SlideShare a Scribd company logo
1 of 17
Download to read offline
Risk Management Basics -
ISO 31000 Standard
Louis Kunimatsu, CRISC
IT Security & Strategy,
Ford Motor Company
Risk Management Basics -
ISO 31000 Standard
1. Risk Management
Basics
2. ISO 31000 – Risk
2. ISO 31000 – Risk
Management
Principles and
Guidelines
Risk Management Basics
Organizational objectives are influenced by internal
and external factors which create uncertainty in
achieving those objectives. The effect of this
uncertainty is “risk” to the organization’s objectives.
Unlike Risk Elimination (approach of military and law
enforcement) which seeks to remove all risk; Risk
Management is the coordinated activities to direct
Management is the coordinated activities to direct
and control an organization with regard to risk.
Risk Management allows for multiple risk responses
dependent upon evaluation and analysis of risk.
RISK = Negative IMPACT to objectives X LIKELIHOOD of
occurrence.
Risk Management Basics
Risk Responses:
1. MITIGATE - corrective action to
eliminate or reduce IMPACT or
LIKELIHOOD
2. AVOID - Cease activity to
eliminate risk
3. TRANSFER - Shift IMPACT to
another entity
4. ACCEPT - No corrective action.
Document acceptance decision
and monitor
ISO 31000: Risk management —
Principles and guidelines
• Published in 2009, to provide “principles & generic
guidelines on risk management”
• “…can be applied to any type of risk, whatever its
nature, whether having positive or negative
consequences”
• “…not intended to promote uniformity of risk
• “…not intended to promote uniformity of risk
management across organizations. The design and
implementation of risk management plans and
frameworks will need to take into account the
varying needs of a specific organization, its
particular objectives, context, structure, operations,
processes,..”
• “…not intended for the purpose of certification”
ISO 31000: Principles, Framework & Process
PRINCIPLES
a) Creates value
b) Integral part of organizational
processes
c) Part of decision making
d) Explicitly addresses uncertainty
e) Systematic, structured & timely
f) Based on the best available
Mandate &
commitment
Design of
framework for
managing risk
FRAMEWORK
f) Based on the best available
information
g) Tailored
h) Takes human & cultural factors
into account
i) Transparent & inclusive
j) Dynamic, iterative and responsive
to change
k) Facilitates continuous
improvement & enhancement of
the organization
Implementing
risk
management
Monitoring &
review of the
framework
Continual
improvement
of the
framework
RISK ASSESSMENT
ISO 31000: Principles, Framework & Process
Establishing the context
Risk identification
PROCESS
Implementing
risk
FRAMEWORK
Monitoring
&
review
Communication
&
consultation
risk
management
Risk analysis
Risk evaluation
Risk treatment
Monitoring
&
review
Communication
&
consultation
Risk Management: Establish the context
External context
• Legal, Regulatory, Financial
• International, national, regional or local
• Relationships with, perceptions and values of external stakeholders
Internal context
• Organizational objectives
• Project, process, or activity objectives
• Project, process, or activity objectives
• Policy, standards, guidelines and models
adopted by the organization
• Contractual relationships
Risk Management process context
• Objectives, scope, responsibilities, methods
• Defining risk criteria – measures, tolerance
levels, views of stakeholders
ISO 31000: Risk Identification
• Process of finding, recognizing and describing
risks
• Comprehensive list of risks based on those
events that might create, enhance, prevent,
degrade, accelerate or delay the
achievement of objectives.
• Identify the risks associated with not pursuing an
opportunity
opportunity
• A risk that is not identified at this
stage will not be included in
further analysis
• Identification should include risks
whether or not their source is
under the control of the
organization
ISO 31000: Risk Analysis
• Process to comprehend the nature of
risk and to determine the level of risk
• “Risk analysis involves consideration of
the causes and sources of risk, their
positive and negative consequences,
and the likelihood that those
and the likelihood that those
consequences can occur.”
• Provides the basis for risk evaluation
and decisions about risk treatment
• Risk analysis includes risk estimation
Risk Analysis
Risk Classifications:
• essential risks,
• risks to be monitored
• risks to be observed
Impact scale:
Likelihood scale:
• more than 10 years
• 5 to 10 years (> 0.1 )
• 3 to 5 years (> 0.2 )
Impact scale:
• very low (< $1k)
• low (< $5k)
• medium (< $25k)
• high (< $100k)
• very high (> $100K)
• 3 to 5 years (> 0.2 )
• 2 to 3 years (> 0,33 )
• less than 2 years (> 0.5 )
OWASP Risk Ranking Methodology
ISO 31000: Risk Evaluation
• The purpose of risk evaluation is to assist in making
decisions, based on the outcomes of risk analysis,
about which risks need treatment and the priority for
treatment implementation
• Decisions should take account of the wider context of
the risk and include consideration of the tolerance of
the risks borne by parties other than the organization
that benefits from the risk
that benefits from the risk
• Decisions should be made in accordance with legal,
regulatory and other requirements
• In some circumstances, the risk evaluation can lead
to a decision to undertake further analysis
• The risk evaluation can also lead to a decision not to
treat the risk in any way other than maintaining
existing controls
ISO 31000: Risk Evaluation
• Decisions should take account of the wider
context of the risk and include
consideration of the tolerance of the risks
borne by parties other than the
organization that benefits from the risk
• Decisions should be made in accordance
• The purpose of risk evaluation is to assist in making decisions,
based on the outcomes of risk analysis, about which risks need
treatment and the priority for treatment implementation
• Decisions should be made in accordance
with legal, regulatory and other
requirements
• In some circumstances, the risk evaluation
can lead to a decision to undertake further
analysis
• The risk evaluation can also lead to a
decision not to treat the risk in any way
other than maintaining existing controls
ISO 31000: Risk Treatment
Risk treatment involves selecting one or more options for modifying
risks, and implementing those options.
Risk treatment options are not necessarily mutually exclusive. The
options can include the following:
TRANSFER
• Sharing the risk with another party or parties (including contracts and
risk financing)
AVOID
AVOID
• Avoiding the risk by deciding not to start or continue with the activity
that gives rise to the risk
• Removing the risk source
MITIGATE
• Changing the likelihood
• Changing the consequences (impact)
ACCEPT
• Retaining the risk by informed decision
• Taking or increasing the risk in order to pursue an opportunity
ISO 31000: Risk Treatment
• Selecting the most appropriate risk treatment
option involves balancing the costs and efforts of
implementation against the benefits derived, with
regard to legal, regulatory, and other requirements
such as social responsibility and the protection of
the natural environment.
• A number of treatment options can be considered
• A number of treatment options can be considered
and applied either individually or in combination.
• Risk treatment itself can introduce risks. A significant
risk can be the failure or ineffectiveness of the risk
treatment measures. Monitoring needs to be an
integral part of the risk treatment plan to give
assurance that the measures remain effective.
ISO 31000: Monitoring & Review
• An integral part of the risk management
process involving regular checking or
surveillance
• Ensure controls are effective & efficient
• Detect change in external or internal context
• Analysis, lessons learned, continuous
• Analysis, lessons learned, continuous
improvement
• Identify emerging risks
Risk Management Basics
- ISO 31000 Standard
Louis Kunimatsu, CRISC
IT Security & Strategy,
Ford Motor Company
THANKS for attending!
ENJOY the conference!

