Risk Management: Difference between revisions

From IT Process Wiki
No edit summary
No edit summary
Line 1: Line 1:
<seo metakeywords="itil risk management, risk management itil, itil risk management process, risk management process" metadescription="Risk Management: ITIL process definition - Sub-processes - Terms - Additional information on ITIL Risk Management." />
<itpmch><title>Risk Management | IT Process Wiki</title>
<meta name="keywords" content="itil risk management, risk management itil, itil risk management process, risk management process" />
<meta name="description" content="Risk Management: ITIL process definition - Sub-processes - Terms - Additional information on ITIL Risk Management." />
</itpmch>
<imagemap>
<imagemap>
Image:ITIL-Wiki-de-es.jpg|DE - ES - Risk Management|100px
Image:ITIL-Wiki-de-es.jpg|DE - ES - Risk Management|100px
Line 8: Line 11:
<br style="clear:both;"/>
<br style="clear:both;"/>


<html><div itemscope="itemscope" itemtype="https://schema.org/WebPage"><!-- define schema.org/WebPage --><p></html>
<p>&nbsp;</p>
<p>&nbsp;</p>


==<span id="ITIL Risk Management">Overview</span>==
'''<span id="Overview">Objective:</span>''' <html><span itemprop="description">The objective of <i><span itemprop="alternativeHeadline">ITIL <span itemprop="name Headline">Risk Management</span></span></i> is to identify, assess and control risks. This includes analyzing the value of assets to the business, identifying threats to those assets, and evaluating how vulnerable each asset is to those threats.</span></p>
 
<p><b>Part of</b>: <a itemprop="isPartOf" href="https://wiki.en.it-processmaps.com/index.php/ITIL_Service_Design" title="ITIL Service Design">Service Design</a></html>
'''Objective''': The objective of ''ITIL Risk Management'' is to identify, assess and control risks. This includes analyzing the value of assets to the business, identifying threats to those assets, and evaluating how vulnerable each asset is to those threats.
 
'''Part of''': [[ITIL V3 Service Design|Service Design]]


'''Process Owner''': [[Risk Management#Risk Manager|Risk Manager]]
'''Process Owner''': [[Risk Management#Risk Manager|Risk Manager]]
Line 20: Line 21:
<p>&nbsp;</p>
<p>&nbsp;</p>


== Process Description ==
==Process Description==


[[Image:Itil-risk-management.jpg|right|thumb|375px|alt=Risk Management ITIL|[https://wiki.en.it-processmaps.com/images/pdf/process_overview_risk_management_itilv3.pdf ITIL Risk Management]]]
[[Image:Itil-risk-management.jpg|right|thumb|375px|alt=Risk Management ITIL|[https://wiki.en.it-processmaps.com/images/pdf/process_overview_risk_management_itilv3.pdf ITIL Risk Management]]]
Line 32: Line 33:
<p>&nbsp;</p>
<p>&nbsp;</p>


== Sub-Processes ==
==Sub-Processes==
 
These are the ITIL Risk Management sub-processes  and their process objectives:


<html><div itemscope="itemscope" itemtype="https://schema.org/ItemList"><!-- define schema.org/ItemList -->
<meta itemprop="itemListOrder" content="Ascending" />
<p><span itemprop="name" content="Risk Management sub-processes:">These are the <strong class="selflink">ITIL Risk Management</strong> sub-processes and their process objectives:</span>
</p>
<p>&#160;</p>
<p><b><span id="ITIL_Risk_Management_Support" itemprop="itemListElement">Risk Management Support</span></b>
</p>
<ul><li itemprop="description">Process Objective: To define a framework for Risk Management. Most importantly, this process specifies how risk is quantified, what risks the organization is willing to accept, and who is in charge of the various Risk Management duties.
</li></ul>
<p><br />
</p><p><b><span id="ITIL_Risk_Analysis" itemprop="itemListElement">Business Impact and Risk Analysis</span></b>
</p>
<ul><li itemprop="description">Process Objective: To quantify the impact to the business that a loss of service or asset would have, and to determine the likelihood of a threat or vulnerability to actually occur. The result of the "<a href="/index.php/Risk_Management#Business_Impact_and_Risk_Analysis" title="Risk Management">Business Impact and Risk Analysis</a>" is the <a href="/index.php/Risk_Management#Risk_Register" title="Risk Management">Risk Register</a>, a prioritized list of risks which must be subsequently addressed.
</li></ul>
<p><br />
</p><p><b><span id="ITIL_Risk_Management_Assessment" itemprop="itemListElement">Assessment of Required Risk Mitigation</span></b>
</p>
<ul><li itemprop="description">Process Objective: To determine where risk mitigation measures are required, and to identify Risk Owners who will be responsible for their implementation and ongoing maintenance.
</li></ul>
<p><br />
</p><p><b><span id="Risk_Monitoring_ITIL" itemprop="itemListElement">Risk Monitoring</span></b>
</p>
<ul><li itemprop="description">Process Objective: To monitor the progress of counter measure implementation, and to take corrective action where necessary.
</li></ul>
</div><!-- end of schema.org/ItemList --><p></html>
<p>&nbsp;</p>
<p>&nbsp;</p>


;<span id="ITIL Risk Management Support">Risk Management Support</span>
==Definitions==
:Process Objective: To define a framework for Risk Management. Most importantly, this process specifies how risk is quantified, what risks the organization is willing to accept, and who is in charge of the various Risk Management duties.
 
