The Pros And Cons Of Risk Assessment

Improved Essays
The policy does not exist. However the risk assessment identified many risk that need to be addressed. Therefore, a policy is needed to address the risk found.

On page 7 of the Risk Assessment it was stated that SHGTS has never had a Risk Assessment before. This means that there was no policy in place to address the need for one.

Section 4.1 of ISO 27002:2005 says that risk assessment needs to be done periodically in a methodological manner (ISO/IEC 27002, 2005).

Since the policy does not exist, then the acceptable risk posture of the organization does not exist in such policy either.

The risk assessment discusses different levels of risk in the findings section on page 19. However acceptable risk was not determined.

Section 4.2 of
…show more content…
Section 4.1 of ISO 27002:2005 Recommends that risk assessment should be done periodically to identify and choose a correct way to handle it. This justified that it should be included in the policy (ISO/IEC 27002, 2005).

Since a policy does not exist, therefore a section on multi-perspectives also does not exist. However, a policy is needed to address the concerns in the risk assessment.

These concerns are listed in the Threat sources and Threat action section of the risk assessment on pages seventeen and eighteen. While Vulnerability space on assets and their impact can be seen on pages nineteen to twenty four. This section has valuable information to help in creating a needed policy.

As justification, I will make reference to the ISO 27002:2005 which in section 4.1 recommend multi-perspectives on risk be included in the ISMS. These perspectives includes Threat, Asset, Vulnerability and impact (ISO/IEC 27002, 2005) .

Since this policy does not exist, then there is no policy for include reporting results
…show more content…
This justifies that the results of the risk

Assessment should be included in the report (ISO/IEC 27002, 2005). Since this policy does not exist, then no section would have existed to include a remediation analysis report.

The risk assessment does not specifically mention the need for a remediation report in the policy. However, there are many recommendations that would aid in creating a report.

Section 14.1.2 of ISO 27002:2005 recommends that a strategy be put in place to address the threats posed by elements of the risk assessment. For this to happen, a remediation analysis report must be included in the policy. Without it this process will be overlooked (ISO/IEC 27002, 2005).

Procedures A procedure does not exist about implementing and enforcing a risk management policy. However the risk management assessment lacking this to help to address the risks identified.

On page 7 of the Risk Assessment stated that this is the first Risk Assessment done. This means that a procedure has not been implemented to enforce risk

Related Documents

  • Improved Essays

    Xacc/280 Week 4

    • 629 Words
    • 3 Pages

    The risk assessment was the challenge this year. I feel that I should be conducting a domestic and international comprehensive risk every year but my budget will not allow it. I selected to do a comprehensive domestic risk assessment this year. I would like to plan to do a domestic and international assessment every other year. I am not too sure that this is a good decision, but I feel that a domestic risk is better than no risk…

    • 629 Words
    • 3 Pages
    Improved Essays
  • Improved Essays

    Nt1330 Unit 7

    • 1149 Words
    • 5 Pages

    1. Focus on the overall “security assessment” risk rating that appears at the top of your report. Considering what security measures you (or the computer owner) have undertaken for your computer, does the assessment surprise you? Why or why not? What measures should you plan to undertake if the green checkmark did not appear?…

    • 1149 Words
    • 5 Pages
    Improved Essays
  • Decent Essays

    Australian Unity Board is responsible for Group governance: approval of strategies, operating plans, budgets; setting and monitoring Group risk management framework; control and accountability policies/systems. Committees include: • Audit and Compliance: approves annual internal audit plan; main objective is to oversee the credibility and objectivity of financial reporting and the compliance with obligations; oversees and appraises the quality of audits conducted by both internal/external auditors (e.g. EY financial auditors); determines adequacy of controls and evaluates adherence. • Risk: oversees risk management framework for identifying, assessing, mitigating and monitoring material risks arising from the business activities; promotes…

    • 221 Words
    • 1 Pages
    Decent Essays
  • Improved Essays

    Safety Factors Nvq

    • 257 Words
    • 2 Pages

    To allocate sufficient resources to maintain safe and healthy conditions of work; • To take steps to ensure that all known safety factors are taken into account in the design, construction, operation and maintenance of plants, machinery and equipment; • To ensure that adequate safety instructions are given to all employees; • To provide wherever necessary protective equipment, safety appliances and clothing and to ensure their proper use; • To inform employees about materials, equipment or processes used in their work which are known to be potentially hazardous to health or safety; • To keep all operations and methods of work under regular review for making necessary changes from the point of view of safety in the light of experience and upto…

    • 257 Words
    • 2 Pages
    Improved Essays
  • Improved Essays

    Evaluating Risk Assessments and Applying the NASW Code of Ethics The Process of Selecting a Good Risk Assessment The first step in the developmental stages of the project at hand, involved the selection of a team of five students who would work toward gathering the information required to complete the assignment. Specifically, each of the five team members was instructed to select two risk assessments. Several factors were considered and needed to be implemented for the sake of clarity and unification.…