More Related Content

What's hot

Anti-Bribery Management Systems: The Impact of Organizational Culture and its...
Anti-Bribery Management Systems: The Impact of Organizational Culture and its...Anti-Bribery Management Systems: The Impact of Organizational Culture and its...
Anti-Bribery Management Systems: The Impact of Organizational Culture and its...PECB
 
Session 02 Risk Assessment Program for YSP_The Risk Assessment Process
Session 02 Risk Assessment Program for YSP_The Risk Assessment ProcessSession 02 Risk Assessment Program for YSP_The Risk Assessment Process
Session 02 Risk Assessment Program for YSP_The Risk Assessment ProcessMuizz Anibire
 
Sécurité de l’information et gouvernance
Sécurité de l’information et gouvernanceSécurité de l’information et gouvernance
Sécurité de l’information et gouvernancePECB
 
Integrating Risk Appetite With Strategy Feb 14 2011
Integrating Risk Appetite With Strategy   Feb 14 2011Integrating Risk Appetite With Strategy   Feb 14 2011
Integrating Risk Appetite With Strategy Feb 14 2011Andrew Smart
 
ISO 55000: Asset Management System Workshop
ISO 55000: Asset Management System WorkshopISO 55000: Asset Management System Workshop
ISO 55000: Asset Management System WorkshopLife Cycle Engineering
 
Are You Ready? Implementing COSO's Updated Internal Controls Framework
Are You Ready? Implementing COSO's Updated Internal Controls FrameworkAre You Ready? Implementing COSO's Updated Internal Controls Framework
Are You Ready? Implementing COSO's Updated Internal Controls FrameworkBlackLine
 
What is GRC – Governance, Risk and Compliance
What is GRC – Governance, Risk and Compliance What is GRC – Governance, Risk and Compliance
What is GRC – Governance, Risk and Compliance BOC Group
 
Pr 1709 - lifting and hoisting procedure lift planning execution
Pr 1709 - lifting and hoisting procedure lift planning executionPr 1709 - lifting and hoisting procedure lift planning execution
Pr 1709 - lifting and hoisting procedure lift planning executionSergio Augusto Esteves
 
MATINÉE PMI : La gestion des risques de sécurité de l'information dans les pr...
MATINÉE PMI : La gestion des risques de sécurité de l'information dans les pr...MATINÉE PMI : La gestion des risques de sécurité de l'information dans les pr...
MATINÉE PMI : La gestion des risques de sécurité de l'information dans les pr...PMI-Montréal
 
