0% found this document useful (0 votes)
20 views66 pages

Risk Management in Information Security

The document discusses risk management frameworks and processes. It outlines the key steps in developing a risk management framework, including executive support, framework design, implementation, and monitoring. It also discusses establishing a risk appetite and defining risks, threats, and vulnerabilities.

Uploaded by

Vako Veii
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
20 views66 pages

Risk Management in Information Security

The document discusses risk management frameworks and processes. It outlines the key steps in developing a risk management framework, including executive support, framework design, implementation, and monitoring. It also discusses establishing a risk appetite and defining risks, threats, and vulnerabilities.

Uploaded by

Vako Veii
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

Information Security

Management Assurance
(ISM811S)
Chapter 5 – Risk Management Summary
29 March 2023

Jaco Cloete (Guest)


CA(SA), M(IT), CISA, CRISC, CISM, C|CISO, CISSP, CSX-P
Legend

• Slides are marked as Formal or Supplementary


• Formal slides are from the official textbook or formal NUST presentations
• Supplementary slides contain guidance from practice, augmentation,
additional non-textbook insights from experience or additional sources

2
Reading Material

• Chitauro M. (2022). Management of Information Security and Assurance


Manual
• Whitman, M.E., and Mattord, H. J. (2019). Management of Information
Security, 6th Edition. Cengage. ISBN: 978·1·337-40571·3

Formal 3
Outline

• Learning Outcomes
• Introduction
• Risk Management Framework
• Risk Management Process
• Risk Analysis
• Case Study

Formal 4
Learning outcomes

• Describe risk management framework;


• Outline risk management process;
• Conduct a risk management process;
• Discuss risk treatment strategies.

Formal 5
Key words
• Enterprise risk management (ERM): The evaluation and reaction to risk to the entire organisation;
ERM is not restricted to the risk facing information assets.
• Information security risk management (ISRM): The entire program of planning for and managing risk
to information assets in the organisation.
• Risk assessment: An approach to combining risk identification, risk analysis, and risk evaluation into a
single strategy.
• Risk Management framework (RMF): The overall structure of the strategic planning and design for the
entirety of the organisation's risk management efforts.
• Risk Management process: The identification, analysis, evaluation, and treatment of risk to
information assets, as specified in the risk management framework
• Risk management policy: “Policy designed to regulate organisational efforts related to the
identification, assessment, and treatment of risk to information assets” (Whitman & Mattord, 2019. pp
308).
• Residual risk: “The risk to information assets that remains even after current controls have been
applied
Formal 6
Key words
• Risk appetite: “The quantity and nature of risk that organisations are willing to accept as they evaluate
the trade-offs between perfect security and unlimited accessibility”
• Risk appetite statement: “A formal document developed by the organisation that specifies its overall
willingness to accept risk to its information assets, based on a synthesis of individual risk tolerances”
Risk management plan: “A document that contains specifications for the implementation and conduct
of risk management efforts”
• Risk tolerance/threshold: “The assessment of the amount of risk an organisation is willing to accept
for a particular information asset, typically synthesized into the organisation's overall risk appetite”
• Zero tolerance risk exposure: “An extreme level of risk tolerance whereby the organisation is unwilling
to allow any successful attacks or suffer any loss to an information asset”

Formal 7
Introduction

• Risk is a probability of a threat exploiting a vulnerability and its associated


impact
• Information security risk, which from the definitions given is a potential
problem that an information system or its users might experience

Formal 8
Threat vs Vulnerability vs Risk

• A threat is something that can, or someone that wants to cause harm to the
organisation and is identified through threat modeling
• A vulnerability is a weakness that can be exploited and is identified through security
testing and vulnerability assessments
• A risk is something bad that can happen and is characterised by having a certain
impact (loss or negative outcome) and probability of occurrence (likelihood)
• Interrelationship
• A threat exploits a vulnerability leading to a risk materialising (consequence)
• Management needs a way to measure risk to indicate to the board that systems are
operating within risk tolerance levels
• A suitable method to do this is through risk appetite model and CyberMIS as part of
the Risk management framework and Risk management process in later slides

Supplementary 9
When is something a risk

• There is a loss associated with the event/incident


• There is a likelihood that the event/incident will occur
• There is a degree to which we can change the outcome

Formal 10
Risk management

• The primary reason of having information security is to manage risk


through establishment of information security programs and information
security governance
• To implement an effective security program and governance program one
needs to do a risk assessment
• “Risk management is the process of discovering and assessing the risks to
an organisation's operations and determining how those risks can be
controlled or mitigated”

Formal 11
Risk management questions

• Where and what is the risk (risk identification)?


