Operational risk · change management · BCP/DR · evidence

🧯 Rủi ro vận hành & tuân thủ CNTT

Notes on the part of the job that only surfaces on the worst day: what happens when a broker's systems go down, get changed, or get audited. Why the trading session does not set your RTO but does set the price of every minute and a deadline that never moves, why HA is not DR and the difference only shows on the day it must not, why one RPO figure for a whole system is a number for the form rather than for the architecture, what a FIX sequence number does after a failover, and why a control you cannot produce evidence for is a control that does not exist.

Sources: hands-on brokerage operations and DR-drill notes · ISO 22301 (business continuity) and ISO 27031 structure · Basel operational-risk event taxonomy · ITIL change-management vocabulary · public exchange and depository rulebooks. Illustrative figures are marked as such; items marked ⚠️ must be checked against the rulebook in force and confirmed with the business side.