Literature Review and the Information Risk Framework

Literature Review and the Information Risk Framework

*&$H,/( ,R#0'0P$0#EG( &$,( P&G,+( "%( ,UY,./&/0"%A( e01D,$(R#&%/0/=( ")( 0%)"$E&/0"%( 1,%,$&/,G( D01D,$( R#&'0/=( ")( ,UY,./&/0"%( E&H0%1( )0%&%.0&'( E&$H,/G( &( 1""+( 0%G/$#E,%/( /"( &''".&/,( .&Y0/&'( &''"[&%.,GA( 3%( G/&%+&$+( )0%&%.0&'( E&$H,/( E"+,'G2( /D,( 0%%,$( Y$"P',E( 0G( ."%.,$%,+( [0/D( /D,( R#&%/0/=( ")( 0%)"$E&/0"%( /D&/( 0G( 0%."$Y"$&/,+( 0%( &GG,/( Y$0.,G(10M,%(&(.,$/&0%(G,/(")(,U0G/0%1(0%)"$E&/0"%A(-%"/D,$(M,$=(0EY"$/&%/(G#Pd,./(0G(/D,(R#&%/0/=(")(/$&+,$G(D&M0%1( 0%)"$E&/0"%( &/( /D,0$( +0GY"G&'2( /D#G( +,)0%0%1( 0%)"$E&/0"%( &G=EE,/$0,GA( N#''=( ,))0.0,%/( E&$H,/G( ,U0G/( [D,%( /D,( ,%/0$,(G,/(")(0%)"$E&/0"%(0G(."%G0+,$,+(0%(Y$0.,(G,//0%12(G"(/D&/(0%)"$E&/0"%(1,/G(&M&0'&P',()"$(&%=(/$&+,$A(4,M,$&'( +,1$,,G( ")( ,))0.0,%.=( .&%( P,( )"#%+( &/( ,EY0$0.&'( ',M,'( &.."$+0%1( /"( /D,( H0%+( ")( 0%)"$E&/0"%( /D&/( 0G( &./#&''=( 0%.'#+,+( 0%( &GG,/( Y$0.,GK( Z,&H( )"$EG( &$,( )"#%+( 0%( /D,( .&G,( ")( D0G/"$0.&':"%'=( 0%)"$E&/0"%( 0G( ."%G0+,$,+]( G,E0:G/$"%1()"$EG(&$,(0%(/D,(.&G,(")(Y&$/0&'(0%)"$E&/0"%(0%.'#G0"%](G/$"%1()"$EG(.&%(P,()"#%+(0%(/D,(.&G,(")(,%/0$,( G,/(0%.'#+,+A(

N$"E( /D,( G,E0%&'( ["$H( ")( N&E&( a6\B?b( G/&/0%1( /D,( &P"M,( )$&E,["$H( )"$( E&$H,/( ,))0.0,%.=( &%&'=G0G2( G,M,$&'(G/#+0,G(/$=(/"(M,$0)=(P"/D(/D,(',M,'G(")(,))0.0,%.=(/D&/(.&%(P,(&.D0,M,+(0%($,&'(E&$H,/G(&%+(/D,(."%+0/0"%G(

B?8(

CeQ(35NcF*-C3c5(F34f(35(CeQ(I-CQ4C(JF3434(

)"$( E&$H,/G( /"( $,&.D( D01D,$( ,))0.0,%.=A( 4/#+=0%1( +,1$,,G( ")( ,))0.0,%.=( &$,( ")( 0%/,$,G/( )"$( $,1#'&/"$G( &0E0%1( /"( Y$"/,./( E&$H,/( 0%M,G/"$G2( [D0',( +,,Y,$( H%"[',+1,( ")( E&$H,/G( +=%&E0.G( P,/[,,%( +0)),$,%/( G/&/,G( ")( ,))0.0,%.=( .&%(D,'Y(E&$H,/(/$&+,$G(/"(1&0%(,U.,GG:$,/#$%2(P"/D(0%('"%1(&%+(GD"$/(/,$EA(

L,(T"%+/(&%+(CD&',$(a6\97b(G#11,G/,+(/D&/(G/".H(E&$H,/G(/,%+(/"(D&M,(,%+"1,%"#G("M,$$,&./0"%2(G"(/D&/( D0G/"$0.&'(',M,'(")(,U.,GG($,/#$%(E&=(0%),$(&P"#/(Y$0.,(/$,%+G(0%()#/#$,(/0E,GA(CD0G(P,0%1(/D,(.&G,(&(^."%/$&$0&%( G/$&/,1=_( E&=( 1,%,$&/,( Y"G0/0M,( ,U/$&:$,/#$%G( a-'YD&Gb( )"$( 0%M,G/"$GA( !"0%/0%1( /D0G( &YY$"&.D( [0/D( N&E&2( "%,( ["#'+( P,( '0H,( /"( G#G/&0%( /D&/( ,))0.0,%.=( 0G( [,&H( &G( )&$( &G( /0E,( ."$$,'&/0"%( ")( ,U/$&:$,/#$%( 0G( ."%.,$%,+( [D0',( ,))0.0,%.=(E&=(P,(D01D,$(&/(&(G/&/0.(/0E,A(

