Тестовий режим. Платформа працює в режимі випробування: частина можливостей ще незавершена, дані можуть змінюватися, а окремі сторінки — виглядати або рахуватися неточно. Як читати показники · Якщо профіль стосується вас
SciNodus
СтаттяЗовнішня публікація🌐 російська

Data security management in financial organizations

Oleg Valeriyevich Boychenko

Анотація

The article studies the current state of the problems of threats and vulnerabilities of data cybersecurity management in financial organizations. The vulnerability of the financial sector to cyberattacks has been established, which indicates that it is particularly attractive to fraudsters. It is determined that to protect data in this sector, cybersecurity must be comprehensive, along with flexible, simple, and scalable security tools and techniques. It is separately established that in order to exclude negative consequences, monetary and reputational losses, it is important to define and implement a set of protective measures to create conditions for effective security of financial data. In order to implement the abovementioned orientation of the cyber protection system, the planning of security policy of a financial organization based on the Bank of Russia standard STO BR BFBO-1.8-2024 is justified in order to differentiate the composition and content of protection measures depending on the type of operation, its criticality and risks. It was determined that the modern information security policy of a financial organization, along with actions to verify the authenticity of the subject of access and/or object of access, as well as to verify the belonging of the access identifier and authentication information presented to the subject of access and/or object of access, provides for the procedure of delegation of identification or authentication in the process of transferring the service provider's obligation or right to carry out identification or authentication of the recipient of services to a trusted third party, which is necessary for the organization's data protection. The implementation of DLP-system for protection of financial organization's data at the moment of their use, transfer and storage, along with creating conditions for detection of suspicious activity of employees, as well as identifying threats and taking action at an early countermeasures stage is proposed.

Класифікація

Ідентифікатори

Рецензій ще немає. Будьте першим!

Коментарі до статті

Коментарів ще немає

Увійдіть щоб залишити коментар

Схожі роботи