SlideShare a Scribd company logo
INFORMATION
MANAGEMENT RISK
ASSESSMENT
Presented by Jim Booth,
Brightstone Consulting
jbooth@brightstoneconsulting.com
Why focus on Information Security & Risk
Assessment?
• Regulatory compliance
• HIPAA
• PCI DSS
• SOX
• Insurance Requirement for E&O/Cyber
coverage
• Red Flags Rule
Why focus on Information Security & Risk
Assessment?
•Operational improvement
•SOPs can be revised to reduce risk
•Training objectives are easier to
focus
•Employees can be a part of solution
– goal is clear
What is involved in a Risk Assessment
process?
• Review risks to the operation that could
interrupt or degrade business operations
• Rank the risks in terms of their probability
• Rank the risks in terms of their impact
• Identify current mitigation strategies in place
• Identify additional mitigation strategies needed
to reduce the probability and/or impact of risks
• Create priorities and assign resources and
deadlines
• Implement and review
Risk assessment plan
• Identify objectives of the risk assessment program
• Outline the steps of the risk assessment process
• Define how the information gained is captured
• Create a process for defining mitigation strategies and
implementing those steps
• Identify how the risk assessment report will be used by
other business units and groups within the organization
• Record how the plan is updated and how the review
process/cycle operates
Risk assessment survey
• Survey instrument should contain natural and man-made
risks
• Should deal with more than disaster – business
interruption, including items like power loss or loss of
Internet connectivity should be included
• Loss of critical personnel should be included as a risk
• Measurement should record both the likelihood of
occurrence (probability) and the severity of the event
(impact)
Quick exercise
• Fire
• Flood
• Employee Error
• Probability Rating Scale = 1(low) to 5 (high)
• Impact Rating Scale = 1(low) to 5 (high)
• Rank it
• Mitigation strategy
Example – assessing risk of fire
• You conducted an internal survey asking employees to rank various
risks.
• Employees ranked fire risk probability as 4 out of 5 and impact as 5
out of 5 for a combined score of 4.5 out of 5.
• Existing mitigation strategy assessment identifies:
• Sprinklers
• Central station monitoring
• Fire extinguishers
• Overall mitigation is seen to reduce the combined score by .5
• Employees identify additional steps to further mitigate risk
• Fire extinguisher training
• Fire drill and evacuation in cooperation with fire department
• Score of additional steps by risk assessment team is additional
.5 reduction in risk for overall risk score of 3.5
Example, implementation
• Employee assigned to identify vendor to train employees
in fire extinguisher use
• Resources allocated to pay for training, or budgeted in
future period for training
• Employee with emergency liaison role with first
responders arranges for fire drill with cooperation of fire
department
• Employees trained in appropriate fire response and
evacuation procedures
• Fire drill conducted with fire department cooperation
• Fire extinguisher training conducted at time identified
Report creation
• Capture all risk measurements and survey data
• Capture methodology and rationale for truncating the list
to a limited number of actionable elements
• Capture any additional information or resources shared
with risk assessment team
• Assign an individual responsibility for each mitigation
element identified and prioritized for action by the team
• Assign a deadline for action for each mitigation element
• Identify the chain of accountability and periodic reporting
requirements for implementation of elements
• Capture completion dates and any additional results
QUESTIONS?
Jim Booth, CAE, Brightstone Insurance and Brightstone
Consulting Services
jbooth@brightstoneins.com 919-696-7754

More Related Content

What's hot

Business continuity management system
Business continuity management systemBusiness continuity management system
Business continuity management system
subbusai82
 
Bcm Framework PowerPoint Presentation Slides
Bcm Framework PowerPoint Presentation SlidesBcm Framework PowerPoint Presentation Slides
Bcm Framework PowerPoint Presentation Slides
SlideTeam
 
Management techniques final2
Management techniques final2Management techniques final2
Management techniques final2
Har Jindal
 
Lab budget
Lab budgetLab budget
Lab budget
magdy abdelghany
 
How to Prioritize Risks with Qualitative and Quantitative Risk analysis
How to Prioritize Risks with Qualitative and Quantitative Risk analysisHow to Prioritize Risks with Qualitative and Quantitative Risk analysis
How to Prioritize Risks with Qualitative and Quantitative Risk analysis
iZenBridge Consultancy Pvt. Ltd.
 
