:::

詳目顯示

回上一頁
題名:行動銀行系統資訊安全管理之研究
書刊名:電腦稽核
作者:李坤清 引用關係蔡旭昇張代興
出版日期:2013
卷期:27
頁次:頁42-53
主題關鍵詞:行動銀行智慧型手機資訊安全ISO 27001Mobile bankingSmart phonesInformation security
原始連結:連回原系統網址new window
相關次數:
  • 被引用次數被引用次數:期刊(0) 博士論文(0) 專書(0) 專書論文(0)
  • 排除自我引用排除自我引用:0
  • 共同引用共同引用:0
  • 點閱點閱:5
智慧型手機功能豐富、使用方便,能讓使用者輕易獲得所需資訊,因此各種行動商務的應用應運而生,行動銀行是其中之一。消費者可透過行動銀行系統進行轉帳、買賣基金及獲得金融與生活資訊,其方便性受到消費者的期待,但因它係以智慧型手機透過無線電信網路暨網際網路與銀行之伺服主機相連接,致衍生安全性相關問題。行動銀行系統暴露在網際網路及無線電信網路的環境裡,除了會受到駭客入侵、木馬程式、阻斷服務或病毒的攻擊,也是病毒、木馬程式等威脅的散播管道,容易遭有心人士入侵系統主機竊取機密資料、篡改文件與破壞系統。因此,如何確保行動銀行交易安全,乃為一項重要議題。本研究為提昇行動銀行交易安全及系統資訊安全風險控管之水準,透過國際標準ISO/IEC27001:2005,來評估行動銀行系統之安全性,並對個人資料保護,以及委外和內部控制措施,提供建議及補償性控制措施(compensating controls)。本研究建議定期對行動銀行系統客戶進行滿意度調查,俾利從中發現問題並採取必要控制措施,以促使行動銀行系統之資通安全更臻於嚴密。本研究主要提供三點結論:(一)智慧型手機行動銀行系統的威脅主要來自內部的人為事件,應以資訊安全標準所建議之控制措施,確實做適當的控制;(二)對行動銀行系統資訊資產風險等級較高者,如消費者行動銀行系統之帳號、密碼,行動銀行應用系統及主機管理人員等應優先實施控制措施,以利將行動銀行系統的風險降至較低水準;(三)對行動銀行系統之帳號、密碼修改、異地/同地備援及權限管理等控制措施不足之處,應以ISO/IEC27001:2005建議之控制措施管理,讓消費者可以在安全的環境下,使用方便的金融服務。金融業可根據上述結論,對其行動銀行建立安全性檢核機制,以提升行動銀行的滿意度。
The smart phone is one of the most popular products because it's feature-rich and easy to use. Because its features so that users can easily obtain the needed information, and the application of a variety of mobile commerce came into being, mobile banking is one of them. Consumers can transfer money, trading funds through the mobile banking system and access to financial information and living information. The smart phone's convenience is expecteds by consumers, but it connects to the bank host through wireless telecommunications network and internet, resulting in security-related issues. Mobile banking system is exposed to the environment of the Internet and wireless telecommunications network. Customers had to be aware that these systems could be subject to attacks by hackers, Trojan horses, denial of service programs or virus, and also made viruses, Trojans and other threats to the spread of the pipeline. It is also vulnerable to the theft of confidential information tampering with files and damage of systems by interested parties. How to ensure the security of mobile banking transactions has gradually become an important issue. This study is to improve the mobile banking transaction security and information security risk management level to assess mobile banking system security through the international-standards ISO/IEC27001:2005, and to provide advice and compensating control measures for the protection of personal data, as well as outsourcing and internal control. The study recommends the implementation of regular customer satisfaction surveys, which will help to find the related problems and to take the necessary control measures, and enhance the information and communication security of the mobile banking. This study's main findings are as follows. (1) the threat of the smart phone mobile banking system is mainly from the personnels inside the organization. Information security standards proposed control measures can be used to ensure the appropriate controls. (2) The