Information Security Management System with ISO/IEC 27000:2018
Information Security Management System with ISO/IEC 27000:2018Information Security Management System with ISO/IEC 27000:2018
Information Security Management System with ISO/IEC 27000:2018Goutama Bachtiar
 
Conférence IFACI DFCG Deloitte - état de l'Art de la gestion des risques
Conférence IFACI DFCG Deloitte - état de l'Art de la gestion des risquesConférence IFACI DFCG Deloitte - état de l'Art de la gestion des risques
Conférence IFACI DFCG Deloitte - état de l'Art de la gestion des risquesEric CASPERS
 
Introduction to Risk Management ISO31000:2009
Introduction to Risk Management ISO31000:2009Introduction to Risk Management ISO31000:2009
Introduction to Risk Management ISO31000:2009Ahmad Azwang Aisram Omar
 
Leveraging ISO 31000 for Effective Integration of Risk Management and Interna...
Leveraging ISO 31000 for Effective Integration of Risk Management and Interna...Leveraging ISO 31000 for Effective Integration of Risk Management and Interna...
Leveraging ISO 31000 for Effective Integration of Risk Management and Interna...International Federation of Accountants
 
ادارة الخطر والتامين
ادارة الخطر والتامينادارة الخطر والتامين
ادارة الخطر والتامينGhamdan Hamam
 
10 Mistakes in Implementing the ISO 37301
10 Mistakes in Implementing the ISO 3730110 Mistakes in Implementing the ISO 37301
10 Mistakes in Implementing the ISO 37301Hernan Huwyler, MBA CPA
 
PECB Webinar: Aligning ISO 31000 and Management of Risk Methodology
PECB Webinar: Aligning ISO 31000 and Management of Risk MethodologyPECB Webinar: Aligning ISO 31000 and Management of Risk Methodology
PECB Webinar: Aligning ISO 31000 and Management of Risk MethodologyPECB
 

What's hot (20)

Anti-Bribery Management Systems: The Impact of Organizational Culture and its...
Anti-Bribery Management Systems: The Impact of Organizational Culture and its...Anti-Bribery Management Systems: The Impact of Organizational Culture and its...
Anti-Bribery Management Systems: The Impact of Organizational Culture and its...
 
Session 02 Risk Assessment Program for YSP_The Risk Assessment Process
Session 02 Risk Assessment Program for YSP_The Risk Assessment ProcessSession 02 Risk Assessment Program for YSP_The Risk Assessment Process
Session 02 Risk Assessment Program for YSP_The Risk Assessment Process
 
Sécurité de l’information et gouvernance
Sécurité de l’information et gouvernanceSécurité de l’information et gouvernance
Sécurité de l’information et gouvernance
 
Integrating Risk Appetite With Strategy Feb 14 2011
Integrating Risk Appetite With Strategy   Feb 14 2011Integrating Risk Appetite With Strategy   Feb 14 2011
Integrating Risk Appetite With Strategy Feb 14 2011
 
ISO 55000: Asset Management System Workshop
ISO 55000: Asset Management System WorkshopISO 55000: Asset Management System Workshop
ISO 55000: Asset Management System Workshop
 
Are You Ready? Implementing COSO's Updated Internal Controls Framework
Are You Ready? Implementing COSO's Updated Internal Controls FrameworkAre You Ready? Implementing COSO's Updated Internal Controls Framework
Are You Ready? Implementing COSO's Updated Internal Controls Framework
 
What is GRC – Governance, Risk and Compliance
What is GRC – Governance, Risk and Compliance What is GRC – Governance, Risk and Compliance
What is GRC – Governance, Risk and Compliance
 
Risk Management
Risk ManagementRisk Management
Risk Management
 
Pr 1709 - lifting and hoisting procedure lift planning execution
Pr 1709 - lifting and hoisting procedure lift planning executionPr 1709 - lifting and hoisting procedure lift planning execution
Pr 1709 - lifting and hoisting procedure lift planning execution
 
MATINÉE PMI : La gestion des risques de sécurité de l'information dans les pr...
MATINÉE PMI : La gestion des risques de sécurité de l'information dans les pr...MATINÉE PMI : La gestion des risques de sécurité de l'information dans les pr...
MATINÉE PMI : La gestion des risques de sécurité de l'information dans les pr...
 
