SlideShare a Scribd company logo
1 of 21
Download to read offline
IT Risk Assessment Project
Project Plan Document
Introductory Project
Intricap, LLC
One month Pilot Project
September 2013
Core Value Proposition
Any company with an IT organization
has to perform IT Risk Assessments
mandatorily as part of various
compliances.
This means every company worth its
salt.
Needs to be done annually
It is boring for IT and IT security
managers.
IT Risk Assessments are done one-
on-one today
A mass customization solution
through Internet and Technology will
find instant adoption.
Competition
None
Most of it is done
internally at present, or
through consultants done
one at a time.
What it takes to do IT Risk
Assessments today
You have to identify all critical ITEMS in
IT infrastructure: Computers, Servers,
Switches, Networks, Locations
Identify THREATS that can do harm to
each of them.
Figure out how VULNERABLE each item is
to each threat
For each vulnerable item, determine the
LIKELIHOOD of getting effected.
Given a likelihood of getting affected,
what will be the IMPACT on each item.
Given all of above, what is the RISK to
each item.
Document and Report
That seems complicated
No. Most of the ratings
are numbers from 1 to 5,
and all you need is to
multiply and add those
numbers to achieve Risk
Ratings
Is there a standard to comply
There are 3 Industry
known standards
NIST SP800-30
ISO 27005
OCTAVE
That’s lot of jargon
IT Industry needs jargon
to look smart. Come on,
admit it. All of us boast a
little. It is just
repackaging the same old
wine, reordering
sequences, and uses
slightly different phrases
So what is your offering
We will offer NIST SP800-
30 compliant Risk
Assessments online
through technology
platform.
Pricing !!!!!
We are working on
pricing. Nothing is fixed
yet
How much would be the possible charges ?
We really want a fast
adoption on this one. We
have not decided the
numbers yet, but we will
take it through a price
discovery mechanism.
What else is your value add ?
For the first time ever, we will
offer VISUAL RISK
assessments.
All present Risk Assessments
are excel based number
assignment. Boring Stuff.
We will make it exciting. Like
visuals running, and playing a
game.
At the end of the game, your
Risk Assessment is done.
Is making it lot of work
NO. In god’s name NOT.
You cannot believe how
easy it is to build cool
visuals using this totally
open technology HTML5.
So Just HTML5
And a bit of PHP and
Javascript.
We need to create Word
reports, so we will use
some third party tools
for it.
How much time to build ?
Maybe 15 days of work.
Maybe less.
Building it is not that hard
work.
MARKETING it is.
MARKETING
Yes. We have to reach all
IT, and IT Security
Managers all over.
Then get them to try it.
That has seemed to be a
toadfull of work elsewhere.
So !!!!!!
So out of box marketing
techniques would be the
most crucial factor in the
success of this project.
Its all about MARKETING
OK, and what are the returns ?
At 100 USD per customer
paying, if 1000 customers sign
up, that is USD 100,000 per
year.
With 10,000 customers, it is 1
Million USD per year.
The world market is 100,000
customers.
Remember it is PER YEAR, not
one time
That’s not bad for one month
of work
I told you so.
And regular costs ?
After initial heavy effort
in building and marketing
has been done, it will not
take more than 2 people
to run the whole show.
This will be a profitable
project.
Future ~!!
Once a relationship is
built with all IT Managers,
and if they kinda like you.
Then there are more
things to be done ;)
OK I am interested
All rights: INTRICAP, LLC
rohit@intricap.com
Prepared on a bus from Monterrey to Mexico
City,
1st September, 2013 .
Hurrah Internet on buses

More Related Content

What's hot

Dealing with Estimation, Uncertainty, Risk, and Commitment
Dealing with Estimation, Uncertainty, Risk, and CommitmentDealing with Estimation, Uncertainty, Risk, and Commitment
Dealing with Estimation, Uncertainty, Risk, and CommitmentTechWell
 
