SlideShare a Scribd company logo
1 of 61
Operations
         Risk
‘Management’

                          ISSA NL
   Eurojust Den Haag, June 20 2012
               Jurgen van der Vlugt
Agenda

                                                     Intro

                                                     ORM

          The Totalitarian Dictatorship
                                 of the
               Perfected Bureaucracy

                                                 Was Nun?
Operations Risk 'Management' ISSA June 20 2012
•   Jurgen = Ir.drs. J. van der Vlugt RE CISA CRISC
•   Maverisk Consultancy, IS Audit and Advisory services
    (KPMG, ABN AMRO, Noordbeek, Achmea, ABN AMRO
     322 (F16) sqn, RNLAF Vlb Leeuwarden-Noord)
•   (IS) Audit, (Info)Security, Y2k, BCM, ERM/ORM
•   ISSA, NOREA: Various committees

                              Operations Risk 'Management' ISSA June 20 2012
You


Interruptions,
Please!
• WIP
• Contestable content



                                                                   (Hi Darryl! )



                  Operations Risk 'Management' ISSA June 20 2012
Agenda

                                                     Intro

                                                 → ORM

          The Totalitarian Dictatorship
                                 of the
               Perfected Bureaucracy

                                                 Was Nun?
Operations Risk 'Management' ISSA June 20 2012
Infosec; traditionally bottom-up




  Operations Risk 'Management' ISSA June 20 2012
B2
    •    5 / 95 pp. Mention of ‘O’ (incl ToC)
    •    ‘Guidance’ → Hobson’s choice …
         … → Catch-22 (zie verderop)
    •    Loss db driven (stats)
    •    Amateur mistakes:
           • Event = 1 Cause, 1 Effect … At best: ± n:1:m
           • Non-orthogonal categories, weak definitions
           • No time aspect, no feedback loops
    •    Modeling: Figure it out yourself
    •    Wrong model




Operations Risk 'Management' ISSA June 20 2012
(Intermission: Turf wars)


                              Many small errors; easily undone or insignificant


Freq
                                   Material (significant) damage; will occur frequently
       Ops                         (but is not ‘routine’)
       Los
       ses

                                                     Break-the-business incidents;
                                                     organization will not survive the hit


             Security
             Incidents
                                               Threats to continuity

                                                               Impact



              Operations Risk 'Management' ISSA June 20 2012
‘Risk’ ‘Methodology’

• Risk = Chance x Impact (H/M/L, 3/5-scale)
         Initiële auditissues                                               Forecast ultimo 2011

                                    1           2

                                        3               4                       4                  3


                                5
                                            9

                          7         8               6
                                                                                            9
  Kans




                                                            Kans
                                                                                    6



                                                                    2
                                                                        7
                                                                    1




                Impact                                                                  Impact




                              Operations Risk 'Management' ISSA June 20 2012
Risk ‘methodologu’
• 1 Kans         Shame!
•  … per? Year? Transaction? Nanosecond?
• 1 Impact       Shame!
•  … Only financial? Reputation, etc.?
• H x H = 25     Shame!
• 3xM=H          Shame!
• ’16’ > ’12’    Shame!
• Who estimates ‘H’;
  how and with what evidence?
• No-one corrects that?

          Operations Risk 'Management' ISSA June 20 2012
n:m and feedback, and time, continuity




          Operations Risk 'Management' ISSA June 20 2012
‘In control’ …?




Operations Risk 'Management' ISSA June 20 2012
Wait, there’s more




Operations Risk 'Management' ISSA June 20 2012
Wait… even more




In particular, for any consistent,
effectively generated formal
theory that proves certain basic
arithmetic truths, there is an
arithmetical statement that is
true, but not provable in the theory.
Kurt Gödel



No matter how perfect you try to
protect, infosec incidents will
happen
Yours Truly             Operations Risk 'Management' ISSA June 20 2012
‘Turkey before Thanksgiving’




Operations Risk 'Management' ISSA June 20 2012
Don’t start on cost issues

What was it astronaut John
Glenn said went through his mind
as he awaited lift-off?
"You're thinking you're sitting on
top of the most complex machine
ever built by man, with a million
separate components, all
supplied by the lowest bidder."

               Operations Risk 'Management' ISSA June 20 2012
Attempting functions


              ∫    ( Chance × Impact )


       ∑( Costs of countermeasures )
For many series of functions and parameters, impact estimate
ranges (…), variable sets of countermeasures
Including variable degrees of effectiveness, with vague notions
of risk appetites in some backs of minds

(I’ll come back to that later)

                      Operations Risk 'Management' ISSA June 20 2012
Yes but …: your arguments

1.    Yes we know all that. Nothing’s perfect.
2.    The assumptions are reasonable.
3.    The assumptions don’t really matter.
4.    The assumptions are conservative.
5.    You cannot prove the assumptions are wrong.
6.    We only do what everyone else does.
7.    The decision maker is better off with us than without us.
8.    The models are not completely useless.
9.    You gotta make the best of the data you’ve got.
10.   You need assumptions to make progress.
11.   The models deserve the benefit of the doubt.
12.   Models and assumptions don’t do any harm so why bother …?

© David Freedman (in Nassim Taleb’s Black Swan)


                      Operations Risk 'Management' ISSA June 20 2012
Operations Risk 'Management' ISSA June 20 2012
Operational Risk (≡ ..?) ‘Management’
Evaluate design &                        Analysis                            Monitor & react
     set-up

                             Operational Risk                               Problem
                              Management                                      Mgt
                                                                                Incidents
  ORAP         Inherent
                                  Controls           Risk indicators            for analysis
               risks                                                            (Problems)

               R(S)A              (K)ORC                      KRI               Incident
              (+Audit)             (Mgt)                     (Mgt)                Mgt           Insu-
                           Designed,         Tuning,
                                                                      Near                      rance
                         Selected for        Mandatory
                                                                      misses        CLD          Mgt
                           efficiency                                  Corrective
                                                       KRI             actions
                                                    values                          Incidents    Indemnities



           Process
                                           Breach
                           Operations Risk 'Management' ISSA June 20 2012
Agenda

                                                     Intro

                                                     ORM

  → The Totalitarian Dictatorship
                           of the
         Perfected Bureaucracy

                                                 Was Nun?
Operations Risk 'Management' ISSA June 20 2012
3LoD quod non

Very, very basically




 Surprise!



             Operations Risk 'Management' ISSA June 20 2012
Operations Risk 'Management' ISSA June 20 2012
Operations Risk 'Management' ISSA June 20 2012
(Defense in Depth)




                                                 …?


Operations Risk 'Management' ISSA June 20 2012
Not to mention
                                                 1937 ..!




Operations Risk 'Management' ISSA June 20 2012
Result




Operations Risk 'Management' ISSA June 20 2012
The Illusion of Being In Control




                                             Hey, Darryl again !)



