Cyber security threats to the payment and banking system have become a worldwide menace. The phenomenon has forced financial institutions to take risks as part of their business model. Hence, deliberate investment in sophisticated technologies and security measures has become imperative to safeguard against heavy financial losses and information breaches that may occur due to cyber-attacks. The proliferation of cyber crimes is a huge concern for various stakeholders in the banking sector. Usually, cyber-attacks are carried out via software systems running on a computing system in cyberspace. As such, to prevent risks of cyber-attacks on software systems, entities operating within cyberspace must be identified and the threats to the application security isolated after analyzing the vulnerabilities and developing defense mechanisms. This paper will examine various approaches that identify assets in cyberspace, classify the cyber threats, provide security defenses and map security measures to control types and functionalities. Thus, adopting the right application to the security threats and defenses will aid IT professionals and users alike in making decisions for developing a strong defense-in-depth mechanism.
翻译:对支付和银行系统的网络安全威胁已成为全球性威胁。这一现象迫使金融机构将风险作为其商业模式的一部分来承担。因此,对尖端技术和安全措施的蓄意投资已成为防范因网络攻击而可能发生的重大金融损失和信息破坏的当务之急。网络犯罪的扩散是银行部门各个利益攸关方的巨大关切。通常,网络攻击是通过在网络空间计算机系统中运行的软件系统进行的。因此,为了防止对软件系统进行网络攻击的风险,必须查明网络空间内运作的实体,在分析弱点和发展防御机制后孤立应用安全面临的威胁。本文件将审查查明网络空间中资产、对网络威胁进行分类、提供安保和制定安全措施以控制类型和功能的各种办法。因此,对安全威胁和防御采用正确的应用将有助于信息技术专业人员和用户做出建立强有力的深入防御机制的决定。