;<span id="ITIL Risk Analysis">Business Impact and Risk Analysis</span>
:Process Objective: To quantify the impact to the business that a loss of service or asset would have, and to determine the likelihood of a threat or vulnerability to actually occur. The result of the "[[Risk Management#Business Impact and Risk Analysis|Business Impact and Risk Analysis]]" is the [[Risk Management#Risk Register|Risk Register]], a prioritized list of risks which must be subsequently addressed.
 
;<span id="ITIL Risk Management Assessment">Assessment of Required Risk Mitigation</span>
: Process Objective: To determine where risk mitigation measures are required, and to identify Risk Owners who will be responsible for their implementation and ongoing maintenance.
 
;<span id="Risk Monitoring ITIL">Risk Monitoring</span>
:Process Objective: To monitor the progress of counter measure implementation, and to take corrective action where necessary.


<html><div itemscope="itemscope" itemtype="https://schema.org/ItemList"><!-- define schema.org/ItemList -->
<meta itemprop="itemListOrder" content="Ascending" />
<p><span itemprop="name">The following <a href="/index.php/ITIL%20Glossary#ITIL%20Glossary%20A-Z" title="ITIL Glossary">ITIL terms and acronyms</a> (<i>information objects</i>) are used in the ITIL Risk Management process to represent process outputs and inputs:</span>
</p>
<p>&#160;</p>
<p><b><span id="Business_Impact_and_Risk_Analysis" itemprop="itemListElement">Business Impact and Risk Analysis</span></b>
</p>
<ul><li itemprop="description">Business Impact Analysis (BIA) and Risk Analysis are concepts associated with Risk Management. Their ultimate goal is to identify which risks must be managed and addressed by risk mitigation measures.
</li></ul>
<p><br />
</p><p><b><span id="Process_and_Asset_Valuation" itemprop="itemListElement">Process and Asset Valuation</span></b>
</p>
<ul><li itemprop="description">An estimate of the value a process or other asset represents for the business. This value is an important input for <a href="/index.php/Risk_Management#Business_Impact_and_Risk_Analysis" title="Risk Management">Risk Analysis</a>.
</li></ul>
<p><br />
</p><p><b><span id="Risk_Management_Policy" itemprop="itemListElement">Risk Management Policy</span></b>
</p>
<ul><li itemprop="description">The Risk Management Policy describes and communicates the organization’s approach to managing risk. Most importantly, it defines how risk is quantified and who is in charge of specific risk management duties. The Risk Management Policy is maintained by the <a href="/index.php/Risk_Management#Risk_Manager" title="Risk Management">Risk Manager</a> role, but to be effective it needs the backing of senior management.
</li></ul>
<p><br />
</p><p><b><span id="Risk_Register" itemprop="itemListElement">Risk Register</span></b>
</p>
<ul><li itemprop="description">The Risk Register is a tool used by the Risk Management process to keep an overview of identified risks and corresponding counter measures. The Risk Register is sometimes referred to as the <i>Risk Log</i>.
</li></ul>
</div><!-- end of schema.org/ItemList --><p></html>
<p>&nbsp;</p>
<p>&nbsp;</p>


== Definitions ==
==Roles | Responsibilities==


The following ITIL terms and acronyms (''information objects'') are used in ITIL Risk Management to represent process outputs and inputs:
'''<span id="Risk Manager">Risk Manager - Process Owner</span>'''
*The Risk Manager is responsible for identifying, assessing and controlling risks. This includes analyzing the value of assets to the business, identifying threats to those assets, and evaluating how vulnerable each asset is to those threats.


<p>&nbsp;</p>
<p>&nbsp;</p>


;<span id="Business Impact and Risk Analysis">Business Impact and Risk Analysis</span>
{| border="1" cellpadding="5" cellspacing="0" style="margin-left: auto; margin-right: auto; text-align:center;" valign="top"
:The Business Impact Analysis (BIA) identifies Vital Business Functions (VBFs) and their dependencies. These dependencies may include suppliers, people, other business processes, services etc.. The Risk Analysis identifies threats and vulnerabilities to business assets, and indicates how vulnerable each asset is to those threats.
 
;<span id="Process and Asset Valuation">Process and Asset Valuation</span>
:An estimate of the value a process or other asset represents for the business. This value is an important input for [[Risk Management#Business Impact and Risk Analysis|Risk Analysis]].
 
;<span id="Risk Management Policy">Risk Management Policy</span>
:The Risk Management Policy describes and communicates the organization’s approach to managing risk. Most importantly, it defines how risk is quantified and who is in charge of specific risk management duties.
:The Risk Management Policy is maintained by the [[Risk Management#Risk Manager|Risk Manager]] role, but to be effective it needs the backing of senior management.
 