Operations Risk 'Management' ISSA June 20 2012
(Intermission: Mandatory Reading)




     Operations Risk 'Management' ISSA June 20 2012
Be my guest




Operations Risk 'Management' ISSA June 20 2012
You of course know better than the
                            Dakota




      Operations Risk 'Management' ISSA June 20 2012
→




Operations Risk 'Management' ISSA June 20 2012
Agenda

                                                       Intro

                                                       ORM

          The Totalitarian Dictatorship
                                 of the
               Perfected Bureaucracy

                                                 → Was Nun?
Operations Risk 'Management' ISSA June 20 2012
Was nun ...? (I)




Operations Risk 'Management' ISSA June 20 2012
Was nun … ? (II)


In theory, nothing works,                  In practice, everything works,
and                                               but no-one knows why.
Everyone knows why.




       We have in our organisation a combination
                of theory and practice.


                    Operations Risk 'Management' ISSA June 20 2012
Was Nun …? (III)

• Alternative approaches from the risk
  perspective
  → Much better modeling
• Alternative approaches from a trust angle
  (Qualitative approaches)
  → Yikes!
• Alternative approaches from the (info)sec field
  → Doing much better what needs to be done

                Operations Risk 'Management' ISSA June 20 2012
Modeling
     in
   rk s
 o
W re s
prog
              =


      Operations Risk 'Management' ISSA June 20 2012
Some pointers; what quant helps out?
• (F)actors
  • ‘Threat’ factors, maybe or maybe not also being
  • ‘Control’ factors, maybe or maybe not also being
  • ‘Vulnerability’ factors
• Continuously (! in time) variable qua
  •   Chance
  •   Severity/size
  •   Impacts (mult.) on (variable #) other factors
  •   Feedback (var. #, impact, time lags) on other
      factors

                  Operations Risk 'Management' ISSA June 20 2012
Which should lead to:

• All sorts of continuous functions,
  continuously variable (time, parameters)
  →
  ‘normal’ Markov chains don’t work
• Bootstrapping parameter estimations →
  lots of data required
• Modeling the unk unk’s; good luck


             Operations Risk 'Management' ISSA June 20 2012
Consumes a lot of time …
• Is all required data available?
• Are the models developed yet,
  and tested for robustness …? (re parameter sensitivity ++)
• What if reality turns out to be uncontrollable ..?
  (Koot&Bie, 1977)

• Ow well, we’ll just sit and wait …?

• And if we don’t get ‘it’ done:
  “Inzicht, doorzicht en op tijd een banaan.”
  Management ≡ Decision making with limited information!


                  Operations Risk 'Management' ISSA June 20 2012
In the mean time

• Do the right thing right
• Stress




               Operations Risk 'Management' ISSA June 20 2012
Doing the right things right




Operations Risk 'Management' ISSA June 20 2012
That is complex enough in itself




   Operations Risk 'Management' ISSA June 20 2012
The new world




Operations Risk 'Management' ISSA June 20 2012
And of course: Stress




Operations Risk 'Management' ISSA June 20 2012
(RNLAF 323sqn vlb Leeuwarden-Zuid)




Operations Risk 'Management' ISSA June 20 2012
We do that already, in infosec (?)

• Data- and system oriented CIA
  Requirements, tests
• Defence in Depth:


 (                                             )
• Monitoring, pentesting, fallback testing, etc.


              Operations Risk 'Management' ISSA June 20 2012
And for the risk managers in the room …




           Operations Risk 'Management' ISSA June 20 2012
Bruce Schneier




Operations Risk 'Management' ISSA June 20 2012
Resultaat




Operations Risk 'Management' ISSA June 20 2012
Top-down and bottom-up

•   And/or middle-out
•   Don’t switch over but continuously all the way
•   Re-think trust-/control-models
•   Do The Right Thing
•   Be certain there’ll be defectors

• Against diffusion of accountability,
• Watch Coase’s ceiling

                 Operations Risk 'Management' ISSA June 20 2012
High demands




Operations Risk 'Management' ISSA June 20 2012
Agenda

                                                       Intro

                                                       ORM

          The Totalitarian Dictatorship
                                 of the
               Perfected Bureaucracy

                                                 → Was Nun?
Operations Risk 'Management' ISSA June 20 2012
Summing up
• Our (O)RM methods are wrong (not a bit)
  • Enthousiastically down a blind alley
  • False view on reality →
  • Wrong risk management. And you know it!
• Totalitarian dictatorship of the perfected
  bureaucracy doesn’t help against anything &
  gives (also) false sense of In Control
• Are you part of that ..?
• Let’s ‘pre-emptively’ build some
  methodology bottom-up
              Operations Risk 'Management' ISSA June 20 2012
Solution: less, more




Operations Risk 'Management' ISSA June 20 2012
Yes, the methodology is Work In Progress,
                                hence …




         Operations Risk 'Management' ISSA June 20 2012
That was all. Thank you.




                  Hope you enjoy(ed) the ride
             Operations Risk 'Management' ISSA June 20 2012
Operations Risk 'Management' ISSA June 20 2012
Contact details

Jurgen van der Vlugt,
Maverisk Consultancy, IS Audit and Advisory services:

•   Jvdvlugt åt maverisk døt nl
•   LinkedIn, Twitter (etc.etc.)
•   Tel +31-(0)6-206.648.23

•   www.maverisk.nl



Motivate yourself! www.despair.com/viewall.html




                          Operations Risk 'Management' ISSA June 20 2012
(Even More Mandatory Reading)




   Operations Risk 'Management' ISSA June 20 2012
The End, really.




                   Unintentionally left blank.
      Really, this was not the plan. The plan called for
lots of stuff here. But noooo, it had to turn out blank. Darn.




                Operations Risk 'Management' ISSA June 20 2012

More Related Content

Similar to ISSA ORM 2012 June 20 v0.3

Webinar | Risk management in asset management
Webinar | Risk management in asset managementWebinar | Risk management in asset management
Webinar | Risk management in asset managementStork
 
Victorallen 120309142950-phpapp01
Victorallen 120309142950-phpapp01Victorallen 120309142950-phpapp01
Victorallen 120309142950-phpapp01mkgmale1
 
Managing Risks on Construction Projects - Victor Allen, DTE Energy
Managing Risks on Construction Projects - Victor Allen, DTE EnergyManaging Risks on Construction Projects - Victor Allen, DTE Energy
Managing Risks on Construction Projects - Victor Allen, DTE EnergyEnergy Network marcus evans
 
Best Practices in Applied Behavioral Finance
Best Practices in Applied Behavioral FinanceBest Practices in Applied Behavioral Finance
Best Practices in Applied Behavioral Financetnunnally
 
IT Risk Management - the right posture
IT Risk Management - the right postureIT Risk Management - the right posture
IT Risk Management - the right postureParag Deodhar
 
CFO Summit XVI - Wheelhouse Advisors LLC
CFO Summit XVI - Wheelhouse Advisors LLCCFO Summit XVI - Wheelhouse Advisors LLC
CFO Summit XVI - Wheelhouse Advisors LLCWheelhouse Advisors LLC
 
