Refernces: R7-MARANAN (3-5) (14-24)
Refernces: R7-MARANAN (3-5) (14-24)
The risk management process did not stop when the risk and sources of risk were
identified. The manager must be able to answer the whys of risk so that proper
treatment could be given. It is not merely stating the fact that there is a possibility
of terrorism, the reason for having such possibility must be addressed as well.
It is the stage wherein the severity of the impact of the said
risk is being weighed to make the most intelligent
decisions for the full implementation of the risk
management plan.
According to RFC4949
It is the determination of a qualitative and quantitative
estimate of risk related to a clear situation and recognized
threat (also called hazard).
The following are some of the options to mitigate risks:
1. Project a novel business procedure with sufficient built-in risk
control and containment measures from the start.
2. Conduct a periodic reassessment of risks that are acceptable in
ongoing processes as a regular feature of business operations
and modify mitigation measures.
3. Handover risks to an external agency like an insurance company
4. Avoid risks altogether
5. Potential risk treatments
The techniques in managing risk may be categorized into
the following:
1. Avoidance
2. Reduction
3. Sharing
4. Retention
According to Dcosta (2015)
Risk management plan evaluates identified risks and
outlines mitigation actions.
The need for periodical updates and expansion in the entire
cycle of the project, as the project becomes more
complexed and more defined.
Dcosta suggest the inclusion of the following in the
formulation of the matrix to prioritize risks
1. Risk and consequence
2. Probability
3. Impact
4. Priority
5. Mitigation response
Consider the practice, experience, and the actual loss results
when you do your modification.
An updated periodic management plan is needed because of
the following reasons:
1. Determination of the applicability and effectiveness of the
previous security controls
2. Understand the possible changes in risk level in the
business environment