A method for assessing the information security level of banking sector organizations based on an analysis of the implementation of protection measures
A methodology is proposed for assessing the information security level of an automated banking system by linking relevant information security threats, the implementation status of organizational and technical security measures, and an integrated regulatory assessment. Relevant threats are identified using the Threat Database maintained by the Federal Service for Technical and Export Control of Russia (FSTEC of Russia). For each threat, a set of required security measures is defined, and the degree of their implementation is assessed according to the criteria of GOST R 57580.2-2018, which take into account the planning, implementation, monitoring, and improvement of information security processes. The resulting assessments of security measures are aggregated into group-level and integrated indicators in accordance with the framework of STO BR IBBS-1.2-2014. The practical significance of the study lies in improving assessment transparency, automating analytical procedures, reducing the workload of information security specialists, and providing a basis for repeated monitoring of the security posture. The methodology is intended to assess the current information security level of the automated banking system under study within the selected scope and does not replace formal procedures for assessing compliance with regulatory requirements.