Compliance Management aims at ensuring regulatory-compliant behaviour of a company’s work force by requiring the presence of control processes which are intended to suppress illegal conduct such as money laundering, insider dealing, and corruption. The design of the individual controls is usually not prescribed by a legislator but is found in standards or best practices instead.
If executed diligently, compliance management is the pre-condition for a company to hope for milder sentences should culprit employees be convicted in a court of law. Since senior executives of a company can be held liable with their personal fortune, it is not surprising to see that compliance management has grown rapidly and control processes are spreading as industries become more regulated.
This spread is disconcerting as compliance management is, unfortunately, more and more applied to securing a company’s information systems (IS). The approach misleads companies to emphasize costly control processes rather than rigorous IS risk management. This yields bureaucracy-like efficiency and effectiveness and its application is disputed, in particular, for the mitigation of Internet threats which are the focus of this work. Compliance management alone does not yield security and complacent control processes may even increase risk. Instead, it is desirable to rigorously apply IS risk management as it promises the efficient and effective selection of security mechanisms for counteracting, e.g., cyber attacks.
Regrettably, the application of IS risk management is impeded by four problems:
• The Ambiguity Problem: In IS, interpretations of risk differ from community to community
• The Likelihood Problem: In practice, likelihood ratings are poorly accepted and subject to controversial discussions
• The Influence Problem: The operational context of IS is not taken into account for considerations on likelihood
• The Decision Problem: Today’s decision criteria for selecting security mechanisms do not fit a rigorous risk approach
To solve the aforementioned problems it was necessary to develop an understanding of the epistemological nature of IS risk. This revealed that today’s IS risk concepts and terminology need revision. Consequently, more mature concepts from disciplines such as the management of risks in technical systems were investigated and adapted.
In particular, the Ambiguity Problem was mainly solved by introducing state-based event sequences for modeling scenarios. Furthermore, we learned that a threat and a security mechanism need to be treated as one indivisible entity. This concept yields an understanding where the threat is described by a distinct probability distribution and the security mechanism responding to the attack is represented by another. By convoluting the two curves – an approach which is commonly used in communications engineering for processing electric signals – the Likelihood Problem is solved. In essence, the Influence Problem is solved by pattern recognition. From a variety of tools and techniques available today, Rough Sets Theory was adopted mainly because of its ability to infer results based on little, incomplete and vague data. The Decision Problem was solved by adapting decision models from Utility Theory, which had not yet been applied for its use in IS risk management. In particular, the risk preferences of corporate decision makers were explored.
As a result, four modules are presented, each of which has been designed to solve one of the aforementioned problems:
1. the Process Module reduces ambiguity in describing risk
2. the Function Module introduces a general approach to estimate likelihood
3. the Influence Module evidences the influence of the context on likelihood
4. the Decision Module makes risk preferences the decisive criteria for developing security policies to counteract threats
The Four Modules form a new and comprehensive model for IS risk management. These are intended for adoption within large companies and supports senior executives in risk informed decision making. Finally, the practical applicability of the modules has been successfully verified by a case study at a global financial institution.
Domenico Salvati
Entscheidungsprobleme Fallstudien Führungsinformationssysteme Informationssysteme Risikoanalyse Unternehmen Unternehmensführung