• How severe is the current level of risk (risk analysis)?
• Is the current level of risk acceptable (risk evaluation)?
• What do I need to do to bring the risk to an acceptable level (risk
treatment)?

Formal 12
Information security risk management methodologies (ISRM)

• ISRM is a complex process that is best achieved through formal methods


• SDLC
• The Operationally Critical Threat, Asset, and Vulnerability Evaluation (OCTAVE)
• FAIR
• ISO and ISACA also have ISRM frameworks
• Framework from NIST as a formal methodology for risk management

Formal 13
NIST framework processes

• Setting goals and objectives;


• Identifying assets, systems, and networks;
• Prioritising and implementing protection programs and resiliency
strategies;
• Measuring performance; and
• Taking corrective action

Formal 14
Risk management framework and process

Formal 15
Risk management framework and process

Formal 16
Risk management framework steps

Executive governance
and support
Step 1 • Initially CISO and top
management must
develop and enable the
risk management
framework and its
resulting risk management
process.

Formal 17
Risk management framework steps

• Ensuring compliance with all legal and regulatory statutes and mandates;
• Guiding the development of, and formally approving, the risk management
policy.
• Recommending performance measures for the risk management effort and
ensuring that they are compatible with other performance measures in the
organisation;
• Assigning roles and responsibilities;
• Ensuring that the selected goals and objectives are appropriate and in
alignment with the organisation's strategic goals and objectives;
• Providing needed resources

Formal 18
Risk management framework steps

Framework design
• risk management process
Step 2 design.
• determine current levels of risk
and controls to reduce risk
level down to acceptable levels
specified by the risk appetite.
• define the organisation's risk
appetite and draft the risk
management plan.

Formal 19
Risk management framework steps

Framework
implementation
Step 3
• Implement the controls
and describe how the
controls are employed
within the system and
its environment of
operation
Formal 20
Risk management framework steps

Framework
Monitoring and
Step 4 Review
• evaluate the implemented
controls to determine if the
controls are implemented
correctly, operating as
intended, and producing
the desired outcome

Formal 21
Risk management framework steps

CyberMIS
• Create Cyber Management Information System (CyberMIS) in line with
the risk appetite model
• Use data from diverse data sources to build data models of all items that
drive risk for measurement
• Link data models on common fields to build a 3D model of the
environment and how it interacts
• Refresh the live environment on at least a daily basis
• Visualise the result for various reporting and operational purposes

Supplemental 22
Risk management framework steps
CyberMIS
Data warehouse
Applied to users
Extract via ETL

Publish view to
Or
SQL database

Emp ID Name/surname
In the datamart

6 1
Data models

Awareness User
5 2 Entity
Model

4 3 Risk score
Crown jewel

1 4 5 6
From data sources

2 3
Data tables

User data User data Risk data Crown jewel Awareness stats User data
(Name/surname) (Entity) (app risk score) indicator (Emp ID)

Source: HR system Source: HR system Source: IAM tool Source: eg Excel Source: Awareness Source: HR system
Method: Flat file Method: Flat file via Method: Data Method: Template software Method: Flat file via
via data import data import import import Method: Data import data import

Supplemental 23
Risk management framework steps
CyberMIS
Data warehouse
Applied to workstations
Extract via ETL

Publish view to
Or
SQL database

8
8 Network Network
Software status interaction
Asset ID
In the datamart

6 1
Data models

Source: Netflow
AV status Workstation Method: Data import
5 2 Emp ID
Model 7
4 3 Encr status IP address
Crown jewel
7 IP address
Source: SCCM or
Netflow
Method: Data import
1 4 5 6
From data sources

2 3
Data tables

Logon data Logon data Encryption Crown jewel Anti-virus status Software status
(Asset ID) (Emp ID) status indicator

Source: Active Source: Active Source: Encr software Source: eg Excel Source: AV software Source: SCCM
directory directory Method: Data import Method: Template Method: Data import Method: Data import
Method: Flat file Method: Flat file via import
via data import data import

Supplemental 24
Risk management framework steps
CyberMIS
Join data models on common fields