The Role of CRO at Credit Suisee
The Role of CRO at Credit SuiseeThe Role of CRO at Credit Suisee
The Role of CRO at Credit SuiseeCapco
 
Annual Company Risk Assessment
Annual Company Risk AssessmentAnnual Company Risk Assessment
Annual Company Risk AssessmentMusavie Abdillah
 
Workshop project risk management (29 june 2012)
Workshop   project risk management (29 june 2012)Workshop   project risk management (29 june 2012)
Workshop project risk management (29 june 2012)bfriday
 

Similar to ISSA ORM 2012 June 20 v0.3 (11)

Webinar | Risk management in asset management
Webinar | Risk management in asset managementWebinar | Risk management in asset management
Webinar | Risk management in asset management
 
Victorallen 120309142950-phpapp01
Victorallen 120309142950-phpapp01Victorallen 120309142950-phpapp01
Victorallen 120309142950-phpapp01
 
Managing Risks on Construction Projects - Victor Allen, DTE Energy
Managing Risks on Construction Projects - Victor Allen, DTE EnergyManaging Risks on Construction Projects - Victor Allen, DTE Energy
Managing Risks on Construction Projects - Victor Allen, DTE Energy
 
Tc Sms 09
Tc Sms 09Tc Sms 09
Tc Sms 09
 
Best Practices in Applied Behavioral Finance
Best Practices in Applied Behavioral FinanceBest Practices in Applied Behavioral Finance
Best Practices in Applied Behavioral Finance
 
IT Risk Management - the right posture
IT Risk Management - the right postureIT Risk Management - the right posture
IT Risk Management - the right posture
 
Interest rate risk modeling day sun_gard_ambit banking
Interest rate risk modeling day sun_gard_ambit bankingInterest rate risk modeling day sun_gard_ambit banking
Interest rate risk modeling day sun_gard_ambit banking
 
CFO Summit XVI - Wheelhouse Advisors LLC
CFO Summit XVI - Wheelhouse Advisors LLCCFO Summit XVI - Wheelhouse Advisors LLC
CFO Summit XVI - Wheelhouse Advisors LLC
 
The Role of CRO at Credit Suisee
The Role of CRO at Credit SuiseeThe Role of CRO at Credit Suisee
The Role of CRO at Credit Suisee
 
Annual Company Risk Assessment
Annual Company Risk AssessmentAnnual Company Risk Assessment
Annual Company Risk Assessment
 
Workshop project risk management (29 june 2012)
Workshop   project risk management (29 june 2012)Workshop   project risk management (29 june 2012)
Workshop project risk management (29 june 2012)
 

More from Jurgen van der Vlugt

ACAM-VDA NOREA Adviesdiensten 21 juni 2012
ACAM-VDA NOREA Adviesdiensten 21 juni 2012ACAM-VDA NOREA Adviesdiensten 21 juni 2012
ACAM-VDA NOREA Adviesdiensten 21 juni 2012Jurgen van der Vlugt
 
Adviesdiensten Norea Regio Noord 2012 05 10
Adviesdiensten Norea Regio Noord 2012 05 10Adviesdiensten Norea Regio Noord 2012 05 10
Adviesdiensten Norea Regio Noord 2012 05 10Jurgen van der Vlugt
 
Van Plank Misslaan Naar Spijker Op De Kop V0.3
Van Plank Misslaan Naar Spijker Op De Kop V0.3Van Plank Misslaan Naar Spijker Op De Kop V0.3
Van Plank Misslaan Naar Spijker Op De Kop V0.3Jurgen van der Vlugt
 
Advies Assurance September 2011 V0.97
Advies Assurance September 2011 V0.97Advies Assurance September 2011 V0.97
Advies Assurance September 2011 V0.97Jurgen van der Vlugt
 
VU Information Risk Management Security Management 2010 JvdV
VU Information Risk Management  Security Management 2010 JvdVVU Information Risk Management  Security Management 2010 JvdV
VU Information Risk Management Security Management 2010 JvdVJurgen van der Vlugt
 
VU Organisatie van het beroep Reglementering Deel I 21 mei 2010
VU Organisatie van het beroep   Reglementering Deel I 21 mei 2010VU Organisatie van het beroep   Reglementering Deel I 21 mei 2010
VU Organisatie van het beroep Reglementering Deel I 21 mei 2010Jurgen van der Vlugt
 
VU Uitvoering van de audit 28 mei 2010
VU Uitvoering van de audit 28 mei 2010VU Uitvoering van de audit 28 mei 2010
VU Uitvoering van de audit 28 mei 2010Jurgen van der Vlugt
 
Saxion Enschedé College Security 2009
Saxion Enschedé College Security 2009Saxion Enschedé College Security 2009
Saxion Enschedé College Security 2009Jurgen van der Vlugt
 
NOREA Update congres 2007 incl notes
NOREA Update congres 2007 incl notesNOREA Update congres 2007 incl notes
NOREA Update congres 2007 incl notesJurgen van der Vlugt
 
NOREA Regiosessie Reglementen 2010
NOREA Regiosessie Reglementen 2010NOREA Regiosessie Reglementen 2010
NOREA Regiosessie Reglementen 2010Jurgen van der Vlugt
 
Saxion Enschedé College Security 2010
Saxion Enschedé College Security 2010Saxion Enschedé College Security 2010
Saxion Enschedé College Security 2010Jurgen van der Vlugt
 

More from Jurgen van der Vlugt (13)

Much Data 0.95
Much Data 0.95Much Data 0.95
Much Data 0.95
 
ACAM-VDA NOREA Adviesdiensten 21 juni 2012
ACAM-VDA NOREA Adviesdiensten 21 juni 2012ACAM-VDA NOREA Adviesdiensten 21 juni 2012
ACAM-VDA NOREA Adviesdiensten 21 juni 2012
 
Adviesdiensten Norea Regio Noord 2012 05 10
Adviesdiensten Norea Regio Noord 2012 05 10Adviesdiensten Norea Regio Noord 2012 05 10
Adviesdiensten Norea Regio Noord 2012 05 10
 
Van Plank Misslaan Naar Spijker Op De Kop V0.3
Van Plank Misslaan Naar Spijker Op De Kop V0.3Van Plank Misslaan Naar Spijker Op De Kop V0.3
Van Plank Misslaan Naar Spijker Op De Kop V0.3
 
Advies Assurance September 2011 V0.97
Advies Assurance September 2011 V0.97Advies Assurance September 2011 V0.97
Advies Assurance September 2011 V0.97
 
VU Information Risk Management Security Management 2010 JvdV
VU Information Risk Management  Security Management 2010 JvdVVU Information Risk Management  Security Management 2010 JvdV
VU Information Risk Management Security Management 2010 JvdV
 
VU Organisatie van het beroep Reglementering Deel I 21 mei 2010
VU Organisatie van het beroep   Reglementering Deel I 21 mei 2010VU Organisatie van het beroep   Reglementering Deel I 21 mei 2010
VU Organisatie van het beroep Reglementering Deel I 21 mei 2010
 