Risk management
Risk managementRisk management
Risk management
Manish Tiwari
 
Curcial Factors that affect Cost Management.
Curcial Factors that affect Cost Management.Curcial Factors that affect Cost Management.
Curcial Factors that affect Cost Management.
Ahmed Al-Senosy Ph.D(cand),MSc,PMP,RMP
 
Preventative Maintenance
Preventative MaintenancePreventative Maintenance
Preventative Maintenance
CoAction Staff Association
 
Risk management
Risk managementRisk management
Risk management
RajuPrasad33
 
Monitoring&evaluation best practices
Monitoring&evaluation best practicesMonitoring&evaluation best practices
Monitoring&evaluation best practices
Dr Ghaiath Hussein
 
Cost effectiveness and cost containment
Cost effectiveness and cost containmentCost effectiveness and cost containment
Cost effectiveness and cost containment
Saumya Srivastava
 
Construction Cost Control
Construction Cost ControlConstruction Cost Control
Construction Cost Control
Sunayana Miglani
 
Risk Register.docx
Risk Register.docxRisk Register.docx
Risk Register.docx
CPA Australia
 
Premise control
Premise control Premise control
Premise control
Anand Verma
 
Business Continuity Planning Presentation
Business Continuity Planning PresentationBusiness Continuity Planning Presentation
Business Continuity Planning Presentation
The Chamber For a Greater Chapel Hill-Carrboro
 
Risk management
Risk managementRisk management
Risk management
Mahmoud Shaqria
 
Ranking and optimization in pavements
Ranking and optimization in pavementsRanking and optimization in pavements
Ranking and optimization in pavements
Bhavya Jaiswal
 
Business Continuity Planning
Business Continuity PlanningBusiness Continuity Planning
Business Continuity Planning
Bharath Rao
 
Drp Bcp Testing Alternatives
Drp Bcp Testing AlternativesDrp Bcp Testing Alternatives
Drp Bcp Testing Alternatives
Gewurtz
 
008 christoph hartebrodt
008 christoph hartebrodt008 christoph hartebrodt

What's hot (20)

Business continuity management system
Business continuity management systemBusiness continuity management system
Business continuity management system
 
Bcm Framework PowerPoint Presentation Slides
Bcm Framework PowerPoint Presentation SlidesBcm Framework PowerPoint Presentation Slides
Bcm Framework PowerPoint Presentation Slides
 
Management techniques final2
Management techniques final2Management techniques final2
Management techniques final2
 
Lab budget
Lab budgetLab budget
Lab budget
 
How to Prioritize Risks with Qualitative and Quantitative Risk analysis
How to Prioritize Risks with Qualitative and Quantitative Risk analysisHow to Prioritize Risks with Qualitative and Quantitative Risk analysis
How to Prioritize Risks with Qualitative and Quantitative Risk analysis
 
Risk management
Risk managementRisk management
Risk management
 
Curcial Factors that affect Cost Management.
Curcial Factors that affect Cost Management.Curcial Factors that affect Cost Management.
Curcial Factors that affect Cost Management.
 
Preventative Maintenance
Preventative MaintenancePreventative Maintenance
Preventative Maintenance
 
Risk management
Risk managementRisk management
Risk management
 
Monitoring&evaluation best practices
Monitoring&evaluation best practicesMonitoring&evaluation best practices
Monitoring&evaluation best practices
 
Cost effectiveness and cost containment
Cost effectiveness and cost containmentCost effectiveness and cost containment
Cost effectiveness and cost containment
 
Construction Cost Control
Construction Cost ControlConstruction Cost Control
Construction Cost Control
 
Risk Register.docx
Risk Register.docxRisk Register.docx
Risk Register.docx
 
Premise control
Premise control Premise control
Premise control
 
Business Continuity Planning Presentation
Business Continuity Planning PresentationBusiness Continuity Planning Presentation
Business Continuity Planning Presentation
 
Risk management
Risk managementRisk management
Risk management
 
Ranking and optimization in pavements
Ranking and optimization in pavementsRanking and optimization in pavements
Ranking and optimization in pavements
 
Business Continuity Planning
Business Continuity PlanningBusiness Continuity Planning
Business Continuity Planning
 
Drp Bcp Testing Alternatives
Drp Bcp Testing AlternativesDrp Bcp Testing Alternatives
Drp Bcp Testing Alternatives
 
008 christoph hartebrodt
008 christoph hartebrodt008 christoph hartebrodt
008 christoph hartebrodt
 

Viewers also liked

Deepwater Horizon Oil Spill
Deepwater Horizon Oil SpillDeepwater Horizon Oil Spill
Deepwater Horizon Oil Spill
Jessica Goodman
 
Networking Strategies
Networking StrategiesNetworking Strategies
Networking Strategies
Jim Maginnis, MBA
 
Quality Audits
Quality Audits  Quality Audits
Quality Audits
Vasanth Kumar
 
Data integrity. swapan
Data integrity. swapanData integrity. swapan
Data integrity. swapan
swapan Bandyopadhyay
 
Kingspan Klargester draingae solutions | Technical Guide
Kingspan Klargester draingae solutions | Technical GuideKingspan Klargester draingae solutions | Technical Guide
Kingspan Klargester draingae solutions | Technical Guide
KingspanKlargester
 
Site assessment risk scoring guide june 2011
Site assessment risk scoring guide   june 2011Site assessment risk scoring guide   june 2011
Site assessment risk scoring guide june 2011
noshah
 
