International Journal of Networked and Distributed Computing (IJNDC) (Dec 2017)

Assessing Risk of Security Non-compliance of Banking Security Requirements Based on Attack Patterns

  • Krissada Rongrat,
  • Twittie Senivongse

DOI
https://doi.org/10.2991/ijndc.2018.6.1.1
Journal volume & issue
Vol. 6, no. 1

Abstract

Read online

Information systems such as those in the Banking sector need to comply with security regulations to assure that necessary security controls are in place. This paper presents an initial risk assessment method to assist a banking information system project in validating security requirements of the system. Dissimilarity between the textual security requirements of the system and the security regulations is determined to identify security non-compliance. A risk index model is then proposed to determine the risk level based on the severity and likelihood of exploit of any security attack patterns that could potentially affect the system if the missing regulations are not implemented. In an experiment using a case study of nine Thai commercial banks and the IT Best Practices of the Bank of Thailand as the regulations, the performance of compliance checking is evaluated in terms of F-measure and accuracy. It is also found that there is a strong positive correlation, with the coefficient of over 0.6, between the risk indices from the method and the security expert judgment.

Keywords