= Information System Management
RISK Management
1
=
Learning Objectives
Upon completion of this lecture, students will be able to:
Understand the difference between risks and
issues.
Identify different types of risks and the process to
handle risks in an IT project.
Outcome:
Understand the roles, responsibilities of risk
management.
Understand organization risks and the potential
of these risks in a global enterprise.
2
=
Where Are We Going? Will We Make It?
3
= Risk or Issue?
4
=
Risk Management Definition
Risks are events that occur, causing problems.
Risk management is the process that allows IT
managers to balance the operational and economic
costs of protective measures in IT systems to
support the business’ missions.
5
= Risk Management
In the new economy and global enterprise, the nature of IT
risk has changed, from preventing events in IT projects, to
managing integrated business and technology exposure.
With extended enterprise and globalization, the visibility of
IT risk and potential business loss resulting from IT failure
are increasing for the enterprise and their suppliers and
customers.
Most CIOs are aware of traditional IT risk categories such
as project, vendor and technology risk. But the nature of IT
risk has changed… with the impact of some IT risk,
especially when compounded by regulatory penalties and
market reactions.
6
=
Risk Management Process
Risk Identification: Identify risk and mapping of the:
• Scope of risk management
• Source of risks
• Basis upon which risks will be evaluated
Risk Analysis: Review and analyze risks involved in the
process.
Risk Assessment: Identify options of handling risks.
Mitigation: Prevent or lessen the risk using available
resources.
7
= Risk Management Process
8
=
Source Of Risks
Risk identification can start with the source of problems. Risk
sources may be internal or external to the organization or the
project.
For example:Customers of a project may decide to cancel it. Key employee of a
project involved in an accident. Weather at an airport can delay a flight.
9
=
Risk Assessment
10
= Risk Analysis
11
=
Risk Analysis
• If risks are improperly assessed and prioritized, time canbe
wasted in dealing with risks that are not likely to occur.
• Spending too much time assessing and managing unlikely risks
can divert resources that could be used else [Link]
events do occur but it may be better to simply retain the risk
and deal with the result if the loss does occur.
12
=
Risk Management - Key Attributes
A good risk management process includes:
• Documented plan, tailored to program needs.
• Identical processes used across all teams and functions.
• Analysis criteria that are consistently applied.
• Disciplined escalation [Link] to customer and key
supplier risks.
• Mitigation plans, when required, included in team schedules.
• Fallback plans included in mitigation for high risks.
For best chance of success:
– Start early.
– Monitor and manage actively.
– Stay focused on the end objectives.
– Keep high risk visible.
13
=
Project Risks
In projects, risk management may include:
• Planning how risk management will be held in the project.
• Risk management plans should include risk managementtasks,
responsibilities, activities and budget.
• Risk management plans may include a team member other than
a project manager who is responsible for managing potential
project problems.
• Each risk should have the following attributes: opening
date,title, short description, probability and importance.
• Each project team member should report risk in the project.
• Risk mitigation plans should describe how particular risk willbe
handled – what, when, by who and how will it be done toavoid
or minimize consequences if it becomes a liability.
14
=
Project Risk Identification
Estimation risk (Scope, size, function)
Business impact risk (Market, management)
Customer relationship risk (Communication)
Process definition risk (Standards, tailoring)
Environment risk (Quality, tools)
Technology risk (Complexity & changes)
People risk (Staff & experiences)
15
= Roles
16
=
Project Risk Table
17
=
Risk Example
ABC company has introduced object-oriented (OO) technology into its IT
organization by selecting a well-defined project "X“ with schedule constraints to pilot
the use of the technology.
Although many "X" project personnel were familiar with the OO concept, it had not
been part of their development process, and they have had very little experience and
training in the technology's application.
It is taking project personnel longer than expected to learn the new technology.
Some personnel are concerned, for example, that the modules implemented to date
might be too inefficient to satisfy project "X" performance requirements.
The risk is: Given the lack of OO technology experience and training, there is a
possibility that the product will not meet performance or functionality requirements
within the defined schedule.
18
=
Organization Risks
Organization risks are risk factors related to business continuityand other
risks that impact the business.
The connected economy opens the door to new dependencies and
threats. Regulation is tightening corporate governance and management.
Governments are legislating on privacy and security changes to protect
individuals.
IT failures create new legal liabilities because many processes are
depending on Information systems.
Senior management such as CIOs must address these risks by:
Establishing a baseline of risk management processes to quantify and
manage current risk exposure.
Standardizing the technology base to reduce integration risks and ensure
compatibility and interoperability.
Issue risk management governance processes to build the business’s risk
management confidence and awareness.
19
= Organization Risk Categories
The interconnection of global businesses increasesdependencies and
exposure to theft and misuse of [Link] and access for partners,
suppliers, outsourcing suppliersare new risks outside the traditional IS.
Executive criminality has produced many corporate failuresand new
legislation aimed at reducing such abuses. These lawspresent new legal
risks in handling and safeguarding information(i.e., Sarbanes – Oxley).
Consumer demand for privacy protection. The risingincidence of identity
theft, and increased theft of sensitivepersonal information led people to
demand privacy [Link] complying with these new privacy laws is a
new legal risk.
IT failures, with new legal liabilities - increasing risky business.
20
=
Organization Risks
21
Value of Risk Management
=
22
=
Risk Management Tools and Techniques
There are a variety of tools to help manage risk effectively.
Risk analysis methods vary from simple qualitative to
complex quantitative approaches.
Focus should be on identification and mitigation.
Several database tools are available to keep track of risk
and mitigation plans.
Smaller programs may simply use Excel lists.
Keys to successful implementation are top-level support,
team roles, responsibilities and accountabilities,
widespread participation, coordination, visibility,
communication and discipline.
23
=
Example Of 12 Month Risk Status
24
=
Example Of Team Risk Summary Chart
25
=
Simple Risk Analysis Templates
26
=
Easy Communication of Key Risks
27
= Summary
Risk is an undesirable situation which may, or may not, occur.
Risk management is a systematic decision-making process that:
o Efficiently identifies risk.
o Assesses risk levels.
o Handles risk effectively to achieve program goals, including
mitigation when appropriate.
Risk identification is done continuously in all program areas with
appropriate management, visibility and participation.
Risk analysis identifies significant items for the program manager’s
attention, and does not need to be an end unto itself.
Risk mitigation plans should be included in team plans, and each
mitigation action should include associated risk reductions.
Integrated product teams own the risk associated with their areas.
Preventive action is cheaper than corrective action, therefore handle
the risks before they turn into problems or issues.
28
=
Questions & Answers
29