GROUP PROJECT
COURSE TITLE: SECURITY ADMINISTRATION
COURSE CODE: DCSS 021
PROJECT TITLE: RISK ANALYSIS
LEVEL:100 LEVEL
LECTURER NAME: DR EMMANUEL UZUEGBU-WILSON
NAME MATRIC NUMBER
EZEME SOMTOCHUKWU 24/1311
FAJIMI MANUELA 24/1988
RISK ANALYSIS
INTRODUCTION
“Life is inherently risky. There is only one big risk you should avoid at all costs, and that
is the risk of doing nothing. Denis Waitley quotes - brainy quote. (n.d.).
What is Risk Analysis?
Risk analysis is the process of identifying, assessing, and prioritizing potential risks or
threats to an organization, asset, or individual. It involves evaluating the likelihood and
potential impact of a risk, as well as identifying ways to mitigate or manage it. Risk
analysis is important in important in every aspect of life as decisions tend to go
sideways. There should be an assessment of the probability of the outcome of every
action.
Significance of Risk Analysis in Security Management
The following are the distinguished significance of risk analysis in security
management:
• Identifying Potential Threats: Risk analysis helps identify potential threats and
vulnerabilities, enabling security managers to make informed decisions about
resource allocation.
• Optimizing Security Measures: Risk analysis helps security managers optimize
security measures, such as personnel, technology, and procedures, to mitigate
identified risks. (N.d.-b)
• Optimizing Security Measures: Risk analysis helps security managers optimize
security measures, such as personnel, technology, and procedures, to mitigate
identified risks.
• Meeting Regulatory Requirements: Risk analysis helps security managers meet
regulatory requirements and compliance standards, such as HIPAA, PCI-DSS, or
GDPR. What are regulatory requirements? Compliance corner: Cube. CUBE
global. (n.d.).
In summary, risk analysis is a critical component of security management, enabling
security managers to make informed decisions, allocate resources effectively,
enhance security posture, meet compliance requirements, and drive continuous
improvement.
Types of Risk
• Financial Risk: this has to do with risk associated with finance and its
industries. They usually analysis risk in relation to their consequences in
aspect of market fluctuation also in relation to credit risks and liquidity risks.
The theme financial risk does not stand on its own as there are various factors
which make up financial risk which would have to be addressed on their own
before the as a whole risk involved in financial activities would be effectively
managed Financial Risk Management: 15 strategies to minimize risk - read
more. Home. (n.d.).
• Operational Risk: Operational risk is the risk of losses caused by flawed or
failed processes, policies, systems or events that disrupt business operations.
Employee errors, criminal activity such as fraud and physical events are among
the factors that can trigger operational risk. Morgan, L. (2024, February 15). What
is operational risk? Definition from TechTarget. Search Security.
• Environmental Risk: this refers to activities which possess significant threat to
the normal day to day functioning of the [Link] is further referred
to circumstances or situations which further affect the functioning of the eco system.
Google. (n.d.). Google search.
• Safety Risk: this by far the most important when it comes to risk analysis and
management as this actually serves as a threat to humans, their property and
even their environs. This evaluates how humans and their fellow human
activities may serve as a potential danger to others and even themselves.
Risk Analysis Processes
In order to effectively explain what risk analysis is all about, one must first adequately
understand that it does not only involve been able to see situations which stand as
threats but been able professionally explain which that has been assessed as a risk
and find various strategies to neutralize the risk.
The Risk Analysis Process
Risk Analysis Risk Assessment
Risk Analysis
Process
Risk
Risk Mitigation
Prioritization
• Risk Identification: the risk analysis process starts with the process of been able
to identify a potential threat. There are various ways which have been
exemplified as strategies for risk analysis such as; brain storming, SWOT
analysis, Delphi technique, interviews, Root cause analysis, document reviews.
However, the most distinguished strategy would be the SWOT technique.
S: strength
W: weaknesses
O: opportunities
T: threats
• Risk Assessment: the process of risk assessment involves evaluating the likely
hood and impact risk using the techniques available to find out their
consequences on the situations. There are various methods which can be used
in exercises such as probability impact matrices, risk scoring, qualitative risk
assessment, FMEA, failure mode effect analysis.
• Risk Prioritization: after the other processes have been carried out, there must be
an effective plan carried out to determine how the resources would be utilized on
the previously identified and assessed risks. There must be an outlined scale to
show risks from the most dangerous to the least dangerous till they can be
effectively utilized.
• Risk Mitigation: there is a process of mitigating the identified risk to prevent
them from escalating to dangers to various situations. There should be
effectively neutralized. The process of neutralization is the most important
factor of risk mitigation.
Identify all possible
events in which risk Perform a risk
is presented. Prioritize risks.
assessment.
Track risks. Implement and
monitor progress.
