Top Banner
29
Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: Risk Management - Jisc Digital Festival 2015
Page 2: Risk Management - Jisc Digital Festival 2015

Risk management workshop

Page 3: Risk Management - Jisc Digital Festival 2015

» Information security manager

» Certified ISO 27005:2011 ISMS Risk Manager

Risk management workshop

09/03/2015 Jisc Digital Festival, 9-10 March 2015, ICC Birmingham 3

Page 4: Risk Management - Jisc Digital Festival 2015

Risk management workshop

09/03/2015 Jisc Digital Festival, 9-10 March 2015, ICC Birmingham 4

» Sharing some of my experiences of risk management

» How to think about what risk means to you

» Ideas on what makes for an effective process

» NOT: a prescriptive guide to risk management

What’s covered in this risk assessment

Page 5: Risk Management - Jisc Digital Festival 2015

What is risk?

09/03/2015 Jisc Digital Festival, 9-10 March 2015, ICC Birmingham 5

Risk management workshop

Page 6: Risk Management - Jisc Digital Festival 2015

What is risk?

09/03/2015 Jisc Digital Festival, 9-10 March 2015, ICC Birmingham 6

» “The effect of uncertainty on objectives”ISO Guide 73:2009

» Will it snow?

» How much effort should we spend planning for floods?

Risk management workshop

Page 7: Risk Management - Jisc Digital Festival 2015

What is risk management?

09/03/2015 Jisc Digital Festival, 9-10 March 2015, ICC Birmingham 7

Risk management workshop

» The tools that allow us to deal with the uncertainty inherent in our activities

» If we spend £10,000 now, we can halve the impact of one-in-ten-year floods

Page 8: Risk Management - Jisc Digital Festival 2015

09/03/2015 Jisc Digital Festival, 9-10 March 2015, ICC Birmingham 8

» We operate in an uncertain environment

» Analysing uncertainty allows us to spot opportunity and make failure less likely

Why risk management?

Risk management workshop

Page 9: Risk Management - Jisc Digital Festival 2015

Group exercise 1:

09/03/2015 Jisc Digital Festival, 9-10 March 2015, ICC Birmingham 9

» Is there one method for risk assessment? Does the type of risk affect the method?

» Compare two types of risk assessment you’ve encountered. Why were they different?

Risk management workshop

Page 10: Risk Management - Jisc Digital Festival 2015

Group exercise 1:

09/03/2015 Jisc Digital Festival, 9-10 March 2015, ICC Birmingham 10

» ISO 31000:2009 – Risk Management

» ISO 27005:2011 – Information Security Risk Management

» M_o_R Management of Risk

» COSO 2004 Enterprise Risk Management

Risk management workshop

Page 11: Risk Management - Jisc Digital Festival 2015

09/03/2015 Jisc Digital Festival, 9-10 March 2015, ICC Birmingham 11

“The effect of uncertainty on objectives”ISO Guide 73:2009

Is this definition useful?

Risk management workshop

Page 12: Risk Management - Jisc Digital Festival 2015

09/03/2015 Jisc Digital Festival, 9-10 March 2015, ICC Birmingham 12

» Risk is often expressed as a combination of the impact of an event, and the likelihood that the event will occur

Risk = Impact x Probability

Another definition

Risk management workshop

Page 13: Risk Management - Jisc Digital Festival 2015

09/03/2015 Jisc Digital Festival, 9-10 March 2015, ICC Birmingham 13

Impact

Trivial Minor Moderate Major Extreme

Pro

bab

ility

Rare Low Low Low Medium Medium

Unlikely Low Low Medium Medium High

Moderate Low Medium Medium Medium High

Likely Medium Medium Medium High High

Very Likely Medium Medium High High High

Risk Matrix

Risk management workshop

Page 14: Risk Management - Jisc Digital Festival 2015

09/03/2015 Jisc Digital Festival, 9-10 March 2015, ICC Birmingham 14

» Risk = Impact x Probability

» Does this accurately capture your organization's risk attitude?

» What else might be needed?

Group exercise 2.1

Risk management workshop

Page 15: Risk Management - Jisc Digital Festival 2015

Group exercise 2.2

09/03/2015 Jisc Digital Festival, 9-10 March 2015, ICC Birmingham 15

Risk management workshop

» Risk context – the internal and external parameters to be taken into account when managing risk

» What parameters might you want to take into account?