Risk Assessment at Swansea ITeC
Risk Assessment at Swansea ITeCRisk Assessment at Swansea ITeC
Risk Assessment at Swansea ITeC
iteclearners
 
OHS Risk Assessment and Hierarchy of Control
OHS Risk Assessment and Hierarchy of ControlOHS Risk Assessment and Hierarchy of Control
OHS Risk Assessment and Hierarchy of Control
PECB
 
Health and Safety Risk Assessment
Health and Safety Risk AssessmentHealth and Safety Risk Assessment
Health and Safety Risk Assessment
Thuvaa Kuru
 
Risk Assessment Workshop
Risk Assessment WorkshopRisk Assessment Workshop
Risk Assessment Workshop
Bozward0901
 
Health and Safety Risk Assessment
Health and Safety Risk AssessmentHealth and Safety Risk Assessment
Health and Safety Risk Assessment
louise davies
 
Data Integrity in a GxP-regulated Environment - Pauwels Consulting Academy
Data Integrity in a GxP-regulated Environment - Pauwels Consulting AcademyData Integrity in a GxP-regulated Environment - Pauwels Consulting Academy
Data Integrity in a GxP-regulated Environment - Pauwels Consulting Academy
Pauwels Consulting
 
Data Integrity webinar - Essentials & Solutions
Data Integrity webinar - Essentials & SolutionsData Integrity webinar - Essentials & Solutions
Data Integrity webinar - Essentials & Solutions
pi
 
Risk assessment tesco
Risk assessment tescoRisk assessment tesco
Risk assessment tesco
nikonmedia
 
New PICS Guidance on Data Integrity and Management.
New PICS Guidance on Data Integrity and Management.New PICS Guidance on Data Integrity and Management.
New PICS Guidance on Data Integrity and Management.
GMP EDUCATION : Not for Profit Organization
 
Neurovascular assessment
Neurovascular assessmentNeurovascular assessment
Neurovascular assessment
Siuk Yi Lim
 
6 Steps to an Effective Needs Assessment
6 Steps to an Effective Needs Assessment6 Steps to an Effective Needs Assessment
6 Steps to an Effective Needs Assessment
Erin Lett
 
Quality audits
Quality auditsQuality audits
Quality audits
Vasanth Kumar
 
Film production risk assessment form
Film production risk assessment formFilm production risk assessment form
Film production risk assessment form
cembitmead
 
Operational Risk : Take a look at the raw canvas
Operational Risk : Take a look at the raw canvasOperational Risk : Take a look at the raw canvas
Operational Risk : Take a look at the raw canvas
Treat Risk
 

Viewers also liked (20)

Deepwater Horizon Oil Spill
Deepwater Horizon Oil SpillDeepwater Horizon Oil Spill
Deepwater Horizon Oil Spill
 
Networking Strategies
Networking StrategiesNetworking Strategies
Networking Strategies
 
Quality Audits
Quality Audits  Quality Audits
Quality Audits
 
Data integrity. swapan
Data integrity. swapanData integrity. swapan
Data integrity. swapan
 
Kingspan Klargester draingae solutions | Technical Guide
Kingspan Klargester draingae solutions | Technical GuideKingspan Klargester draingae solutions | Technical Guide
Kingspan Klargester draingae solutions | Technical Guide
 
Site assessment risk scoring guide june 2011
Site assessment risk scoring guide   june 2011Site assessment risk scoring guide   june 2011
Site assessment risk scoring guide june 2011
 
Risk Assessment at Swansea ITeC
Risk Assessment at Swansea ITeCRisk Assessment at Swansea ITeC
Risk Assessment at Swansea ITeC
 
OHS Risk Assessment and Hierarchy of Control
OHS Risk Assessment and Hierarchy of ControlOHS Risk Assessment and Hierarchy of Control
OHS Risk Assessment and Hierarchy of Control
 
Health and Safety Risk Assessment
Health and Safety Risk AssessmentHealth and Safety Risk Assessment
Health and Safety Risk Assessment
 
Risk Assessment Workshop
Risk Assessment WorkshopRisk Assessment Workshop
Risk Assessment Workshop
 
Health and Safety Risk Assessment
Health and Safety Risk AssessmentHealth and Safety Risk Assessment
Health and Safety Risk Assessment
 
Data Integrity in a GxP-regulated Environment - Pauwels Consulting Academy
Data Integrity in a GxP-regulated Environment - Pauwels Consulting AcademyData Integrity in a GxP-regulated Environment - Pauwels Consulting Academy
Data Integrity in a GxP-regulated Environment - Pauwels Consulting Academy
 
Data Integrity webinar - Essentials & Solutions
Data Integrity webinar - Essentials & SolutionsData Integrity webinar - Essentials & Solutions
Data Integrity webinar - Essentials & Solutions
 
Risk assessment tesco
Risk assessment tescoRisk assessment tesco
Risk assessment tesco
 
New PICS Guidance on Data Integrity and Management.
New PICS Guidance on Data Integrity and Management.New PICS Guidance on Data Integrity and Management.
New PICS Guidance on Data Integrity and Management.
 