Greg Jenkins - Functional Dashboards for Sales Reps and Managers
Greg Jenkins - Functional Dashboards for Sales Reps and ManagersGreg Jenkins - Functional Dashboards for Sales Reps and Managers
Greg Jenkins - Functional Dashboards for Sales Reps and ManagersInfusionsoft
 
Thursday - Zeman & Topliff - Product Showcase - 315pm - Final.pptx
Thursday - Zeman & Topliff - Product Showcase - 315pm - Final.pptxThursday - Zeman & Topliff - Product Showcase - 315pm - Final.pptx
Thursday - Zeman & Topliff - Product Showcase - 315pm - Final.pptxJustin Topliff
 
Introducing The Lean Startup
Introducing The Lean StartupIntroducing The Lean Startup
Introducing The Lean StartupThijs Suijten
 
AWS Summit Singapore 2019 | A Founder's Journey to Exit
AWS Summit Singapore 2019 | A Founder's Journey to ExitAWS Summit Singapore 2019 | A Founder's Journey to Exit
AWS Summit Singapore 2019 | A Founder's Journey to ExitAWS Summits
 
conversations-one-pager
conversations-one-pagerconversations-one-pager
conversations-one-pagerBart Adao
 
ONBOARDING AT SCALE AT BOOKING.COM
ONBOARDING AT SCALE AT BOOKING.COMONBOARDING AT SCALE AT BOOKING.COM
ONBOARDING AT SCALE AT BOOKING.COMSavage Marketing
 
Lindsay Bayuk & Brian Gates - Infuisonsoft Product Update
Lindsay Bayuk & Brian Gates - Infuisonsoft Product UpdateLindsay Bayuk & Brian Gates - Infuisonsoft Product Update
Lindsay Bayuk & Brian Gates - Infuisonsoft Product UpdateInfusionsoft
 
100% cloud: Your action plan for success
100% cloud: Your action plan for success 100% cloud: Your action plan for success
100% cloud: Your action plan for success Intuit Inc.
 
Better Living Through Analytics - Strategies for Data Decisions
Better Living Through Analytics - Strategies for Data DecisionsBetter Living Through Analytics - Strategies for Data Decisions
Better Living Through Analytics - Strategies for Data DecisionsProduct School
 

What's hot (11)

Dealing with Estimation, Uncertainty, Risk, and Commitment
Dealing with Estimation, Uncertainty, Risk, and CommitmentDealing with Estimation, Uncertainty, Risk, and Commitment
Dealing with Estimation, Uncertainty, Risk, and Commitment
 
Greg Jenkins - Functional Dashboards for Sales Reps and Managers
Greg Jenkins - Functional Dashboards for Sales Reps and ManagersGreg Jenkins - Functional Dashboards for Sales Reps and Managers
Greg Jenkins - Functional Dashboards for Sales Reps and Managers
 
Thursday - Zeman & Topliff - Product Showcase - 315pm - Final.pptx
Thursday - Zeman & Topliff - Product Showcase - 315pm - Final.pptxThursday - Zeman & Topliff - Product Showcase - 315pm - Final.pptx
Thursday - Zeman & Topliff - Product Showcase - 315pm - Final.pptx
 
Introducing The Lean Startup
Introducing The Lean StartupIntroducing The Lean Startup
Introducing The Lean Startup
 
AWS Summit Singapore 2019 | A Founder's Journey to Exit
AWS Summit Singapore 2019 | A Founder's Journey to ExitAWS Summit Singapore 2019 | A Founder's Journey to Exit
AWS Summit Singapore 2019 | A Founder's Journey to Exit
 
conversations-one-pager
conversations-one-pagerconversations-one-pager
conversations-one-pager
 
ONBOARDING AT SCALE AT BOOKING.COM
ONBOARDING AT SCALE AT BOOKING.COMONBOARDING AT SCALE AT BOOKING.COM
ONBOARDING AT SCALE AT BOOKING.COM
 
