ارزیابی امنیت سیستمهای اطلاعاتی با رویکرد پویایی شناسی سیستمها (مورد مطالعه: بانک کشاورزی)
الموضوعات : فناوری اطلاعات و ارتباطاتامیرحسین عبدالعلی پور 1 , محسن شفیعی 2
1 - استادیار، گروه مدیریت صنعتی، دانشکده علوم انسانی، واحد خوی، دانشگاه آزاد اسلامی، خوی، ایران.
2 - کارشناس ارشد مدیریت فناوری اطلاعات، واحد الکترونیک،دانشگاه آزاد اسلامی ، تهران، ایران.
الکلمات المفتاحية: امنیت سیستمهای اطلاعاتی, بانک کشاورزی, پویاییشناسی سیستم, شبیهسازی,
ملخص المقالة :
هدف اصلی پژوهش حاضر، شناسایی و تحلیل تعاملات میان عوامل مختلف مؤثر بر امنیت اطلاعات و ریسکهای سیستمهای اطلاعاتی بانک کشاورزی با استفاده از رهیافت پویاییشناسی سیستمها است. شبیهسازیهای پژوهش نشان میدهد که سناریوهای سناریوی افزایش بودجه امنیتی و ارتقاء آگاهی کارکنان به ترتیب بیشترین کاهش ریسک را در افق زمانی 36 ماهه برای سیستم اطلاعاتی بانک به همراه خواهند داشت. در افق زمانی 3 ساله، سطح ریسک سیستم اطلاعاتی بانک به پایینتر از 01/0 خواهد رسید. درحالیکه با اجرای سناریوی افزایش بودجه امنیتی، این میزان کمتر از 001/0 خواهد بود. در افق زمانی مذکور، با افزایش بودجه از 1000 واحد به 1500 واحد در ماه دهم، سطح ایمنی اطلاعاتی بانک کشاورزی تا حدود 95 درصد افزایش مییابد. برای تحقق این هدف، تخصیص بهینه منابع باید شامل فناوریهای نوین و آموزش مستمر کارکنان باشد. همچنین، توسعه و بهروزرسانی پروتکلهای امنیتی و ارزیابی منظم نقاط ضعف مؤسسات مالی ضروری است. درنهایت، پیشنهاد میشود که نظام پایش و ارزیابی مستمر وضعیت امنیت سیستمهای اطلاعاتی بانک برقرار شود و از مشاوره کارشناسان امنیت اطلاعات بهرهبرداری گردد تا استراتژیها و رویکردهای امنیتی بهینهسازی شوند.
[1] Moore, A., & Warkentin, M. “Cybersecurity: Principles and Practices”. Pearson.2019.
[2] Osmanbegović, E., Piric, N., & Suljic, M. “Information Security Controls As Determinant Of Continuity Of Information System Work”. Vol. XV, Issue 2, 35-42, 2017.
[3] Böhme, R., & Moore, T. (2023). The Economics of Cybersecurity: Principles and Policy Options. Annual Review of Economics, 15, 567-592.
[4] Bock, S. “Human Error and Cybersecurity in the Banking Sector”. Journal of Banking Technology, 15(2), 123-135.2021.
[5] Alshaikh, M., Maynard, S. B., Ahmad, A., & Chang, S. (2023). A Human-Centric Risk-Based Investment Model for Information Security: Empirical Evidence from the Financial Sector. Computers & Security, 128, 103234.
[6] Lubua, E.W., Semlambo, A.A., & Mkude, C.G. “Factors Affecting the Security of Information Systems in Africa: A Literature Review”. University of Dar es Salaam Library Journal, 17(2), 94-114.2022.
[7] Alizadeh, A., Chehrehpak, M., Nasr, A.K., & Zamanifard, S. “An empirical study on effective factors on adoption of cloud computing in electronic banking: a case study of Iran banking sector”. Int. J. Bus. Inf. Syst., 33, 408-428.2020.
[8] Khan, H. U., Malik, M. Z., Nazir, S. , and Khan,F., "Utilizing Bio Metric System for Enhancing Cyber Security in Banking Sector: A Systematic Analysis," in IEEE Access, vol. 11, pp. 80181-80198.2023.
[9] Rapina, R., Carolina, Y., Setiawan, S., Gania, A., Sandra, L.M., Darmasetiawan, J.B., & Fuentes, R.O. “Empirical Study on Banking in Indonesia: Factors Affecting Information Systems Quality”. Proceedings of the 2020 12th International Conference on Information Management and Engineering. 2020.
[10] Alsalamah, A. “Security Risk Management in Online System”. 5th Intl Conf on Applied Computing and Information Technology/4th Intl Conf on Computational Science/Intelligence and Applied Informatics/2nd Intl Conf on Big Data, Cloud Computing, Data Science (ACIT-CSII-BCD), 119-124.2017.
