Operational Risk Assessment Overview



Similar documents
Risk Assessment Guide

HURRICANE DISASTER PREPARATION CHECKLIST AND BUSINESS CONTINUITY PLAN

RLI PROFESSIONAL SERVICES GROUP PROFESSIONAL LEARNING EVENT PSGLE 125. When Disaster Strikes Are You Prepared?

How To Handle An Emergency

Prepared by Rod Davis, ABCP, MCSA November, 2011

Emergency Preparedness for Design Firms. RLI Design Professionals Design Professionals Learning Event DPLE 244 September 16, 2015

WHY DO I NEED DATA PROTECTION SERVICES?

Continuity of Operations Planning. A step by step guide for business

Business Continuity Planning for Risk Reduction

Business, Government & Community Continuity from A to Z Seminar Topics: Continuity Plan Considerations & Project Management Vital Records

Agenda. Creating a Robust Testing Program. Notification Tests. Overview of Testing. Beverly Schulz, CBCP

Cisco Disaster Recovery: Best Practices White Paper

Ready for Anything BUSINESS CONTINUITY GUIDE FOR BUSINESS OWNERS. Plan to Stay in Business

North Carolina Emergency Management

4 Insurance 5 Availability of alternate sources for critical supplies/services

Emergency Preparedness Checklist for Small Businesses

INFORMATION TECHNOLOGY SECURITY STANDARDS

Threat and Hazard Identification and Risk Assessment

Building Economic Resilience to Disasters: Developing a Business Continuity Plan

Statewide Disaster Recovery Coordinator Meeting. October 31, 2012

Operational Risk Management Policy

Disaster Recovery Plan Checklist

EMERGENCY ASSESSMENT AND RESOURCES

The University of Iowa. Enterprise Information Technology Disaster Plan. Version 3.1

Business Continuity Planning Guide

Disaster Recovery And Contingency Plan Design and Implementation Manual For Utilities

Disaster Recovery & Business Continuity Dell IT Executive Learning Series

By: Tracy Hall. Community Bank Auditors Group Taking Your Business Continuity Plan To The Next Level. June 9, 2015

BEST PRACTICES FOR COMMERCIAL COMPLIANCE

The Business Case for Electronic Visitor Management

Free Guide: THE FACILITY MANAGER S DISASTER RECOVERY & RESPONSE ROADMAP

This document contains the text of Secretary of the State regulations concerning

Ensure Absolute Protection with Our Backup and Data Recovery Services. ds-inc.com (609)

[Insert Company Logo]

Disaster Ready. By: Katie Tucker, Sales Representative, Rolyn Companies, Inc

New York State Unified Court System. Workplace Safety Assessment

Nine Steps to Smart Security for Small Businesses

ISO Controls and Objectives

Disaster Recovery Best Practices & Lessons Learned

ministry operations fire safety relocations designations evacuation bomb threat closure operations back-up of records weather policy

MAJOR PROJECTS CONSTRUCTION SAFETY STANDARD HS-09 Revision 0

Office of Human Resources A Shared Service of DHS and OHA

Business Unit CONTINGENCY PLAN

Subject: County of Los Angeles Data Center Space Requirement

Business Continuity Management & Disaster Recovery GETTING STARTED Checklist for Local Businesses & Organisations

SHARED ASSESSMENTS PROGRAM STANDARD INFORMATION GATHERING (SIG) QUESTIONNAIRE 2014 MAPPING TO OCC GUIDANCE ( ) ON THIRD PARTY RELATIONSHIPS

Winter Conference 2014 Presented By Mark Wingfield Sales Manager PropertyInfo Co., Inc.

Vendor Management. Outsourcing Technology Services

Threat and Hazard Identification and Risk Assessment Guide. Comprehensive Preparedness Guide (CPG) 201

JUMP START DISASTER RECOVERY PLAN FOR HOSPITALITY

A Sample Disaster Response Plan

DISASTER RESPONSE: MANAGING THE ENVIRONMENTAL RISKS. By Frank Westfall and Robert Winterburn

This presentation will introduce you to the concepts and terminology related to disaster recovery planning for businesses.