8 Network
Software status
Asset ID Emp ID Name/surname
6 1 6 1
AV status Workstation Awareness User
5 2 Emp ID 5 2 Entity
Model Model

4 3 Encr status 4 3 Risk score


Crown jewel Crown jewel
7 IP address

Create and calculate metrics based on data models

□ Metric 1: % of unencrypted workstations for plant1 = number of Workstation Model: Encr status = “no” and
where User Model: Entity = Plant1 , divided by total count of Workstation Model where User Model: Entity
= “plant1”
□ Metric 2: % of Water Pump crown jewel users in plant1 not completing awareness training = number of
User Model:Crown jewel = “Water Pump” and User Model:Awareness = “No” and User Model:Entity =
“Plant1” divided by total count of User Model: Crown jewel = Water Pump and User Model: Entity =
“plant1”
□ Etc.
Supplemental 25
Risk management framework steps
CyberMIS
1. Accuracy and completeness of the live environment and data sources

□ Any data source item that does not join to the model becomes a reconciling item
□ Reconciling items need to be investigated and fixed eg. a missing agent for that data source
□ All fixed items will the next day join and the data sources will become more accurate and in sync

Data sources before modelling Data source after modelling


Data source 4
Data source 2

Data source 5

Data source 5
Data source 4
Data source 3
Data source 2
Data source 1
Data source 1

Data source 3

670
699
733 Valid recon items
710 710 710 710 710 Eg. new machines
730 in AD but still
712 being loaded with
other agents

Supplemental 26
Risk management framework steps
CyberMIS
2. Calculating cyber posture

□ Visualise results through visualisation tools eg. PowerBI


□ Each metric gets a lower and upper threshold eg. under 20% is green, over 80% is read and inbetween yellow
□ All metrics % are aggregated and weighted based on contribution to calculate an overall % for cyber
□ Overall cyber posture % are visually displayed as a % on a dial
□ Appetite is depicted a green on the dial based on aggregate and weighting of lower thresholds

Appetite is the green line based


on aggregate and weighting of
lower thresholds

Supplemental 27
Risk management framework steps

Continuous Improvement
• Is a maintenance process to
continuously review and improve risk

Step 5 management efforts.


• It is a review plan of the risk
management framework and risk
management process to compare
outcomes from past and current
performance against the desired
outcomes.
• If a gap exists between desired
outcomes and current performance
changes are to keep the project working
toward those desired outcomes

Formal 28
Risk management framework and process

Formal 29
Risk management process steps

Establishing the context/Process preparation


Identifying risk
Analyzing risk
Evaluating the risk
Treating the unacceptable risk
Process communication
Process monitoring and review
Formal 30
Risk management process steps
Establishing the context
• Guidance is given by risk
management framework
team to risk management
Step 1 process team on work to be
done by risk management
team.
• Responsibilities are spelled
out and the risk management
process plan is reviewed.
• Consider internal and
external context
Formal 31
Risk management process steps

Identify the purpose of Identify the scope of the


the assessment assessment

Identify the assumptions Identify the sources of

Step 1 and constraints


associated with the
assessment
information to be used
as inputs to the
assessment

Identify the risk model


and analytic approaches
to be employed during
the assessment.

Formal 32
Risk management process steps
Risk identification
• Creating an inventory of
information assets
• Classifying and organizing
Step 2 those assets meaningfully
• Assigning a value to each
information asset
• Identifying threats to the
cataloged assets
• Pinpointing vulnerable assets
by tying specific threats to
specific assets
Formal 33
Risk management process steps
Identification of technical assets
• Using scanners are common in many organisations, however it is
dangerous as it can bring systems down
• Most appropriate and safest method to obtain an accurate view of the
environment is by analysing network traffic
• Tap network traffic via span ports through popular tools eg. DarkTrace or
Qradar Network Insights
• Event collectors collect traffic via switch span ports
• Learn what is normal traffic and what not
• Artificial Intelligence and behavioural analysis
• Create accurate view of the environment and monitor for any changes
• Correlate with other sources as per CyberMIS golden data sources

Supplementary 34
Risk management process steps

Information asset: is any asset that collects,


stores, processes, or transmits information, or
any collection, set, or database of information
Step 2 that is of value to the organisation” (Whitman
& Mattord, 2019, pp 320)

Formal 35
Risk management process steps
Information Assets
Information System Risk Management Example Risk Management components
Components components
People Internal personnel Trusted employees
External personnel Other staff members
People we trust outside our organisation
Strangers