N&E&(&%+(N$,%.D(a6\99&2(6\99Pb(G#11,G/,+(/D&/(G/".H($,/#$%G(&$,(E,&%($,M,$/0%12(&/(',&G/(0%(&('"%1(/,$E2( G"( /D&/( &( G/&P',( 4,.#$0/=( *&$H,/( I0%,( a&.."$+0%1( /"( J&Y0/&'( -GG,/( `$0.0%1( *"+,'b( .&%( P,( )"#%+A( I"( &%+( *&.f0%'&=(a6\99b(G#11,G/,+(&'/,$%&/0M,G(/"($&%+"E([&'H(&YY$"&.D(0%(/,$EG(")(&#/":."$$,'&/,+(Y$0.,(Y&/D(/D&/( .&%(P,(#G,+()"$(1&0%0%1(,U.,GG($,/#$%A(

c/D,$(&#/D"$G(/$=(/"(G/#+=(E&$H,/(,))0.0,%.=($,'&/,+(/"(GY,.0)0.(.'&GG,G(")(0%)"$E&/0"%(1,//0%1(&M&0'&P',()"$( /D,(E&$H,/A(T&G#(a6\BBb(GD"[,+(/D,(&%"E&'0,G(/D&/(.&%(P,(1,%,$&/,+(P=(`$0.,:/":Q&$%0%1($&/0"K(J"EY&%0,G([0/D( '"[,$(`hQ(/,%+(/"(1,%,$&/,(D01D,$($,/#$%()"$(/D,(0%M,G/"$GA(J"%/$&$0&%(,M0+,%.,(0G(GD"[%(0%(N&E&(&%+(N$,%.D( a6\\>b( /D&/( )0U( /D,( J$"GG:G,./0"%( ")( /D,( QUY,./,+( 4/".H( F,/#$%( G#11,G/0%1( &( Y"G0/0M,( $,'&/0"%GD0Y( P,/[,,%( $,/#$%G( &%+( `hQ( $&/0"GA( -GR#0/D( &%+( *#''0%G( a6\9;b( &%+( *&G#'0G( &%+( f"$[&$( a6\9;b( ")),$,+( 0%+0.&/0"%( 0%( /D,( .&G,(")(,R#0/=(0GG#,G](0%(/D0G(.&G,2(,R#0/=(0GG#0%1(G01%&'G(/"(/D,(E&$H,/(&(Y"GG0P',(0%)"$E&/0"%(&G=EE,/$=(G"(/D&/( /D,(E&$H,/(+$"Y(0%(Y$0.,GA(

4"E,(/,.D%0.&'(,UY'&%&/0"%(E&=(G#YY"$/(/D,(&./#&'(+,1$,,(")(E&$H,/(,))0.0,%.=(/""A(I&H"%0GD"H(&%+(4E0/+( a6\99b( 1&M,( ,M0+,%.,( ")( /D,( $,'&/0"%GD0Y( P,/[,,%( G,&G"%&'( ,)),./( &%+( ,U.,GG:$,/#$%( /D&/( &$,( [,''( H%"[%( P=( E&$H,/(/0E,$GA(L,(I"%12(4D',0),$2(4#EE,$G2(&%+(Z&'+E&%%(a6\\?b(GD"[,+(,M0+,%.,(/D&/(Y,$G0G/,%.,(0%(Y$0.,( 1&YG( M,$G#G( /D,0$( )#%+&E,%/&'( M&'#,G( .&%( P,( ,UY'&0%,+( 0%( /,$EG( ")( /$&+,:"))( P,/[,,%( ."G/G( &%+( Y$")0/( &$0G0%1( )$"E(E&$H,/(/$&%G&./0"%A(

3%( '&/,G/( &%&'=G0G2( /D,( $,G,&$.D( 0%/,$,G/( D&G( )".#G,+( E"$,( "%( /D,( &M&0'&P0'0/=( ")( /D,( ,%/0$,( 0%)"$E&/0"%:G,/( &%+("%(/D,(R#&'0/=(")(0%)"$E&/0"%(/D&/(.&%(P,(&M&0'&P',(/"(/$&+,$GA(Q))0.0,%.=(0G(%"(E"$,(&(G0EY',(^G/&/,(")(/D,( E&$H,/_(P#/(1,/G(E"$,(&%+(E"$,(&(^R#&'0/=(")(/D,(E&$H,/_A(N&E&(a6\\6b(GD"[,+(/D&/(P0&G,G(0%($,/#$%(,G/0E&/0"%( +#,( /"( 0%."$$,./( a#G,( ")( &b( E"+,'( E&=( 1,%,$&/,( E&$H,/( 0%,))0.0,%.=( 0%( /,$EG( ")( G,'):."$$,'&/0"%( ")( Y$0.,G( &%+( G01%&'0%1(0%)"$E&/0"%(&$0G0%1()$"E(`$0.,:/":Q&$%0%1(&%+(`$0.,:/":T""H(M&'#,($&/0"GA(3%("#$("Y0%0"%2(/D0G(N&E&VG( ["$H(0G(&G(G,E0%&'(&G(/D,(6\B?G("%,2(G0%.,(0/(0G()0U0%1(/D,(Y$"P',E($,),$$0%1(/"(/D,(Y$".,GG(P=([D0.D(0%)"$E&/0"%( 0G( Y$".,GG,+( 0%G0+,( /D,( E&$H,/GK( CD,( G&E,( D=Y"/D,G0G( [,( [0''( G/&$/( )$"EA( 4/0''2( N&E&( a6\\9b( /$0,+( /"( )0%+( &( Y"GG0P',( ,UY'&%&/0"%( /"( E&$H,/( 0%,))0.0,%.=( 0%( /,$EG( ")( P,D&M0"$&'( ."EY"%,%/G( /D&/( &$,( &%=[&=( )"#%+( /"( P,( .&G#&'/=( 0%( "M,$h#%+,$( $,&./0"%( &%+2( &1&0%2( P0&G,G( 0%( ,G/0E&/0"%GA( CD,( G&E,( '"10.&'( )$&E,["$H( &$,( L0,/D,$2( *&''"=2( &%+( 4.D,$P0%&( a>??>b2( G/&/0%1( /D&/( [0+,( +0)),$,%.,G( 0%( &%&'=G/( "Y0%0"%( .&%( G"#$.,( '"[,$( $,/#$%A( T,$/0%,//0( ,/( &'A( a>??8b( +,E"%G/$&/,+( /D,( ,U0G/,%.,( ")( &%( 0%)"$E&/0"%( $0GH( 0%( )0%&%.0&'( E&$H,/G( +#,( /"( G#P:"Y/0E&'( G/&%+&$+G( 0%( 0%)"$E&/0"%( GY$,&+0%1( 0%/"( /D,( E&$H,/( /D&/( E&=( 1,%,$&/,( "M,$:M"'&/0'0/=A( CD,=( G#11,G/,+( /D&/( )0%&%.0&'( ."EE#%0.&/0"%( E&=( 1,%,$&/,( ."%/0%1,%/( G/&/,( ")( 0%,))0.0,%.=( &%+( /D&/( 1"M,$%&%.,( E"+,'G(&+"Y/,+(E&=(E"+0)=(/D,(0EY&./(")(/D,(0%)"$E&/0"%($0GH(/"(E&$H,/(,R#0'0P$0#EA(