Neurovascular assessment
Neurovascular assessmentNeurovascular assessment
Neurovascular assessment
 
6 Steps to an Effective Needs Assessment
6 Steps to an Effective Needs Assessment6 Steps to an Effective Needs Assessment
6 Steps to an Effective Needs Assessment
 
Quality audits
Quality auditsQuality audits
Quality audits
 
Film production risk assessment form
Film production risk assessment formFilm production risk assessment form
Film production risk assessment form
 
Operational Risk : Take a look at the raw canvas
Operational Risk : Take a look at the raw canvasOperational Risk : Take a look at the raw canvas
Operational Risk : Take a look at the raw canvas
 

Similar to How to conduct a risk assessment

BSBWHS501 Element 4
BSBWHS501 Element 4BSBWHS501 Element 4
BSBWHS501 Element 4
Michael Brown
 
training
trainingtraining
training
hi2shilpa
 
training evaluation
 training evaluation training evaluation
training evaluation
Farida Kandoriwala
 
Internal Audit Best Practices for Safety, Environment, and Quality Audits
Internal Audit Best Practices for Safety, Environment, and Quality AuditsInternal Audit Best Practices for Safety, Environment, and Quality Audits
Internal Audit Best Practices for Safety, Environment, and Quality Audits
Nimonik
 
Module 5 Training Evaluation.pptx
Module 5 Training Evaluation.pptxModule 5 Training Evaluation.pptx
Module 5 Training Evaluation.pptx
aradhnayadav2
 
Compliance Basics Presentation
Compliance Basics PresentationCompliance Basics Presentation
Compliance Basics Presentation
Compliagent
 
What do the changes to ISO14001 mean for business?
What do the changes to ISO14001 mean for business? What do the changes to ISO14001 mean for business?
What do the changes to ISO14001 mean for business?
Ardea International
 
Training Evaluation
Training EvaluationTraining Evaluation
Training Evaluation
Preeti Bhaskar
 
Topic 1 - Risk Auditing 1-17.pdf
Topic 1 - Risk Auditing 1-17.pdfTopic 1 - Risk Auditing 1-17.pdf
Topic 1 - Risk Auditing 1-17.pdf
Javier138365
 
Contractor Safety Beyond Compliance
Contractor Safety Beyond ComplianceContractor Safety Beyond Compliance
Contractor Safety Beyond Compliance
browzcompliance
 
Action Plan to be Implimented.pptx
Action Plan to be Implimented.pptxAction Plan to be Implimented.pptx
Action Plan to be Implimented.pptx
FlavianAtieno
 
BSBMGT517 Manage operational planPart C– Project Managing an op.docx
BSBMGT517 Manage operational planPart C– Project Managing an op.docxBSBMGT517 Manage operational planPart C– Project Managing an op.docx
BSBMGT517 Manage operational planPart C– Project Managing an op.docx
AASTHA76
 
Unit 8 updated
Unit 8 updatedUnit 8 updated
Unit 8 updated
Abidin mokhlas sdn. bhd
 
Training Need Assessment
Training Need AssessmentTraining Need Assessment
Training Need Assessment
Seta Wicaksana
 
Unit IV_Monitoring_and_Evaluation.pptx
Unit IV_Monitoring_and_Evaluation.pptxUnit IV_Monitoring_and_Evaluation.pptx
Unit IV_Monitoring_and_Evaluation.pptx
MusondaMofu2
 
OHSAS 18001 + ISO 14001 – Implementation Methods
OHSAS 18001 + ISO 14001 – Implementation MethodsOHSAS 18001 + ISO 14001 – Implementation Methods
OHSAS 18001 + ISO 14001 – Implementation Methods
PECB
 
HRM Auditing – Principles, Practice and Process
HRM Auditing – Principles, Practice and Process HRM Auditing – Principles, Practice and Process
HRM Auditing – Principles, Practice and Process
Charles Cotter, PhD
 
CompTIA Security+.pptx
CompTIA Security+.pptxCompTIA Security+.pptx
CompTIA Security+.pptx
KiranKumar24546
 
Measuring_HR_ROI-1.pdf
Measuring_HR_ROI-1.pdfMeasuring_HR_ROI-1.pdf
Measuring_HR_ROI-1.pdf
HarmanSingh510326
 
Evaluation of training Program
Evaluation of training ProgramEvaluation of training Program
Evaluation of training Program
Somya Tiwari
 

Similar to How to conduct a risk assessment (20)

