There is a newer version of the record available.

Published November 9, 2022 | Version v1
Journal article Open

INFORMATION SECURITY GAP ANALYSIS: AN APPLIED STUDY ON THE YEMENI BANKING SECTOR'S TECHNOLOGY AND INNOVATION PRACTICES

  • 1. Department of Computer Science, Faculty of Computer and Information Technology, Sana'a University, Sana'a, Yemen
  • 2. Department of Information Systems and Computer Science, Faculty of Sciences, Sa'adah University, Sa'adah, Yemen, Modern Specialized College of Medical and Technical Sciences, Sana'a, Yemen
  • 3. Modern Specialized College of Medical and Technical Sciences, Sana'a, Yemen
  • 4. Faculty of Computer and Information Systems, Thamar University, Thamar, Yemen
  • 5. Yemen Academy for Graduate Studies, Sana'a, Yemen

Description

Abstract:

This study aims to analyze the level of compliance of Yemeni banks' information security management systems (ISMSs) with technology and innovation controls, identify strengths and weaknesses in their practices, and provide appropriate solutions and treatments to reduce the gap. To this end, drawing on the analysis of previous studies, the problem of the study was determined, its dimensions were explained, and the appropriate assessment framework and maturity model were selected. A questionnaire was used to collect information from 26 carefully selected experts to assess the maturity level of 13 local banks in the Yemeni capital, Sana'a. Through data analysis, it was found that the level of security maturity in the banking sector meets only the key requirements of technology and innovation security, moving away from the ideal maturity level by a gap of 1.1 out of five. In addition, detailed results on maturity levels, weaknesses, and average applied gaps in TI practices were obtained. By interpreting the findings, a classification and ranking of indicators that represent the most likely technological weaknesses for banks and the average level of security gaps that must be reduced by each of them were determined. Finally, the classification and ranking presentations and proposals enable banks to compare their security status with each other, and to build appropriate strategies to bridge the gap and improve their competitive position. Accordingly, the classification and ranking presentations made by this study will enable banks to compare their security situations and take appropriate actions, policies, and technical solutions to bridge the gap and improve their competitive position.

Files

V17I11A9.pdf

Files (707.1 kB)

Name Size Download all
md5:3a62d3c08e98ac3d9314aac09ad18296
707.1 kB Preview Download