VU Uitvoering van de audit 28 mei 2010
VU Uitvoering van de audit 28 mei 2010VU Uitvoering van de audit 28 mei 2010
VU Uitvoering van de audit 28 mei 2010
 
Saxion Enschedé College Security 2009
Saxion Enschedé College Security 2009Saxion Enschedé College Security 2009
Saxion Enschedé College Security 2009
 
NOREA Update congres 2007 incl notes
NOREA Update congres 2007 incl notesNOREA Update congres 2007 incl notes
NOREA Update congres 2007 incl notes
 
NOREA ALV Symposium Advies 2010
NOREA ALV Symposium Advies 2010NOREA ALV Symposium Advies 2010
NOREA ALV Symposium Advies 2010
 
NOREA Regiosessie Reglementen 2010
NOREA Regiosessie Reglementen 2010NOREA Regiosessie Reglementen 2010
NOREA Regiosessie Reglementen 2010
 
Saxion Enschedé College Security 2010
Saxion Enschedé College Security 2010Saxion Enschedé College Security 2010
Saxion Enschedé College Security 2010
 

Recently uploaded

Kenya Coconut Production Presentation by Dr. Lalith Perera
Kenya Coconut Production Presentation by Dr. Lalith PereraKenya Coconut Production Presentation by Dr. Lalith Perera
Kenya Coconut Production Presentation by Dr. Lalith Pereraictsugar
 
Digital Transformation in the PLM domain - distrib.pdf
Digital Transformation in the PLM domain - distrib.pdfDigital Transformation in the PLM domain - distrib.pdf
Digital Transformation in the PLM domain - distrib.pdfJos Voskuil
 
India Consumer 2024 Redacted Sample Report
India Consumer 2024 Redacted Sample ReportIndia Consumer 2024 Redacted Sample Report
India Consumer 2024 Redacted Sample ReportMintel Group
 
8447779800, Low rate Call girls in Uttam Nagar Delhi NCR
8447779800, Low rate Call girls in Uttam Nagar Delhi NCR8447779800, Low rate Call girls in Uttam Nagar Delhi NCR
8447779800, Low rate Call girls in Uttam Nagar Delhi NCRashishs7044
 
Global Scenario On Sustainable and Resilient Coconut Industry by Dr. Jelfina...
Global Scenario On Sustainable  and Resilient Coconut Industry by Dr. Jelfina...Global Scenario On Sustainable  and Resilient Coconut Industry by Dr. Jelfina...
Global Scenario On Sustainable and Resilient Coconut Industry by Dr. Jelfina...ictsugar
 
Call Girls in DELHI Cantt, ( Call Me )-8377877756-Female Escort- In Delhi / Ncr
Call Girls in DELHI Cantt, ( Call Me )-8377877756-Female Escort- In Delhi / NcrCall Girls in DELHI Cantt, ( Call Me )-8377877756-Female Escort- In Delhi / Ncr
Call Girls in DELHI Cantt, ( Call Me )-8377877756-Female Escort- In Delhi / Ncrdollysharma2066
 
Marketplace and Quality Assurance Presentation - Vincent Chirchir
Marketplace and Quality Assurance Presentation - Vincent ChirchirMarketplace and Quality Assurance Presentation - Vincent Chirchir
Marketplace and Quality Assurance Presentation - Vincent Chirchirictsugar
 
Pitch Deck Teardown: Geodesic.Life's $500k Pre-seed deck
Pitch Deck Teardown: Geodesic.Life's $500k Pre-seed deckPitch Deck Teardown: Geodesic.Life's $500k Pre-seed deck
Pitch Deck Teardown: Geodesic.Life's $500k Pre-seed deckHajeJanKamps
 
MAHA Global and IPR: Do Actions Speak Louder Than Words?
MAHA Global and IPR: Do Actions Speak Louder Than Words?MAHA Global and IPR: Do Actions Speak Louder Than Words?
MAHA Global and IPR: Do Actions Speak Louder Than Words?Olivia Kresic
 
2024 Numerator Consumer Study of Cannabis Usage
2024 Numerator Consumer Study of Cannabis Usage2024 Numerator Consumer Study of Cannabis Usage
2024 Numerator Consumer Study of Cannabis UsageNeil Kimberley
 
Buy gmail accounts.pdf Buy Old Gmail Accounts
Buy gmail accounts.pdf Buy Old Gmail AccountsBuy gmail accounts.pdf Buy Old Gmail Accounts
Buy gmail accounts.pdf Buy Old Gmail AccountsBuy Verified Accounts
 
PSCC - Capability Statement Presentation
PSCC - Capability Statement PresentationPSCC - Capability Statement Presentation
PSCC - Capability Statement PresentationAnamaria Contreras
 
Call US-88OO1O2216 Call Girls In Mahipalpur Female Escort Service
Call US-88OO1O2216 Call Girls In Mahipalpur Female Escort ServiceCall US-88OO1O2216 Call Girls In Mahipalpur Female Escort Service
Call US-88OO1O2216 Call Girls In Mahipalpur Female Escort Servicecallgirls2057
 
Traction part 2 - EOS Model JAX Bridges.
Traction part 2 - EOS Model JAX Bridges.Traction part 2 - EOS Model JAX Bridges.
Traction part 2 - EOS Model JAX Bridges.Anamaria Contreras
 
Memorándum de Entendimiento (MoU) entre Codelco y SQM
Memorándum de Entendimiento (MoU) entre Codelco y SQMMemorándum de Entendimiento (MoU) entre Codelco y SQM
Memorándum de Entendimiento (MoU) entre Codelco y SQMVoces Mineras
 
Cybersecurity Awareness Training Presentation v2024.03
Cybersecurity Awareness Training Presentation v2024.03Cybersecurity Awareness Training Presentation v2024.03
Cybersecurity Awareness Training Presentation v2024.03DallasHaselhorst
 
8447779800, Low rate Call girls in Tughlakabad Delhi NCR
8447779800, Low rate Call girls in Tughlakabad Delhi NCR8447779800, Low rate Call girls in Tughlakabad Delhi NCR
8447779800, Low rate Call girls in Tughlakabad Delhi NCRashishs7044
 
Investment in The Coconut Industry by Nancy Cheruiyot
Investment in The Coconut Industry by Nancy CheruiyotInvestment in The Coconut Industry by Nancy Cheruiyot
Investment in The Coconut Industry by Nancy Cheruiyotictsugar
 
8447779800, Low rate Call girls in Saket Delhi NCR
8447779800, Low rate Call girls in Saket Delhi NCR8447779800, Low rate Call girls in Saket Delhi NCR
8447779800, Low rate Call girls in Saket Delhi NCRashishs7044
 

Recently uploaded (20)

Kenya Coconut Production Presentation by Dr. Lalith Perera
Kenya Coconut Production Presentation by Dr. Lalith PereraKenya Coconut Production Presentation by Dr. Lalith Perera
Kenya Coconut Production Presentation by Dr. Lalith Perera
 
Digital Transformation in the PLM domain - distrib.pdf
Digital Transformation in the PLM domain - distrib.pdfDigital Transformation in the PLM domain - distrib.pdf
Digital Transformation in the PLM domain - distrib.pdf
 
India Consumer 2024 Redacted Sample Report
India Consumer 2024 Redacted Sample ReportIndia Consumer 2024 Redacted Sample Report
India Consumer 2024 Redacted Sample Report
 
8447779800, Low rate Call girls in Uttam Nagar Delhi NCR
8447779800, Low rate Call girls in Uttam Nagar Delhi NCR8447779800, Low rate Call girls in Uttam Nagar Delhi NCR
8447779800, Low rate Call girls in Uttam Nagar Delhi NCR
 
Global Scenario On Sustainable and Resilient Coconut Industry by Dr. Jelfina...
Global Scenario On Sustainable  and Resilient Coconut Industry by Dr. Jelfina...Global Scenario On Sustainable  and Resilient Coconut Industry by Dr. Jelfina...
Global Scenario On Sustainable and Resilient Coconut Industry by Dr. Jelfina...
 
