信息安全研究 ›› 2018, Vol. 4 ›› Issue (10): 940-945.

• 风险评估专题 • 上一篇    下一篇

商业银行信息系统安全风险识别与风险库研究

郭汉利1,张辉1,杨宝辉2,顾呈页2   

  1. 1. 中国建设银行股份有限公司 信息技术管理部
    2. 中国建设银行股份有限公司金融科技部
  • 收稿日期:2018-10-11 出版日期:2018-10-15 发布日期:2018-10-11
  • 通讯作者: 郭汉利
  • 作者简介:郭汉利 工学学士,高级工程师,主要研究领域为信息安全管理、安全技术架构。 张辉 工学硕士,主要研究领域信息安全技术架构 杨宝辉 工学硕士,主要研究领域信息安全技术架构 顾呈页 工学学士,主要研究领域信息安全管理

Research on Information System Security Risk Identification and Risk Database Construction of Commercial Bank

  • Received:2018-10-11 Online:2018-10-15 Published:2018-10-11

摘要: 风险识别是商业银行信息系统安全风险管理的基础,风险被识别后才能进行有效管理.目前业界缺少可操作性强的风险识别方法和通用的信息系统风险基础库,导致风险管理更多以控制为核心而非以风险为核心.通过借鉴国内外业界标准和实践,深入分析大量信息系统安全风险事件,建立风险要素模型、风险识别方法和风险数据库,统一风险认知,实现对信息系统安全风险的有效识别,明确风险管控目标和重点,提高银行信息科技风险管理水平,增强风险管控能力,支持银行金融科技创新和发展.

关键词: 商业银行, 信息系统, 风险识别方法, 风险基础库, 风险特征

Abstract: Risk identification is the basis of the information system security risk management of the commercial Banks. The known risks can be managed effectively and efficiency. However, there is not a feasible risk identification method and lack of the common information system risk database in the banking industry. Because of that, it may lead to take the control as the core rather than the risk. Based on the industry standards and practices at home and abroad, and thorough analysis of a large number of information system security risk incidents, this essay established the risk factor model, risk identification method and risk database. Those unified risk perception; achieved effective information system security risk identification; clearly defined objectives and priorities of risk management and control; improved the level of bank information technology risk management; strengthened risk control ability; and offered support to the innovation and development of banking fintech.

Key words: commercial bank, information system, risk identification, risk database, risk features