    • 1115 Words
    • 5 Pages
    Improved Essays
  • Improved Essays

    Evaluate the risk and create policies and procedures to negate or reduce them. Educate and communicate with management and staff about risk factors. Rank risks according to likelihood of occurrences for each dept. Periodically review and update risks, and risks management programs. (Rubbens, 2007)…

    • 819 Words
    • 4 Pages
    Improved Essays
  • Great Essays

    Unit 4222-320 Support individuals to live at home Outcome 1 Understand the principles of supporting individuals to live at home 1. describe how being supported to live at home can benefit an individual…

    • 2495 Words
    • 10 Pages
    Great Essays
  • Improved Essays

    As nursing leaders we must empower our staff to improve the quality and safety of patient care. The Management and Leadership track of the American Sentinel MSN program has guided me towards cultivating future nurse leaders to prepare them to create a sense of ownership and commitment to their work and the organization as a whole. The evidenced based practice project proposed to be implemented at the Veterans Administration Medical Center (VAMC) will cultivate the staff to improve the quality of care for the veteran population. The proposed practice change project focuses on improving diabetic foot related problems in the End Stage Renal Disease population receiving hemodialysis/peritoneal dialysis. End Stage Renal Disease is a slow progressive…

    • 1107 Words
    • 5 Pages
    Improved Essays
  • Improved Essays

    1.1 Describe how current health and safety legislation, policies and procedures are practiced in the setting. Primary legislation: Health and safety at work act: Everyone in the organisation is required to: 1. Report any Hazards 2. Follow the school's Safety Policy 3. Make sure their actions do not harm themselves or others 4.…

    • 665 Words
    • 3 Pages
    Improved Essays
  • Improved Essays

    Risk assessments must be carried out to eliminate or reduce risks with any findings recorded. Any arrangements made must be monitored and reviewed by appointed person's with the training, knowledge and skills to carry out these arrangements. It is the appointed person's (Health and Safety Co-ordinator) responsibility to ensure that everyone within the setting is made aware of, read and signed the changed or new policies and procedures. People within the work setting must be made aware of where of the Health and Safety Policy is kept, up to date training must be provided and copies of risk assessments must be given when necessary, for example when going on school trips, all adults on the trip must read the risk assessment specifies such as the minibus for travelling in, wearing visors, appointed first aiders, trip and group leaders and toilet trips. This ensures the staff are aware of risks and hazards, how to deal with them efficiently and who to report…

    • 987 Words
    • 4 Pages
    Improved Essays
  • Decent Essays

    Policies and procedures of an organisation are in place in the aim of harmonisation of the work place. It provides a nationally consistent frame work to ensure health safety and welfare of the workers and workplace. All organisations require their staff and all visitors to take reasonable care for health and safety. Managers and staff have a legal duty to work with in the legislation, regulations and their organisations policies and procedures, the organisations workplace health and safety managements plan and standards. Business Organisations need policies and procedures in relation to work health and safety.…

    • 277 Words
    • 2 Pages
    Decent Essays
  • Great Essays

    Write an explanation of how you will create and ensure a Healthy and Safe Home based environment that you can show to parents and as evidence for CSSIW. Take into consideration: • What steps you take to make your setting healthy and safe…

    • 2498 Words
    • 10 Pages
    Great Essays
  • Improved Essays

    Identifying and managing risks is a critical responsibility of project managers. Risk is defined as the probability of a specified threat and the subsequent impact that the event produces (Vaidyanathan, 2013). Risks can also bring about either positive or negative outcomes for a project or organization. A project manager must identify potential risks and evaluate each one to determine the severity and likelihood of each event. Only by completing the risk management process, a project manager can determine what approach would work best to avoid, mitigate, and/or transfer the risk.…

    • 730 Words
    • 3 Pages
    Improved Essays
  • Improved Essays

    Risk analysis is an important element of risk management process which is been introduced in the organizations on frequent basis to have a depth analysis of risks associated with petrochemical industry or some other process industries (Tularam & Attili 2012). Risk analysis is an important aspect and have a great significance in analysis of identified risk events during risk identification or hazard identification phase of risk management. Risk analysis enables the evaluation of an identified risk event about its respective frequency of occurrence as well the potential of identified risk as what could be the severity level of the consequences caused due to that particular risk event. In addition to this risk analysis is an effective approach in order to determine the relationship between the resulting outcomes of an identified risk event and probability of occurrence of risk event (Khan et al. 1998). Furthermore, after determination of this relationship between these two concepts, it becomes possible to define the risk level of an identified risk.…

    • 1227 Words
    • 5 Pages
    Improved Essays
  • Improved Essays

    Business Continuity Management (BCM) – Key Performance Indicators (KPI's) By: Arunkumar Durairaj 14-Nov-16 1. Introduction The purpose of BCM KPI's are to monitor and measure the performance of Business Continuity Management(BCM) program based on the refernces obtained through achivement of processes or goals . These indicators are used to help organization evaluate its progress and / or performance (in terms of efficiency, effectiveness, robustness, and so on) of its BCM processes while pursuing short term, medium term and / or long-term goals / plans.…

    • 1403 Words
    • 6 Pages
    Improved Essays