| Recently,technology and internet are connected closely;however,people are annoyed by the lack of security while enjoying the convenience and high efficiency brought by them.Information disclosures,computer hackers,information defraud are not uncommon in our real life.Due to the negative externality of the internet,public economy and society will be highly influenced if the risk which detailed above occurs.Commercial banks play a vital role in a country’s economic regulation,therefore,making sure the secure operation of commercial banks not only benefit banks themselves,but also maintain the national economy and the stability of society.Due to the risk of information-security,information-security is classified as a kind of bank operation risk in Basel II.Therefore,a mature risk analysis and assessment can be used in the management of information-security.ISMS is a system used around the world and it provides the framework and guideline of information-security for companies.ISMS can also be referred in the construction of commercial banks and the operation of information-security-management.Document research approach and empirical research are used in this essay which analyze the characteristic of information-security in our country,introduces the national regulation related with information-security,argues the necessity of ISMS in risk assessment approach and information-security,propose that it will be more efficient to combine two approaches together to improve the construction and operation of commercial bank information-security management.Finally,the suitability of combining risk assessment with ISMS is being verifying through the practice of bank A,in addition,the conclusion from approaches and processes in assessing information-security risks and constructing the framework of Bank A,can be seen as a reference for other commercial banks and financial organizations,furthermore,it can enrich the information-security cases in other commercial banks as well. |