Chapter 6: Mitigation Strategies

Emergency Management Audit For Businesses

EMERGENCY PREPAREDNESS PLAN Business Continuity Plan

CHECKLIST FOR A CHURCH EMERGENCY MANAGEMENT PLAN INTRODUCTION

The Orange County Farmers Museum Emergency Preparedness Plan

Starbucks Creating a Connected Organization through Critical Communications

Datacenter Assessment

Federal Financial Institutions Examination Council FFIEC. Business Continuity Planning BCP MARCH 2003 MARCH 2008 IT EXAMINATION

Business Continuity Planning. Presentation and. Direction

STEP-BY-STEP BUSINESS CONTINUITY AND EMERGENCY PLANNING MAY

EMERGENCY EVACUATION PROCEDURES

BUSINESS CONTINUITY PLAN

Identifying Key Risk Indicator

Defense in Depth: Off-Site Storage of Biological Specimens and Biopharmaceuticals. for Risk Mitigation

Emergency Management is responsible for coordinating the City of Houston s preparation for and response to emergency situations.

Workforce Solutions Business Continuity Plan May 2014

Fire Safety Log Book

Emergency Plan Starter Kit

What is an Exercise? Agenda. Types of Exercises. Tabletop Exercises for Executives. Defining the Tabletop Exercise. Types of Tabletop Exercises

How To Protect Decd Information From Harm

Best Practices module

How to Prepare for Business Continuity After A Disaster

Text Box 1 Important Actions, Questions and Constraints to Consider on Standards and Vulnerability

BMUSF Marine Seminar. Project Cargo Panel. May 4, 2012 San Francisco, California

EMERGENCY PREPAREDNESS TEMPLATE

Federal Financial Institutions Examination Council FFIEC BCP. Business Continuity Planning FEBRUARY 2015 IT EXAMINATION H ANDBOOK

How to carry out a risk assessment and create a safety statement

Creating a Business Continuity Plan for your Health Center

Union College Campus Safety Emergency Action Guide

Best Practices in ICS Security for System Operators. A Wurldtech White Paper

SECURITY VULNERABILITY CHECKLIST FOR ACADEMIC AND SMALL CHEMICAL LABORATORY FACILITIES

THE USE OF TRIZ IN BUSINESS CONTINUITY PLANNING

Network Traffic Management under Disaster Conditions. Hediye Tuydes PhD Candidate Northwestern University

Music Recording Studio Security Program Security Assessment Version 1.1

NCUA LETTER TO CREDIT UNIONS

Georgia Creson Assistant Director of Career Development, Fine Arts

ISO27001 Controls and Objectives

BNA FEDERAL CREDIT UNION DISASTER RECOVERY PLAN

Assessment of natural hazards, man made hazards, technical and societal related risks and associated impact.

BUSINESS CONTINUITY PLANNING GUIDELINES

Insurance Boot Camp. Understanding Coverages for Your School Division, Staff and Students

Visit the GPA website to:

CORPORATE OVERVIEW. Our Mission and Our Name

U.S. Department of Housing and Urban Development Office of Public and Indian Housing. A Good Place to Live!

Emergency Management Specialists

Exit Routes, Emergency Action Plans, Fire Prevention Plans, and Fire Protection. OSHA Office of Training and Education 1

Transcription:

Operational Risk Assessment Overview Goal of Operational Risk Assessment Common Risk Types and Categories What to Assess Most Overlooked Items Rating Risk and Reporting Mitigation Strategies Recommendations

The Operational Risk Assessment Goal is to: Discover and categorize exposures that could reduce the effectiveness, compromise, disrupt or destroy the continuity of business operations by negatively impacting: Business reputation, revenues or fiscal stability Personnel, clients and partners Confidentiality, integrity or availability of data, business applications, systems and networks Hard business assets and facilities Risk Types and Categories

Common Risk Types Financial Risk Market Credit Liquidity Business/Product Risk Legal/Regulatory Risk Operational Risk Other Risk Outside the control of the Company Miscellaneous exposures Operational Risks Exposures the Company has some control over Mitigation can be put in place at various levels based on risk appetite and cost Transfer of risk is possible for some of the exposures Business Continuity Plans and Disaster Recovery Plans provide a certain level of mitigation for assumed risk exposures

