Powered by OpenAIRE graph
Found an issue? Give us feedback
image/svg+xml art designer at PLoS, modified by Wikipedia users Nina, Beao, JakobVoss, and AnonMoos Open Access logo, converted into svg, designed by PLoS. This version with transparent background. http://commons.wikimedia.org/wiki/File:Open_Access_logo_PLoS_white.svg art designer at PLoS, modified by Wikipedia users Nina, Beao, JakobVoss, and AnonMoos http://www.plos.org/ Vilnius University I...arrow_drop_down
image/svg+xml art designer at PLoS, modified by Wikipedia users Nina, Beao, JakobVoss, and AnonMoos Open Access logo, converted into svg, designed by PLoS. This version with transparent background. http://commons.wikimedia.org/wiki/File:Open_Access_logo_PLoS_white.svg art designer at PLoS, modified by Wikipedia users Nina, Beao, JakobVoss, and AnonMoos http://www.plos.org/
addClaim

Įmonės atitikties mokėjimo kortelių pramonės duomenų saugumo standartui (angl. PCI DSS) įvertinimo metodas, grindžiamas TOPSIS metodu

A method for assessing a company’s compliance with the pci dss standard based on the topsis method
Authors: Švetkauskaitė, Dainora;

Įmonės atitikties mokėjimo kortelių pramonės duomenų saugumo standartui (angl. PCI DSS) įvertinimo metodas, grindžiamas TOPSIS metodu

Abstract

With the rapid growth of the number of electronic payments and increasing threats to information security, payment card data protection has become a key priority for organizations. The Payment Card Industry Data Security Standard (PCI DSS) is a widely recognized international information security standard that all organizations processing, storing, or transmitting cardholder data must comply with. It has been observed that many organizations face challenges in implementing PCI DSS requirements, ranging from insufficient compliance monitoring to ineffective risk management. The topic of this paper is a method for assessing a company's compliance with the PCI DSS based on the TOPSIS method. The large volume of electronic payments and the increasing number of cyber threats pose challenges for organizations, as it is becoming increasingly important to ensure not only formal but also actual compliance with PCI DSS requirements. In practice, there is often a lack of a structured and quantitatively based method that would allow for an objective assessment of the level of compliance and the identification of priority areas for improvement. The aim of this work is to accelerate the process of assessing a company's compliance with PCI DSS standard, which would allow for a systematic assessment of the organization's security status according to 12 PCI DSS requirements and assessment criteria. The method integrates assessments of the company's current level, desired security goals, and priorities. These main objects are used to calculate dynamic criteria weights and determine the overall level of compliance. During the analysis, the assessment method allows for identifying the weakest areas of security, determining the gap from the ideal level of compliance, and comparing improvement solutions. The TOPSIS method is used to evaluate software and hardware suppliers. It would show the optimal solution to be selected according to the company's strategic priorities. The synthesized results of the study showed that the TOPSIS method is a suitable and practical tool for assessing PCI DSS compliance, enabling objective, data-driven decisions, and targeted planning to improve the organization's PCI DSS standard compliance.

Sparčiai augant elektroninių mokėjimų skaičiui ir grėsmėms informacijos saugumui, mokėjimo kortelių duomenų apsauga tapo vienu iš esminių organizacijų prioritetų. Mokėjimo kortelių pramonės duomenų saugumo standartas (toliau PCI DSS) yra plačiai taikomas tarptautinis informacijos saugumo standartas, kurio laikymasis būtinas visoms organizacijoms, tvarkančioms, saugančioms ar perduodančioms kortelių turėtojų duomenis. Pastebima, kad daugelis organizacijų susiduria su iššūkiais įgyvendindamos PCI DSS reikalavimus – nuo nepakankamos atitikties stebėsenos iki neefektyvaus rizikų valdymo. Darbo tema – įmonės atitikties mokėjimo kortelių pramonės duomenų saugumo standartui (angl. PCI DSS) įvertinimo metodas, grindžiamas TOPSIS metodu. Didelės elektroninių mokėjimų apimtys ir didėjantis kibernetinių grėsmių kiekis sukelia sunkumų organizacijoms, kadangi tampa vis svarbiau užtikrinti ne tik formalią, bet ir realią PCI DSS reikalavimų atitiktį. Praktikoje dažnai trūksta struktūruoto ir kiekybiškai pagrįsto metodo, leidžiančio objektyviai įvertinti atitikties lygį bei nustatyti prioritetines tobulinimo sritis. Šio darbo tikslas – pagreitinti įmonės atitikimo PCI DSS standarto reikalavimams įvertinimo procesą, kuris leistų sistemingai įvertinti organizacijos saugumo būklę pagal 12 PCI DSS reikalavimų ir vertinimo kriterijus. Įvertinimo metode integruojami įmonės dabartinio lygio įvertinimai, norimi pasiekti saugumo tikslai bei prioritetai, pagal kuriuos apskaičiuojami dinaminiai kriterijų svoriai ir nustatomas bendras atitikties lygis. Darbo metu sukurtas įvertinimo metodas leidžia identifikuoti silpniausias saugumo sritis, nustatyti atotrūkį nuo idealaus atitikties lygio bei palyginti galimus tobulinimo sprendimus. Taikant TOPSIS metodą atliekamas programinės ir techninės įrangos tiekėjų vertinimas, leidžiantis parinkti optimaliausią sprendimą pagal įmonės strateginius prioritetus. Sintetinti tyrimo rezultatai parodė, kad TOPSIS metodas yra tinkamas ir praktiškai pritaikomas įrankis PCI DSS atitikties įvertinimui, suteikiantis galimybę priimti objektyvius, duomenimis pagrįstus sprendimus ir kryptingai planuoti organizacijos PCI DSS standarto atitikties didinimą.

Country
Lithuania
Related Organizations
Keywords

PCI DSS, standartas, TOPSIS metodas, įvertinimo metodas

  • BIP!
    Impact byBIP!
    selected citations
    These citations are derived from selected sources.
    This is an alternative to the "Influence" indicator, which also reflects the overall/total impact of an article in the research community at large, based on the underlying citation network (diachronically).
    0
    popularity
    This indicator reflects the "current" impact/attention (the "hype") of an article in the research community at large, based on the underlying citation network.
    Average
    influence
    This indicator reflects the overall/total impact of an article in the research community at large, based on the underlying citation network (diachronically).
    Average
    impulse
    This indicator reflects the initial momentum of an article directly after its publication, based on the underlying citation network.
    Average
Powered by OpenAIRE graph
Found an issue? Give us feedback
selected citations
These citations are derived from selected sources.
This is an alternative to the "Influence" indicator, which also reflects the overall/total impact of an article in the research community at large, based on the underlying citation network (diachronically).
BIP!Citations provided by BIP!
popularity
This indicator reflects the "current" impact/attention (the "hype") of an article in the research community at large, based on the underlying citation network.
BIP!Popularity provided by BIP!
influence
This indicator reflects the overall/total impact of an article in the research community at large, based on the underlying citation network (diachronically).
BIP!Influence provided by BIP!
impulse
This indicator reflects the initial momentum of an article directly after its publication, based on the underlying citation network.
BIP!Impulse provided by BIP!
0
Average
Average
Average
Green