PSD: Risk Management
Dec 3rd, 2007 by Jesper Kråkhede
In the same article and point as in my previous entry risk management is mentioned. This is a very important function in any kind of security architecture. Without sound risk analysis you cannot produce any kind of security due to the fact that you do not know what the risks are. The directive in this case is a bit unclear in its scope. It is stated that “those arrangements, procedures and mechanisms shall be comprehensive and proportionate to the nature, scale and complexity of the payment services provided by the payment institution.”
This of course is very different for different organizations. But there are of course some risks that are generic regarding the industry and that are those that are dependent on the setup of an infrastructure. Other risk are those that exist due to the type of business you are in. Robbery has of moved from the actually robbery of a bank to become fraud on the payment transactions instead. This of course is a obvious risk for the payment industry.
I would say that the most importent part is to map the identified risk to the security controls, monitoring and reporting that is done. This really puts the need for a sound security architecture on the frontline.