Methodologies for Evaluating Information Security Investments - What Basel II Can Change in the Financial Industry
نویسنده
چکیده
The New Basel Capital Accord (Basel II) will include operational risk to the calculation of necessary regulatory capital in financial institutions after year-end 2006. Most of the banks have already developed sophisticated risk management frameworks helping to quantify and manage operational risk. Information security has direct impact on operational risk, but risk managers consider Information Systems (IS) related risks not enough by now. This problem mainly depends on the variety of methods used by security managers to evaluate systems security and to develop security concepts. Even little efforts would enable information security officers to quantify the benefits of information security investments using operational risk quantification methods. The security community has not yet addressed this opportunity. The article discusses models used for decisions about security investments known from the field of security economics and accounting and illustrates the problems by applying these models. Based on a general operational risk management framework of a bank, this article introduces a new approach using accepted risk management methods.
منابع مشابه
Enhanced Prudential Standards Under Basel Iii: What Consequences For The Profitability Of Banks
Since the subprime financial crisis, international financial regulatory institutions (Basel, MIFID, Dodd-Frank), have strengthened regulatory requirements on systemically important banks. The Basel Committee on Banking Supervision, and based on the G20 recommendations, has drawn up a reform program to reconfigure the banking system, based mainly on increasing the capital requirement. The progra...
متن کاملHow can the change of Basel Capital Requirements affect the Monetary Policy Impact on the Iranian Economy and Banking System?
In this study, we examined the effects of monetary policy shocks on the performance of the Iranian macroeconomy and the banking system, under the different situations of the Basel II and III capital requirements regulations. By developing a DSGE Model and according to its structural shocks, four observable variables including output gap, bank capital adequacy, inflation, and money base growth r...
متن کاملRisk Management Framework in Islamic Banking: Basel II and III, Challenges and Implications in Islamic Banking
The time to fix the roof is when the sun is shining risk management has not been uppermost on the Islamic banking sector’s agenda in recent years. It is crucial for Islamic banks (IBs) to have comprehensive risk management framework as there is growing realization among IBs that sustainable growth critically depends on the development of a comprehensive risk management framework. Islamic b...
متن کاملO12: Off the Couch and Out the Door: Improving Treatment Through a Refined Understanding of Psychotherapeutic Change
State-of-the-art psychotherapy for anxiety disorders represents some of the most efficacious treatments in the mental health literature. Nevertheless, these treatments are not panacea. Too many patients drop out of treatment, response rates leave room for improvement, and residual symptomatology is common. The quest to improve therapy for patients suffering from mental disorders necessitates on...
متن کاملCredit risk management: A multicriteria approach to assess creditworthiness
Credit risk management is a key issue for any company at anytime, but is especially important in the case of the banking industry. This fact is more than evident in times of financial crises, when financial institutions can suffer high losses due to unpaid credits. For this reason, international financial supervisors and authorities have forced banks to monitor their credit risk and this risk i...
متن کامل