Lindsay Bayuk & Brian Gates - Infuisonsoft Product Update
Lindsay Bayuk & Brian Gates - Infuisonsoft Product UpdateLindsay Bayuk & Brian Gates - Infuisonsoft Product Update
Lindsay Bayuk & Brian Gates - Infuisonsoft Product Update
 
100% cloud: Your action plan for success
100% cloud: Your action plan for success 100% cloud: Your action plan for success
100% cloud: Your action plan for success
 
Endpoint mgr.9
Endpoint mgr.9Endpoint mgr.9
Endpoint mgr.9
 
Better Living Through Analytics - Strategies for Data Decisions
Better Living Through Analytics - Strategies for Data DecisionsBetter Living Through Analytics - Strategies for Data Decisions
Better Living Through Analytics - Strategies for Data Decisions
 

Similar to IT Risk Assessment Plan

Security practices in game design and development
Security practices in game design and developmentSecurity practices in game design and development
Security practices in game design and developmentNarola Infotech
 
Webinar for Apr 2019 - AI Powered Insurer
Webinar for Apr 2019 - AI Powered InsurerWebinar for Apr 2019 - AI Powered Insurer
Webinar for Apr 2019 - AI Powered InsurerThe Digital Insurer
 
Outside the Comfort Zone: Cross Industry Use Cases in Big Data Analytics
Outside the Comfort Zone: Cross Industry Use Cases in Big Data AnalyticsOutside the Comfort Zone: Cross Industry Use Cases in Big Data Analytics
Outside the Comfort Zone: Cross Industry Use Cases in Big Data AnalyticsRising Media Ltd.
 
Career in IT Industry; A Smart Choice!
Career in IT Industry; A Smart Choice!Career in IT Industry; A Smart Choice!
Career in IT Industry; A Smart Choice!Samidha Takle
 
What every developer can learn from startups
What every developer can learn from startupsWhat every developer can learn from startups
What every developer can learn from startupsOleg Podsechin
 
How Dashboard Analytics Bolster Security and Risk Management Across IT Supply...
How Dashboard Analytics Bolster Security and Risk Management Across IT Supply...How Dashboard Analytics Bolster Security and Risk Management Across IT Supply...
How Dashboard Analytics Bolster Security and Risk Management Across IT Supply...Dana Gardner
 
Software Development Company In USA
Software Development Company In USASoftware Development Company In USA
Software Development Company In USAMedRecTechnologies1
 
MedRec Technologies Software Company.pdf
MedRec Technologies Software Company.pdfMedRec Technologies Software Company.pdf
MedRec Technologies Software Company.pdfMedRecTechnologies1
 
Leading Software And App Development Company In USA, UK & India.pdf
Leading Software And App Development Company In USA, UK & India.pdfLeading Software And App Development Company In USA, UK & India.pdf
Leading Software And App Development Company In USA, UK & India.pdfMedRecTechnologies1
 
Fearless IT Outsourcing
Fearless IT OutsourcingFearless IT Outsourcing
Fearless IT OutsourcingAndy Hilliard
 
So... you want to be a security consultant
So... you want to be a security consultant So... you want to be a security consultant
So... you want to be a security consultant abnmi
 
Top 10 Revolutionary Leaders Changing The Face of Business in 2021
Top 10 Revolutionary Leaders Changing The Face of Business in 2021Top 10 Revolutionary Leaders Changing The Face of Business in 2021
Top 10 Revolutionary Leaders Changing The Face of Business in 2021Swiftnlift
 
Presentation Orange Sputnik
Presentation Orange SputnikPresentation Orange Sputnik
Presentation Orange SputnikMaria Ostapenko
 
How we successfully implemented ai in audit by venkat vajradhar _ dec, 202...
How we successfully implemented ai in audit    by venkat vajradhar _ dec, 202...How we successfully implemented ai in audit    by venkat vajradhar _ dec, 202...
How we successfully implemented ai in audit by venkat vajradhar _ dec, 202...venkatvajradhar1
 
2009 10 28 The Lean Startup In Paris
2009 10 28 The Lean Startup In Paris2009 10 28 The Lean Startup In Paris
2009 10 28 The Lean Startup In ParisEric Ries
 