Information Security Management System with ISO/IEC 27000:2018
Information Security Management System with ISO/IEC 27000:2018Information Security Management System with ISO/IEC 27000:2018
Information Security Management System with ISO/IEC 27000:2018
 
Introduction to Risk Management
Introduction to Risk ManagementIntroduction to Risk Management
Introduction to Risk Management
 
Conférence IFACI DFCG Deloitte - état de l'Art de la gestion des risques
Conférence IFACI DFCG Deloitte - état de l'Art de la gestion des risquesConférence IFACI DFCG Deloitte - état de l'Art de la gestion des risques
Conférence IFACI DFCG Deloitte - état de l'Art de la gestion des risques
 
Introduction to Risk Management ISO31000:2009
Introduction to Risk Management ISO31000:2009Introduction to Risk Management ISO31000:2009
Introduction to Risk Management ISO31000:2009
 
ISO 37001 Anti-Bribery Management System
ISO 37001 Anti-Bribery Management SystemISO 37001 Anti-Bribery Management System
ISO 37001 Anti-Bribery Management System
 
Leveraging ISO 31000 for Effective Integration of Risk Management and Interna...
Leveraging ISO 31000 for Effective Integration of Risk Management and Interna...Leveraging ISO 31000 for Effective Integration of Risk Management and Interna...
Leveraging ISO 31000 for Effective Integration of Risk Management and Interna...
 
ادارة الخطر والتامين
ادارة الخطر والتامينادارة الخطر والتامين
ادارة الخطر والتامين
 
10 Mistakes in Implementing the ISO 37301
10 Mistakes in Implementing the ISO 3730110 Mistakes in Implementing the ISO 37301
10 Mistakes in Implementing the ISO 37301
 
PECB Webinar: Aligning ISO 31000 and Management of Risk Methodology
PECB Webinar: Aligning ISO 31000 and Management of Risk MethodologyPECB Webinar: Aligning ISO 31000 and Management of Risk Methodology
PECB Webinar: Aligning ISO 31000 and Management of Risk Methodology
 
Risk Appetite
Risk AppetiteRisk Appetite
Risk Appetite
 

Similar to Iso 31000.pdf

PECB Webinar: ISO 31000 - The Benchmark for Risk Management in uncertain times
PECB Webinar: ISO 31000 - The Benchmark for Risk Management in uncertain timesPECB Webinar: ISO 31000 - The Benchmark for Risk Management in uncertain times
PECB Webinar: ISO 31000 - The Benchmark for Risk Management in uncertain timesPECB
 
Risk management ppt mimi
Risk management ppt mimiRisk management ppt mimi
Risk management ppt mimimbondgulo
 
Bcu msc cg week 4 risk management
Bcu msc cg week 4 risk managementBcu msc cg week 4 risk management
Bcu msc cg week 4 risk managementStephen Ong
 
Implementation of Enterprise Risk Management with ISO 31000 Risk Management S...
Implementation of Enterprise Risk Management with ISO 31000 Risk Management S...Implementation of Enterprise Risk Management with ISO 31000 Risk Management S...
Implementation of Enterprise Risk Management with ISO 31000 Risk Management S...PECB
 
risk.ppt shrey vashistha.ppt
risk.ppt shrey vashistha.pptrisk.ppt shrey vashistha.ppt
risk.ppt shrey vashistha.pptUmangVashistha2
 
AbstractKey FeaturesAssessmentIntroductionMeasur.docx
AbstractKey FeaturesAssessmentIntroductionMeasur.docxAbstractKey FeaturesAssessmentIntroductionMeasur.docx
AbstractKey FeaturesAssessmentIntroductionMeasur.docxransayo
 
Session 6 Power Point
Session 6   Power PointSession 6   Power Point
Session 6 Power Pointhiratufail
 
Presentation on Risk management & controlling (Corporate Finance & Internatio...
Presentation on Risk management & controlling (Corporate Finance & Internatio...Presentation on Risk management & controlling (Corporate Finance & Internatio...
Presentation on Risk management & controlling (Corporate Finance & Internatio...Suyash Rewale
 
Information Security Risk Management
Information Security Risk ManagementInformation Security Risk Management
Information Security Risk ManagementNikhil Soni
 
Lecture 02. OSH Risk Assessment
Lecture 02. OSH Risk Assessment Lecture 02. OSH Risk Assessment
Lecture 02. OSH Risk Assessment KateKazhan
 
The IRM India- A Risk Management Standard
The IRM India- A Risk Management StandardThe IRM India- A Risk Management Standard
The IRM India- A Risk Management StandardThe IRM India
 
Practical approach to security risk management
Practical approach to security risk managementPractical approach to security risk management
Practical approach to security risk managementG3 intelligence Ltd
 
Risk Management Fundamentals
Risk Management FundamentalsRisk Management Fundamentals
Risk Management Fundamentalsmikaelastafrace
 
Pm0016 set-1
Pm0016 set-1Pm0016 set-1
Pm0016 set-1Paul Hunt
 

Similar to Iso 31000.pdf (20)

PECB Webinar: ISO 31000 - The Benchmark for Risk Management in uncertain times
PECB Webinar: ISO 31000 - The Benchmark for Risk Management in uncertain timesPECB Webinar: ISO 31000 - The Benchmark for Risk Management in uncertain times
PECB Webinar: ISO 31000 - The Benchmark for Risk Management in uncertain times
 
