Appendix 3: Relevant information standards
Introduction: Money is information on the move
Trends in digital money
How digital money creates new operational risks
Operational risk and cryptography
Operational risks of digital money
Commercial bank digital money
Private digital money, including cryptocurrencies
Public digital money, including CBDCs
Impact of digitisation on operational risk management
Impact of digitisation on operational risk organisations
Impact of digital money and operational resilience on ORM processes and people
Impact of digitisation on operational risk management in the future
Theory of money
Information theory
Classical cryptography
Modern cryptography
Conclusion
Acknowledgements
Appendix 1: Significant contributors to information theory and cryptography
Appendix 2: Timeline of significant contributions to information theory and cryptography
Appendix 3: Relevant information standards
Appendix 4: High-level risk registers
Bibliography
International standards bodies include the following.
-
American National Standards Institute (ANSI).
-
International Electrotechnical Commission (IEC).
-
International Organization for Standardization (ISO).
-
Global System for Mobile Communications (GSM) developed by the European Telecommunications Standards Institute (ETSI).
-
US National Institute of Standards and Technology (NIST).
-
Payment Card Industry (PCI).
Relevant standards include (but are not limited to) the following.
Standard | Published by | Covers |
ANSI X9.102-2020 | ANSI | Symmetric Key Cryptography for the Financial Services Industry – Wrapping of Keys and Associated Data |
ANSI X9.142-2020 | ANSI | Public Key Cryptography for the Financial Services Industry – The Elliptic Curve Digital Signature |
ANSI X9.82: Part 4-2011 (R2017) | ANSI | Random Number Generation – Part 4: Random Bit Generator Constructions |
GSM 11.11 | GSM | Specification of the Subscriber Identity Module – Mobile Equipment (SIM-ME) Interface |
ISO 20022 | ISO | Specification of message formats, becoming standard in payment systems |
ISO 27799 | ISO | Information security management in health using ISO/IEC 27002 – guides health industry organisations on how to protect personal health information using ISO/IEC |
Copyright Infopro Digital Limited. All rights reserved.
As outlined in our terms and conditions, https://www.infopro-digital.com/terms-and-conditions/subscriptions/ (point 2.4), printing is limited to a single copy.
If you would like to purchase additional rights please email info@risk.net
Copyright Infopro Digital Limited. All rights reserved.
You may share this content using our article tools. As outlined in our terms and conditions, https://www.infopro-digital.com/terms-and-conditions/subscriptions/ (clause 2.4), an Authorised User may only make one copy of the materials for their own personal use. You must also comply with the restrictions in clause 2.5.
If you would like to purchase additional rights please email info@risk.net