Integrity in very large information systems: dealing with information risk black swans

  • Authors:
  • Beat Liver;Helmut Kaufmann

  • Affiliations:
  • Credit Suisse Information Technology, Zurich, Switzerland;Credit Suisse Information Technology, Zurich, Switzerland

  • Venue:
  • CAiSE'13 Proceedings of the 25th international conference on Advanced Information Systems Engineering
  • Year:
  • 2013

Quantified Score

Hi-index 0.00

Visualization

Abstract

Multi-national enterprises, like financial services companies, operate large and critical information systems around the globe on a 24/7 basis. In an information-based business, even a single inadequately designed, implemented, tested and operated business application can put the existence of the enterprise at risk. For adequately securing the integrity of business critical information and hence ensuring that such information is meaningful, accurate and timely, we present our risk assessment and controls framework: First, we introduce our criticality rating scheme that is based on the recoverability from integrity failures. For dealing with dependencies among applications, we present our approach based on services given a Service-Oriented Architecture (SOA). Second, we provide an overview of our design-related controls including a data analytics approach to continuously audit the most critical information assets. Finally, we present our learnings from a first implementation of the presented framework.