Risk management ppt mimi
Risk management ppt mimiRisk management ppt mimi
Risk management ppt mimi
 
Iso 31000
Iso 31000Iso 31000
Iso 31000
 
Bcu msc cg week 4 risk management
Bcu msc cg week 4 risk managementBcu msc cg week 4 risk management
Bcu msc cg week 4 risk management
 
G31000 Risk Management Maturity Model
G31000 Risk Management Maturity ModelG31000 Risk Management Maturity Model
G31000 Risk Management Maturity Model
 
Implementation of Enterprise Risk Management with ISO 31000 Risk Management S...
Implementation of Enterprise Risk Management with ISO 31000 Risk Management S...Implementation of Enterprise Risk Management with ISO 31000 Risk Management S...
Implementation of Enterprise Risk Management with ISO 31000 Risk Management S...
 
Iso 31000 presentation
Iso 31000 presentationIso 31000 presentation
Iso 31000 presentation
 
Risk management
Risk managementRisk management
Risk management
 
risk.ppt shrey vashistha.ppt
risk.ppt shrey vashistha.pptrisk.ppt shrey vashistha.ppt
risk.ppt shrey vashistha.ppt
 
AbstractKey FeaturesAssessmentIntroductionMeasur.docx
AbstractKey FeaturesAssessmentIntroductionMeasur.docxAbstractKey FeaturesAssessmentIntroductionMeasur.docx
AbstractKey FeaturesAssessmentIntroductionMeasur.docx
 
Beyond Compliance
Beyond ComplianceBeyond Compliance
Beyond Compliance
 
Session 6 Power Point
Session 6   Power PointSession 6   Power Point
Session 6 Power Point
 
Presentation on Risk management & controlling (Corporate Finance & Internatio...
Presentation on Risk management & controlling (Corporate Finance & Internatio...Presentation on Risk management & controlling (Corporate Finance & Internatio...
Presentation on Risk management & controlling (Corporate Finance & Internatio...
 
Information Security Risk Management
Information Security Risk ManagementInformation Security Risk Management
Information Security Risk Management
 
Lecture 02. OSH Risk Assessment
Lecture 02. OSH Risk Assessment Lecture 02. OSH Risk Assessment
Lecture 02. OSH Risk Assessment
 
The IRM India- A Risk Management Standard
The IRM India- A Risk Management StandardThe IRM India- A Risk Management Standard
The IRM India- A Risk Management Standard
 
Risk Assessment
Risk AssessmentRisk Assessment
Risk Assessment
 
Practical approach to security risk management
Practical approach to security risk managementPractical approach to security risk management
Practical approach to security risk management
 
Risk Management Fundamentals
Risk Management FundamentalsRisk Management Fundamentals
Risk Management Fundamentals
 
Pm0016 set-1
Pm0016 set-1Pm0016 set-1
Pm0016 set-1
 

Recently uploaded

Solving Puzzles Benefits Everyone (English).pptx
Solving Puzzles Benefits Everyone (English).pptxSolving Puzzles Benefits Everyone (English).pptx
Solving Puzzles Benefits Everyone (English).pptxOH TEIK BIN
 
Employee wellbeing at the workplace.pptx
Employee wellbeing at the workplace.pptxEmployee wellbeing at the workplace.pptx
Employee wellbeing at the workplace.pptxNirmalaLoungPoorunde1
 
How to Make a Pirate ship Primary Education.pptx
How to Make a Pirate ship Primary Education.pptxHow to Make a Pirate ship Primary Education.pptx
How to Make a Pirate ship Primary Education.pptxmanuelaromero2013
 
Software Engineering Methodologies (overview)
Software Engineering Methodologies (overview)Software Engineering Methodologies (overview)
Software Engineering Methodologies (overview)eniolaolutunde
 
Class 11 Legal Studies Ch-1 Concept of State .pdf
Class 11 Legal Studies Ch-1 Concept of State .pdfClass 11 Legal Studies Ch-1 Concept of State .pdf
Class 11 Legal Studies Ch-1 Concept of State .pdfakmcokerachita
 
Separation of Lanthanides/ Lanthanides and Actinides
Separation of Lanthanides/ Lanthanides and ActinidesSeparation of Lanthanides/ Lanthanides and Actinides
Separation of Lanthanides/ Lanthanides and ActinidesFatimaKhan178732
 
Contemporary philippine arts from the regions_PPT_Module_12 [Autosaved] (1).pptx
Contemporary philippine arts from the regions_PPT_Module_12 [Autosaved] (1).pptxContemporary philippine arts from the regions_PPT_Module_12 [Autosaved] (1).pptx
Contemporary philippine arts from the regions_PPT_Module_12 [Autosaved] (1).pptxRoyAbrique
 