Z,( E"M,( )$"E( /D,( 0+,&( /D&/( 0%)"$E&/0"%( 0G( &( +=%&E0.( ."EY"%,%/( ")( /D,( E&$H,/( /D&/( E&=( &)),./( E&$H,/( ,R#0'0P$0#E(0%+,Y,%+,%/'=()$"E(/D,(,))0.0,%.=(G/&/#G(")(/D,(E&$H,/A(QU/$&:M"'&/0'0/=(.&%(P,(,0/D,$(&%(0%+0.&/0"%( ")( '"[:,))0.0,%/( E&$H,/2( "$( /D,( G#11,G/0"%( /D&/( E&$H,/G( &$,( E"M0%1( /"[&$+( &( %,[( '"%1:/,$E( ,R#0'0P$0#EA( c#$(

CeQ(35NcF*-C3c5(F34f(35(CeQ(I-CQ4C(JF3434(

B?7

$,G,&$.D( R#,G/0"%( 0G( /"( 0%),$( &P"#/( /D,( +,/,$E0%&%/G( ")( /D,( 0%)"$E&/0"%( $0GH( 0%( "$+,$( /"( G#YY"$/( &( E"+,'( )"$( )0U0%1(&%(0%)"$E&/0"%($0GH(Y$,E0#E2(0)(&%=A(

3%(G/&%+&$+(J&Y0/&'(-GG,/(`$0.0%1(*"+,'2($,G0+#&'G(0%($,/#$%(D&M,(X,$"(,UY,./,+(M&'#,A(3%("#$(&YY$"&.D2([,( G#11,G/(/D&/($,G0+#&'G(GD"#'+(P,(GY'0/(0%/"(/["(Y&$/G2(/D,()"$E,$(D&M0%1(X,$"(,UY,./,+(M&'#,(aN&E&VG("$/D"+"U:( 6\B?(&YY$"&.D(/"(E&$H,/(,))0.0,%.=b([D0',(/D,('&//,$(D&M0%1(,UY,./,+(M&'#,(/D&/(.&%(+0)),$()$"E(X,$"(/D&/(.&%(P,( ,UY'&0%,+(P=(/D,(+$0M,$G(")(/D,(,."%"E0.(M&'#,(")(0%)"$E&/0"%(aN&E&VG(%,[(Y"G/:6\\6(&YY$"&.D(/"(,))0.0,%.=bA(