Procedures Procedures IT and business-standard procedures


IT and business-sensitive procedures

Data Data/information Transmission


Processing

Step 2.1 Software Software


Storage
Applications
Operating systems
Utilities
Create inventory of Hardware Hardware
Security components
Systems and peripherals
information assets Security devices
Network-attached process control
devices and
other embedded systems (Internet of
Things)
Networking Networking Local area network components
Intranet components
Internet or extranet components
Cloud-based components

Formal 36
Risk management process steps
Information Assets Classification
Asset Internal Public Confidentiality Integrity Availability

People

Procedures

Step 2.2 Data

Classify the Software

information assets Hardware

Networking

Formal 37
Risk management process steps

• Which assets are the most critical to the


organisation?
• Which assets produce the most revenue
• Which assets will case the greatest harm if
Step 2.3.1 compromised?
Assign a value to • Which assets are the most expensive to
information assets replace?

Formal 38
Risk management process steps
Weighted score table
Asset Criteria1 Criteria2 Criteria3 Criteria4 Weighted score

Asset1

Step 2.3.2
Asset2

Asset3
Prioritise
information assets Asset4

(rank order) Asset5

Asset6

Formal 39
Risk management process steps

Crown Jewels
• Assets/systems with the highest impact if compromised are crown jewels
• Crown jewels are a small number of critical systems, the rest are jewels
• Eg. an assessment could yield 30 candidates (jewels) of which 5 or 6 are critical
(crown jewels)

Scenario analysis
• Consider and review examples of cyber attacks that occurred in the world
• Analyse how those were executed
• Consider potential losses of similar attacks that could happen in the
organisation against similar crown jewels
• Consider assets end to end through what an attacker would need to accomplish
Supplementary 40
Risk management process steps
Scenario analysis (also part of external context)
Event Type Date Description Gross Loss

Loss of data 2011 Global Payments: A US payment processing company, reported that it had lost $92.5M due to information theft.
In March 2012, Global Payments reported a data breach that affected approximately .95M credit card customers.
$92.5m
Thieves accessed Global Payments' servers and stole card numbers and other information from Visa, MasterCard,
American Express, and Discover Financial Services customers.
Loss of data 2019 Capital One: This data breach ranks as one of the biggest in history. A hacker named Paige Thompson infiltrated the
servers of a third-party cloud computing company (AWS S3) contracted for use by Capital One. According to the
$150m
U.S. Department of Justice, Thompson exploited a misconfigured web application firewall to gain access to the
information.
Bangladesh central bank, reported that it lost $81M (6.2B BDT) due to a hacking incident. In early February 2016,
hackers breached Bangladesh Bank's computer systems and submitted 35 payment requests worth $951M
Loss of money 2016 (72.79B BDT) to the Federal Reserve Bank of New York (NY Federal Reserve). The hackers had the necessary codes $81m
to authorise Swift transfers from the central bank's account, and they submitted the requests on a weekend when
they would receive less scrutiny.
Loss of money 2012 Postbank: Hackers used the login credentials for two Postbank employees to gain remote access to the employees'
R42m
computers and moved funds from legitimate Postbank accounts into the bogus accounts which was then
withdrawn from ATMs
Loss of money 2016 Standard Bank: Attackers managed to withdraw money from international ATMs using 1600 cards
R300m

Loss of data 2014 Target: The attackers found their way into Target's corporate network by compromising a third-party vendor, Fazio
Mechanical, a refrigeration contractor. A phishing email caught a Fazio employee, allowing Citadel, a variant of the
Zeus banking trojan, to be installed on Fazio computers. With Citadel in place, the attackers obtained Fazio $202m
Mechanical's login credentials to Target’s network. Compromised Target servers and lastly Point of Sale devices to
steal card data. BlackPOS malware was used to scrape card details from the server memory.
Loss of systems 2017 Maersk: NotPetya malware infected the company’s network and operations ground to a halt. All end-user devices,
including 49,000 laptops and print capability, were destroyed, all 1,200 applications were inaccessible and
$300m+
approximately 1,000 were destroyed. Backups couldn’t be restored as they were immediately re-infected. Around
3,500 of 6,200 servers were destroyed and couldn’t be reinstalled.

