{"title":"银行公司安全风险管理的优化模型","authors":"Ulrich Faisst, Oliver Prokein","doi":"10.1109/ICECT.2005.21","DOIUrl":null,"url":null,"abstract":"The increasing importance of information and communication technologies (ICT), new regulatory obligations (e.g. Basel II) and growing external risks (e.g. hacker attacks) put security risks in the management focus of banking companies. The management has to decide whether to accept expected losses or to invest in technical security mechanisms in order to decrease the frequency of events or to invest in insurance policies in order to lower the severity of events. This paper contributes to the development of an optimization model that aims to determine the optimal amount to be invested in technical security mechanisms and insurance policies. Furthermore the model considers budget and risk limits as constraints and is supposed to help practitioners in controlling security risks.","PeriodicalId":312957,"journal":{"name":"Seventh IEEE International Conference on E-Commerce Technology (CEC'05)","volume":"1 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2005-07-19","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"12","resultStr":"{\"title\":\"An optimization model for the management of security risks in banking companies\",\"authors\":\"Ulrich Faisst, Oliver Prokein\",\"doi\":\"10.1109/ICECT.2005.21\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"The increasing importance of information and communication technologies (ICT), new regulatory obligations (e.g. Basel II) and growing external risks (e.g. hacker attacks) put security risks in the management focus of banking companies. The management has to decide whether to accept expected losses or to invest in technical security mechanisms in order to decrease the frequency of events or to invest in insurance policies in order to lower the severity of events. This paper contributes to the development of an optimization model that aims to determine the optimal amount to be invested in technical security mechanisms and insurance policies. Furthermore the model considers budget and risk limits as constraints and is supposed to help practitioners in controlling security risks.\",\"PeriodicalId\":312957,\"journal\":{\"name\":\"Seventh IEEE International Conference on E-Commerce Technology (CEC'05)\",\"volume\":\"1 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2005-07-19\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"12\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"Seventh IEEE International Conference on E-Commerce Technology (CEC'05)\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/ICECT.2005.21\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"Seventh IEEE International Conference on E-Commerce Technology (CEC'05)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ICECT.2005.21","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
An optimization model for the management of security risks in banking companies
The increasing importance of information and communication technologies (ICT), new regulatory obligations (e.g. Basel II) and growing external risks (e.g. hacker attacks) put security risks in the management focus of banking companies. The management has to decide whether to accept expected losses or to invest in technical security mechanisms in order to decrease the frequency of events or to invest in insurance policies in order to lower the severity of events. This paper contributes to the development of an optimization model that aims to determine the optimal amount to be invested in technical security mechanisms and insurance policies. Furthermore the model considers budget and risk limits as constraints and is supposed to help practitioners in controlling security risks.