N".#G0%1( "%( /D,( )0%&%.0&'( ,)),./G( ")( P,//,$( 0%)"$E&/0"%( .0$.#'&/0"%2( [,( E&=( )0%+( &( ."#Y',( ")( Y"GG0P',( ,UY'0.&/0"%(")(."G/(")(.&Y0/&'($,+#./0"%(ae,&'=(g(`&',Y#2(>??6bA(CD,()"$E,$(0G(+#,(/"(/D,(0%.$,&G,(")('0R#0+0/=(")( /D,(G,.#$0/=2(/D#G($,+#.0%1(/D,(,R#0/=(."G/(")(.&Y0/&'(P=(&%(0%.$,&G,(0%(/D,(+,E&%+(")(/D,(G,.#$0/=(aL0&E"%+(g( @,$$,..D0&2( 6\\6b( &%+( &( $,+#./0"%( 0%(/D,( ,UY,./,+( M&'#,(")('"GG,G(+#,( /"( /$&%G&./0"%( &1&0%G/( 0%)"$E,+( /$&+,$G( aQ&G',=( g( cVe&$&2( >??8bA( CD,( $,+#./0"%( ")( /$&%G&./0"%( ."G/G( E01D/( &'G"( &)),./( /D,( P0+:&GH( GY$,&+( 0%( G,.#$0/=( /$&+0%1( a-E0D#+( g( *,%+,'G"%2( 6\9;bA( 4"E,( &#/D"$G( G/$0H,( "#/( &( Y"GG0P',( Y"G0/0M,( $,'&/0"%GD0Y( &E"%1( M"'#%/&$=( +0G.'"G#$,2( 0%)"$E&/0"%( &G=EE,/$0,G2( &%+( ,R#0/=( ."G/( ")( .&Y0/&'( af0E( g( @,$$,..D0&2( 6\\8]( iD&%12( >??6b2(,M,%(0)(G,M,$&'(,EY0$0.&'(,M0+,%.,G(G#YY"$/(&(%,1&/0M,(."$$,'&/0"%(aZ,'H,$2(6\\7](J"'',$(g(j"D%2(6\\B]( e,&'=2(e#//"%2(g(`&',Y#2(6\\\](I,#X(g(@,$$,..D0&2(>???](e,)'0%2(4D&[2(g(Z0'+2(>??7](T$"[%(g(e0'',1,0G/2( >??BbA( 5"/( &''( /D,( ,EY0$0.&'( $,G,&$.D,G( G,,E( /"( P,( ."%G0G/,%/( aN$&%.0G2( >??9bA( CD,( '&//,$2( 0G( ."%%,./,+( /"( /D,( &GG#EY/0"%(/D&/([D,%(/D,(+0G.'"G#$,(0G(0EY,$),./2(0%M,G/"$G(&$,(.D&$1,+([0/D(&()#$/D,$(0%)"$E&/0"%($0GH(+#,(/"( [0+,$(#%.,$/&0%/=(0%(,UY,./&/0"%G(."%.,$%0%1(Y&="))GA(3)(/D0G(H0%+(")($0GH(0G(G=G/,E&/0.(aT&$$=(g(T$"[%2(6\97]( e&%+&(g(I0%%2(6\\<](J"',G2(I",[,%G/,0%2(g(4#&=2(6\\7b2(E&%=(0%M,G/"$G([0''($,R#0$,(&()#$/D,$($,/#$%(/"(P,&$( G#.D( &( $0GH]( E"$,( $,.,%/'=( a*&%/"M&%02( >??9b( 0%)"$E&/0"%( $0GH( Y$,E0#E( '0%H( /"( )0$E:GY,.0)0.( $0GH( D&G( P,,%( +0G."M,$,+A( 3%( )&./2( /D,$,( G,,EG( /"( P,( %"( )#''( ."%G,%G#G( &P"#/( /D,( ,)),./0M,( Y"GG0P0'0/=( /"( +0M,$G0)=( /D,( 0%)"$E&/0"%($0GH(aJ'&$HG"%2(O#,+,G2(g(CD"EYG"%2(6\\;b(&%+(D"[(+0G.'"G#$,(E01D/($,+#.,(0/2(D&M0%1($,+#%+&%/( ,M0+,%.,( &P"#/( /D0G( aT"/"G&%2( >??;bA( 4"E,( &#/D"$G( GD"[,+( &( G01%0)0.&%/( $,'&/0"%GD0Y( "%'=( 0%( /D,( .&G,( ")( G,.#$0/0,G(1,%,$&/0%1('"[(0%/,$,G/()"$(&%&'=G/(aT"/"G&%2(6\\Bb("$(."$Y"$&/0"%(.&$$=0%1("%(&11$,GG0M,(&.."#%/0%1( G/$&/,10,G( aO0,/XE&%%( g( 3$,'&%+2( >??7b2( "$( .&$$=0%1( "%( disclosure( G/$&/,10,G( "%'=( /D$"#1D( /D,( &%%#&'( $,Y"$/( aT"/"G&%(g(`'#EP',,2(>??>bA(

N"$( G#$,2( $,G#'/G( )$"E( ,EY0$0.&'( ,M0+,%.,( E01D/( P,( ."%%,./,+( /"( /D,( .D"0.,G( E&+,( P=( $,G,&$.D,$G( )"$( E,&G#$0%1(+0G.'"G#$,K(4,'):E&+,($&/0"G(.&%("M,$[,01D/(G"E,(G#Pd,./G(&.."$+0%1(/"(/D,($,G,&$.D,$(Y"0%/(")(M0,[2( [D0',( 0%+,Y,%+,%/( 0%+,U( aG#.D( &G( /D,( -3*F( "%,b( E&=( P,( 0%,))0.0,%/( /"( +,G.$0P,( /D,( GY,.0)0.( Y$"P',E( /"( P,( 0%M,G/01&/,+A(e,&'=(&%+(`&',Y#(a>??6b(G#YY"$/,+(/D,(#G,(")(G,'):E&+,($&/0"G(P,.&#G,(")(/D,0$(P,//,$(G#YY"$/(/"(&( GY,.0)0.( +0G.'"G#$,(0%M,G/01&/0"%2( P#/( /D,=(G/$0H,( "#/( /D,(D01D,$( ."G/G(")( /D,0$( ."EY#/&/0"%( 0%(/,$EG( ")( $,+#.,G( G&EY',G(/D&/(.&%(P,(&%&'=X,+A(CD&/(0G([D=(G,M,$&'($,G,&$.D(P&G,+("%(G,'):E&+,($&/0"G(+"(%"/(&//$0P#/,($,'&/0M,( [,01D/( /"( /D,( 0EY"$/&%.,( ")( GY,.0)0.( 0/,EG( a-DE,+( g( J"#$/0G2( 6\\\bA( 3%( "#$( "Y0%0"%2( /D,( $,&'( Y$"P',E( 0G( ."%%,./,+(/"(/D,(.D"0.,(")("%'=(E,&G#$0%1(/D,(',M,'(")(+0G.'"G#$,2(/D#G(E&H0%1(/D,(D=Y"/D,G0G(/D&/(R#&'0/=(&%+( R#&%/0/=(")(+0G.'"G#$,([0''(P,(G/$"%1'=($,'&/,+(aT"/"G&%2(6\\BbA(Z,(G#11,G/2(0%G/,&+2(&(+0G.'"G#$,(0%+,U([0''(%"/( P,(&P',(/"(."%G0+,$(&''(/D,($,'&/0"%GD0YG(P,/[,,%(/D,(+0)),$,%/(."EY"%,%/G(")(/D,(0/,EG(/"(P,(."EE#%0.&/,+2(d#G/( '0H,( /D,( G/$&/,1=( ")( +0G.'"G#$,( GD"#'+( G#11,G/( /"( ."$Y"$&/0"%GA( CD#G2( [,( G#YY"$/( /D,( 0+,&( ")( $,d,./( /D,( E,$,( R#&%/0/&/0M,( &YY$"&.D( /"( &+"Y/( &( E"$,( G=G/,E0.( "%,( aL$&X0%( g( @&%( +,( @,%2( 6\97b( "$( &( ."%)01#$&/0M,( "%,( a*,=,$2( CG#02( g( e0%0%1G2( 6\\<b( &G( #G#&''=( +"%,( 0%( /D,( &%&'=G0G( ")( G/$&/,10,G( ")( Y$"+#./0"%2( "$1&%0X&/0"%( &%+( ."EY,/0/0"%(aL,GG2(5,[Y"$/2(g(F&GD,,+2(6\\<](*0'',$2(6\9;](*0'1$"E( g(F"P,$/G2(6\\7b2(d#G/('0H,(&(Y&Y,$(")( JD&M,%/2(L0%12(N#2(4/"'"[=2(&%+(Z&%1(a>??;b(Y$"Y"G,+A(

