Lecture 14
Risk Management
Course Outline
• Introduction
• Ethics and codes of conduct
• Structure of organization (Software House)
• Financial practices
• Human resource management
• Intellectual property
• Cyber law
• Software related contracts
• Software Safety
• Social networking responsibilities and ethics
• Information security and privacy
Previous Lecture
• Information Security: practice of defending information
from unauthorized access, use, disclosure, disruption,
modification, inspection, recording or destruction.
• The CIA principle
– Confidentiality(unauthorized disclosure include medical,
financial, academic and criminal)
– Integrity(unauthorized modification of files)
– Availability(unauthorized withholding of information)
• Information Classification
– Government classifications
– Private Sector classifications
– Criteria
Chapter 3: Software Issues: Risk and Liability
(8.3)
Book: Ethics and Social Issue in Information
age by Joseph Migga Kizza, 2017
RISK
MANAGEMENT
LECTURE REVIEW
• Introduction
• Overview of Risk management
• Risk identification
• Risk assessment
• Risk control strategies
OVERVIEW OF RISK MANAGEMENT
Risk is the likelihood of the occurrence of a
vulnerability
MULTIPLIED
by the value of the information asset
MINUS
the percentage of risk mitigated by current controls
PLUS
the uncertainty of current knowledge of the
vulnerability.
Risk
• HAZARD. is a state or set of conditions of a system or an object
that, together with other conditions in the environment of the
system, or object, will lead inevitably to an accident.
• According to Leveson, hazard has two components:
– Severity
– likelihood of occurrence.
• These two form the hazard level.
• RISK is a hazard level together with the likelihood of an accident to
occur and the severity of the potential consequences
• Risk can also be defined in simpler terms as the potential or
possibility of suffering harm or loss—danger, in short
OVERVIEW OF RISK MANAGEMENT
• Risk Management is identifying, evaluating, and mitigating
risk to an organization.
– It’s a cyclical, continuous process
– Need to know what you have
– Need to know what threats are likely
– Need to know how and how well it is protected
• a systematic process of evaluating the potential risks that
may be involved in a projected activity or undertaking.
Process of Risk Analysis
Step #1 – Identification of Risk
• The First step comes as identifying the risk. Team members shall
gather all the inputs that shall be used in the projects and
recognize the outcome of the projects and the number of ways
such is risk involved in the process, etc.
Step #2 – Analyzing the Risk
• After identifying risk, it’s likely to understand and assess the
extent of risk and nature of risk that most likely to happen and
to what extent it may occur to the organization shall be
analyzed.
Process of Risk Analysis
Step #3 – Evaluating the Risk
• Analyzing risk helps you to estimate the capacity of risk that may
happen. Hence in evaluating the risk, the team shall rank the calculated
risk to decide whether to accept such risk or not.
Step #4 – Treat the Risk
• In this step, the team shall decide whether to continue the project or
not; if so, the project is accepted, then they shall try to treat or resolve
the issue by modifying any changes required in the project.
Step #5 – Review the Risk
• As the risk is uncertain at any point in time, reviewing risk is essential to
evaluate risk in the project from time to time to avoid any future
disturbance.
Risk Management Process
1. Identify potential risks
What can possibly go wrong?
• The four main risk categories of risk are
– hazard risks, such as fires or injuries;
– operational risks, including turnover
– supplier failure; financial risks, such as economic recession;
– strategic risks, which include new competitors and brand reputation.
Being able to identify what types of risk you have is vital to the risk
management process.
• An organization can identify their risks through experience and
internal history, consulting with industry professionals, and
external research. They may also try interviews or group
brainstorming.
• It’s important to remember that the risk environment is always
changing, so this step should be revisited regularly.
RISK IDENTIFICATION
• Assets
• Threats
– Threat sources: Man made or natural
• Vulnerabilities
– Weakness
• Controls
– Safeguard
2. Measure frequency and severity
What is the likelihood of a risk occurring and if it did, what
would be the impact?
• Many organizations use a heat map to measure their risks on
this scale. A risk map is a visual tool that details which risks are
frequent and which are severe This will help you identify which
are very unlikely or would have low impact, and which are very
likely and would have a significant impact.
• Knowing the frequency and severity of your risks will show you
where to spend your time and money, and allow your team to
prioritize their resources.
RISK ASSESMENT
• Assessing Potential Loss (measuring)
• Percentage of Risk Mitigated by Current Controls
– Uncertainty
• Risk Determination
• Likelihood and Consequences
EXAMPLES
3. Examine alternative solutions
What are the potential ways to treat the risk and of these, which
strikes the best balance between being affordable and effective?
Organizations usually have the options to accept, avoid, control, or
transfer a risk.
• Accepting the risk means deciding that some risks are inherent in
doing business and that the benefits of an activity outweigh the
potential risks.
• To avoid a risk, the organization simply has to not participate in
that activity.
• Risk control involves prevention (reducing the likelihood that the
risk will occur) or mitigation, which is reducing the impact it will have
if it does occur.
• Risk transfer involves giving responsibility for any negative
outcomes to another party, as is the case when an organization
purchases insurance.
RISK CONTROL STRATEGIES
• Identify Possible Controls
– For each threat and its associated vulnerabilities that have
residual risk, create a preliminary list of control ideas.
– Three general categories of controls exist:
• Policies
• Programs
• Technical controls
4. Decide which solution to use and implement
• Once all reasonable potential solutions are listed, pick
the one that is most likely to achieve desired outcomes.
• Find the needed resources, such as personnel and
funding, and get the necessary buy-in. Senior
management will likely have to approve the plan, and
team members will have to be informed and trained if
necessary.
• Set up a formal process to implement the solution
logically and consistently across the organization, and
encourage employees every step of the way.
5. Monitor results
• Risk management is a process, not a project that can be
“finished” and then forgotten about. The organization, its
environment, and its risks are constantly changing, so the
process should be consistently revisited.
• Determine whether the initiatives are effective and whether
changes or updates are required. Sometimes, the team may
have to start over with a new process if the implemented
strategy is not effective.
• If an organization gradually formalizes its risk management
process and develops a risk culture, it will become more
resilient and adaptable in the face of change. This will also
mean making more informed decisions based on a complete
picture of the organization’s operating environment and
creating a stronger bottom line over the long-term.