![]() |
|
Information Security Risk AssessmentInformation Technology Risk Management Program (IT-RMP)Office of the Comptroller of the Currency (OCC)Risk Management The quality of security controls can significantly influence all categories of risk.additional information. Traditionally, examiners and bankers recognize the direct impact on operational/transaction risk from incidents related to fraud, theft, or accidental damage. Many security weaknesses, however, can directly increase exposure in other risk areas. For example, the GLBA introduced additional legal/compliance risk due to the potential for regulatory noncompliance in safeguarding customer information. The potential for legal liability related to customer privacy breaches may present additional risk in the future. Effective application access controls can reduce credit and market risk by imposing risk limits on loan officers or traders. If a trader were to exceed the intended trade authority, the institution may unknowingly assume additional market risk exposure.
|
||||||||||||||||||||||||||||||