BSBWHS501 Element 4
BSBWHS501 Element 4BSBWHS501 Element 4
BSBWHS501 Element 4
 
training
trainingtraining
training
 
training evaluation
 training evaluation training evaluation
training evaluation
 
Internal Audit Best Practices for Safety, Environment, and Quality Audits
Internal Audit Best Practices for Safety, Environment, and Quality AuditsInternal Audit Best Practices for Safety, Environment, and Quality Audits
Internal Audit Best Practices for Safety, Environment, and Quality Audits
 
Module 5 Training Evaluation.pptx
Module 5 Training Evaluation.pptxModule 5 Training Evaluation.pptx
Module 5 Training Evaluation.pptx
 
Compliance Basics Presentation
Compliance Basics PresentationCompliance Basics Presentation
Compliance Basics Presentation
 
What do the changes to ISO14001 mean for business?
What do the changes to ISO14001 mean for business? What do the changes to ISO14001 mean for business?
What do the changes to ISO14001 mean for business?
 
Training Evaluation
Training EvaluationTraining Evaluation
Training Evaluation
 
Topic 1 - Risk Auditing 1-17.pdf
Topic 1 - Risk Auditing 1-17.pdfTopic 1 - Risk Auditing 1-17.pdf
Topic 1 - Risk Auditing 1-17.pdf
 
Contractor Safety Beyond Compliance
Contractor Safety Beyond ComplianceContractor Safety Beyond Compliance
Contractor Safety Beyond Compliance
 
Action Plan to be Implimented.pptx
Action Plan to be Implimented.pptxAction Plan to be Implimented.pptx
Action Plan to be Implimented.pptx
 
BSBMGT517 Manage operational planPart C– Project Managing an op.docx
BSBMGT517 Manage operational planPart C– Project Managing an op.docxBSBMGT517 Manage operational planPart C– Project Managing an op.docx
BSBMGT517 Manage operational planPart C– Project Managing an op.docx
 
Unit 8 updated
Unit 8 updatedUnit 8 updated
Unit 8 updated
 
Training Need Assessment
Training Need AssessmentTraining Need Assessment
Training Need Assessment
 
Unit IV_Monitoring_and_Evaluation.pptx
Unit IV_Monitoring_and_Evaluation.pptxUnit IV_Monitoring_and_Evaluation.pptx
Unit IV_Monitoring_and_Evaluation.pptx
 
OHSAS 18001 + ISO 14001 – Implementation Methods
OHSAS 18001 + ISO 14001 – Implementation MethodsOHSAS 18001 + ISO 14001 – Implementation Methods
OHSAS 18001 + ISO 14001 – Implementation Methods
 
HRM Auditing – Principles, Practice and Process
HRM Auditing – Principles, Practice and Process HRM Auditing – Principles, Practice and Process
HRM Auditing – Principles, Practice and Process
 
CompTIA Security+.pptx
CompTIA Security+.pptxCompTIA Security+.pptx
CompTIA Security+.pptx
 
Measuring_HR_ROI-1.pdf
Measuring_HR_ROI-1.pdfMeasuring_HR_ROI-1.pdf
Measuring_HR_ROI-1.pdf
 
Evaluation of training Program
Evaluation of training ProgramEvaluation of training Program
Evaluation of training Program
 

Recently uploaded

Authentically Social by Corey Perlman - EO Puerto Rico
Authentically Social by Corey Perlman - EO Puerto RicoAuthentically Social by Corey Perlman - EO Puerto Rico
Authentically Social by Corey Perlman - EO Puerto Rico
Corey Perlman, Social Media Speaker and Consultant
 
Top mailing list providers in the USA.pptx
Top mailing list providers in the USA.pptxTop mailing list providers in the USA.pptx
Top mailing list providers in the USA.pptx
JeremyPeirce1
 
Dpboss Matka Guessing Satta Matta Matka Kalyan Chart Satta Matka
Dpboss Matka Guessing Satta Matta Matka Kalyan Chart Satta MatkaDpboss Matka Guessing Satta Matta Matka Kalyan Chart Satta Matka
Dpboss Matka Guessing Satta Matta Matka Kalyan Chart Satta Matka
➒➌➎➏➑➐➋➑➐➐Dpboss Matka Guessing Satta Matka Kalyan Chart Indian Matka
 
Hamster Kombat' Telegram Game Surpasses 100 Million Players—Token Release Sch...
Hamster Kombat' Telegram Game Surpasses 100 Million Players—Token Release Sch...Hamster Kombat' Telegram Game Surpasses 100 Million Players—Token Release Sch...
Hamster Kombat' Telegram Game Surpasses 100 Million Players—Token Release Sch...
SOFTTECHHUB
 
-- June 2024 is National Volunteer Month --
-- June 2024 is National Volunteer Month ---- June 2024 is National Volunteer Month --
-- June 2024 is National Volunteer Month --
NZSG
 
amptalk_RecruitingDeck_english_2024.06.05
amptalk_RecruitingDeck_english_2024.06.05amptalk_RecruitingDeck_english_2024.06.05
amptalk_RecruitingDeck_english_2024.06.05
marketing317746
 