Types of Risk Analysis
Not every industry conducts risk analysis the same way. Each organization will adjust
these types of analyses to fit its situation when they are identifying the different types of
risks in various situations. When it comes down to preventing, detecting, and
investigating risk, having more than one type of risk analysis as part of your risk
management process is more beneficial than not having any. In many cases,
organizations will use more than one type to get a fuller understanding of the risks they
face. The various types are:
• Risk-benefit Analysis: This is a technique nearly all organizations are familiar
with. As any successful company knows, some risks are worth taking. “Enterprise
risks such as new products and markets, new technologies, and strategic
acquisitions can boost top-line growth and profitability. By contrast, “operational
risks” can potentially threaten a company’s operations. Risk-benefit analysis
helps a company determine what category certain risks may fall into. Many
people are aware of a cost-benefit analysis. In this type of analysis, an analyst
compares the benefits a company receives to the financial and non-financial
expenses related to the benefits. The potential benefits may cause other, new
types of potential expenses to occur. In a similar manner, a risk-benefit analysis
compares potential benefits with associated potential risks. Benefits may be
ranked and evaluated based on their likelihood of success or the projected
impact the benefits may have.
• Business Impact Analysis: Conducting impact analysis can determine how
disruptive the impacts of a potential risk event might be. There are numerous
types of risk where this kind of analysis can be useful. Some are relatively
obvious, such as supply shortages and natural disasters. Other risk events might
be less apparent, including the effects of rising interest rates and the retirement
of key employees with highly specialized knowledge. In many cases, a business
may see a potential risk looming and wants to know how the situation may
impact the business. For example, consider the probability of a concrete worker
strike to a real estate developer. The real estate developer may perform a
business impact analysis to understand how each additional day of the delay
may impact their operations.
• Needs Assessment Analysis: A needs risk analysis is an analysis of the current
state of a company. Often, a company will undergo a needs assessment to better
understand a need or gap that is already known. Alternatively, a needs
assessment may be done if management is not aware of gaps or deficiencies.
This analysis lets the company know where they need to spend more resources
in. A needs assessment analysis can also reveal any gaps or deficiencies in an
organization’s operations. By conducting this kind of risk analysis, the company
can better determine where it needs to allocate its risk mitigation resources.
• Root Cause Analysis: Opposite to a need analysis, a root cause analysis is
performed because something is happening that shouldn't be. This type of risk
analysis strives to identify and eliminate processes that cause issues. Whereas
other types of risk analysis often forecast what needs to be done or what could
be getting done, a root cause analysis aims to identify the impact of things that
have happened or continued to happen and the existing processes that could
cause disruptions to the organization in the future. An example might be long-
used software that might be out of date and thus might render a company
vulnerable to a data breach or to a competitor with more effective digital tools.
Advantages and Disadvantages of Risk Analysis
Advantages
May aid in minimizing losses due to management preemptively forming a risk plan.
May allow management to quantify risks and assign dollars to future events.
May protect company resources, produce better processes, and mitigate overall
risk.
Disadvantages
Relies heavily on estimates, so it may be difficult to perform for certain risks.
Cannot predict unpredictable, black swan events.
May underestimate risk magnitude or occurrence, leading to overconfident
operations.
Conclusion
Regardless of the types and techniques a company chooses, risk analysis is an
essential practice for all types of organizations. Which approaches a company
takes will vary based on its industry, size, competitive landscape, market, and
other organizational considerations. To make its risk analysis efforts as effective as
possible, companies should also consider integrating digital risk assessment tools
into their processes. Such tools, if carefully vetted and chosen, can help an
organization be more accurate and efficient throughout every aspect of risk
assessment, including risk identification, risk management, and risk mitigation. In
an increasingly complicated organization environment, companies need these
kinds of tools to manage the complexity of the risks they must address.
REFERENCES
Denis Waitley quotes - brainyquote. (n.d.).
[Link] quotes(N.d.-b).
Abbas, A. (2024, March 19). What are regulatory requirements? CUBE Global.
[Link]
requirements#:~:text=Regulatory%20requirements%20are%20rules%20that%20busine
sses%20must%20follow.,as%20regulations%2C%20these%20obligations%20can%20
specify%20different%[Link] Risk Management: 15 strategies to minimize
risk - read more. . (n.d.). [Link]
Center/Financial- Risk- Management-15-Strategies-to-Minimize-Risk
Morgan, L. (2024, February 15). What is operational risk?: Definition from TechTarget.
Search Security.
[Link]
Google. (n.d.). Google search.
[Link]
Brisk&gs_lcrp=EgZjaHJvbWUyBggAEEUYOTINCAEQABiRAhiABBiKBTINCAIQ
ABiAhiABBiKBTINCAMQABiRAhiABBiKBTINCAQQABiRAhiABBiKBTINCAUQABiAhi
ABBiKBTIJCAYQABgKGIAEMgkIBxAAGAoYgAQyCQgIEAAYChiABDIM
CAkQABgKGLEDGIAE0gEJMTE2MzFqMGo3qAIAsAIA&sourceid=chrome&ie=U TF-
8
What is risk identification? definition and tools [Link]. (n.d.-b).
[Link] identification read, A.
byJairus A. min, Andales, A. byJairus, by, A., & Article byJairus AndalesSafetyCulture
Content SpecialistJai Andales is a content writer and researcher for SafetyCulture
since 2018. As a content specialist. (2024, September 12). Risk assessment:
Process, tools, & techniques. SafetyCulture. [Link]
assessment/