MTB_REPORT_WIPRO_0406
MTB_REPORT_WIPRO_0406MTB_REPORT_WIPRO_0406
MTB_REPORT_WIPRO_0406Elliot Tally
 
Rich Napoli - NJTC Corner Office
Rich Napoli - NJTC Corner OfficeRich Napoli - NJTC Corner Office
Rich Napoli - NJTC Corner OfficeRelevantz
 

Similar to IT Risk Assessment Plan (20)

Security practices in game design and development
Security practices in game design and developmentSecurity practices in game design and development
Security practices in game design and development
 
Career Assignment
Career AssignmentCareer Assignment
Career Assignment
 
Webinar for Apr 2019 - AI Powered Insurer
Webinar for Apr 2019 - AI Powered InsurerWebinar for Apr 2019 - AI Powered Insurer
Webinar for Apr 2019 - AI Powered Insurer
 
Outside the Comfort Zone: Cross Industry Use Cases in Big Data Analytics
Outside the Comfort Zone: Cross Industry Use Cases in Big Data AnalyticsOutside the Comfort Zone: Cross Industry Use Cases in Big Data Analytics
Outside the Comfort Zone: Cross Industry Use Cases in Big Data Analytics
 
Career in IT Industry; A Smart Choice!
Career in IT Industry; A Smart Choice!Career in IT Industry; A Smart Choice!
Career in IT Industry; A Smart Choice!
 
Computers and technology
Computers and technologyComputers and technology
Computers and technology
 
What every developer can learn from startups
What every developer can learn from startupsWhat every developer can learn from startups
What every developer can learn from startups
 
How Dashboard Analytics Bolster Security and Risk Management Across IT Supply...
How Dashboard Analytics Bolster Security and Risk Management Across IT Supply...How Dashboard Analytics Bolster Security and Risk Management Across IT Supply...
How Dashboard Analytics Bolster Security and Risk Management Across IT Supply...
 
Software Development Company In USA
Software Development Company In USASoftware Development Company In USA
Software Development Company In USA
 
MedRec Technologies Software Company.pdf
MedRec Technologies Software Company.pdfMedRec Technologies Software Company.pdf
MedRec Technologies Software Company.pdf
 
Leading Software And App Development Company In USA, UK & India.pdf
Leading Software And App Development Company In USA, UK & India.pdfLeading Software And App Development Company In USA, UK & India.pdf
Leading Software And App Development Company In USA, UK & India.pdf
 
Fearless IT Outsourcing
Fearless IT OutsourcingFearless IT Outsourcing
Fearless IT Outsourcing
 
So... you want to be a security consultant
So... you want to be a security consultant So... you want to be a security consultant
So... you want to be a security consultant
 
InterVenture 360° Tech Consulting
InterVenture 360° Tech ConsultingInterVenture 360° Tech Consulting
InterVenture 360° Tech Consulting
 
Top 10 Revolutionary Leaders Changing The Face of Business in 2021
Top 10 Revolutionary Leaders Changing The Face of Business in 2021Top 10 Revolutionary Leaders Changing The Face of Business in 2021
Top 10 Revolutionary Leaders Changing The Face of Business in 2021
 
Presentation Orange Sputnik
Presentation Orange SputnikPresentation Orange Sputnik
Presentation Orange Sputnik
 
How we successfully implemented ai in audit by venkat vajradhar _ dec, 202...
How we successfully implemented ai in audit    by venkat vajradhar _ dec, 202...How we successfully implemented ai in audit    by venkat vajradhar _ dec, 202...
How we successfully implemented ai in audit by venkat vajradhar _ dec, 202...
 
