DSpace Repository

Developing and managing information technology risk management framework case study of a commercial bank

Show simple item record

dc.contributor.advisor Parveen, Dr. Sultana
dc.contributor.author Hossen, Abid
dc.date.accessioned 2019-11-24T04:19:01Z
dc.date.available 2019-11-24T04:19:01Z
dc.date.issued 2019-02-26
dc.identifier.uri http://lib.buet.ac.bd:8080/xmlui/handle/123456789/5384
dc.description.abstract The aim of this research is to establish a IT risk management framework for a commercial bank by which an organization can identify, measure, manage, monitor and report a risk. Framework helps the bank to manage its IT related risk l to evaluate, response and governance of risks. In order to prepare for IT related risk, organization must understand all domain, process goal and key activities under each process goal to handle risk effectively and efficiently. This thesis is based on both qualitative and quantitative research methodology. A part of the report looks into the details of different framework and standard which are related to Information technology risk. Therefore performing gap analysis a suitable framework was selected for further usage in terms of governance, risk evaluation and risk mitigation. The author used a survey among IT officials from different financial organizations in Bangladesh to determine whether they are acquainted with different framework and which is most appropriate framework for them. Survey suggests that Risk IT framework is the most suitable framework which is aligned with the gap analysis performed earlier. The author used AHP and FAHP method to identify the most important key activities of Risk IT framework by collecting expert opinion from a commercial bank. Following the method a commercial bank can be beneficial to identify the appropriate key activities among set of activities for establishing a framework to manage, evaluate and response the IT related risk. en_US
dc.language.iso en en_US
dc.publisher Department of Industrial and Production Engineering en_US
dc.subject Computer security en_US
dc.title Developing and managing information technology risk management framework case study of a commercial bank en_US
dc.type Thesis-MSc en_US
dc.contributor.id 0411082110 en_US
dc.identifier.accessionNumber 117208
dc.contributor.callno 005.8/ABI?2019 en_US


Files in this item

This item appears in the following Collection(s)

Show simple item record

Search BUET IR


Advanced Search

Browse

My Account