Understanding User Needs and Satisfying Them
Understanding User Needs and Satisfying ThemUnderstanding User Needs and Satisfying Them
Understanding User Needs and Satisfying Them
Aggregage
 
Unveiling the Dynamic Personalities, Key Dates, and Horoscope Insights: Gemin...
Unveiling the Dynamic Personalities, Key Dates, and Horoscope Insights: Gemin...Unveiling the Dynamic Personalities, Key Dates, and Horoscope Insights: Gemin...
Unveiling the Dynamic Personalities, Key Dates, and Horoscope Insights: Gemin...
my Pandit
 
Structural Design Process: Step-by-Step Guide for Buildings
Structural Design Process: Step-by-Step Guide for BuildingsStructural Design Process: Step-by-Step Guide for Buildings
Structural Design Process: Step-by-Step Guide for Buildings
Chandresh Chudasama
 
Best practices for project execution and delivery
Best practices for project execution and deliveryBest practices for project execution and delivery
Best practices for project execution and delivery
CLIVE MINCHIN
 
Best Forex Brokers Comparison in INDIA 2024
Best Forex Brokers Comparison in INDIA 2024Best Forex Brokers Comparison in INDIA 2024
Best Forex Brokers Comparison in INDIA 2024
Top Forex Brokers Review
 
Lundin Gold Corporate Presentation - June 2024
Lundin Gold Corporate Presentation - June 2024Lundin Gold Corporate Presentation - June 2024
Lundin Gold Corporate Presentation - June 2024
Adnet Communications
 
The Heart of Leadership_ How Emotional Intelligence Drives Business Success B...
The Heart of Leadership_ How Emotional Intelligence Drives Business Success B...The Heart of Leadership_ How Emotional Intelligence Drives Business Success B...
The Heart of Leadership_ How Emotional Intelligence Drives Business Success B...
Stephen Cashman
 
Income Tax exemption for Start up : Section 80 IAC
Income Tax  exemption for Start up : Section 80 IACIncome Tax  exemption for Start up : Section 80 IAC
Income Tax exemption for Start up : Section 80 IAC
CA Dr. Prithvi Ranjan Parhi
 
Creative Web Design Company in Singapore
Creative Web Design Company in SingaporeCreative Web Design Company in Singapore
Creative Web Design Company in Singapore
techboxsqauremedia
 
The APCO Geopolitical Radar - Q3 2024 The Global Operating Environment for Bu...
The APCO Geopolitical Radar - Q3 2024 The Global Operating Environment for Bu...The APCO Geopolitical Radar - Q3 2024 The Global Operating Environment for Bu...
The APCO Geopolitical Radar - Q3 2024 The Global Operating Environment for Bu...
APCO
 
Easily Verify Compliance and Security with Binance KYC
Easily Verify Compliance and Security with Binance KYCEasily Verify Compliance and Security with Binance KYC
Easily Verify Compliance and Security with Binance KYC
Any kyc Account
 
How to Implement a Strategy: Transform Your Strategy with BSC Designer's Comp...
How to Implement a Strategy: Transform Your Strategy with BSC Designer's Comp...How to Implement a Strategy: Transform Your Strategy with BSC Designer's Comp...
How to Implement a Strategy: Transform Your Strategy with BSC Designer's Comp...
Aleksey Savkin
 
Organizational Change Leadership Agile Tour Geneve 2024
Organizational Change Leadership Agile Tour Geneve 2024Organizational Change Leadership Agile Tour Geneve 2024
Organizational Change Leadership Agile Tour Geneve 2024
Kirill Klimov
 
Industrial Tech SW: Category Renewal and Creation
Industrial Tech SW:  Category Renewal and CreationIndustrial Tech SW:  Category Renewal and Creation
Industrial Tech SW: Category Renewal and Creation
Christian Dahlen
 

Recently uploaded (20)

Authentically Social by Corey Perlman - EO Puerto Rico
Authentically Social by Corey Perlman - EO Puerto RicoAuthentically Social by Corey Perlman - EO Puerto Rico
Authentically Social by Corey Perlman - EO Puerto Rico
 
Top mailing list providers in the USA.pptx
Top mailing list providers in the USA.pptxTop mailing list providers in the USA.pptx
Top mailing list providers in the USA.pptx
 
Dpboss Matka Guessing Satta Matta Matka Kalyan Chart Satta Matka
Dpboss Matka Guessing Satta Matta Matka Kalyan Chart Satta MatkaDpboss Matka Guessing Satta Matta Matka Kalyan Chart Satta Matka
Dpboss Matka Guessing Satta Matta Matka Kalyan Chart Satta Matka
 
Hamster Kombat' Telegram Game Surpasses 100 Million Players—Token Release Sch...
Hamster Kombat' Telegram Game Surpasses 100 Million Players—Token Release Sch...Hamster Kombat' Telegram Game Surpasses 100 Million Players—Token Release Sch...
Hamster Kombat' Telegram Game Surpasses 100 Million Players—Token Release Sch...
 