2009 10 28 The Lean Startup In Paris
2009 10 28 The Lean Startup In Paris2009 10 28 The Lean Startup In Paris
2009 10 28 The Lean Startup In Paris
 
MTB_REPORT_WIPRO_0406
MTB_REPORT_WIPRO_0406MTB_REPORT_WIPRO_0406
MTB_REPORT_WIPRO_0406
 
Rich Napoli - NJTC Corner Office
Rich Napoli - NJTC Corner OfficeRich Napoli - NJTC Corner Office
Rich Napoli - NJTC Corner Office
 

Recently uploaded

Key Features Of Token Development (1).pptx
Key  Features Of Token  Development (1).pptxKey  Features Of Token  Development (1).pptx
Key Features Of Token Development (1).pptxLBM Solutions
 
Gen AI in Business - Global Trends Report 2024.pdf
Gen AI in Business - Global Trends Report 2024.pdfGen AI in Business - Global Trends Report 2024.pdf
Gen AI in Business - Global Trends Report 2024.pdfAddepto
 
Unraveling Multimodality with Large Language Models.pdf
Unraveling Multimodality with Large Language Models.pdfUnraveling Multimodality with Large Language Models.pdf
Unraveling Multimodality with Large Language Models.pdfAlex Barbosa Coqueiro
 
"LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks...
"LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks..."LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks...
"LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks...Fwdays
 
Designing IA for AI - Information Architecture Conference 2024
Designing IA for AI - Information Architecture Conference 2024Designing IA for AI - Information Architecture Conference 2024
Designing IA for AI - Information Architecture Conference 2024Enterprise Knowledge
 
Nell’iperspazio con Rocket: il Framework Web di Rust!
Nell’iperspazio con Rocket: il Framework Web di Rust!Nell’iperspazio con Rocket: il Framework Web di Rust!
Nell’iperspazio con Rocket: il Framework Web di Rust!Commit University
 
"ML in Production",Oleksandr Bagan
"ML in Production",Oleksandr Bagan"ML in Production",Oleksandr Bagan
"ML in Production",Oleksandr BaganFwdays
 
Artificial intelligence in the post-deep learning era
Artificial intelligence in the post-deep learning eraArtificial intelligence in the post-deep learning era
Artificial intelligence in the post-deep learning eraDeakin University
 
My INSURER PTE LTD - Insurtech Innovation Award 2024
My INSURER PTE LTD - Insurtech Innovation Award 2024My INSURER PTE LTD - Insurtech Innovation Award 2024
My INSURER PTE LTD - Insurtech Innovation Award 2024The Digital Insurer
 
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmatics
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmaticsKotlin Multiplatform & Compose Multiplatform - Starter kit for pragmatics
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmaticscarlostorres15106
 
Unblocking The Main Thread Solving ANRs and Frozen Frames
Unblocking The Main Thread Solving ANRs and Frozen FramesUnblocking The Main Thread Solving ANRs and Frozen Frames
Unblocking The Main Thread Solving ANRs and Frozen FramesSinan KOZAK
 
Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...
Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...
Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...shyamraj55
 
SIP trunking in Janus @ Kamailio World 2024
SIP trunking in Janus @ Kamailio World 2024SIP trunking in Janus @ Kamailio World 2024
SIP trunking in Janus @ Kamailio World 2024Lorenzo Miniero
 
Bun (KitWorks Team Study 노별마루 발표 2024.4.22)
Bun (KitWorks Team Study 노별마루 발표 2024.4.22)Bun (KitWorks Team Study 노별마루 발표 2024.4.22)
Bun (KitWorks Team Study 노별마루 발표 2024.4.22)Wonjun Hwang
 
costume and set research powerpoint presentation
costume and set research powerpoint presentationcostume and set research powerpoint presentation
costume and set research powerpoint presentationphoebematthew05
 
Bluetooth Controlled Car with Arduino.pdf
Bluetooth Controlled Car with Arduino.pdfBluetooth Controlled Car with Arduino.pdf
Bluetooth Controlled Car with Arduino.pdfngoud9212
 
APIForce Zurich 5 April Automation LPDG
APIForce Zurich 5 April  Automation LPDGAPIForce Zurich 5 April  Automation LPDG
APIForce Zurich 5 April Automation LPDGMarianaLemus7
 