» Would you expect the output of your first risk assessment to closely match current working practices? If not, why?

Page 16: Risk Management - Jisc Digital Festival 2015

Process

09/03/2015 Jisc Digital Festival, 9-10 March 2015, ICC Birmingham 16

Risk management workshop

» Risk Assessments need to be robust, repeatable and reproducible – this normally requires a documented process

» Risks need ownership so that people take responsibility for them: track progress and monitor for changes and effectiveness of controls

Page 17: Risk Management - Jisc Digital Festival 2015

Problems with process

09/03/2015 Jisc Digital Festival, 9-10 March 2015, ICC Birmingham 17

Risk management workshop

» It’s easy to blindly follow a process or flow-chart even when you can see the train wreck ahead

» Any process that doesn’t take this into account will fail hard

Page 18: Risk Management - Jisc Digital Festival 2015

Problems with process

09/03/2015 Jisc Digital Festival, 9-10 March 2015, ICC Birmingham 18

Risk management workshop

» How to cope with failure?

» Stop. Check. Think. Revisit your assumptions

Page 19: Risk Management - Jisc Digital Festival 2015

09/03/2015 Jisc Digital Festival, 9-10 March 2015, ICC Birmingham 19

» What’s worked well in risk assessments you’ve been involved in?

» What went wrong?

» Did having a good process help?

Group exercise 3:

Risk management workshop

Page 20: Risk Management - Jisc Digital Festival 2015

Group exercise 3:

09/03/2015 Jisc Digital Festival, 9-10 March 2015, ICC Birmingham 20

Risk management workshop

» Risk assessment of the first service took much longer time than anticipated

» Subsequent risk assessments took less time than anticipated

» Risk were more closely related to activities (processing personal data, running a server…) than to the service

Page 21: Risk Management - Jisc Digital Festival 2015

Communication

09/03/2015 Jisc Digital Festival, 9-10 March 2015, ICC Birmingham 21

Risk management workshop

» Even a small risk assessment can provide a lot of output

Page 22: Risk Management - Jisc Digital Festival 2015

Communication

09/03/2015 Jisc Digital Festival, 9-10 March 2015, ICC Birmingham 22

Risk management workshop

» Present it in full like this?

Page 23: Risk Management - Jisc Digital Festival 2015

Communication

09/03/2015 Jisc Digital Festival, 9-10 March 2015, ICC Birmingham 23

Risk management workshop

» Present it visually?

Page 24: Risk Management - Jisc Digital Festival 2015

Communication

09/03/2015 Jisc Digital Festival, 9-10 March 2015, ICC Birmingham 24

Risk management workshop

» Summarize it in a high level report?

Page 25: Risk Management - Jisc Digital Festival 2015

Communication

09/03/2015 Jisc Digital Festival, 9-10 March 2015, ICC Birmingham 25

Risk management workshop

» Present it in PowerPoint!

Page 26: Risk Management - Jisc Digital Festival 2015

09/03/2015 Jisc Digital Festival, 9-10 March 2015, ICC Birmingham 26

» How would you provide results to the manager of a technical group?

» How would you provide results to the governing body?

» How would you share the results with a peer?

Group Exercise 4

Risk management workshop

Page 27: Risk Management - Jisc Digital Festival 2015

Group Exercise 4

09/03/2015 Jisc Digital Festival, 9-10 March 2015, ICC Birmingham 27

Risk management workshop

» In-depth technical results are shared with service managers

» Also made available to top management

» Top management receives a high level risk treatment plan, highlighting residual risks and areas of concern

Page 28: Risk Management - Jisc Digital Festival 2015

Pod surgery

09/03/2015 Jisc Digital Festival, 9-10 March 2015, ICC Birmingham 28

Risk management workshop

» Feel free to come along to my Pod surgery from 15:30 – 16:30

» Thank you!

Page 29: Risk Management - Jisc Digital Festival 2015

Find out more…

Contact…

Except where otherwise noted, this work is licensed under CC-BY-NC-ND

James DavisInformation security manager, Jisc

[email protected]