Operational Risk Categories Environment Building Safety Security Human Regulatory Client Nature Neighbors Risk Management and Business Continuity What to Assess

Environment/Building Environment Geography What is dangerous and quantify the amount Building Structure composite Age and condition Glass HVAC systems Wiring and power

Safety Stairs handrails Tripping, falling hazards Equipment safety features Chemical on premise controls Defibrillators Evacuation routes Emergency response plans and training Workplace violence controls Security Building and entrance Floor and suite security Facility systems - access and security controls IT Network Systems production, test and development Applications Mobility controls Data Access controls Monitoring Encryption Employee training Vendor management Audit internal and external

Human Employees Pre employment screening Policies AUP Desktop Security Onboarding process Monitoring compliance Termination process Contractors Security and Data Privacy adherence Vendors Supply Chain Management

Clients Who are they Their product risk and how they manage it Are they regulated and if so, what are their controls Ethics and integrity Your internal sales process are you vetting clients Financial stability Company history and reputation Contracts Liability language Cyber Regulatory Legal Contractual obligations SLAs State and federal requirements Fiduciary responsibility Social responsibility Societal security Compliance monitoring Internal External - audits

Nature Winter Ice Blizzard term first coined in Emmetsburg, Iowa Summer Lightening Floods or mudslides Tornado, hurricanes or cyclones Earthquakes and fault zones Heat and drought Daylight to night ratio

Neighbors Dams or locks Grain elevators Petroleum or ethanol plants Chemical plants Government offices Transportation routes and cargos Railroad tracks Interstate Ingress/egress speeds Religious sites Schools/colleges/universit ies Financial institutions High profile national monuments or tourist sites Utilities: power, water, communication sites Nuclear sites and targets Others nearly endless

Risk & Business Continuity Management Program Risk and BC Management Program and Policy Policies and Procedures with Executive Approval Assessments Mitigation and Control Strategies Assumption of Risk Process Risk Monitoring and Review Business Continuity Planning (your mitigation for the unfixable ) Program Life Cycle Exercise and Testing Auditable Proofs Most Overlooked Exposures

Most Overlooked Exposures Employee practices Desktop security Company policy enforcement Corporate reputation management Fire suppression Power failure conditions Recovery test compliance Old mining locations now abandoned Sink holes Risk Rating and Reporting

Rating Risk Complex Availability of historical data and loss ratios Need actuaries Simple Zero, Low, Medium, High Business impacts from disruption Cost of impacts Probability Base on how much is present How often it occurs in the region Color code for easy viewing Operational Risk Assessment Collection Tool

Compound Risk These are the What Ifs No fire suppression, no alarms, no conduit for wires in public areas High risk neighbors, next to a train track within 10 yards of your facility Facility is in a flood plain and the demarc along with the generator is in the basement Long time employees and perpetual downsizing and reorganizations Your customer is under attack by PETA and your name is in the paper with them for a new joint venture Report Types Executive summary usually 1 to 3 pages depending on site Risk report 12 to 15 pages Overview Details Recommendations Summary Detailed information as a reference Visuals All the high risks by site Site criticality Revenue impacts Effects of mitigation controls

L O C A T I O N S 1 2 3 4 5 6 7 8 9 10

Mitigation Strategies Mitigation Strategies Pick the highest risk exposures with the most probability Where is your risk appetite? Capital expenditures Cost to fix versus cost if it occurs Use revenue impact by hour, day, week, month Reduce risk transfer costs

Mitigation Strategies Human controls Policies and procedures Training Auditing Transfer of risks insurance Business continuity and DR plans Monitoring controls and testing Recommendations

Recommendations Keep it as simple as possible Look for mitigation and controls that will fix more than one exposure Monitor progress of mitigation and controls Test the controls from time to time Make it visual so it s easy to see and understand Questions? Vicky McKim, MBCP, MBCI vmckim@netins.com 515-830-0233