Call Girls in DELHI Cantt, ( Call Me )-8377877756-Female Escort- In Delhi / Ncr
Call Girls in DELHI Cantt, ( Call Me )-8377877756-Female Escort- In Delhi / NcrCall Girls in DELHI Cantt, ( Call Me )-8377877756-Female Escort- In Delhi / Ncr
Call Girls in DELHI Cantt, ( Call Me )-8377877756-Female Escort- In Delhi / Ncr
 
Marketplace and Quality Assurance Presentation - Vincent Chirchir
Marketplace and Quality Assurance Presentation - Vincent ChirchirMarketplace and Quality Assurance Presentation - Vincent Chirchir
Marketplace and Quality Assurance Presentation - Vincent Chirchir
 
Pitch Deck Teardown: Geodesic.Life's $500k Pre-seed deck
Pitch Deck Teardown: Geodesic.Life's $500k Pre-seed deckPitch Deck Teardown: Geodesic.Life's $500k Pre-seed deck
Pitch Deck Teardown: Geodesic.Life's $500k Pre-seed deck
 
MAHA Global and IPR: Do Actions Speak Louder Than Words?
MAHA Global and IPR: Do Actions Speak Louder Than Words?MAHA Global and IPR: Do Actions Speak Louder Than Words?
MAHA Global and IPR: Do Actions Speak Louder Than Words?
 
2024 Numerator Consumer Study of Cannabis Usage
2024 Numerator Consumer Study of Cannabis Usage2024 Numerator Consumer Study of Cannabis Usage
2024 Numerator Consumer Study of Cannabis Usage
 
Buy gmail accounts.pdf Buy Old Gmail Accounts
Buy gmail accounts.pdf Buy Old Gmail AccountsBuy gmail accounts.pdf Buy Old Gmail Accounts
Buy gmail accounts.pdf Buy Old Gmail Accounts
 
PSCC - Capability Statement Presentation
PSCC - Capability Statement PresentationPSCC - Capability Statement Presentation
PSCC - Capability Statement Presentation
 
Call US-88OO1O2216 Call Girls In Mahipalpur Female Escort Service
Call US-88OO1O2216 Call Girls In Mahipalpur Female Escort ServiceCall US-88OO1O2216 Call Girls In Mahipalpur Female Escort Service
Call US-88OO1O2216 Call Girls In Mahipalpur Female Escort Service
 
Traction part 2 - EOS Model JAX Bridges.
Traction part 2 - EOS Model JAX Bridges.Traction part 2 - EOS Model JAX Bridges.
Traction part 2 - EOS Model JAX Bridges.
 
Corporate Profile 47Billion Information Technology
Corporate Profile 47Billion Information TechnologyCorporate Profile 47Billion Information Technology
Corporate Profile 47Billion Information Technology
 
Memorándum de Entendimiento (MoU) entre Codelco y SQM
Memorándum de Entendimiento (MoU) entre Codelco y SQMMemorándum de Entendimiento (MoU) entre Codelco y SQM
Memorándum de Entendimiento (MoU) entre Codelco y SQM
 
Cybersecurity Awareness Training Presentation v2024.03
Cybersecurity Awareness Training Presentation v2024.03Cybersecurity Awareness Training Presentation v2024.03
Cybersecurity Awareness Training Presentation v2024.03
 
8447779800, Low rate Call girls in Tughlakabad Delhi NCR
8447779800, Low rate Call girls in Tughlakabad Delhi NCR8447779800, Low rate Call girls in Tughlakabad Delhi NCR
8447779800, Low rate Call girls in Tughlakabad Delhi NCR
 
Investment in The Coconut Industry by Nancy Cheruiyot
Investment in The Coconut Industry by Nancy CheruiyotInvestment in The Coconut Industry by Nancy Cheruiyot
Investment in The Coconut Industry by Nancy Cheruiyot
 
8447779800, Low rate Call girls in Saket Delhi NCR
8447779800, Low rate Call girls in Saket Delhi NCR8447779800, Low rate Call girls in Saket Delhi NCR
8447779800, Low rate Call girls in Saket Delhi NCR
 

