The virtual asset industry is still actively traded 15 years after Bitcoin was developed and is growing into various types of services. However, accidents involving theft of virtual assets due to hacking damage are frequently occurring regardless of t...
The virtual asset industry is still actively traded 15 years after Bitcoin was developed and is growing into various types of services. However, accidents involving theft of virtual assets due to hacking damage are frequently occurring regardless of the service type of the virtual asset service provider. In Korea, acquisition of ISMS certification was set as a mandatory screening requirement when reporting a virtual asset service provider, and ISMS detailed inspection items for virtual asset service provider were added to enhance the security and reliability of virtual asset service provider. However, as hacking accidents continue to occur even for virtual asset service provider who have acquired ISMS certification, the need for ISMS control items tailored to the actual environment of virtual asset service provider is being raised.
In this study, 80 ISMS certification items and 290 major checks for virtual asset service provider, CCSS of C4, and crypto asset audit guidelines of the Korea Certified Public Accountants Association were compared in detail to derive detailed check items necessary for actual virtual asset service provider. And we verified the appropriateness and effectiveness of this study through a survey.
Through the above study results, we were able to establish a secure virtual asset security system by presenting improved ISMS control items considering the working environment of virtual asset service provider, which is meaningful in that it contributed to securing the reliability of virtual asset service provider and revitalizing the blockchain industry.