[11] Lestari, D., Tama, A., Karlina, S., Sultan, A., & Tarwoto, T. “Factors Affecting Security Information Systems: Information Security, Threats and Cyber Attack, Physical Security, and Information Technology”. International Journal of Informatics and Information Systems, 7(1), 16-21.2024.
[12] Noubissi, A.C., Iguchi-Cartigny, J., & Lanet, J. “Hot updates for Java based smart cards”. IEEE 27th International Conference on Data Engineering Workshops, 168-173.2011.
[13] Putra Utama, F., & Hilmi Nurhadi, R.M. “Uncovering the Risk of Academic Information System Vulnerability through PTES and OWASP Method”, COMMIT (Communication and Information Technology) Journal. 18(1), 39-51.2024.
[14] Smith, J. (2023). The Role of Artificial Intelligence in Banking Risk Management. Journal of Banking and Finance, 134, 1-10.
[15] Rajendran, S. R., N. F., Dipu, Tarek, S., H. M., Kamali, Farahmandi F. and Tehranipoor, M., "Exploring the Abyss? Unveiling Systems-on-Chip Hardware Vulnerabilities Beneath Software," in IEEE Transactions on Information Forensics and Security, vol. 19, pp. 3914-3926, 2024.
[16] ENISA (European Union Agency for Cybersecurity). (2022). Threat Landscape for Information Integrity in Financial Services.
[17] Duddu, S., Rishita sai, A., Sowjanya, C.L., Rao, G.R., & Siddabattula, K. (2020). Secure Socket Layer Stripping Attack Using Address Resolution Protocol Spoofing. 2020 4th International Conference on Intelligent Computing and Control Systems (ICICCS), 973-978.
[18] Gai, K., Qiu, M., & Qiu, L. (2022). Security and Privacy Issues: A Survey on FinTech in Banking Systems. Future Generation Computer Systems, 135, 386-399.
[19] Brown, L., & Green, T. (2022). The Impact of Data Types on Cyber Threats in Financial Institutions. International Journal of Cyber Studies, 9(2), 123-139.
[20] Li, Z., Xu, W., Shi, H., Zhang, Y., & Yan, Y. “Security and Privacy Risk Assessment of Energy Big Data in Cloud Environment”. Computational intelligence and neuroscience, 2398460. 2021. https://doi.org/10.1155/2021/2398460 (Retraction published Comput Intell Neurosci. 2023 Oct 18; 2023:9896475. doi: 10.1155/2023/9896475).
[21] Blesswin, J., Mary, S.J., Suryawanshi, S., Kshirsagar, V.G., Pabalkar, S.Y., Venkatesan, M., & Karunya, C.E. “Secure transmission of grayscale images with triggered error visual sharing”. Journal of Autonomous Intelligence. 2023.
[22] اکبرنژاد، ابوالقاسم و چشک، کریم، "اولویتبندی مؤلفههای اثرگذار بر سیاست دفاعی- امنیتی جمهوری اسلامی ایران". 1399
[23] جلالی، محمد و افشاری، مریم و مزینانیان، زینب،"تأثیر ابعاد زیستمحیطی تغییرات اقلیمی بر امنیت ملی". 1399.
[24] Alsmadi, I., & Zarour, M. (2023). Cybersecurity in Banking: Risks, Challenges, and Solutions. Journal of Banking and Financial Technology, 7(1), 21-34.
[25] خون جوش, ف.خ. و عاشوری, م. "بررسی تأثیر تنظیمات پارامترهای سختافزاری بر انرژی مصرفی در الگوریتم ضرب برداری ماتریسهای تنک بر روی پردازندههای گرافیکی" فصلنامه فناوری اطلاعات و ارتباطات ایران، (9)31، 78-67. 1398.
[26] Lee, S. Y. (2022). Physical Security Threats to Banking Information Systems. Journal of Financial Risk Management, 11(3), 1-12.
[27] Hassan, R., Bandi, C., Tsai, M., Golchin, S., P D, S.M., Rafatirad, S., & Salehi, S. (2023). Automated Supervised Topic Modeling Framework for Hardware Weaknesses. 2023 24th International Symposium on Quality Electronic Design (ISQED), 1-8.
[28] Shehab, R., s.alismail, A., Amin Almaiah, D.M., Alkhdour, D.T., AlWadi, D.B., & Alrawad, D.M. “Assessment of Cybersecurity Risks and threats on Banking and Financial Services. Journal of Internet Services and Information Security” 14(3), 167-190.2024.