Supplementary 41
Risk management process steps
• The impact on the business can be material and can be so severe that a well-
managed and successful organisation that is profitable and running smoothly can
be severely damaged or terminated by a single cyber incident, and needs a
comprehensive business response vs a technical response eg cyber crisis
management team (CCMT)
Hacker shuts down Rogue engineer manipulates Manufacturing plant shuts Reputational damage
manufacturing plant PLC down
Social media fallout
Hacker steals designs from Compromise of database Database extracted to the
database through SQL injection Internet
Loss of market share

Regulatory fines
Hacker extorts money by Staff member inserts a Ransomware encrypts the
shutting down operations malicious USB thumb drive Windows estate Liability for loss of life

Scenario Technical response Business response

Incident response | 10 November 2021


Left side BOOM! Right side

Supplemental 42
Risk management process steps

• Threat assessment is assessing potential


weaknesses in each information asset.
• This is done by
• identifying the threats
Step 2.4 • assessing the threats and
Threat assessment • rank ordering them

Formal 43
Risk management process steps

Step 2.4.1
Identifying threats

Formal 44
Risk management process steps

• Which threats represent an actual danger to our


information assets?
• Which threats have the highest probability of
occurrence?
• Which threats have the highest probability of
success?
Step 2.4.2 • Which threats could result in the greatest loss if
Assessing threats successful?
• Which threats is the organisation least prepared
to handle?
• Which threats cost the most to protect against?
• Which threats cost the most to recover from?

Formal 45
Risk management process steps

Threat modelling
• Who/what is likely to attack the organisation, what methods will they use
and how will it be done
• Threat identification
• Threat actors eg nation state
• Threat vector eg USB media
• Threat event eg inject malicious software into organisational systems

Supplementary 46
Risk management process steps

Left side of the Right side of the


BOOM! BOOM!
Threat modelling - The cyber kill chain *

• Analyse each stage to understand what could go wrong and how to defend
• Avoid right side of the BOOM
* Developed my Lockheed Martin Supplementary 47
Risk management process steps

Threat modelling – Mitre Att@ck

• Knowledge base of adversary tactics and techniques based on real-world observations


• Some resemblance to cyber kill chain
Supplementary 48
Risk management process steps

List the categories of threats it


faces

Select categories that correspond


to the questions of interest

Assign a weighted value to each


Step 2.4.3 question category
Prioritise threats Assign a value to each threat with
respect to each question category

Result is a prioritized list of threats

Formal 49
Risk management process steps

Weighted score table


Threats Rate Rank Combined Overall rank

Threat1

Threat2

Step 2.4.3 Threat3

Prioritise threats Threat4

Threat5

Threat6

Formal 50
Risk management process steps

• Identify the vulnerabilities and factors that


affect the probability of threat exploiting a
vulnerability.
• The result at this stage is an understanding
Step 2.4.4 of the degree to which information assets
Vulnerability are vulnerable to threats
assessment

Formal 51
Risk management process steps
Vulnerability assessment of a DMZ router
Threat Possible vulnerabilities
Compromises to intellectual property Router has little intrinsic value, but other assets protected by this device could be
attacked if it is compromised.
Espionage or trespass Router has little intrinsic value, but other assets protected by this device could be
attacked if it is compromised.
Forces of nature All information assets in the organisation are subject to forces of nature unless suitable
controls are provided.
Human error or failure Employees or contractors may cause an outage if configuration errors are made.
Information extortion Router has little intrinsic value, but other assets protected by this device could be
attacked if it is compromised.
Quality-of-service deviations from Unless suitable electrical power conditioning is provided, failure is probable over time.

Step 2.4.4
service providers
Sabotage or vandalism IP is vulnerable to denial-of-service attacks.
Device may be subject to defacement or cache poisoning.

Vulnerability Software attacks IP is vulnerable to denial-of-service attacks.


Outsider IP fingerprinting activities can reveal sensitive information unless suitable

assessment
controls are implemented.
Technical hardware failures or errors Hardware could fail and cause an outage.
Power system failures are always possible.
Technical software failures or errors Vendor-supplied routing software could fail and cause an outage.
Technological obsolescence If it is not reviewed and periodically updated, a device may fall too far behind its vendor
support model to be kept in service.
Theft Router has little intrinsic value, but other assets protected by this device could be
attacked if it is stolen.