-- June 2024 is National Volunteer Month --
-- June 2024 is National Volunteer Month ---- June 2024 is National Volunteer Month --
-- June 2024 is National Volunteer Month --
 
amptalk_RecruitingDeck_english_2024.06.05
amptalk_RecruitingDeck_english_2024.06.05amptalk_RecruitingDeck_english_2024.06.05
amptalk_RecruitingDeck_english_2024.06.05
 
Understanding User Needs and Satisfying Them
Understanding User Needs and Satisfying ThemUnderstanding User Needs and Satisfying Them
Understanding User Needs and Satisfying Them
 
Unveiling the Dynamic Personalities, Key Dates, and Horoscope Insights: Gemin...
Unveiling the Dynamic Personalities, Key Dates, and Horoscope Insights: Gemin...Unveiling the Dynamic Personalities, Key Dates, and Horoscope Insights: Gemin...
Unveiling the Dynamic Personalities, Key Dates, and Horoscope Insights: Gemin...
 
Structural Design Process: Step-by-Step Guide for Buildings
Structural Design Process: Step-by-Step Guide for BuildingsStructural Design Process: Step-by-Step Guide for Buildings
Structural Design Process: Step-by-Step Guide for Buildings
 
Best practices for project execution and delivery
Best practices for project execution and deliveryBest practices for project execution and delivery
Best practices for project execution and delivery
 
Best Forex Brokers Comparison in INDIA 2024
Best Forex Brokers Comparison in INDIA 2024Best Forex Brokers Comparison in INDIA 2024
Best Forex Brokers Comparison in INDIA 2024
 
Lundin Gold Corporate Presentation - June 2024
Lundin Gold Corporate Presentation - June 2024Lundin Gold Corporate Presentation - June 2024
Lundin Gold Corporate Presentation - June 2024
 
The Heart of Leadership_ How Emotional Intelligence Drives Business Success B...
The Heart of Leadership_ How Emotional Intelligence Drives Business Success B...The Heart of Leadership_ How Emotional Intelligence Drives Business Success B...
The Heart of Leadership_ How Emotional Intelligence Drives Business Success B...
 
Income Tax exemption for Start up : Section 80 IAC
Income Tax  exemption for Start up : Section 80 IACIncome Tax  exemption for Start up : Section 80 IAC
Income Tax exemption for Start up : Section 80 IAC
 
Creative Web Design Company in Singapore
Creative Web Design Company in SingaporeCreative Web Design Company in Singapore
Creative Web Design Company in Singapore
 
The APCO Geopolitical Radar - Q3 2024 The Global Operating Environment for Bu...
The APCO Geopolitical Radar - Q3 2024 The Global Operating Environment for Bu...The APCO Geopolitical Radar - Q3 2024 The Global Operating Environment for Bu...
The APCO Geopolitical Radar - Q3 2024 The Global Operating Environment for Bu...
 
Easily Verify Compliance and Security with Binance KYC
Easily Verify Compliance and Security with Binance KYCEasily Verify Compliance and Security with Binance KYC
Easily Verify Compliance and Security with Binance KYC
 
How to Implement a Strategy: Transform Your Strategy with BSC Designer's Comp...
How to Implement a Strategy: Transform Your Strategy with BSC Designer's Comp...How to Implement a Strategy: Transform Your Strategy with BSC Designer's Comp...
How to Implement a Strategy: Transform Your Strategy with BSC Designer's Comp...
 
Organizational Change Leadership Agile Tour Geneve 2024
Organizational Change Leadership Agile Tour Geneve 2024Organizational Change Leadership Agile Tour Geneve 2024
Organizational Change Leadership Agile Tour Geneve 2024
 
Industrial Tech SW: Category Renewal and Creation
Industrial Tech SW:  Category Renewal and CreationIndustrial Tech SW:  Category Renewal and Creation
Industrial Tech SW: Category Renewal and Creation
 