ISSA ORM 2012 June 20 v0.3

  • 1. Operations Risk ‘Management’ ISSA NL Eurojust Den Haag, June 20 2012 Jurgen van der Vlugt
  • 2. Agenda Intro ORM The Totalitarian Dictatorship of the Perfected Bureaucracy Was Nun? Operations Risk 'Management' ISSA June 20 2012
  • 3. Jurgen = Ir.drs. J. van der Vlugt RE CISA CRISC • Maverisk Consultancy, IS Audit and Advisory services (KPMG, ABN AMRO, Noordbeek, Achmea, ABN AMRO 322 (F16) sqn, RNLAF Vlb Leeuwarden-Noord) • (IS) Audit, (Info)Security, Y2k, BCM, ERM/ORM • ISSA, NOREA: Various committees Operations Risk 'Management' ISSA June 20 2012
  • 4. You Interruptions, Please! • WIP • Contestable content (Hi Darryl! ) Operations Risk 'Management' ISSA June 20 2012
  • 5. Agenda Intro → ORM The Totalitarian Dictatorship of the Perfected Bureaucracy Was Nun? Operations Risk 'Management' ISSA June 20 2012
  • 6. Infosec; traditionally bottom-up Operations Risk 'Management' ISSA June 20 2012
  • 7. B2 • 5 / 95 pp. Mention of ‘O’ (incl ToC) • ‘Guidance’ → Hobson’s choice … … → Catch-22 (zie verderop) • Loss db driven (stats) • Amateur mistakes: • Event = 1 Cause, 1 Effect … At best: ± n:1:m • Non-orthogonal categories, weak definitions • No time aspect, no feedback loops • Modeling: Figure it out yourself • Wrong model Operations Risk 'Management' ISSA June 20 2012
  • 8. (Intermission: Turf wars) Many small errors; easily undone or insignificant Freq Material (significant) damage; will occur frequently Ops (but is not ‘routine’) Los ses Break-the-business incidents; organization will not survive the hit Security Incidents Threats to continuity Impact Operations Risk 'Management' ISSA June 20 2012
  • 9. ‘Risk’ ‘Methodology’ • Risk = Chance x Impact (H/M/L, 3/5-scale) Initiële auditissues Forecast ultimo 2011 1 2 3 4 4 3 5 9 7 8 6 9 Kans Kans 6 2 7 1 Impact Impact Operations Risk 'Management' ISSA June 20 2012
  • 10. Risk ‘methodologu’ • 1 Kans Shame! • … per? Year? Transaction? Nanosecond? • 1 Impact Shame! • … Only financial? Reputation, etc.? • H x H = 25 Shame! • 3xM=H Shame! • ’16’ > ’12’ Shame! • Who estimates ‘H’; how and with what evidence? • No-one corrects that? Operations Risk 'Management' ISSA June 20 2012
  • 11. n:m and feedback, and time, continuity Operations Risk 'Management' ISSA June 20 2012
  • 12. ‘In control’ …? Operations Risk 'Management' ISSA June 20 2012
  • 13. Wait, there’s more Operations Risk 'Management' ISSA June 20 2012
  • 14. Wait… even more In particular, for any consistent, effectively generated formal theory that proves certain basic arithmetic truths, there is an arithmetical statement that is true, but not provable in the theory. Kurt Gödel No matter how perfect you try to protect, infosec incidents will happen Yours Truly Operations Risk 'Management' ISSA June 20 2012
  • 15. ‘Turkey before Thanksgiving’ Operations Risk 'Management' ISSA June 20 2012
  • 16. Don’t start on cost issues What was it astronaut John Glenn said went through his mind as he awaited lift-off? "You're thinking you're sitting on top of the most complex machine ever built by man, with a million separate components, all supplied by the lowest bidder." Operations Risk 'Management' ISSA June 20 2012
  • 17. Attempting functions ∫ ( Chance × Impact ) ∑( Costs of countermeasures ) For many series of functions and parameters, impact estimate ranges (…), variable sets of countermeasures Including variable degrees of effectiveness, with vague notions of risk appetites in some backs of minds (I’ll come back to that later) Operations Risk 'Management' ISSA June 20 2012
  • 18. Yes but …: your arguments 1. Yes we know all that. Nothing’s perfect. 2. The assumptions are reasonable. 3. The assumptions don’t really matter. 4. The assumptions are conservative. 5. You cannot prove the assumptions are wrong. 6. We only do what everyone else does. 7. The decision maker is better off with us than without us. 8. The models are not completely useless. 9. You gotta make the best of the data you’ve got. 10. You need assumptions to make progress. 11. The models deserve the benefit of the doubt. 12. Models and assumptions don’t do any harm so why bother …? © David Freedman (in Nassim Taleb’s Black Swan) Operations Risk 'Management' ISSA June 20 2012
  • 19. Operations Risk 'Management' ISSA June 20 2012
  • 20. Operational Risk (≡ ..?) ‘Management’ Evaluate design & Analysis Monitor & react set-up Operational Risk Problem Management Mgt Incidents ORAP Inherent Controls Risk indicators for analysis risks (Problems) R(S)A (K)ORC KRI Incident (+Audit) (Mgt) (Mgt) Mgt Insu- Designed, Tuning, Near rance Selected for Mandatory misses CLD Mgt efficiency Corrective KRI actions values Incidents Indemnities Process Breach Operations Risk 'Management' ISSA June 20 2012
  • 21. Agenda Intro ORM → The Totalitarian Dictatorship of the Perfected Bureaucracy Was Nun? Operations Risk 'Management' ISSA June 20 2012
  • 22. 3LoD quod non Very, very basically Surprise! Operations Risk 'Management' ISSA June 20 2012
  • 23. Operations Risk 'Management' ISSA June 20 2012
  • 24. Operations Risk 'Management' ISSA June 20 2012
  • 25. (Defense in Depth) …? Operations Risk 'Management' ISSA June 20 2012
