1. Embrechts, P., Furrer, H., Kaufmann, R.: Quantifying regulatory capital for operational risk. Derivatives Use, Trading and Regulation 9, 217–233 (2003)
2. Weis, J.D.: A system security engineering process. In: Proceedings of the 14th National Computer Security Conference (1991)
3. Leippold, M., Vanini, P.: The quantification of operational risk (November 2003)
4. Böcker, K., Klüppelberg, C.: Operational var: A closed-form approximation (December 2005)
5. SC27, ISO/IEC 27001:2005, information technology - security techniques - information security management systems - requirements. Beuth-Verlag, Berlin (October 2005)