[29] White, R., & Black, S. “Historical Cyber Attacks and Their Future Implications for Banks. Cybersecurity Review”, 15(1), 88-102.2023.
[30] Shams, S., & Soltanifar, M. (2023). The Impact of Cyberattacks on Customer Trust in the Banking Sector: Evidence from Emerging Markets. Journal of Financial Crime, 30(2), 545-562.
[31] Lavanya, M., & Mangayarkarasi, D.S. “A Review on Detection of Cybersecurity Threats in Banking Sectors Using AI Based Risk Assessment”. Journal of Electrical Systems. Vol. 20 No. 6s, 1359-1365.2024.
[32] Dawodu, S.O., Omotosho, A., Akindote, O.J., Adegbite, A.O., & Ewuga, S.K. “CYBERSECURITY RISK ASSESSMENT IN BANKING: METHODOLOGIES AND BEST PRACTICES”. Computer Science & IT Research Journal, 4(3), 220-243. 2023.
[33] عزیزی سرخانی, محمدجواد و کردلوئی, حمیدرضا. "بررسی ابزارهای امنیتی بانکداری الکترونیک در بخش بانکداری دولتی بانکهای هند با مروری بر جهانی شدن". دانش سرمایهگذاری، (18) 5، 262-253، 1395.
[34] فرزام نیا، نیما، عبدی, بهنام و رضائیان، علی. "ارائه الگوی حکمرانی خوب امنیت فضای سایبری در سازمانهای دفاعی"، فصلنامه مدیریت نظامی، (77)20، 81-120. 1399.
[35] Dhanya, C., & Ramya, K. “Impact of System-Level Indicators of Chatbots on Perceived Usefulness and Intention to use for Banking Services”. The Review of Finance and Banking, 16(1), 43-55.2024.
[36] Fatoki, J.O. “The influence of cyber security on financial fraud in the Nigerian banking industry”. International Journal of Science and Research Archive, 9(02), 503–515.2023.
[37] شفیعی نیکآبادی، محسن، حکاکی، امیر و غلامشاهی، سارا. "مدلی پویا جهت ارزیابی امنیت سیستمهای اطلاعاتی با استفاده از رویکرد پویاییشناسی سیستمها" ، فصلنامه رشد فناوری، (16)64، 61-52. 1399.
[38] Damenu, T.K., & Beaumont, C. “Analysing information security in a bank using soft systems methodology”. Inf. Comput. Secur., 25, 240-258.2017.
[39] Cheng, L., Liu, F., Yao, D., & Wang, X. (2022). ATM Security: Threats, Vulnerabilities, and Countermeasures in the Era of Digital Banking. Computers & Security, 119, 102765.
[40] Sarumi, J.A., Longe, O.B., & Adelodun, F.O. “An Empirical Evaluation of the Effectiveness of the Computer-Based Network Security and Firewall in Banking Systems”. Advances in Multidisciplinary and scientific Research Journal Publication, 10(1), 21-33. 2022.
[41] Ewuga, S.K., Egieya, Z.E., Omotosho, A., & Adegbite, A.O. “ISO 27001 IN BANKING: AN EVALUATION OF ITS IMPLEMENTATION AND EFFECTIVENESS IN ENHANCING INFORMATION SECURITY”. Finance & Accounting Research Journal, 5(12), 405-426.2024.
[42] Somogyi, T., & Nagy, R. “The Impact of the War in Ukraine on the Information Security of the European Union’s Banking Industry – A Case Study of Hungary And Slovakia”. CONTEMPORARY MILITARY CHALLENGES, 25, 23 - 32. 2023.
[43] Al-Hadhrami, A., Alghamdi, A., & Alfarraj, O. (2022). Perceived Security Threats and Their Impact on the Adoption of Accounting Information Systems in the Banking Sector. Journal of Information Security and Applications, 68, 103236.
[44] Zhou, Y., Li, X., & Wang, J. (2023). Security Assessment and Vulnerability Analysis of Online Banking Systems: Recent Advances and Challenges. Computers & Security, 126, 103140.
[45] Pérez, J., et al. "Risk Assessment of Cloud Migration in Banking Sector." Journal of Financial Services Technology.2020.
[46] پیکری، حمیدرضا و بنازاده، بابک. "رابطۀ آگاهی از امنیت اطلاعات با قصد نقض امنیت اطلاعات با نقش میانجی هنجارهای فردی و خودکنترلی عنوان مکرر: قصد نقض امنیت اطلاعات". پژوهشهای راهبردی مسائل اجتماعی، (4)7، 41-58، 1397.
[47] Zhou, Y., Li, X., & Wang, J. (2023). Security Assessment and Vulnerability Analysis of Online Banking Systems: Recent Advances and Challenges. Computers & Security, 126, 103140.
