Search

Using incident response trees as a tool for risk management of online financial services

Recurso electrónico / electronic resource
Section: Articles
Title: Using incident response trees as a tool for risk management of online financial services / Dan GortonAuthor: Gorton, Dan
Notes: Sumario: The article introduces the use of probabilistic risk assessment for modeling the incident response process of online financial services. The main contribution is the creation of incident response trees, using event tree analysis, which provides us with a visual tool and a systematic way to estimate the probability of a successful incident response process against the currently known risk landscape, making it possible to measure the balance between front-end and back-end security measures. The model is presented using an illustrative example, and is then applied to the incident response process of a Swedish bank. Access to relevant data is verified and the applicability and usability of the proposed model is verified using one year of historical data. Potential advantages and possible shortcomings are discussed, referring to both the design phase and the operational phase, and future work is presented.Related records: En: Risk analysis : an international journal. - McLean, Virginia : Society for Risk Analysis, 1987-2015 = ISSN 0272-4332. - 01/09/2014 Volumen 34 Número 9 - septiembre 2014 , p. 1763-1774Materia / lugar / evento: Gerencia de riesgos Evaluación de riesgos Modelos probabílisticos Árbol de sucesos Servicios financieros Banca electrónica Fraude Casos prácticos Other categories: 7
See issue detail