How to conduct a risk assessment

  • 1. INFORMATION MANAGEMENT RISK ASSESSMENT Presented by Jim Booth, Brightstone Consulting jbooth@brightstoneconsulting.com
  • 2. Why focus on Information Security & Risk Assessment? • Regulatory compliance • HIPAA • PCI DSS • SOX • Insurance Requirement for E&O/Cyber coverage • Red Flags Rule
  • 3. Why focus on Information Security & Risk Assessment? •Operational improvement •SOPs can be revised to reduce risk •Training objectives are easier to focus •Employees can be a part of solution – goal is clear
  • 4. What is involved in a Risk Assessment process? • Review risks to the operation that could interrupt or degrade business operations • Rank the risks in terms of their probability • Rank the risks in terms of their impact • Identify current mitigation strategies in place • Identify additional mitigation strategies needed to reduce the probability and/or impact of risks • Create priorities and assign resources and deadlines • Implement and review
  • 5. Risk assessment plan • Identify objectives of the risk assessment program • Outline the steps of the risk assessment process • Define how the information gained is captured • Create a process for defining mitigation strategies and implementing those steps • Identify how the risk assessment report will be used by other business units and groups within the organization • Record how the plan is updated and how the review process/cycle operates
  • 6. Risk assessment survey • Survey instrument should contain natural and man-made risks • Should deal with more than disaster – business interruption, including items like power loss or loss of Internet connectivity should be included • Loss of critical personnel should be included as a risk • Measurement should record both the likelihood of occurrence (probability) and the severity of the event (impact)
  • 7. Quick exercise • Fire • Flood • Employee Error • Probability Rating Scale = 1(low) to 5 (high) • Impact Rating Scale = 1(low) to 5 (high) • Rank it • Mitigation strategy
  • 8. Example – assessing risk of fire • You conducted an internal survey asking employees to rank various risks. • Employees ranked fire risk probability as 4 out of 5 and impact as 5 out of 5 for a combined score of 4.5 out of 5. • Existing mitigation strategy assessment identifies: • Sprinklers • Central station monitoring • Fire extinguishers • Overall mitigation is seen to reduce the combined score by .5 • Employees identify additional steps to further mitigate risk • Fire extinguisher training • Fire drill and evacuation in cooperation with fire department • Score of additional steps by risk assessment team is additional .5 reduction in risk for overall risk score of 3.5
  • 9. Example, implementation • Employee assigned to identify vendor to train employees in fire extinguisher use • Resources allocated to pay for training, or budgeted in future period for training • Employee with emergency liaison role with first responders arranges for fire drill with cooperation of fire department • Employees trained in appropriate fire response and evacuation procedures • Fire drill conducted with fire department cooperation • Fire extinguisher training conducted at time identified
  • 10. Report creation • Capture all risk measurements and survey data • Capture methodology and rationale for truncating the list to a limited number of actionable elements • Capture any additional information or resources shared with risk assessment team • Assign an individual responsibility for each mitigation element identified and prioritized for action by the team • Assign a deadline for action for each mitigation element • Identify the chain of accountability and periodic reporting requirements for implementation of elements • Capture completion dates and any additional results
  • 11. QUESTIONS? Jim Booth, CAE, Brightstone Insurance and Brightstone Consulting Services jbooth@brightstoneins.com 919-696-7754

Editor's Notes

  1. When you sign a BAA you are agreeing to requirements in the law, especially obligations imposed by the privacy rule and security rule. Policy provides a place to define these Risk assessment helps you find weaknesses in your processes or technology requirements of the security rule. PCIDSS directly requires documentation in multiple areas including: “7.3 Ensure that security policies and operational procedures for restricting access to cardholder data are documented, in use, and known to all affected parties.” As of June 30, 2015 in 12.9 you are required to acknowledge in writing that you are responsible for the data of others in your care custody and control. This is new and legally significant. Talk to your attorney. SOX-impacted corporations may need to see infrastructure that supports the part of their information system that you control (and may require SSAE 16 verification) Insurance – ask your agent for a copy of the application for your E&O/Cyber Liability policy and pay attention to what the insurance company wants to know. This is where they think you are vulnerable. Red Flags Rule – when you do a risk assessment you are trying to identify the same weak points that the Red Flags Rule wants you to locate. Crafting a response strategy puts you that much closer to compliance (or at least creates a more legally defensible position) if your compliance is called into question.
  2. FRESH SET OF EYES theory – Missouri Restaurant Association, restaurateurs used to go eat in someone else’s restaurant and make notes about all the bad stuff. Then they would come back to their own operation and see how much of the same things are going on. EMPLOYEE TRAINING is the first line of defense. Prevention of errors is a direct function of training. There has to be something to train from – that’s why you need SOPs. Jim Spinney and Patty Huber – created publication Standard Operating Procedures for Commercial Records Centers. Free download for PRISM members. Employees need to understand that they would be better off losing a records carton full of $100 bills than losing a large transfer case filled with unencrypted data tapes that contain individual financial or medical information. Ponemon – “As revealed in the 2014 Cost of Data Breach Study: Global Analysis, sponsored by IBM, the average cost to a company was $3.5 million in US dollars and 15 percent more than what it cost last year.” “An interesting finding is the important role cyber insurance can play in not only managing the risk of a data breach but in improving the security posture of the company. While it has been suggested that having insurance encourages companies to slack off on security, our research suggests the opposite. Those companies with good security practices are more likely to purchase insurance.” Malicious attacks breach $246 per record – employee error breach $160 per record