The Risk Assessment Executives Are Begging For. Presentation Overview. Terminology

Similar documents
Security Risk Management

USF System Compliance & Ethics Program. Risk Assessment Process. Enterprise-Wide Risk Assessment

Enhanced Cyber Risk Management Standards. Advance Notice of Proposed Rulemaking

Fraud Risk Management

ENTERPRISE RISK MANAGEMENT (ERM) GOVERNANCE POLICY PEDERNALES ELECTRIC COOPERATIVE, INC.

ISO/DIS 9001:2015 Risk-Based Thinking

Understanding Enterprise Risk Management: An Overview

Break the Risk Paradigms - Overhauling Your Risk Program

Best Practices in ENTERPRISE RISK MANAGEMENT. [ Managing Risks Holistically ]

CNAM Risk Management for Utility Managers

Risk Management FUN! Humor Me

UPDATING MITIGATION PLANS

1. Define risk. Which are the various types of risk?

Use of FEMA Non regulatory Flood Risk Products in Planning

Relevance of Operational Risk to the FCA Jill Savager Manager, Operational Risk, Financial Conduct Authority

Delivering Clarity to Credit Unions Through Expertise and Experience

Business Auditing - Enterprise Risk Management. October, 2018

ENTERPRISE RISK MANAGEMENT (ERM) POLICY Republic Glass Holdings Corporation. Purpose. Goals

Introduction to Risk for Project Controls

Subject ST9 Enterprise Risk Management Syllabus

Procedures for Management of Risk

Subject SP9 Enterprise Risk Management Specialist Principles Syllabus

Integrating Trade Finance and Accounts Payable Automation: The Basics

Interpretation Note on Environmental and Social Categorization

Managing Olympic Risks. Dr Will Jennings University of Southampton

ENTERPRISE RISK MANAGEMENT POLICY FRAMEWORK

Product Recall Risk Assessment By Tony Munns. Product recall is a key area of risk for today s company. With greater focus

Data Governance Risk Calculation Forum. Challenges in Information Security Risk Analysis

Now THAT YOUR ORGANIZATION'S INITIAL WORK

FAIS Risk Management Plan

7/25/2013. Presented by: Erike Young, MPPA, CSP, ARM. Chapter 2. Root Cause Analysis

ก ก Tools and Techniques for Enterprise Risk Management (ERM)

Guidance for Analysis Required by COMAR Hazardous Material Security

Academy Presentation to NAIC ORSA Implementation (E) Subgroup

There are many definitions of risk and risk management.

Quality Control & Compliance Initiative. This document is publicly available to any staff member on the following network path:

The Mississippi State Department of Health EOPs and HVAs Presented By: Lillie Bailey

Enterprise Risk Management (ERM) & Compliance

MONROE COUNTY 2015 LMS STEP TWO: CHARACTERIZATION FORM

How to Compile and Maintain a Risk Register

Identification & Assessment of Risks Authors: Ali Basharat & Zeenoor Sohail Sheikh

MILA SULLIVAN PROCUREMENT CONSULTANT

What Is Enterprise Risk Management?

4.1 Risk Assessment and Treatment Assessing Security Risks

Applying COSO s Enterprise Risk Management Integrated Framework

Emergency Preparedness. Emergency Preparedness & the Senior Housing Provider. The Speakers LEGAL REQUIREMENTS

Enterprise Risk Management From Book to Board Room

Economic Capital 4.14 Solvency II and Basel II and III Regulatory Standards 4.19 NAIC Own Risk and Solvency Assessment (ORSA) 4.23 Summary 4.

Trial by fire* Protected. But under pressure to perform

Enterprise Risk Management Balancing Risks & Identifying Opportunities WEBINAR

Making the Jump to Risk Management. Jeff Blackmon, FBCI, CISSP, CBCP, ITIL Strategic Continuity Solutions, LLC.

Reliability Risk Analysis

SCCE 2012 COMPLIANCE & ETHICS INSTITUTE. Workshop Agenda

Business Continuity, Risk Management & Pandemic Planning

Credit Score Basics, Part 3: Achieving the Same Risk Interpretation from Different Models with Different Ranges

Client Risk Solutions Going beyond insurance. Risk solutions for Financial Institutions. Start

Prerequisites for EOP Creation: Hazard Identification and Assessment

Client Risk Solutions Going beyond insurance. Risk solutions for Real Estate. Start

Practical aspects of determining and applying a risk appetite for SMEs

Qualitative versus Quantitative Analysis. two types of assessments Qualitative and Quantitative.