  • 26. Not to mention 1937 ..! Operations Risk 'Management' ISSA June 20 2012
  • 28. The Illusion of Being In Control Hey, Darryl again !) Operations Risk 'Management' ISSA June 20 2012
  • 29. (Intermission: Mandatory Reading) Operations Risk 'Management' ISSA June 20 2012
  • 30. Be my guest Operations Risk 'Management' ISSA June 20 2012
  • 31. You of course know better than the Dakota Operations Risk 'Management' ISSA June 20 2012
  • 32. → Operations Risk 'Management' ISSA June 20 2012
  • 33. Agenda Intro ORM The Totalitarian Dictatorship of the Perfected Bureaucracy → Was Nun? Operations Risk 'Management' ISSA June 20 2012
  • 34. Was nun ...? (I) Operations Risk 'Management' ISSA June 20 2012
  • 35. Was nun … ? (II) In theory, nothing works, In practice, everything works, and but no-one knows why. Everyone knows why. We have in our organisation a combination of theory and practice. Operations Risk 'Management' ISSA June 20 2012
  • 36. Was Nun …? (III) • Alternative approaches from the risk perspective → Much better modeling • Alternative approaches from a trust angle (Qualitative approaches) → Yikes! • Alternative approaches from the (info)sec field → Doing much better what needs to be done Operations Risk 'Management' ISSA June 20 2012
  • 37. Modeling in rk s o W re s prog = Operations Risk 'Management' ISSA June 20 2012
  • 38. Some pointers; what quant helps out? • (F)actors • ‘Threat’ factors, maybe or maybe not also being • ‘Control’ factors, maybe or maybe not also being • ‘Vulnerability’ factors • Continuously (! in time) variable qua • Chance • Severity/size • Impacts (mult.) on (variable #) other factors • Feedback (var. #, impact, time lags) on other factors Operations Risk 'Management' ISSA June 20 2012
  • 39. Which should lead to: • All sorts of continuous functions, continuously variable (time, parameters) → ‘normal’ Markov chains don’t work • Bootstrapping parameter estimations → lots of data required • Modeling the unk unk’s; good luck Operations Risk 'Management' ISSA June 20 2012
  • 40. Consumes a lot of time … • Is all required data available? • Are the models developed yet, and tested for robustness …? (re parameter sensitivity ++) • What if reality turns out to be uncontrollable ..? (Koot&Bie, 1977) • Ow well, we’ll just sit and wait …? • And if we don’t get ‘it’ done: “Inzicht, doorzicht en op tijd een banaan.” Management ≡ Decision making with limited information! Operations Risk 'Management' ISSA June 20 2012
  • 41. In the mean time • Do the right thing right • Stress Operations Risk 'Management' ISSA June 20 2012
  • 42. Doing the right things right Operations Risk 'Management' ISSA June 20 2012
  • 43. That is complex enough in itself Operations Risk 'Management' ISSA June 20 2012
  • 44. The new world Operations Risk 'Management' ISSA June 20 2012
  • 45. And of course: Stress Operations Risk 'Management' ISSA June 20 2012
  • 46. (RNLAF 323sqn vlb Leeuwarden-Zuid) Operations Risk 'Management' ISSA June 20 2012
  • 47. We do that already, in infosec (?) • Data- and system oriented CIA Requirements, tests • Defence in Depth: ( ) • Monitoring, pentesting, fallback testing, etc. Operations Risk 'Management' ISSA June 20 2012
  • 48. And for the risk managers in the room … Operations Risk 'Management' ISSA June 20 2012
  • 49. Bruce Schneier Operations Risk 'Management' ISSA June 20 2012
  • 51. Top-down and bottom-up • And/or middle-out • Don’t switch over but continuously all the way • Re-think trust-/control-models • Do The Right Thing • Be certain there’ll be defectors • Against diffusion of accountability, • Watch Coase’s ceiling Operations Risk 'Management' ISSA June 20 2012
  • 52. High demands Operations Risk 'Management' ISSA June 20 2012
  • 53. Agenda Intro ORM The Totalitarian Dictatorship of the Perfected Bureaucracy → Was Nun? Operations Risk 'Management' ISSA June 20 2012
  • 54. Summing up • Our (O)RM methods are wrong (not a bit) • Enthousiastically down a blind alley • False view on reality → • Wrong risk management. And you know it! • Totalitarian dictatorship of the perfected bureaucracy doesn’t help against anything & gives (also) false sense of In Control • Are you part of that ..? • Let’s ‘pre-emptively’ build some methodology bottom-up Operations Risk 'Management' ISSA June 20 2012
  • 55. Solution: less, more Operations Risk 'Management' ISSA June 20 2012
  • 56. Yes, the methodology is Work In Progress, hence … Operations Risk 'Management' ISSA June 20 2012
  • 57. That was all. Thank you. Hope you enjoy(ed) the ride Operations Risk 'Management' ISSA June 20 2012
  • 58. Operations Risk 'Management' ISSA June 20 2012
  • 59. Contact details Jurgen van der Vlugt, Maverisk Consultancy, IS Audit and Advisory services: • Jvdvlugt åt maverisk døt nl • LinkedIn, Twitter (etc.etc.) • Tel +31-(0)6-206.648.23 • www.maverisk.nl Motivate yourself! www.despair.com/viewall.html Operations Risk 'Management' ISSA June 20 2012
  • 60. (Even More Mandatory Reading) Operations Risk 'Management' ISSA June 20 2012
  • 61. The End, really. Unintentionally left blank. Really, this was not the plan. The plan called for lots of stuff here. But noooo, it had to turn out blank. Darn. Operations Risk 'Management' ISSA June 20 2012