Are Multi-Cloud and Serverless Good or Bad?
Are Multi-Cloud and Serverless Good or Bad?Are Multi-Cloud and Serverless Good or Bad?
Are Multi-Cloud and Serverless Good or Bad?Mattias Andersson
 

Recently uploaded (20)

Key Features Of Token Development (1).pptx
Key  Features Of Token  Development (1).pptxKey  Features Of Token  Development (1).pptx
Key Features Of Token Development (1).pptx
 
Gen AI in Business - Global Trends Report 2024.pdf
Gen AI in Business - Global Trends Report 2024.pdfGen AI in Business - Global Trends Report 2024.pdf
Gen AI in Business - Global Trends Report 2024.pdf
 
DMCC Future of Trade Web3 - Special Edition
DMCC Future of Trade Web3 - Special EditionDMCC Future of Trade Web3 - Special Edition
DMCC Future of Trade Web3 - Special Edition
 
Unraveling Multimodality with Large Language Models.pdf
Unraveling Multimodality with Large Language Models.pdfUnraveling Multimodality with Large Language Models.pdf
Unraveling Multimodality with Large Language Models.pdf
 
"LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks...
"LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks..."LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks...
"LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks...
 
Designing IA for AI - Information Architecture Conference 2024
Designing IA for AI - Information Architecture Conference 2024Designing IA for AI - Information Architecture Conference 2024
Designing IA for AI - Information Architecture Conference 2024
 
Nell’iperspazio con Rocket: il Framework Web di Rust!
Nell’iperspazio con Rocket: il Framework Web di Rust!Nell’iperspazio con Rocket: il Framework Web di Rust!
Nell’iperspazio con Rocket: il Framework Web di Rust!
 
"ML in Production",Oleksandr Bagan
"ML in Production",Oleksandr Bagan"ML in Production",Oleksandr Bagan
"ML in Production",Oleksandr Bagan
 
Artificial intelligence in the post-deep learning era
Artificial intelligence in the post-deep learning eraArtificial intelligence in the post-deep learning era
Artificial intelligence in the post-deep learning era
 
My INSURER PTE LTD - Insurtech Innovation Award 2024
My INSURER PTE LTD - Insurtech Innovation Award 2024My INSURER PTE LTD - Insurtech Innovation Award 2024
My INSURER PTE LTD - Insurtech Innovation Award 2024
 
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmatics
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmaticsKotlin Multiplatform & Compose Multiplatform - Starter kit for pragmatics
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmatics
 
Unblocking The Main Thread Solving ANRs and Frozen Frames
Unblocking The Main Thread Solving ANRs and Frozen FramesUnblocking The Main Thread Solving ANRs and Frozen Frames
Unblocking The Main Thread Solving ANRs and Frozen Frames
 
Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...
Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...
Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...
 
E-Vehicle_Hacking_by_Parul Sharma_null_owasp.pptx
E-Vehicle_Hacking_by_Parul Sharma_null_owasp.pptxE-Vehicle_Hacking_by_Parul Sharma_null_owasp.pptx
E-Vehicle_Hacking_by_Parul Sharma_null_owasp.pptx
 
SIP trunking in Janus @ Kamailio World 2024
SIP trunking in Janus @ Kamailio World 2024SIP trunking in Janus @ Kamailio World 2024
SIP trunking in Janus @ Kamailio World 2024
 
Bun (KitWorks Team Study 노별마루 발표 2024.4.22)
Bun (KitWorks Team Study 노별마루 발표 2024.4.22)Bun (KitWorks Team Study 노별마루 발표 2024.4.22)
Bun (KitWorks Team Study 노별마루 발표 2024.4.22)
 
costume and set research powerpoint presentation
costume and set research powerpoint presentationcostume and set research powerpoint presentation
costume and set research powerpoint presentation
 
Bluetooth Controlled Car with Arduino.pdf
Bluetooth Controlled Car with Arduino.pdfBluetooth Controlled Car with Arduino.pdf
Bluetooth Controlled Car with Arduino.pdf
 
APIForce Zurich 5 April Automation LPDG
APIForce Zurich 5 April  Automation LPDGAPIForce Zurich 5 April  Automation LPDG
APIForce Zurich 5 April Automation LPDG
 
Are Multi-Cloud and Serverless Good or Bad?
Are Multi-Cloud and Serverless Good or Bad?Are Multi-Cloud and Serverless Good or Bad?
Are Multi-Cloud and Serverless Good or Bad?
 

