A Framework for the Comparison of Best Practice Recommendations and Legal Requirements for South African Banks

نویسندگان

  • Carla-Lee Botha
  • Elmarie Kritzinger
  • Marianne Loock
چکیده

South African home users of the Internet use it to perform various everyday functions. These functions include, but are not limited to, online shopping, online gaming, social networking and online banking. Home users of online banking face multiple threats, such as phishing and social engineering. These threats come from hackers attempting to obtain confidential information, such as online banking authentication credentials, from home users. It is, thus, essential that home users of online banking be made aware of these threats, how to identify them and what countermeasures to implement to protect themselves from hackers. In this respect, information security awareness (ISA) programmes are an effective way of making the home users of online banking aware of both the threats they face and the countermeasures available to protect themselves from these threats. South African banks have to comply with certain legal requirements when implementing information security awareness initiatives. Noncompliance or failure to demonstrate due care and due diligence, should a security incident occur, will result in financial penalties for the bank as well as possible brand damage and loss of customers. Banks implement international best practice recommendations in an effort to comply with legislation. These include recommendations for information security awareness. This research proposes a framework which, predominantly, can be applied when determining and comparing information security best practice recommendations and information security legal requirements for online banking. The primarily aim of this paper is to investigate whether the implementation of best practices are sufficient to comply with legal requirements. A selected list of information security best practices was investigated for best practice recommendations while a selected list of information security legislation was also investigated for legal requirements imposed on South African banks. A gap analysis was performed on both these recommendations and requirements to determine whether the implementation of best practice recommendations results in compliance with legal requirements. The gap analysis found that the implementation of best practice recommendations does not result in compliance with legal requirements. Accordingly, the outcome of this research highlights the importance of applying such a framework in a comprehensive fashion to understand the legal requirements imposed and ensure that adequate controls are in place for achieving compliance.

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

HIV vaccine research--South Africa's ethical-legal framework and its ability to promote the welfare of trial participants.

An effective ethical-legal framework for the conduct of research is critical. We describe five essential components of such a system, review the extent to which these components have been realised in South Africa, present brief implications for the ethical conduct of clinical trials of HIV vaccines in South Africa and make recommendations. The components of an effective ethical-legal system tha...

متن کامل

domestic and international regulations and standards for risk disclosure in banks

Reporting by stakeholder groups, especially shareholders, has always been a demand And reporting and disclosure for the banking network is important. In Iran, banks require disclosing and reporting information and financial and economic events, but there are many international rules and standards for this disclosure. In addition, domestic regulations and requirements are also unclear due to the...

متن کامل

The Effect of Regulatory Policy on Efficiency under Prudential Framework among Listed Iranian Banks

This study examines the effect of regulatory policy on efficiency under prudential framework among banks listed in the Iranian Securities and Exchange Organization over the period 2003 to 2015. Arellano-Bond estimation method has been patronized to investigate the effect of regulatory policies on efficiency. Results indicate that regulatory policy indicator indexing reserve requirement on inves...

متن کامل

Voluntary informed consent and good clinical practice for clinical research in South Africa: ethical and legal perspectives.

Most differences, shortcomings and contradictions regarding voluntary informed consent for participation in clinical research relate to the South African-specific guidance documents, i.e. South African Guidelines for Good Practice in the Conduct of Clinical Trials with Human Participants in South Africa (2006) and Ethics in Health Research: Principles, Structures and Processes (2004). These doc...

متن کامل

Does One Size Fit All? The Impact of Liquidity Requirements on Bank\'s Insolvency: Evidence from Iranian Listed Banks

According to the Basel III regulatory framework, uniform minimum liquidity requirements have been imposed on all types of banks. Using an agent-based model of a banking system, we investigate the effects of liquidity requirements on banks' insolvency under two policy experiments in one of which the minimum liquidity requirements are applied uniformly and in the other differentially across banks...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

عنوان ژورنال:
  • J. UCS

دوره 18  شماره 

صفحات  -

تاریخ انتشار 2012