Multi-Hazard Risk Management Project The Smithsonian Institution (SI)

Information Management Business Area. National Policing Information Risk Escalation Policy V1.0

Risk Management in Uncertain Times

Community Trust Company Basel III Pillar 3 Disclosures June 30, 2018

TONGA NATIONAL QUALIFICATIONS AND ACCREDITATION BOARD

Procedure: Risk management

Risk Management Policy and Processes

A Causal Chain Risk Framework for Risk Management. Professor Johan Rene van Dorp, D.Sc.

Enterprise Risk Management Sources. Universe. Tolerance. Appetite

Applying Risk-based Decision-making Methods/Tools to U.S. Navy Antiterrorism Capabilities

Catastrophe Risks and their Financing in India including Regulatory Landscape

Zurich Hazard Analysis (ZHA) Introducing ZHA

The Proactive Quality Guide to. Embracing Risk

Community Trust Company Basel III Pillar 3 Disclosures December 31, 2017

CITY OF JOHANNESBURG METROPOLITAN MUNICIPALITY GROUP RISK AND ASSURANCE SERVICES GROUP RISK MANAGEMENT POLICY

Senior Director, Fire Life Safety & Risk Management

Section Defining Risk Management. 11. Principles of Risk Management

ENTERPRISE RISK MANAGEMENT (ERM) The Conceptual Framework

Enterprise Risk Management (ERM)

A Multihazard Approach to Building Safety: Using FEMA Publication 452 as a Mitigation Tool

An Introduction to Risk

Knight Capital Europe Limited. Capital Requirements Directive Pillar 3 Disclosure Statement 31 December 2012

Risk Management: Assessing and Controlling Risk

Making the Business Case for Risk- Based Asset Management

360 Degrees of Enterprise Risk Management

Community Trust Company Basel III Pillar 3 Disclosures March 31, 2017

1 Rare Hazard event is not likely to occur within 100 years. 2 Occasional Hazard event is likely to occur within 100 years

Office of the Superintendent of Financial Institutions (OSFI) - Enterprise-wide Risk Management (ERM)

Workshop Standard on Asset Bank & Liability African Central Management Bank Conference. Developing a Strategic Asset

Post-Class Quiz: Information Security and Risk Management Domain

1st Capacity Building Seminar on Enterprise Risk Management

WELCOME!! Please sign in on one of the attendance rosters

THERE S NO SUCH THING AS A CYBER- RISK

Presented by Kristina Narvaez President & CEO ERM Strategies, LLC

Allen D. Becker MMA, , ITILv3. Risk Management. Allen D. Becker - MMA, PMP, ITILv3 Sr. Security Consultant Business Development Specialist

HUBTOWN LIMITED REVISED RISK MANAGEMENT POLICY. (Effective from December 1, 2015)

Guidance Note: Stress Testing Credit Unions with Assets Greater than $500 million. May Ce document est également disponible en français.

SECTION 1 INTRODUCTION

An Introduction to Enterprise Risk Management. Mark Brown, SVP, Chief Financial Officer First Carolina Corporate Credit Union

Regional Healthcare Hazard Vulnerability Assessment

Transcription:

The Risk Assessment Executives Are Begging For Brian Zawada Rob Giffin Avalution Consulting LLC Presentation Overview Level-setting Regarding Terminology Likelihood Versus Severity Common Approaches to Performing Risk Assessments Where s the Value? Bridging the Expectations Gap Focusing on Likelihood Walking Through a Value-based Approach Terminology Business Continuity Planning / Management Business Impact Analysis Risk Assessment Risk versus Threat Severity versus Likelihood 1