most important mobile banking's information assets, such as consumer's ID and password, mobile banking systems, and host management. The bank should take much control for those assets to lower the risk. (3) The insufficient of important information asset control for the mobile banking system, such as off-site / local backup system, mobile banking ID / password management, the permissions of the host management, and log server management, should be based on the ISO 27001 proposed control measures. As a result consumers can be in a safe, easy to use financial services environment.
期刊論文
1.Streff, Kevi、Haar, Justin(2009)。An Examination of Information Security in Mobile Banking Architectures。Journal of Information Systems Applied Research,6(2),1-16。  new window
2.Vaidya, Shripad Ramakant(2011)。Emerging Trends on functional utilization of mobile banking in developed markets in next 3-4 years。International Review of Business Research Papers,7(1),301-312。  new window
3.李坤清、蔡旭昇、丁惠梅(20100200)。以ISO 27001控制標準稽核證券商網路下單系統資訊安全之研究。電腦稽核,21,1-15。new window  延伸查詢new window
4.尤克熙(20021200)。Smart Phone發展現況與趨勢分析。產業透析. IA 產業與市場透析,2-12。  延伸查詢new window
5.Christensen, Frans Moller、Andersen, Ole、Duijm, Nijs Jan、Harremoes, Poul(2003)。Risk terminology: a platform for common understanding and better communication。Journal of Hazardous Materials,103(3),181-203。  new window
6.Li, Bo、Im, Eul Gyu(2011)。Smartphone, promising battlefield for hackers。Journal of Security Engineering,8(1),89-110。  new window
會議論文
1.Barateiro, Jose、Borbinha, Jose(2011)。Integrated management of risk information。The Federated Conference on Computer Science and Information Systems,791-798。  new window
學位論文
1.王占魁(2009)。智慧型手機網路使用意願及相關因素探討(碩士論文)。樹德科技大學。  延伸查詢new window
2.葉怡亨(2011)。從品牌體驗觀點探討消費者忠誠度--以智慧型手機為例(碩士論文)。國立中正大學。  延伸查詢new window
3.柯燕茹(2011)。智慧型手機行動銀行消費者使用行為意圖研究--以理性行為理論及科技接受模型觀點(碩士論文)。國立成功大學。  延伸查詢new window
4.曾健豪(2007)。WAP行動銀行系統(碩士論文)。世新大學。  延伸查詢new window
圖書
1.Tiwari, R.、Buse, S.(2007)。The Mobile Commerce Prospects: A Strategic Analysis of Opportunities in the Banking Sector。Hamburg University Press。  new window
其他
1.(2011)。A Window Into Mobile Device Security,http://www.Symantec.com/coniiect/sites/default/files/A%20Window%20Into%20Mobile%20Device%20Security.pdf。  new window
2.(2011)。2011年第二季臺灣手機市場,http://www.idc.com.tw/about/detail.jsp?id=Mzc2。  new window
3.李慧蘭(2008)。國際資訊安全標準ISO27001之網路架構設計--以國網中心為例探討風險管理,http://sts.dhp.ks.edu.tw/andy/2006TANET/D00018.pdf。  延伸查詢new window
4.陳瑞甫,黃興進,蕭如淵,翁明正,吳欽和,陳雪樺,莊勝富(2010)。新興行動金融服務及其商業營運模式於臺灣之應用研究,http://ir.chna.edu.tw/bitstream/310902800/22457/l/982410H0411.pdf。  延伸查詢new window
5.Ai, Niwaeer,Lu, Ying,Deogirn, Jitender(2008)。The Smart Phones of Tomorrow,http://delivery.acm.org/10.1145/1370000/1366299/pl6-ai.pdf?ip=192.192.150.16&acc=ACTIVE%20SERVICE&CFID=54467262&CFTOKEN=95420438&_acm_=1321769388_93a9ee6cf36cl76194dd60fa9aa0de99。  new window
6.ISO(2009)。ISO/IEC Guide 73 Risk Management-Vocabulary-Guidelines for Use in Standards,ISO。  new window
 
 
 
 
第一頁 上一頁 下一頁 最後一頁 top
QR Code
QRCODE