2012Information Security and Communications PrivacyRequires access

Research and Implementation of Risk Assessment for Commercial Bank Information Technology

Hui Ding

Open publisher page 0 citations

Abstract

Banking data concentration leads to risk concentration,and an information security incident would lead to the bankruptcy of the bank Information technology risk assessment could help identify and eliminate potential risks in advance. The paper summarizes five domestic and foreign risk assessment standards,including ISO27001,ISO15408,ISO13335,NIST Risk management framework and GB/T 20984,then gives the four risk assessment methods,including baseline risk assessment,important system risk assessment,process risk assessment and asset risk assessment,and finally describes three tools,including management tools,technical tools and auxiliary tool. The authors hope that these could promote the banking risk assessment.

About this research paper

What this paper is about

Banking data concentration leads to risk concentration,and an information security incident would lead to the bankruptcy of the bank Information technology risk assessment could help identify and eliminate potential risks in advance. The paper summarizes five domestic and foreign risk assessment standards,including ISO27001,ISO15408,ISO13335,NIST Risk management framework and GB/T 20984,then gives the four risk assessment methods,including baseline risk assessment,important system risk assessment,process risk assessment and asset risk assessment,and finally describes three tools,including management tools,technical tools and auxiliary tool. The authors hope that these could promote the banking risk assessment.

Why it matters

A significance statement is not available in the OpenAlex record.

Key contribution

A contribution statement is not available in the OpenAlex record.

Method / approach

Method details are not available in the OpenAlex metadata.

Main findings

Findings are not separately available in the OpenAlex metadata.

Limitations

Limitations are not available in the OpenAlex metadata.

Applications

Application details are not available in the OpenAlex metadata.

Available abstract

Banking data concentration leads to risk concentration,and an information security incident would lead to the bankruptcy of the bank Information technology risk assessment could help identify and eliminate potential risks in advance. The paper summarizes five domestic and foreign risk assessment standards,including ISO27001,ISO15408,ISO13335,NIST Risk management framework and GB/T 20984,then gives the four risk assessment methods,including baseline risk assessment,important system risk assessment,process risk assessment and asset risk assessment,and finally describes three tools,including management tools,technical tools and auxiliary tool. The authors hope that these could promote the banking risk assessment.

Key concepts: Risk assessment, IT risk management, Risk management, Computer science, Risk analysis (engineering), Asset (computer security), Risk management plan, Risk management information systems

Related papers

Back to paper searchBrowse research topicsOriginal source
Research and Implementation of Risk Assessment for Commercial Bank Information Technology — Research Paper | ScholarLens