Research and Implementation of Risk Assessment for Commercial Bank Information Technology
Hui Ding
Abstract
Hui Ding
Abstract
Banking data concentration leads to risk concentration,and an information security incident would lead to the bankruptcy of the bank Information technology risk assessment could help identify and eliminate potential risks in advance. The paper summarizes five domestic and foreign risk assessment standards,including ISO27001,ISO15408,ISO13335,NIST Risk management framework and GB/T 20984,then gives the four risk assessment methods,including baseline risk assessment,important system risk assessment,process risk assessment and asset risk assessment,and finally describes three tools,including management tools,technical tools and auxiliary tool. The authors hope that these could promote the banking risk assessment.
A significance statement is not available in the OpenAlex record.
A contribution statement is not available in the OpenAlex record.
Method details are not available in the OpenAlex metadata.
Findings are not separately available in the OpenAlex metadata.
Limitations are not available in the OpenAlex metadata.
Application details are not available in the OpenAlex metadata.
Banking data concentration leads to risk concentration,and an information security incident would lead to the bankruptcy of the bank Information technology risk assessment could help identify and eliminate potential risks in advance. The paper summarizes five domestic and foreign risk assessment standards,including ISO27001,ISO15408,ISO13335,NIST Risk management framework and GB/T 20984,then gives the four risk assessment methods,including baseline risk assessment,important system risk assessment,process risk assessment and asset risk assessment,and finally describes three tools,including management tools,technical tools and auxiliary tool. The authors hope that these could promote the banking risk assessment.
Key concepts: Risk assessment, IT risk management, Risk management, Computer science, Risk analysis (engineering), Asset (computer security), Risk management plan, Risk management information systems