SOCIAL AND HISTORICAL CONTEXT - LFTVD.pptx
SOCIAL AND HISTORICAL CONTEXT - LFTVD.pptxSOCIAL AND HISTORICAL CONTEXT - LFTVD.pptx
SOCIAL AND HISTORICAL CONTEXT - LFTVD.pptxiammrhaywood
 
Presentation by Andreas Schleicher Tackling the School Absenteeism Crisis 30 ...
Presentation by Andreas Schleicher Tackling the School Absenteeism Crisis 30 ...Presentation by Andreas Schleicher Tackling the School Absenteeism Crisis 30 ...
Presentation by Andreas Schleicher Tackling the School Absenteeism Crisis 30 ...EduSkills OECD
 
Kisan Call Centre - To harness potential of ICT in Agriculture by answer farm...
Kisan Call Centre - To harness potential of ICT in Agriculture by answer farm...Kisan Call Centre - To harness potential of ICT in Agriculture by answer farm...
Kisan Call Centre - To harness potential of ICT in Agriculture by answer farm...Krashi Coaching
 
Organic Name Reactions for the students and aspirants of Chemistry12th.pptx
Organic Name Reactions  for the students and aspirants of Chemistry12th.pptxOrganic Name Reactions  for the students and aspirants of Chemistry12th.pptx
Organic Name Reactions for the students and aspirants of Chemistry12th.pptxVS Mahajan Coaching Centre
 
Introduction to ArtificiaI Intelligence in Higher Education
Introduction to ArtificiaI Intelligence in Higher EducationIntroduction to ArtificiaI Intelligence in Higher Education
Introduction to ArtificiaI Intelligence in Higher Educationpboyjonauth
 
Alper Gobel In Media Res Media Component
Alper Gobel In Media Res Media ComponentAlper Gobel In Media Res Media Component
Alper Gobel In Media Res Media ComponentInMediaRes1
 
How to Configure Email Server in Odoo 17
How to Configure Email Server in Odoo 17How to Configure Email Server in Odoo 17
How to Configure Email Server in Odoo 17Celine George
 
URLs and Routing in the Odoo 17 Website App
URLs and Routing in the Odoo 17 Website AppURLs and Routing in the Odoo 17 Website App
URLs and Routing in the Odoo 17 Website AppCeline George
 
Hybridoma Technology ( Production , Purification , and Application )
Hybridoma Technology  ( Production , Purification , and Application  ) Hybridoma Technology  ( Production , Purification , and Application  )
Hybridoma Technology ( Production , Purification , and Application ) Sakshi Ghasle
 

Recently uploaded (20)

Solving Puzzles Benefits Everyone (English).pptx
Solving Puzzles Benefits Everyone (English).pptxSolving Puzzles Benefits Everyone (English).pptx
Solving Puzzles Benefits Everyone (English).pptx
 
Employee wellbeing at the workplace.pptx
Employee wellbeing at the workplace.pptxEmployee wellbeing at the workplace.pptx
Employee wellbeing at the workplace.pptx
 
How to Make a Pirate ship Primary Education.pptx
How to Make a Pirate ship Primary Education.pptxHow to Make a Pirate ship Primary Education.pptx
How to Make a Pirate ship Primary Education.pptx
 
Código Creativo y Arte de Software | Unidad 1
Código Creativo y Arte de Software | Unidad 1Código Creativo y Arte de Software | Unidad 1
Código Creativo y Arte de Software | Unidad 1
 
Software Engineering Methodologies (overview)
Software Engineering Methodologies (overview)Software Engineering Methodologies (overview)
Software Engineering Methodologies (overview)
 
Class 11 Legal Studies Ch-1 Concept of State .pdf
Class 11 Legal Studies Ch-1 Concept of State .pdfClass 11 Legal Studies Ch-1 Concept of State .pdf
Class 11 Legal Studies Ch-1 Concept of State .pdf
 
Separation of Lanthanides/ Lanthanides and Actinides
Separation of Lanthanides/ Lanthanides and ActinidesSeparation of Lanthanides/ Lanthanides and Actinides
Separation of Lanthanides/ Lanthanides and Actinides
 
Contemporary philippine arts from the regions_PPT_Module_12 [Autosaved] (1).pptx
Contemporary philippine arts from the regions_PPT_Module_12 [Autosaved] (1).pptxContemporary philippine arts from the regions_PPT_Module_12 [Autosaved] (1).pptx
Contemporary philippine arts from the regions_PPT_Module_12 [Autosaved] (1).pptx
 
SOCIAL AND HISTORICAL CONTEXT - LFTVD.pptx
SOCIAL AND HISTORICAL CONTEXT - LFTVD.pptxSOCIAL AND HISTORICAL CONTEXT - LFTVD.pptx
SOCIAL AND HISTORICAL CONTEXT - LFTVD.pptx
 
9953330565 Low Rate Call Girls In Rohini Delhi NCR
9953330565 Low Rate Call Girls In Rohini  Delhi NCR9953330565 Low Rate Call Girls In Rohini  Delhi NCR
9953330565 Low Rate Call Girls In Rohini Delhi NCR
 
Presentation by Andreas Schleicher Tackling the School Absenteeism Crisis 30 ...
Presentation by Andreas Schleicher Tackling the School Absenteeism Crisis 30 ...Presentation by Andreas Schleicher Tackling the School Absenteeism Crisis 30 ...
Presentation by Andreas Schleicher Tackling the School Absenteeism Crisis 30 ...
 
