| Home

Overview


Original Research

INFORMATION SECURITY GAP ANALYSIS: AN APPLIED STUDY ON THE YEMENI BANKING SECTOR'S TECHNOLOGY AND INNOVATION PRACTICES

ABDUALMAJED A. G. AL-KHULAIDI 1, ADEL A. NASSER 2, NADA K. AL-ANESI 3, MUNEER A. S. HAZAA 4, MIJAHED ALJOBER 5, and NESMAH A. AL-KHULAIDI 6.

Vol 17, No 11 ( 2022 )   |  DOI: 10.5281/zenodo.7318124   |   Author Affiliation: Department of Computer Science, Faculty of Computer and Information Technology, Sana'a University, Sana'a, Yemen 1; Department of Information Systems and Computer Science, Faculty of Sciences, Sa’adah University, Sa’adah, Yemen, Modern Specialized College of Medical and Technical Sciences, Sana'a, Yemen 2; Modern Specialized College of Medical and Technical Sciences, Sana'a, Yemen 3; Faculty of Computer and Information Systems, Thamar University, Thamar, Yemen 4; Modern Specialized College of Medical and Technical Sciences, Sana'a, Yemen 5; Yemen Academy for Graduate Studies, Sana'a, Yemen 6.   |   Licensing: CC 4.0   |   Pg no: 106–132   |   To cite: ABDUALMAJED A. G. AL-KHULAIDI, et al., (2022). INFORMATION SECURITY GAP ANALYSIS: AN APPLIED STUDY ON THE YEMENI BANKING SECTOR'S TECHNOLOGY AND INNOVATION PRACTICES. 17(11), 106–132. https://doi.org/10.5281/zenodo.7318124   |   Published on: 09-11-2022

Abstract

This study aims to analyze the level of compliance of Yemeni banks' information security management systems (ISMSs) with technology and innovation controls, identify strengths and weaknesses in their practices, and provide appropriate solutions and treatments to reduce the gap. To this end, drawing on the analysis of previous studies, the problem of the study was determined, its dimensions were explained, and the appropriate assessment framework and maturity model were selected. A questionnaire was used to collect information from 26 carefully selected experts to assess the maturity level of 13 local banks in the Yemeni capital, Sana'a. Through data analysis, it was found that the level of security maturity in the banking sector meets only the key requirements of technology and innovation security, moving away from the ideal maturity level by a gap of 1.1 out of five. In addition, detailed results on maturity levels, weaknesses, and average applied gaps in TI practices were obtained. By interpreting the findings, a classification and ranking of indicators that represent the most likely technological weaknesses for banks and the average level of security gaps that must be reduced by each of them were determined. Finally, the classification and ranking presentations and proposals enable banks to compare their security status with each other, and to build appropriate strategies to bridge the gap and improve their competitive position. Accordingly, the classification and ranking presentations made by this study will enable banks to compare their security situations and take appropriate actions, policies, and technical solutions to bridge the gap and improve their competitive position.


Keywords

Banking Sector, Gap Analysis, Information Security Assessment, Maturity Index, Maturity Level, Maturity Model, Technology and Innovation, Yemen