations & Related Records
연도 인용수 순위
  • Reference
1 Financial Services Commission, "ELECTRONIC FINANCIAL TRANSACTIONS ACT," Jan. 2016
2 Financial Services Commission, "ELECTRONIC FINANCIAL TRANSACTIONS ACT DECREE," Dec. 2015
3 Financial Services Commission, "ELECTRONIC FINANCIAL SUPERVISORY REGULATIONS (Financial Services Commission Notice No. 2015-18)," Jun. 2015
4 Financial Supervisory Service, "ELECTRONIC FINANCIAL SUPERVISORY REGULATIONS DETAILED ENFORCEMENT REGULATIONS," May. 2016
5 Korea Communications Commission, "ACT ON PROMOTION OF INFORMATION AND COMMUNICATIONS NETWORK UTILIZATION AND INFORMATION PROTECTION, ETC.," Dec. 2015
6 Korea Communications Commission.Ministry of Science, ICT and Future Planning, "ENFORCEMENT DECREE OF THE ACT ON PROMOTION OF INFORMATION AND COMMUNICATIONS NETWORK UTILIZATION AND INFORMATION PROTECTION, ETC.," May. 2016
7 Ministry of Science, ICT and Future Planning, "Notice Concerning Information Security Management System Certification, Etc. (Ministry of Science, ICT and Future Planning Notice No. 2016-59)," Jun. 2016
8 Ministry of Science, ICT and Future Planning, "ACT ON THE PROTECTION OF INFORMATION AND COMMUNICATIONS INFRASTRUCTURE," Jun. 2015
9 Ministry of Science, ICT and Future Planning, "ENFORCEMENT DECREE OF THE ACT ON THE PROTECTION OF INFORMATION AND COMMUNICATIONS INFRASTRUCTURE," Dec. 2015
10 Ministry of Science, ICT and Future Planning, "Critical Network Infrastructure Vulnerability Analysis and Measurement Criteria(Ministry of Science, ICT and Future Planning Notice No. 2013-37)," Aug. 2013
11 Ministry of the Interior, "Ensure Safety Criteria of Personal Information (Ministry of the Interior Notice No. 2014-7)," Dec. 2014
12 Ministry of Science, ICT and Future Planning, "ACT ON PROMOTION OF INFORMATION SECURITY INDUSTRY," Jun. 2015
13 Korea Internet & Security Agency, "ISMS Certification System Guide," pp. 5-9, Mar. 2016
14 IBK Capital, "Request for Proposal of Electronic Financial Infrastructure Vulnerability Inspection," pp. 11-23, May. 2014
15 Korea Security Evaluation Laboratory Co., Ltd., "http://www.ksel.co.kr/secu_star_summary.php)," Jun. 2016
16 Korea Internet & Security Agency, "http://isms.kisa.or.kr/kor/issue/issue01.jsp?certType=ISMS)," Jun. 2016
17 Qualys Inc., "https://www.ssllabs.com/ssltest/," Jun. 2016
18 Keun-Dug Park, "Improved measurements of information security management based on compliance in financial companies," Soonchunhyang University, pp. 88-110, Sep. 2015
19 Korea Federation of Banks , "http://www.kfb.or.kr/cms.html?S=AC," Jun. 2016
20 Korea Financial Investment Association, "http://www.kofia.or.kr/member_status/m_15/sub0202.do," Mar. 2016
21 Korea Life Insurance Association, "http://www.klia.or.kr/aklia/aklia_090101.do," Jun. 2016
22 The Credit Finance Association Of Korea, "https://www.crefia.or.kr/portal/company/membership/membershipIntroduction.xx?coCodeSubId=1#," Jun. 2016
23 General Insurance Association of Korea, "http://www.knia.or.kr/about/partner/partner01/," Jun. 2016