Model Call Girl in Bikash Puri Delhi reach out to us at 🔝9953056974🔝
Model Call Girl in Bikash Puri  Delhi reach out to us at 🔝9953056974🔝Model Call Girl in Bikash Puri  Delhi reach out to us at 🔝9953056974🔝
Model Call Girl in Bikash Puri Delhi reach out to us at 🔝9953056974🔝
 
Kisan Call Centre - To harness potential of ICT in Agriculture by answer farm...
Kisan Call Centre - To harness potential of ICT in Agriculture by answer farm...Kisan Call Centre - To harness potential of ICT in Agriculture by answer farm...
Kisan Call Centre - To harness potential of ICT in Agriculture by answer farm...
 
Organic Name Reactions for the students and aspirants of Chemistry12th.pptx
Organic Name Reactions  for the students and aspirants of Chemistry12th.pptxOrganic Name Reactions  for the students and aspirants of Chemistry12th.pptx
Organic Name Reactions for the students and aspirants of Chemistry12th.pptx
 
Introduction to ArtificiaI Intelligence in Higher Education
Introduction to ArtificiaI Intelligence in Higher EducationIntroduction to ArtificiaI Intelligence in Higher Education
Introduction to ArtificiaI Intelligence in Higher Education
 
Alper Gobel In Media Res Media Component
Alper Gobel In Media Res Media ComponentAlper Gobel In Media Res Media Component
Alper Gobel In Media Res Media Component
 
How to Configure Email Server in Odoo 17
How to Configure Email Server in Odoo 17How to Configure Email Server in Odoo 17
How to Configure Email Server in Odoo 17
 
URLs and Routing in the Odoo 17 Website App
URLs and Routing in the Odoo 17 Website AppURLs and Routing in the Odoo 17 Website App
URLs and Routing in the Odoo 17 Website App
 
Hybridoma Technology ( Production , Purification , and Application )
Hybridoma Technology  ( Production , Purification , and Application  ) Hybridoma Technology  ( Production , Purification , and Application  )
Hybridoma Technology ( Production , Purification , and Application )
 
Staff of Color (SOC) Retention Efforts DDSD
Staff of Color (SOC) Retention Efforts DDSDStaff of Color (SOC) Retention Efforts DDSD
Staff of Color (SOC) Retention Efforts DDSD
 