Editor's Notes

  1. Operations Risk 'Management'Van plank misslaan naar spijker op de kop ISSA NL Eurojust Den Haag June 20 2012ISACA Roundtable 5 maart 2012 Breukelen Had ook kunnen heten: Op het verkeerde paard gewed Een doodlopende straat in Eind zoek, al zoek
  2. Operations Risk 'Management'Van plank misslaan naar spijker op de kop ISSA NL Eurojust Den Haag June 20 2012ISACA Roundtable 5 maart 2012 Breukelen The Future of Risk Management / Where Will Risk Management Go ..? ISSA Interntional Conference Baltimore October 2011
  3. Operations Risk 'Management'Van plank misslaan naar spijker op de kop ISSA NL Eurojust Den Haag June 20 2012ISACA Roundtable 5 maart 2012 Breukelen
  4. Operations Risk 'Management'Van plank misslaan naar spijker op de kop ISSA NL Eurojust Den Haag June 20 2012ISACA Roundtable 5 maart 2012 Breukelen The Future of Risk Management / Where Will Risk Management Go ..? ISSA Interntional Conference Baltimore October 2011
  5. Operations Risk 'Management'Van plank misslaan naar spijker op de kop ISSA NL Eurojust Den Haag June 20 2012ISACA Roundtable 5 maart 2012 Breukelen The Future of Risk Management / Where Will Risk Management Go ..? ISSA Interntional Conference Baltimore October 2011
  6. Operations Risk 'Management'Van plank misslaan naar spijker op de kop ISSA NL Eurojust Den Haag June 20 2012ISACA Roundtable 5 maart 2012 Breukelen The Future of Risk Management / Where Will Risk Management Go ..? ISSA Interntional Conference Baltimore October 2011
  7. Operations Risk 'Management'Van plank misslaan naar spijker op de kop ISSA NL Eurojust Den Haag June 20 2012ISACA Roundtable 5 maart 2012 Breukelen The Future of Risk Management / Where Will Risk Management Go ..? ISSA Interntional Conference Baltimore October 2011
  8. Operations Risk 'Management'Van plank misslaan naar spijker op de kop ISSA NL Eurojust Den Haag June 20 2012ISACA Roundtable 5 maart 2012 Breukelen The Future of Risk Management / Where Will Risk Management Go ..? ISSA Interntional Conference Baltimore October 2011
  9. Operations Risk 'Management'Van plank misslaan naar spijker op de kop ISSA NL Eurojust Den Haag June 20 2012ISACA Roundtable 5 maart 2012 Breukelen The Future of Risk Management / Where Will Risk Management Go ..? ISSA Interntional Conference Baltimore October 2011
  10. Operations Risk 'Management'Van plank misslaan naar spijker op de kop ISSA NL Eurojust Den Haag June 20 2012ISACA Roundtable 5 maart 2012 Breukelen The Future of Risk Management / Where Will Risk Management Go ..? ISSA Interntional Conference Baltimore October 2011 Niks is perfect maar weinig is zo gebrekkig en fout als uw modellen. De aannames zijn niet redelijk. En een aap gooit beter dartpijltjes (geen bias). Als ze er niet toe doen, niet doen punt. En ze doen er wel toe, anders hebt u nooit een functioneel model. Conservatief ten opzichte van ..? En waarom niet accuraat boven conservatief (biased). En als ze niet accuraat maar conservatief zijn, hebben odellen dus geen realiteitsgehalte. Conservatisme kan eenvoudig leiden tot onjuiste conclusies. Uw annames worden oneindig eenvoudiger aangetoond verkeerd te zijn dan dat ze juist zijn. Ík heb geen bewijslast, maar u! Geldt ook indien niet ‘bewijs’ maar ‘aannemelijkheid’ wordt gevraagd. Dus als iedereen in het water springt, springt u erachteraan? CYA is niet goed genoeg… Ah, de valse profeet. Is de beslisser beter af als hij wordt mis leid …? Oh jawel dat zijn ze wel want ze misleiden tot u weet welke delen wél zouden werken. Waarom dan de rest niet weggegooid? Of gebruik een horoscoop, die bezweert ook een hoop onzekerheid. Garbage in, garbage out. En je best is wellicht gewoon niet goed genoeg zelfs als de data correct zouden zijn. Volledigheid, iemand? Ja. Maar doe dan wel de juiste aannames en wees rücksichtlos in de beoordeling van hun waarheidsgehalte, én bepaal de variabiliteit in uitkomsten bij variatie van aannames. Doet u dat, ooit? Hoezo? Het zijn geen babies. Het zijn hulpmiddelen. Het kwaad schuilt in de misleiding van uw klanten, in des keizers nieuwe kleren gezet. Vlieg van Schiphol naar O’Hare met brandstof en plattegrond van Eelde!
  11. Operations Risk 'Management'Van plank misslaan naar spijker op de kop ISSA NL Eurojust Den Haag June 20 2012ISACA Roundtable 5 maart 2012 Breukelen The Future of Risk Management / Where Will Risk Management Go ..? ISSA Interntional Conference Baltimore October 2011
  12. Operations Risk 'Management'Van plank misslaan naar spijker op de kop ISSA NL Eurojust Den Haag June 20 2012ISACA Roundtable 5 maart 2012 Breukelen The Future of Risk Management / Where Will Risk Management Go ..? ISSA Interntional Conference Baltimore October 2011
  13. Operations Risk 'Management'Van plank misslaan naar spijker op de kop ISSA NL Eurojust Den Haag June 20 2012ISACA Roundtable 5 maart 2012 Breukelen
  14. Operations Risk 'Management'Van plank misslaan naar spijker op de kop ISSA NL Eurojust Den Haag June 20 2012ISACA Roundtable 5 maart 2012 Breukelen The Future of Risk Management / Where Will Risk Management Go ..? ISSA Interntional Conference Baltimore October 2011
  15. Operations Risk 'Management'Van plank misslaan naar spijker op de kop ISSA NL Eurojust Den Haag June 20 2012ISACA Roundtable 5 maart 2012 Breukelen The Future of Risk Management / Where Will Risk Management Go ..? ISSA Interntional Conference Baltimore October 2011
  16. Operations Risk 'Management'Van plank misslaan naar spijker op de kop ISSA NL Eurojust Den Haag June 20 2012ISACA Roundtable 5 maart 2012 Breukelen The Future of Risk Management / Where Will Risk Management Go ..? ISSA Interntional Conference Baltimore October 2011
  17. Operations Risk 'Management'Van plank misslaan naar spijker op de kop ISSA NL Eurojust Den Haag June 20 2012ISACA Roundtable 5 maart 2012 Breukelen The Future of Risk Management / Where Will Risk Management Go ..? ISSA Interntional Conference Baltimore October 2011
  18. Operations Risk 'Management'Van plank misslaan naar spijker op de kop ISSA NL Eurojust Den Haag June 20 2012ISACA Roundtable 5 maart 2012 Breukelen
  19. Operations Risk 'Management'Van plank misslaan naar spijker op de kop ISSA NL Eurojust Den Haag June 20 2012ISACA Roundtable 5 maart 2012 Breukelen The Future of Risk Management / Where Will Risk Management Go ..? ISSA Interntional Conference Baltimore October 2011
  20. Operations Risk 'Management'Van plank misslaan naar spijker op de kop ISSA NL Eurojust Den Haag June 20 2012ISACA Roundtable 5 maart 2012 Breukelen The Future of Risk Management / Where Will Risk Management Go ..? ISSA Interntional Conference Baltimore October 2011
  21. Operations Risk 'Management'Van plank misslaan naar spijker op de kop ISSA NL Eurojust Den Haag June 20 2012ISACA Roundtable 5 maart 2012 Breukelen The Future of Risk Management / Where Will Risk Management Go ..? ISSA Interntional Conference Baltimore October 2011
  22. Operations Risk 'Management'Van plank misslaan naar spijker op de kop ISSA NL Eurojust Den Haag June 20 2012ISACA Roundtable 5 maart 2012 Breukelen The Future of Risk Management / Where Will Risk Management Go ..? ISSA Interntional Conference Baltimore October 2011
  23. Operations Risk 'Management'Van plank misslaan naar spijker op de kop ISSA NL Eurojust Den Haag June 20 2012ISACA Roundtable 5 maart 2012 Breukelen The Future of Risk Management / Where Will Risk Management Go ..? ISSA Interntional Conference Baltimore October 2011
  24. Operations Risk 'Management'Van plank misslaan naar spijker op de kop ISSA NL Eurojust Den Haag June 20 2012ISACA Roundtable 5 maart 2012 Breukelen The Future of Risk Management / Where Will Risk Management Go ..? ISSA Interntional Conference Baltimore October 2011
  25. Operations Risk 'Management'Van plank misslaan naar spijker op de kop ISSA NL Eurojust Den Haag June 20 2012ISACA Roundtable 5 maart 2012 Breukelen The Future of Risk Management / Where Will Risk Management Go ..? ISSA Interntional Conference Baltimore October 2011
  26. Operations Risk 'Management'Van plank misslaan naar spijker op de kop ISSA NL Eurojust Den Haag June 20 2012ISACA Roundtable 5 maart 2012 Breukelen The Future of Risk Management / Where Will Risk Management Go ..? ISSA Interntional Conference Baltimore October 2011
  27. Operations Risk 'Management'Van plank misslaan naar spijker op de kop ISSA NL Eurojust Den Haag June 20 2012ISACA Roundtable 5 maart 2012 Breukelen The Future of Risk Management / Where Will Risk Management Go ..? ISSA Interntional Conference Baltimore October 2011
  28. Operations Risk 'Management'Van plank misslaan naar spijker op de kop ISSA NL Eurojust Den Haag June 20 2012ISACA Roundtable 5 maart 2012 Breukelen The Future of Risk Management / Where Will Risk Management Go ..? ISSA Interntional Conference Baltimore October 2011
  29. Operations Risk 'Management'Van plank misslaan naar spijker op de kop ISSA NL Eurojust Den Haag June 20 2012ISACA Roundtable 5 maart 2012 Breukelen The Future of Risk Management / Where Will Risk Management Go ..? ISSA Interntional Conference Baltimore October 2011
  30. Operations Risk 'Management'Van plank misslaan naar spijker op de kop ISSA NL Eurojust Den Haag June 20 2012ISACA Roundtable 5 maart 2012 Breukelen The Future of Risk Management / Where Will Risk Management Go ..? ISSA Interntional Conference Baltimore October 2011
  31. Operations Risk 'Management'Van plank misslaan naar spijker op de kop ISSA NL Eurojust Den Haag June 20 2012ISACA Roundtable 5 maart 2012 Breukelen The Future of Risk Management / Where Will Risk Management Go ..? ISSA Interntional Conference Baltimore October 2011
  32. Operations Risk 'Management'Van plank misslaan naar spijker op de kop ISSA NL Eurojust Den Haag June 20 2012ISACA Roundtable 5 maart 2012 Breukelen The Future of Risk Management / Where Will Risk Management Go ..? ISSA Interntional Conference Baltimore October 2011
  33. Operations Risk 'Management'Van plank misslaan naar spijker op de kop ISSA NL Eurojust Den Haag June 20 2012ISACA Roundtable 5 maart 2012 Breukelen