Compliance is not enough
The demands of regulatory compliance are among the factors driving IT and security managers within large organisations to improve their user-access governance processes, but the issues are broader and deeper than any regulations - and more serious than many senior executives think. The recent scandal at Societe Generale offers lessons from which every chief risk officer, chief information officer and chief security officer should learn, writes Brian Cleary
Risks related to unauthorised or inappropriate access to information resources can appear anywhere within an organisation at any time and spread rapidly through the business. All it takes is a single person with the wrong access. Such events range from minor policy and compliance violations to major operational failures with substantial financial, legal and reputational consequences.
While user
Only users who have a paid subscription or are part of a corporate subscription are able to print or copy content.
To access these options, along with all other subscription benefits, please contact info@risk.net or view our subscription options here: http://subscriptions.risk.net/subscribe
You are currently unable to print this content. Please contact info@risk.net to find out more.
You are currently unable to copy this content. Please contact info@risk.net to find out more.
Copyright Infopro Digital Limited. All rights reserved.
As outlined in our terms and conditions, https://www.infopro-digital.com/terms-and-conditions/subscriptions/ (point 2.4), printing is limited to a single copy.
If you would like to purchase additional rights please email info@risk.net
Copyright Infopro Digital Limited. All rights reserved.
You may share this content using our article tools. As outlined in our terms and conditions, https://www.infopro-digital.com/terms-and-conditions/subscriptions/ (clause 2.4), an Authorised User may only make one copy of the materials for their own personal use. You must also comply with the restrictions in clause 2.5.
If you would like to purchase additional rights please email info@risk.net
More on Risk management
Slimmed-down and automated, ERM seeks a seat at the top table
Latest Risk Benchmarking exercise finds ERM growing in influence, even as headcounts shrink
From Pillar to Pillar… to post: where now for op risk in Europe?
Experts think enhanced Pillar 2 charge informed by Dora would be more useful than a blunt Pillar 1
JSCC faces pushback on plans to merge futures default funds
Members say commodities products should be kept fully segregated because of different risk profile
CME aims to offer client UST cross-margining internally in 2027
CCP has filed initial proposal with SEC; wants to offer more products than joint FICC programme
Manuela Veloso on how banks can make their AI dreams reality
Former JP Morgan head of AI research says open-ended enquiry will unlock technology’s full potential
The ECB’s geopolitical stress test needs a price
Only a market can say how much it should cost to insure against losses from a geopolitical risk event, and none exists, argues academic
Risk managers grapple with hazards and benefits of intraday repo
Expected increase in collateral velocity and re-use could also boost leverage and risk in markets
Repo tokens won’t be cleared. Or will they?
Uncertainty lingers over clearing status of tokenised Treasuries, with decision likely devolved to DTCC