4.2.1.1
Operational Risk
According to our respondent from NCCPL, she is information security group head at NCCPL
and her team responsibility is to manage any types of information security and operational risks
in the organization. Our respondent defined operational risk as it is defined in Basel II (see
Appendix 4) which is; operational risk is the risk of losses which comes as a result from poor or
failed external events, internal processes, systems and people. She further explained the different
areas which are included in operational risk i.e. legal risk, process risk, information technology
security, event risk and compliance risk. According to our respondent, generally operational risks
are divided into event risks and process risks and it is hard to rank the different areas of
operational risks in an organization.
Do'stlaringiz bilan baham: |