B?;(

CeQ(35NcF*-C3c5(F34f(35(CeQ(I-CQ4C(JF3434(

F,),$$0%1( %"[( /"( /D,( E,&G#$,E,%/( ")( 0%)"$E&/0"%( $0GH2( [,( E#G/( )0$G/( +0G/0%1#0GD( P,/[,,%( $0GH( ,U0G/,%.,( &%+( /D,( ,)),./0M,( 0EY&./2( 0/( E&=( D&M,( "%( /D,( )0%&%.0&'( E&$H,/G( ,R#0'0P$0#E( aG"2( /D,( ,U0G/,%.,( ")( &%( &./#&'( 0%)"$E&/0"%($0GH(Y$,E0#EbA(CD0G(G,Y&$&/0"%(0G($,R#0$,+(0%("$+,$(/"()0%+(&%(,."%"E0.(G#YY"$/(/"(/D,(.D"0.,G(0%( /,$EG(")(+0G.'"G#$,G](0%()&./2(&G(&(Y&$&+"U2(0%(&(["$'+([0/D"#/(0%)"$E&/0"%($0GH(Y$,E0#E2(%"(,."%"E0.(0%.,%/0M,( ["#'+( ,U0G/G( /"( .&$$=( "%( G/$&/,10,G( ")( M"'#%/&$=( +0G.'"G#$,A( CD,( R#,G/0"%( 0G( G/0''( E"$,( ."EY'0.&/,+( )$"E( /D,( %,.,GG0/=(/"(G/&%+&$+0X,(/D,(0%)"$E&/0"%()'"[G(/"(/D,(0%M,G/"$G(a/D#G(0%.$,&G0%1(/D,(0%)"$E&/0"%(,))0.0,%.=(")(/D,( E&$H,/Gb(&1&0%G/(/D,(Y"GG0P0'0/=(/D&/(D01D'=(G/&%+&$+0X,+(0%)"$E&/0"%()'"[G(.&%(0EY,+,(/"(+0))#G,(M,$=(GY,.0)0.( Y0,.,G( ")( 0%)"$E&/0"%2( Y&$/0.#'&$'=( /D"G,( ."%%,./,+( /"( /D,( ."EY,/0/0M,( &+M&%/&1,( ")( /D,( ."$Y"$&/0"%( a/D#G( 0EY&./0%1("%(/D,(M&'#,(.$,&/0"%(Y$".,GGbA(CD&/(0G([D=(0/(0G(/,.D%0.&''=(Y"GG0P',(/D&/(&%(0%.$,&G,(0%(/D,(R#&%/0/=( ")(0%)"$E&/0"%(."#'+($,+#.,(0/G(R#&'0/=(&%+2(0%(/D&/([&=2(/D,(&YY,/0/,()"$(&(GY,.0)0.(0%M,G/E,%/A(-'',%(&%+(O&',( a6\\8b(Y$"Y"G,+(/"(GY'0/(/D,(/"/&'($0GH(")(&%(0%M,G/E,%/(0%/"(/["(."EY"%,%/GK(CD,(^Y&="))($0GH_2($,Y$,G,%/0%1( /D,(&./#&'($0GH(,EP,++,+(0%(.&GD()'"[G(&%+(/D,(^0%)"$E&/0"%($0GH_(P,0%1(0/(/D,(1&Y(P,/[,,%(/D,($0GHG(Y,$.,0M,+( )$"E(0%M,G/"$G(&%+(/D,(Y&="))("%,A(CD,(&./#&'(0%M,G/E,%/(P,D&M0"$([0''(P,(P&G,+("%(/D,(G#E(")(/D,(/["($0GHG( &%+2( 0%( /D0G( [&=2( /D,( &./#&'( ',M,'( ")( /D,( Y$0.,G( ")( /D,( G,.#$0/0,GA( T,$/0%,//0( ,/( &'A( a>??8b( /$0,+( /"( &%&'=X,( /D,( Y"GG0P',(G"#$.,G(")(0%)"$E&/0"%($0GH(&%+()"#%+("#/(/D&/(G"E,(")(/D,E(&$,(,%+"1,%"#G(/"(/D,()0%&%.0&'(E&$H,/G( G"( &$,( ")( G=G/,E&/0.( G"#$.,A( C["( .'&GG,G( ")( G=G/,E&/0.( 0%)"$E&/0"%( $0GH( D&M,( P,,%( 0+,%/0)0,+K( a6b( CD"G,( 1,%,$&/,+( P=( /D,( 0%)"$E&/0"%( /0E0%1( a0A,A2( ."%%,./,+( /"( /D,( %&/#$&'( R#&%/0/=( ")( /0E,( $,R#0$,+( /"( [0+,GY$,&+( 0%)"$E&/0"%(0%/"(/D,(E&$H,/Gb](a>b(/D"G,(1,%,$&/,+(P=(/D,(G"(.&'',+(^0%)"$E&/0"%(,$$"$_(a0A,A2($,'&/,+(/"(P0&G,G(0%( Y,$.,Y/0"%(")($0GH(+#,(/"(/D,(&YY'0.&/0"%(")(GY,.0)0.(/,.D%0R#,GbA(-(/D0$+(Y"GG0P',(G"#$.,(")(0%)"$E&/0"%($0GH(E&=( P,(/D,()0%&%.0&'(."EE#%0.&/0"%(Y$".,GG,G(aT,$/0%,//02(>??;b(E&0%'=(."%%,./,+(/"(/D,()0$E:GY,.0)0.(Y&$/(")(0/A(

