首页> 外文会议>International Conference on Information Security and Cyber Forensics >Is the Security Bubble Within the Banking Sector About to BURST?
【24h】

Is the Security Bubble Within the Banking Sector About to BURST?

机译:银行部门的安全泡沫即将爆发吗?

获取原文

摘要

- In the context of Access provision, Identity access management holds the key to administering, monitoring and assurance of access to information within the Bank, both internal premises and application hosted on cloud. It is vital that the information is available when required providing both integrity and confidentiality. Failure to deliver information on time, lacking in integrity could results in compensation, loss of business, disclosure of company secrets and compliance issues. Identity management is widely herald as an opportunity for enhancing the operational process in information security, reducing cost, enhanced reporting capability and regulatory compliance. However in recent year this has proven to be the concept misunderstood, complex and costly. A case study within an investment Bank information system department is used to highlight issues around access management and the controls. Organisation is still reliant of manual provisioning of information access, user access addition, removal and update. This leave user under-privilege or over privilege access, high risk of human error and this could open up the organisation fraud risk. In this paper we extend the, issues within the previous unsuccessful implementation of Identity access management solution and highlight flaws within the access control provisioning requirements within investment banks by proposing a model framework to be used by the banks to enhance the process of access control and to be use by software vendors as a guideline in developing access provisioning identity access management software.
机译:- 在访问提供的上下文中,Identity Access Management保存在云上托管在银行内的信息的访问权限,监控和保证信息的关键。重要的是,信息可在需要时提供完整性和机密性。未能按时提供信息,缺乏诚信可能会导致赔偿,损失,披露公司秘密和合规问题。身份管理是广泛的先驱,作为加强信息安全,降低成本,增强的报告能力和监管合规性的运营过程的机会。然而,近年来,这已被证明是误解,复杂和昂贵的概念。投资银行信息系统部门内的案例研究用于突出访问管理和控件的问题。组织仍依赖于手动配置信息访问,用户访问添加,删除和更新。这留下了用户欠特权或过度访问权限,人为错误的高风险,这可能会开辟组织欺诈风险。在本文中,我们通过提出银行使用的模型框架来提高进入访问控制的模型框架,延长了身份访问管理解决方案的先前不成功访问管理解决方案中的问题,并在投资银行内的访问控制供应要求中突出显示漏洞。软件供应商用作开发访问配置身份访问管理软件的指导方针。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号