Critical Data Security Model: Gap Security Identification and Risk Analysis In Financial Sector

Cesar Humberto Ortiz Huamán, Nilcer Fernandez Fuster, Ademir Cuadros Luyo, Jimmy Armas-Aguirre

Producción científica: Capítulo del libro/informe/acta de congresoContribución a la conferenciarevisión exhaustiva

2 Citas (Scopus)

Resumen

In this paper, we proposed a data security model of a big data analytical environment in the financial sector. Big Data can be seen as a trend in the advancement of technology that has opened the door to a new approach to understanding and decision making that is used to describe the vast amount of data (structured, unstructured and semi-structured) that is too time consuming and costly to load a relational database for analysis. The increase in cybercriminal attacks on an organization's assets results in organizations beginning to invest in and care more about their cybersecurity points and controls. The management of business-critical data is an important point for which robust cybersecurity controls should be considered. The proposed model is applied in a datalake and allows the identification of security gaps on an analytical repository, a cybersecurity risk analysis, design of security components and an assessment of inherent risks on high criticality data in a repository of a regulated financial institution. The proposal was validated in financial entities in Lima, Peru. Proofs of concept of the model were carried out to measure the level of maturity focused on: leadership and commitment, risk management, protection control, event detection and risk management. Preliminary results allowed placing the entities in level 3 of the model, knowing their greatest weaknesses, strengths and how these can affect the fulfillment of business objectives.

Idioma originalInglés
Título de la publicación alojadaProceedings of 2022 17th Iberian Conference on Information Systems and Technologies, CISTI 2022
EditoresAlvaro Rocha, Borja Bordel, Francisco Garcia Penalvo, Ramiro Goncalves
EditorialIEEE Computer Society
ISBN (versión digital)9789893334362
DOI
EstadoPublicada - 2022
Evento17th Iberian Conference on Information Systems and Technologies, CISTI 2022 - Madrid, Espana
Duración: 22 jun. 202225 jun. 2022

Serie de la publicación

NombreIberian Conference on Information Systems and Technologies, CISTI
Volumen2022-June
ISSN (versión impresa)2166-0727
ISSN (versión digital)2166-0735

Conferencia

Conferencia17th Iberian Conference on Information Systems and Technologies, CISTI 2022
País/TerritorioEspana
CiudadMadrid
Período22/06/2225/06/22

Huella

Profundice en los temas de investigación de 'Critical Data Security Model: Gap Security Identification and Risk Analysis In Financial Sector'. En conjunto forman una huella única.

Citar esto