T&G,+( "%( T,$/0%,//0( ,/( &'A( a>??8b2( *&%/"M&%0( a>??8b( Y$"Y"G,+( &%( "$010%&'( E,/D"+"'"1=( /"( 0%+,%/0)=( G"E,( Y$"U0,G(")(/D,(0%)"$E&/0"%($0GH(/D&/(,%/0/',(/"(+0G/0%1#0GD(P,/[,,%(G=G/,E&/0.(&%+()0$E(GY,.0)0.(."EY"%,%/G(")(0/A( CD,(E,/D"+"'"1=(0G(P&G,+("%(/D,(0+,&(/D&/(0%()0%&%.0&'(E&$H,/G(,M"'M0%1(/"[&$+(,))0.0,%.=(a,M,%(0%(&([,&H()"$Eb2( /D,( 0%)"$E&/0"%( $0GH( .&%( P,( Y$"U=( P=( /D,( GY$,&+( ,U0G/0%1( P,/[,,%( '"%1:/,$E( &%+( GD"$/:/,$E( M"'&/0'0/=( ")( G/".H( $,/#$%GA(3%()&./2(0%M,G/"$G([0''(.D""G,(0%M,G/E,%/G("%(/D,(P&G,(")(P0&G,+(GD"$/:/,$E(M"'&/0'0/=([D0',(/D,(&./0"%(")( /D,(0%)"$E&/0"%(/$&+,$G([0''(."%/$0P#/,(/"([0+,GY$,&+(0%)"$E&/0"%(0%G0+,(/D,(E&$H,/(aO$"GGE&%(g(4/01'0X2(6\9?b2( /D#G()0U0%1(/D,(M"'&/0'0/=(/"(/D,('"%1:/,$E(M&'#,(a0A,A2(/"(/D,(Y&="))($0GH("%'=bA(CD,([0+,$(0G(/D,(/0E,([0%+"[(#G,+( /"( ."EY#/,( /D,( GD"$/:/,$E( M"'&/0'0/=( /D,( '"[,$( [0''( P,( /D,( 1&Y( P,/[,,%( '"%1:/,$E( &%+( GD"$/:/,$E( ."EY#/&/0"%A( T,$/0%,//0(,/(&'A(a>??8b(/$0,+(/"(/,G/(/D,(E"+,'(P=(+,/,./0%1(/D,(0%)"$E&/0"%($0GH(Y$,E0#E(0%(GY,.0&'(,M,%/G(0%(/D,( )0%&%.0&'( E&$H,/G( G#.D( &G( /D,( G&',( ")( %,['=( 0GG#,+( GD&$,G2( ."EY&$0%1( /D,( ,UY,$0,%.,( 0%( +0)),$,%/( Q#$"Y,&%( J"#%/$0,G(a3/&'=2(N$&%.,2(&%+(4Y&0%b]($,',M&%/($,G#'/G([,$,()"#%+2(/D#G(/$#G/0%1(/D,(E,/D"+"'"1=A(O&$+,%&'(a>??Bb( /$0,+( /"( +,/,./( /D,( ."%%,./0"%G( P,/[,,%( /D,( 0%)"$E&/0"%( $0GH( &%+( /D,( $0GH( &M,$G0"%( ")( 0%M,G/"$G( 0%( &( P,D&M0"$&'( )0%&%.,(."%/,U/2([D0',(*&%/"M&%0(a>??9b(Y$"Y"G,+(&(M,$=('"%1:/,$E(&%&'=G0G(a67(=,&$Gb()"$(/D,(0%)"$E&/0"%($0GH( /"()0%+("#/(/D,(Y"GG0P',(+$0M,$G(")(&%(0%)"$E&/0"%($0GH(Y$,E0#E(E"+,'A(