Formal 52
Risk management process steps

Risk analysis
Step 3 •Assigning a score to
each vulnerability
•Determine likelihood
•Determine Impact
•Risk determination

Formal 53
Risk management process steps

• Assess the likelihood (probability) that threat


events will be initiated (for adversarial threat
events) or will occur (for non-adversarial
threat events);
• Assess the likelihood that threat events once
initiated or occurring, will result in adverse
Step 3.1 impacts to organisational operations and
assets, individuals, other organisations, or the
Determine likelihood Nation;
• Assess the overall likelihood as a combination
of likelihood of initiation/occurrence (step 1)
and likelihood of resulting in adverse impact
(step 2).

Formal 54
Risk management process steps

• Determining the consequences of a


successful attack in the event that a threat
successfully exploits a vulnerability which
will be labelled as potential harm.
• Potential harms assist organisations to
Step 3.2 determine where to prioritise protection
Determine impact measures.
• The ranking used in risk identification can
help organisations better understand the
magnitude of a successful breach.

Formal 55
Risk management process steps

• Risk=likelihood of threat event X impact ± uncertainty


• Where:
• likelihood of threat event (attack) (obtained in step 3.1);
• impact (obtained in step 3.2);
• uncertainty is an estimate about error inherent in determining
Step 3.3 impact of a successful attack which can be due to:
• limitations on the extent to which the future will resemble the past;
Risk determination • imperfect or incomplete knowledge of the threat (e.g., characteristics
of adversaries, including tactics, techniques, and procedures);
• undiscovered vulnerabilities in technologies or products; and
• unrecognized dependencies, which can lead to unforeseen impacts

Formal 56
Risk management process steps

Risk evaluation
• Evaluating the risk to the organization's
key assets and comparing identified
Step 4 uncontrolled risks against its risk
appetite
• Identifying individual risk tolerances
for each information asset
• Combining or synthesizing these
individual risk tolerances into a
coherent risk appetite statement
• Informs the risk treatment approach

Formal 57
Risk management process steps
Five step risk appetite process

Formulate overarching risk appetite


statements
Top down approach (from statements to metrics)

Bottom up approach (from metrics to statements)

Quantitative / Qualitative
Cascade through the security value chain

Cascade for key risk drivers

Define metrics per driver

Set metrics thresholds

Supplementary 58
Risk management process steps
Five step risk appetite process

The organisation has no appetite for shutdown of the power


Top down approach (from statements to metrics)

grid

Bottom up approach (from metrics to statements)

Quantitative / Qualitative
(1) Staff, (2) Computer systems

(1) Staff security awareness, (2) Computer configuration

(1) % admins not completing awareness training, (2) %


engineering workstations not complying with security
standards

(1) 0%, (2) 0%

Supplementary 59
Risk management process steps

Risk treatment
• Determining which
treatment/control strategy is
Step 5 best considering the value of the
information asset and which
control options are cost effective
• Acquiring or installing the
appropriate controls
• Overseeing processes to ensure
that the controls remain
effective

Formal 60
Risk management process steps

Treating risk begins with an understanding of what


risk treatment strategies are and how to formulate
them. The chosen strategy may include applying
Step 5 additional or newer controls to some or all of the
Risk treatment assets and vulnerabilities

Formal 61
Risk management process steps

Risk treatment strategies

Step 5
Risk treatment

Formal 62
Risk management process steps
• Based on priorities, implement required controls and countermeasures
• Preventative controls – prevent something going wrong
• Detective controls – detect if something went wrong
• Corrective controls – fix something that went wrong
• Deterrent controls – discourage an attacker to do something wrong
• Consider resiliency controls ie. defending against unknown APT attacks

Prevention vs response
Apply more resources to prevention of high risk hazards and
more resources to response to low-risk hazards
• I don’t want high risk incidents to occur but I don’t mind to
rather respond to a low risk incident if it occurs

Supplemental 63
Risk management process steps

Process communication
• Process communication is when
risk assessment results are
Step 6 communicated to organisational
decision makers to support risk
responses.
• The communication can be
formal or informal and can
happen through executive
briefings, risk assessment
reports, dashboards

Formal 64
Risk management process steps

Process monitoring and


review
Step 7 • The objective of this step is to keep
current the specific knowledge of
the risk the organisation incurs.
• The results of risk assessments
inform risk management decisions
and guide risk responses.
• Risk assessment is used to effect
changes needed during monitoring

Formal 65
Thank you

66

You might also like