IT Risk Assessment Plan

  • 1. IT Risk Assessment Project Project Plan Document Introductory Project Intricap, LLC One month Pilot Project September 2013
  • 2. Core Value Proposition Any company with an IT organization has to perform IT Risk Assessments mandatorily as part of various compliances. This means every company worth its salt. Needs to be done annually It is boring for IT and IT security managers. IT Risk Assessments are done one- on-one today A mass customization solution through Internet and Technology will find instant adoption.
  • 3. Competition None Most of it is done internally at present, or through consultants done one at a time.
  • 4. What it takes to do IT Risk Assessments today You have to identify all critical ITEMS in IT infrastructure: Computers, Servers, Switches, Networks, Locations Identify THREATS that can do harm to each of them. Figure out how VULNERABLE each item is to each threat For each vulnerable item, determine the LIKELIHOOD of getting effected. Given a likelihood of getting affected, what will be the IMPACT on each item. Given all of above, what is the RISK to each item. Document and Report
  • 5. That seems complicated No. Most of the ratings are numbers from 1 to 5, and all you need is to multiply and add those numbers to achieve Risk Ratings
  • 6. Is there a standard to comply There are 3 Industry known standards NIST SP800-30 ISO 27005 OCTAVE
  • 7. That’s lot of jargon IT Industry needs jargon to look smart. Come on, admit it. All of us boast a little. It is just repackaging the same old wine, reordering sequences, and uses slightly different phrases
  • 8. So what is your offering We will offer NIST SP800- 30 compliant Risk Assessments online through technology platform.
  • 9. Pricing !!!!! We are working on pricing. Nothing is fixed yet
  • 10. How much would be the possible charges ? We really want a fast adoption on this one. We have not decided the numbers yet, but we will take it through a price discovery mechanism.
  • 11. What else is your value add ? For the first time ever, we will offer VISUAL RISK assessments. All present Risk Assessments are excel based number assignment. Boring Stuff. We will make it exciting. Like visuals running, and playing a game. At the end of the game, your Risk Assessment is done.
  • 12. Is making it lot of work NO. In god’s name NOT. You cannot believe how easy it is to build cool visuals using this totally open technology HTML5.
  • 13. So Just HTML5 And a bit of PHP and Javascript. We need to create Word reports, so we will use some third party tools for it.
  • 14. How much time to build ? Maybe 15 days of work. Maybe less. Building it is not that hard work. MARKETING it is.
  • 15. MARKETING Yes. We have to reach all IT, and IT Security Managers all over. Then get them to try it. That has seemed to be a toadfull of work elsewhere.
  • 16. So !!!!!! So out of box marketing techniques would be the most crucial factor in the success of this project. Its all about MARKETING
  • 17. OK, and what are the returns ? At 100 USD per customer paying, if 1000 customers sign up, that is USD 100,000 per year. With 10,000 customers, it is 1 Million USD per year. The world market is 100,000 customers. Remember it is PER YEAR, not one time
  • 18. That’s not bad for one month of work I told you so.
  • 19. And regular costs ? After initial heavy effort in building and marketing has been done, it will not take more than 2 people to run the whole show. This will be a profitable project.
  • 20. Future ~!! Once a relationship is built with all IT Managers, and if they kinda like you. Then there are more things to be done ;)
  • 21. OK I am interested All rights: INTRICAP, LLC rohit@intricap.com Prepared on a bus from Monterrey to Mexico City, 1st September, 2013 . Hurrah Internet on buses