4#YY"G,( &( G,.#$0/=( D&M0%1( &%( 0%0/0&'( Y$0.,( &/( 6??( &%+( &%( &./#&'( &%%#&'( $,/#$%( &/( 6?k( a?A?8>k( +&0'=( ,UY,./,+($,/#$%bA(J"%G0+,$0%1(&(/D$,,(E"%/D(")(&%&'=G0G(a;;(/$&+0%1(+&=Gb(&%+(G#YY"G0%1(/D&/(/D,(G,.#$0/=([0''( %"/(Y&=(+0M0+,%+G(+#$0%1(/D&/(Y,$0"+2([,(.&%(,UY,./(/D,(Y$0.,(&/(/D,(,%+(")(/D,(Y,$0"+(/"(P,(6?>ABB\6A(3%(.&G,(")( %"(%,[(0%)"$E&/0"%2(/D,($,'&/0"%GD0Y(P,/[,,%(/0E,(&%+(Y$0.,([0''(P,('0%,&$2(G"(/D&/(+&0'=($,/#$%()"$(0%M,G/"$G([0''( P,(,)),./0M,'=(?A?8>k(&%+(/D,0$(G/&%+&$+(+,M0&/0"%([0''(P,(?k(a/D0G(%&0M,(["$'+(0G(G#11,G/("%'=(/"(P,%.DE&$H( [D&/([0''(&./#&''=(D&YY,%(0%($,&'(/,$EGbA(

J"%G0+,$( %"[( /D,( .&G,( [D,$,( &)/,$( <<( /$&+0%1( +&=G2( &(Y0,.,( ")( 0%)"$E&/0"%( 0G( &M&0'&P',( &%+( 0EE,+0&/,'=(

CeQ(35NcF*-C3c5(F34f(35(CeQ(I-CQ4C(JF3434(

B?B

0%."$Y"$&/,+( 0%( /D,( E&$H,/( Y$0.,G2( 1,%,$&/0%1( &%( &P%"$E&'( $,/#$%( &/( ;k( a/D0G( &P%"$E&'( $,/#$%( 0G( +#,( /"( /D,( Y&="))($0GH(&.."$+0%1(/"(-'',%(&%+(O&',2(6\\8bA(CD,(Y$"P',E(0G(D"[(/D0G(%,[(0%)"$E&/0"%([0''([0+,GY$,&+(0%/"( /D,(E&$H,/A(-.."$+0%1(/"(&%("$/D"+"U(&YY$"&.D(a0A,A2(0%(.&G,(")(%"(0%)"$E&/0"%($0GHb2(/D,(0EY&./("M,$(Y$0.,([0''( P,( 0EE,+0&/,2( /D#G( "PG,$M0%1( &( ;k( Y$0.,:d#EY( "%'=( "%( +&=( <<A( CD,( )0%&'( Y$0.,( "%( +&=( ;;( [0''( P,( )0U,+( 0%( 6?9A\8<<](+&0'=(&M,$&1,($,/#$%([0''(1$"[(#Y(/"(?A6<87k(a)$"E(?A?8>kb(GD"[0%1(&(?A?\><k(0%.$,&G,(+#,(/"(/D,( &P%"$E&'($,/#$%A(N01#$,(6(P,'"[(GD"[G(/D,(Y$0.,(Y&/DA(

T heoretical price path of Security X

QM,%/(+,Y,%+,%/

e ic 105.0000

Normal Pr 104.0000

Event dependent

5"$E&'

Tra ding da y

Figure 1A(CD,"$,/0.&'(Y$0.,(Y&/D(")(4,.#$0/=(lA(4"#$.,K(*&%/"M&%0(a>??9bA(

CD,(+&0'=(G/&%+&$+(+,M0&/0"%(")($,/#$%G([0''(1$"[()$"E(X,$"(/"(?AB<97k2(,M,%(0)(="#(D&M,(/"(G/$0H,("#/(/D&/( 0/G( ',M,'( +#$0%1( /D,( <>( /$&+0%1( +&=G( P,)"$,( &%+( &)/,$( /D,( %,[( 0%)"$E&/0"%( +0))#G0"%( [0''( G/0''( P,( &/( X,$"( ',M,'( aG0%.,(+&0'=($,/#$%([0''(."%M,$1,(/"(/D,(&M,$&1,(',M,'(?A?8>kbA(CD,(0EY&./(")(/D,(&P%"$E&'($,/#$%(&%+($0GH("M,$( /D,(&M,$&1,($0GH([0''(P,(+0'#/,+2(&YY$"&.D0%1(X,$"A(

5"( d#EYG( [0''( P,( "PG,$M,+( 0%( $,&'( )0%&%.0&'( E&$H,/GA( CD,( &./#&'( Y$0.,( Y&/D( [0''( ,M"'M,( P,/[,,%( &( )'""$( ',M,'(+,/,$E0%,+(&/(/D,(^%"(0%)"$E&/0"%_(Y&/D(&%+(/D,(^)#''=($,.,0M,+(0%)"$E&/0"%_(.&YA(C0E0%1(&%+(+=%&E0.G( ")(Y$0.,G([0''(P,(E"$,(M"'&/0',(&%+(&%/0.0Y&/,+(&.."$+0%1(/"(/D,(&./#&'(',M,'(")(E&$H,/(,))0.0,%.=(aT,$/0%,//0(,/(&'A2( >??82( 0%( /D,( .&G,( "%( G&',G( ")( %,['=( 0GG#,+( GD&$,GbA( CD,( &./0"%( ")( 0%)"$E&/0"%( /$&+,$G2( ")( G/".H( Y0.H,$G2( &%+( E&$H,/( /0E,$G( ."#'+( )#$/D,$( 0%.$,&G,( /D,( &./#&'( M"'&/0'0/=( P,.&#G,( ")( /D,( "M,$$,&./0"%( /D,=( 1,%,$&/,A( 3%( /D,( Y&$/0.#'&$'=(Y$0.,(Y&/D(GD"[,+(0%(N01#$,(>2(/D,(G/&%+&$+(+,M0&/0"%(")(+&0'=($,/#$%([0''(0%.$,&G,(#Y:/"(6A>8;<k]( G#.D(&()01#$,(."#'+(P,($,+#.,+(%,U/:/":X,$"(0%(.&G,(")([0+,$(/0E,(D"$0X"%(")(."EY#/&/0"%2(&G(,UY'&0%,+(0%(/D,( Y$,M0"#G(,U&EY',A(