Managing Likelihood Versus Severity Limited Time and Investment Risk Management Processes A Focus on Affecting Likelihood and Severity Business Continuity A Focus on Affecting Severity Common Approaches to Assessing Risk From a Business Continuity Perspective Identify Categories of Risk Identify Specific Threats in Each Category Qualify Vulnerability to Each Threat Inherent Risk or Controls-based Estimate Rank Order Threats for Consideration by Management Business Continuity Develops Plans based on Highly Ranked Threats Assumption: Business Begins Managing or Accepting Risk Where s The Value? Does rank-ordering risk add any value? Is risk mitigation (other than Sarbanes-Oxley) rank highly in management s Top 10 list of things to do? Who is best positioned to focus on managing risk? 2

Bridging the Expectations Gap Does identifying risk add value? Does assisting with the development of risk mitigation strategies add value? Bridging the Expectations Gap (cont.) DRI Definition Subject Area #2 Risk Evaluation and Control Determine the events and external surroundings that can adversely affect the organization and its facilities with disruption as well as disaster, the damage such events can cause, and the controls needed to prevent or minimize the effects of potential loss. Provide cost-benefit analysis to justify investment in controls to mitigate risks. 3

NFPA 1600 Section 5.3.1 The entity shall identify hazards, the likelihood of their occurrence, and the vulnerability of the entity to those hazards. Section 5.4.1 The entity shall develop and implement a strategy to eliminate hazards or mitigate the effects of hazards that cannot be eliminated. BASEL II Identify Assess Monitor Control Mitigate Switching Focus - Likelihood Can likelihood be managed 100% of the time for 100% of threats? 4

The Bigger Picture Event Risk Management Business Continuity Professionals are responsible for Event Risk Management (whether you have been told that or not!) Part of a larger ERM program Enables achievement of business objectives Event Risk Assessment Availability Risk Reputational Risk Facilities And Infrastructure Equipment People Information Technology Supply Chain Intellectual Property Strategic Discussion and Scoping Single Points of Failure Health and Performance Labor Relations Capacity Compliance Threats Replacement Change Management Configuration Management Access Security Public Relations Operational Discussion and Scoping Business Process and Technology Controls Affecting Impact and Likelihood Outcomes Assumptions Recommendations Worst-Case / Best-Case / Most Likely Case Planning Scenarios Residual Risks Accepted Risks Tactical Controls Assessment Prioritization Types of Risk Availability Risk Reputational Risk 5

Strategic Discussion and Scoping Defining Strategic Business Objectives Can executive management clearly articulate it s objectives for: 1 Year 5 Years Identifying Threats that Affect those objectives: Facilities and Infrastructure Equipment People Information Technology The Supply Chain Intellectual Property (to include Records and Data) Operational Discussion and Scoping The threats that result in damage, downtime or reputational impact Tactical Controls Assessment Business Controls Technology Controls 6

Prioritization Assumptions Risk Reduction Recommendations Developing Worst-case / Best-case Scenarios Identifying Residual Risks Accepting Residual Risks Case Study Value-based Risk Assessment Questions and Discussion 7

Presenter Contact Information Brian Zawada Director of Consulting Services brian.zawada@avalutionconsulting.com 800.941.0381 (o) 330.321.8650 (m) Rob Giffin Managing Consultant robert.giffin@avalutionconsulting.com 800.941.0381 (o) 216.832.0515 (m) Presentation Abstract More and more business continuity professionals are demoting the risk assessment to a "Tier 2" activity, whereas a growing body of executive managers views the risk assessment as a strategic enabler. Why the disparity? Business continuity professionals often focus on rank-ordering risks and threats, and spend very little time recommending solutions to affect likelihood or manage impact. Rank-ordering alone adds little value to the executive manager. Business leaders who implement enterprise-wide risk management processes rank-order risks, but more importantly, focus on mitigating likelihood and severity to an acceptable level. As a result, executive managers, business continuity planners and other risk management personnel must work together toward the common goal of identifying failure scenarios and exploring cost-effective ways to mitigate risk. This presentation will explore the value of a business continuity-oriented risk assessment and the relationship to enterprise-wide risk management and business impact analysis processes. It will also delve into the ways in which this process can add significant business value. We will discuss the information necessary to enable business decision-making as well as ways to prioritize risk mitigation activities. Ultimately, this presentation will focus on prioritizing risk mitigation, an activity which will elevate the importance and value of the business continuity-oriented risk assessment. 8