Iso 31000.pdf

  • 1. Risk Management Basics - ISO 31000 Standard Louis Kunimatsu, CRISC IT Security & Strategy, Ford Motor Company
  • 2. Risk Management Basics - ISO 31000 Standard 1. Risk Management Basics 2. ISO 31000 – Risk 2. ISO 31000 – Risk Management Principles and Guidelines
  • 3. Risk Management Basics Organizational objectives are influenced by internal and external factors which create uncertainty in achieving those objectives. The effect of this uncertainty is “risk” to the organization’s objectives. Unlike Risk Elimination (approach of military and law enforcement) which seeks to remove all risk; Risk Management is the coordinated activities to direct Management is the coordinated activities to direct and control an organization with regard to risk. Risk Management allows for multiple risk responses dependent upon evaluation and analysis of risk. RISK = Negative IMPACT to objectives X LIKELIHOOD of occurrence.
  • 4. Risk Management Basics Risk Responses: 1. MITIGATE - corrective action to eliminate or reduce IMPACT or LIKELIHOOD 2. AVOID - Cease activity to eliminate risk 3. TRANSFER - Shift IMPACT to another entity 4. ACCEPT - No corrective action. Document acceptance decision and monitor
  • 5. ISO 31000: Risk management — Principles and guidelines • Published in 2009, to provide “principles & generic guidelines on risk management” • “…can be applied to any type of risk, whatever its nature, whether having positive or negative consequences” • “…not intended to promote uniformity of risk • “…not intended to promote uniformity of risk management across organizations. The design and implementation of risk management plans and frameworks will need to take into account the varying needs of a specific organization, its particular objectives, context, structure, operations, processes,..” • “…not intended for the purpose of certification”
  • 6. ISO 31000: Principles, Framework & Process PRINCIPLES a) Creates value b) Integral part of organizational processes c) Part of decision making d) Explicitly addresses uncertainty e) Systematic, structured & timely f) Based on the best available Mandate & commitment Design of framework for managing risk FRAMEWORK f) Based on the best available information g) Tailored h) Takes human & cultural factors into account i) Transparent & inclusive j) Dynamic, iterative and responsive to change k) Facilitates continuous improvement & enhancement of the organization Implementing risk management Monitoring & review of the framework Continual improvement of the framework
  • 7. RISK ASSESSMENT ISO 31000: Principles, Framework & Process Establishing the context Risk identification PROCESS Implementing risk FRAMEWORK Monitoring & review Communication & consultation risk management Risk analysis Risk evaluation Risk treatment Monitoring & review Communication & consultation
  • 8. Risk Management: Establish the context External context • Legal, Regulatory, Financial • International, national, regional or local • Relationships with, perceptions and values of external stakeholders Internal context • Organizational objectives • Project, process, or activity objectives • Project, process, or activity objectives • Policy, standards, guidelines and models adopted by the organization • Contractual relationships Risk Management process context • Objectives, scope, responsibilities, methods • Defining risk criteria – measures, tolerance levels, views of stakeholders
  • 9. ISO 31000: Risk Identification • Process of finding, recognizing and describing risks • Comprehensive list of risks based on those events that might create, enhance, prevent, degrade, accelerate or delay the achievement of objectives. • Identify the risks associated with not pursuing an opportunity opportunity • A risk that is not identified at this stage will not be included in further analysis • Identification should include risks whether or not their source is under the control of the organization
  • 10. ISO 31000: Risk Analysis • Process to comprehend the nature of risk and to determine the level of risk • “Risk analysis involves consideration of the causes and sources of risk, their positive and negative consequences, and the likelihood that those and the likelihood that those consequences can occur.” • Provides the basis for risk evaluation and decisions about risk treatment • Risk analysis includes risk estimation
  • 11. Risk Analysis Risk Classifications: • essential risks, • risks to be monitored • risks to be observed Impact scale: Likelihood scale: • more than 10 years • 5 to 10 years (> 0.1 ) • 3 to 5 years (> 0.2 ) Impact scale: • very low (< $1k) • low (< $5k) • medium (< $25k) • high (< $100k) • very high (> $100K) • 3 to 5 years (> 0.2 ) • 2 to 3 years (> 0,33 ) • less than 2 years (> 0.5 ) OWASP Risk Ranking Methodology
  • 12. ISO 31000: Risk Evaluation • The purpose of risk evaluation is to assist in making decisions, based on the outcomes of risk analysis, about which risks need treatment and the priority for treatment implementation • Decisions should take account of the wider context of the risk and include consideration of the tolerance of the risks borne by parties other than the organization that benefits from the risk that benefits from the risk • Decisions should be made in accordance with legal, regulatory and other requirements • In some circumstances, the risk evaluation can lead to a decision to undertake further analysis • The risk evaluation can also lead to a decision not to treat the risk in any way other than maintaining existing controls
  • 13. ISO 31000: Risk Evaluation • Decisions should take account of the wider context of the risk and include consideration of the tolerance of the risks borne by parties other than the organization that benefits from the risk • Decisions should be made in accordance • The purpose of risk evaluation is to assist in making decisions, based on the outcomes of risk analysis, about which risks need treatment and the priority for treatment implementation • Decisions should be made in accordance with legal, regulatory and other requirements • In some circumstances, the risk evaluation can lead to a decision to undertake further analysis • The risk evaluation can also lead to a decision not to treat the risk in any way other than maintaining existing controls
  • 14. ISO 31000: Risk Treatment Risk treatment involves selecting one or more options for modifying risks, and implementing those options. Risk treatment options are not necessarily mutually exclusive. The options can include the following: TRANSFER • Sharing the risk with another party or parties (including contracts and risk financing) AVOID AVOID • Avoiding the risk by deciding not to start or continue with the activity that gives rise to the risk • Removing the risk source MITIGATE • Changing the likelihood • Changing the consequences (impact) ACCEPT • Retaining the risk by informed decision • Taking or increasing the risk in order to pursue an opportunity
  • 15. ISO 31000: Risk Treatment • Selecting the most appropriate risk treatment option involves balancing the costs and efforts of implementation against the benefits derived, with regard to legal, regulatory, and other requirements such as social responsibility and the protection of the natural environment. • A number of treatment options can be considered • A number of treatment options can be considered and applied either individually or in combination. • Risk treatment itself can introduce risks. A significant risk can be the failure or ineffectiveness of the risk treatment measures. Monitoring needs to be an integral part of the risk treatment plan to give assurance that the measures remain effective.
  • 16. ISO 31000: Monitoring & Review • An integral part of the risk management process involving regular checking or surveillance • Ensure controls are effective & efficient • Detect change in external or internal context • Analysis, lessons learned, continuous • Analysis, lessons learned, continuous improvement • Identify emerging risks
  • 17. Risk Management Basics - ISO 31000 Standard Louis Kunimatsu, CRISC IT Security & Strategy, Ford Motor Company THANKS for attending! ENJOY the conference!