-G(GD"[%(0%(C&P',(62(6A>8;<k(G/&%+&$+(+,M0&/0"%(.&%(P,(/D#G(GY'0/(0%/"(/D$,,(P'".HGK(a6b(T&G0G(M"'&/0'0/=2( ?k(0%(/D,(,U&EY',](a>b(?AB<97k(M"'&/0'0/=(+#,(/"(GY,.0)0.(0%)"$E&/0"%(&P"#/(/D,(."$Y"$&/0"%](&%+(a<b(?A7?B9k( M"'&/0'0/=(a6A>8;<k:?AB<97kb(+#,(/"(/D,(E&$H,/( E,.D&%0GE2(/D#G(1,%,$&/,+(P=(&(G=G/,E&/0.(0%)"$E&/0"%($0GHA( 40E0'&$'=2( ,M,%( /D,( &M,$&1,( +&0'=( $,/#$%( 0%.$,&G,( )$"E( ?A?8>k( /"( ?A6<87k( 0%( .&G,( ")( d#EY( 0%( Y$0.,G2( &%+( /"( D01D,$(',M,'(E"$,(0%(.&G,(")(+0)),$,%/(Y&/DGA(CD,(,U0G/,%.,(")(&(G=G/,E&/0.(G"#$.,(")($0GH(',/(#G(."%.'#+,(/D&/( GY,.0&'( $,/#$%( [0''( P,( ,UY,./,+( a*&%/"M&%02( >??9b2( [D0',( /D,( &./#&'( +0E,%G0"%( ")( /D,( $0GH( Y$,E0#E( [0''( P,( +,Y,%+,%/()$"E(/D,(&./#&'(',M,'("$($0GH(&M,$G0"%(aO&$+,%&'2(>??BbA(

B?9(

CeQ(35NcF*-C3c5(F34f(35(CeQ(I-CQ4C(JF3434(

Theoretical vs. actual price path of Security X

e 105.0000 Normal

ic Pr

Event dependent 104.0000

Z0/D(0%)"$E&/0"%($0GH(

With information risk

QM,%/(+,Y,%+,%/

5"$E&'

Trading day

Figure 2A(CD,"$,/0.&'(MGA(&./#&'(Y$0.,(Y&/D(")(4,.#$0/=(lA(4"#$.,K(*&%/"M&%0(a>??9bA(

C&P',(6( Summary of the Example Data

5"(0%)"$E&/0"%(.&G,(akb(

3%)"$E&/0"%(.&G,([0/D()#''=( 3%)"$E&/0"%(.&G,([0/D( ,))0.0,%/(E&$H,/G(akb(

0%)"$E&/0"%($0GH(akb( -M,$&1,(+&0'=($,/#$%(

?A6<\;( -P%"$E&'($,/#$%(

?A?8>>(

?A6<87(

?A?\B8( 5,[:0%)"$E&/0"%:+$0M,%(

?A????(

?A?\><(

?A?\><( 3%)":$0GH:+$0M,%(

?A????(

?A?\><(

?A??76(a)"$(;;(+&=Gb( 4/&%+&$+(+,M0&/0"%(

?A????(

?A????(

6A>8;<( L&0'=($,/#$%(")(>8?(+&=G(

L&0'=($,/#$%(")(;;(+&=G(

?A????(

?AB<97(

?A;89B( L&0'=($,/#$%(")(89?(+&=G(

?A????(

?A<97B(

?A8;?<( L&0'=($,/#$%(")(T( ΔΊ(f(

?A????(

?A>B<\(

?A????( -P%"$E&'(;;:+&=G(M"'&/0'0/=(

?A????(

?A????(

5,[:0%)"$E&/0"%:+$0M,%(

?AB<97( 3%)":$0GH:+$0M,%(

%A$A(

?AB<97(

%A$A(

?A????(

?A7?B9(

-.."$+0%1(/"(/D,(&P"M,(,U&EY',2([,(E&=(."%.'#+,(/D&/(/D,(0%)"$E&/0"%($0GHK( a6b( 3G( %"/( G0EY'=( '0%H,+( /"( /D,( ^R#&%/0/=( ")( 0%)"$E&/0"%_( +0))#G,+( /"( 0%M,G/"$G( a0)( 0%)"$E&/0"%( .&%%"/( P,(

,'&P"$&/,+(/D,(&.H%"[',+1,(+",G(%"/(0%.$,&G,b(P#/(&'G"(P=(/D,0$(^R#&'0/=_]( a>b( *#G/( P,( GY'0/( 0%/"( /["( Y&$/GK( CD,( G=G/,E&/0.( "%,2( +#,( /"( /D,( E,.D&%0GE( /D&/( 0%( &( ."%.$,/,( [&=( /D,( E&$H,/(#G,(/"(Y$".,GG(0%)"$E&/0"%(aP"/D(R#&%/0/=(&%+(R#&'0/=b](&%+(/D,()0$E:GY,.0)0.("%,2(G/$0./'=(."%%,./,+(/"( /D,(+0G.'"G#$,(G/$&/,10,G(&+"Y/,+(P=(."$Y"$&/0"%GA(