risk management plan

Select appropriate controls or countermeasures to measure each risk. Risk mitigation needs to be approved by the appropriate level of management. For example, a risk concerning the image of the organization should have top management decision behind it whereas IT management would have the authority to decide on computer virus risks.

The risk management plan should propose applicable and effective security controls for managing the risks. For example, an observed high risk of computer viruses could be mitigated by acquiring and implementing antivirus software. A good risk management plan should contain a schedule for control implementation and responsible persons for those actions.

According to ISO/IEC 27001, the stage immediately after completion of the Risk Assessment phase consists of preparing a Risk Treatment Plan, which should document the decisions about how each of the identified risks should be handled. Mitigation of risks often means selection of Security Controls, which should be documented in a Statement of Applicability, which identifies which particular control objectives and controls from the standard have been selected, and why.

Implementation

Follow all of the planned methods for mitigating the effect of the risks. Purchase insurance policies for the risks that have been decided to be transferred to an insurer, avoid all risks that can be avoided without sacrificing the entity’s goals, reduce others, and retain the rest.

Review and evaluation of the plan

Initial risk management plans will never be perfect. Practice, experience, and actual loss results will necessitate changes in the plan and contribute information to allow possible different decisions to be made in dealing with the risks being faced.

Risk analysis results and management plans should be updated periodically. There are two primary reasons for this:

1. to evaluate whether the previously selected security controls are still applicable and effective, and

2. to evaluate the possible risk level changes in the business environment. For example, information risks are a good example of rapidly changing business environment.

delicious | digg | reddit | facebook | technorati | stumbleupon | savetheurl

Random Posts

  • Credit Risk Management
    The active management of credit risk has been receiving increasing regulator attention and strategic focus at many financial institutions. Regulators cite poor credit risk management at the portfolio level, weak credit standards for borrowers and ...
  • Campaign Management
    Prophet is a campaign management software program.Campaign management can be one of the most difficult aspects of a business. A campaign management system is often in order to regulate traffic flow of sales. One of the greatest campaign management...
  • Project Management Requires a Road Map
    Tim Bryce asked: "Having a Project Management system without a methodology is like attaching a speedometer to an orange crate; it measures nothing." - Bryce's LawThe principles of Project Management have been with us for a long time. There has also b...
  • Project Management Certifications Worldwide
    John Reiling asked: There are a number of project management certifications available worldwide. Here is a quick summary of what they are about, and links to learn more.prince2.com is the de facto standard used extensively by the UK Government and is...
  • Project Management Training – Paving way for project success
    The demand for trained and skilled professionals is all time high in India, with increasing number of organizations to government bodies looking for certified professionals. Amongst the available project management certifications PMP® certification...
  • PPC Management Help
    PPC Advertising is the number 1 way to get your site visited by interested customers who are looking for your product or service.  If you have tried to run your own PPC (pay per click) campaign in the past, but were unsuccessul there are a few th...