;<span id="Risk Register">Risk Register</span>
:The Risk Register is a tool used by the Risk Management process to keep an overview of identified risks and corresponding counter measures. The Risk Register is sometimes referred to as the ''Risk Log''.
 
<p>&nbsp;</p>
 
== Roles | Responsibilities ==
 
;<span id="Risk Manager">Risk Manager - Process Owner</span>
:The Risk Manager is responsible for identifying, assessing and controlling risks.
:This includes analyzing the value of assets to the business, identifying threats to those assets, and evaluating how vulnerable each asset is to those threats.
 
<p>&nbsp;</p>
 
{| border="1" align="center" cellpadding="5" cellspacing="0" style="text-align:center;" valign="top"
|-
|-
| valign="top" colspan="6" style="background:#ffffdd;" align="center"| '''Responsibility Matrix: ITIL Risk Management'''
| style="vertical-align:top; text-align:center" colspan="3" style="background:#ffffdd;"| '''<span id="RACI-Matrix-Risk-Management">Verantwortlichkeits-Matrix: ITIL Risk Management</span>'''
|-
|-
! width="50%" align="center" style="background:#ffffee;" | ITIL Role | Sub-Process
!style="background:#ffffee; width: 50%; text-align:center" | ITIL Role | Sub-Process
! style="background:#ffffee;" | [[Risk Management#Risk Manager|Risk Manager]]
! style="background:#ffffee;" | [[Risk Management#Risk Manager|Risk Manager]]
! style="background:#ffffee;" | Other roles involved
! style="background:#ffffee;" | Other roles involved
|-
|-
| align="left" |[[#ITIL Risk Management Support|Risk Management Support]]
|style="text-align:left;" |[[#ITIL Risk Management Support|Risk Management Support]]
| A[[Risk Management#Accountable|<small>[1]</small>]]R[[Risk Management#Responsible|<small>[2]</small>]]
| A[[Risk Management#Accountable|<small>[1]</small>]]R[[Risk Management#Responsible|<small>[2]</small>]]
|  
| -
|-
|-
| align="left" |[[#ITIL Risk Analysis|Business Impact and Risk Analysis]]
|style="text-align:left;" |[[#ITIL Risk Analysis|Business Impact and Risk Analysis]]
| AR
| AR
| R[[Risk Management#ITIL Roles|<small>[3]</small>]][[#ITIL Risk Management Group|<small>[4]</small>]]
| R[[#ITIL Risk Management Group|<small>[3]</small>]]
|-
|-
| align="left" |[[#ITIL Risk Management Assessment|Assessment of Required Risk Mitigation]]
|style="text-align:left;" |[[#ITIL Risk Management Assessment|Assessment of Required Risk Mitigation]]
| AR
| AR
|  
| -
|-
|-
| align="left" |[[#Risk Monitoring ITIL|Risk Monitoring]]
|style="text-align:left;" |[[#Risk Monitoring ITIL|Risk Monitoring]]
| AR
| AR
|  
| -
|-
|-
|}
|}
Line 115: Line 132:
<span id="Responsible">[2] ''R: Responsible'' according to the RACI Model: Those who do the work to achieve a task within Risk Management.</span>
<span id="Responsible">[2] ''R: Responsible'' according to the RACI Model: Those who do the work to achieve a task within Risk Management.</span>


<span id="ITIL Roles">[3] see [[Roles within ITIL V3|&#8594; Role descriptions]]</span>
<span id="ITIL Risk Management Group">[3] Availability Manager, IT Service Continuity Manager, Information Security Manager, Compliance Manager, and Supplier Manager (see [[ITIL Roles|&#8594; Role descriptions]])</span>


<span id="ITIL Risk Management Group">[4] Availability Manager, IT Service Continuity Manager, Information Security Manager, Compliance Manager, and Supplier Manager.
<p>&nbsp;</p>
<p>&nbsp;</p>


<p>&nbsp;</p>
==[ Infobox ]==
 
<html><table class="wikitable">
<tr>
<td>Link to this page:</td>
<td><a itemprop="url" href="https://wiki.en.it-processmaps.com/index.php/Risk_Management">https://wiki.en.it-processmaps.com/index.php/Risk_Management</a></td>
</tr>
<tr>
<td>Languages:</td>
<td><span itemprop="inLanguage" content="en">English</span> | <span><a itemprop="citation" class="external text" href="https://wiki.de.it-processmaps.com/index.php/Risikomanagement" title="Risikomanagement">Deutsch</a></span> | <span><a itemprop="citation" class="external text" href="https://wiki.es.it-processmaps.com/index.php/ITIL_Gestion_del_Riesgo" title="Gestión del Riesgo">espa&#xf1;ol</a></span></td>
</tr>
<tr>
<td>Image:</td>
<td style="vertical-align:top"><a itemprop="primaryImageOfPage" href="https://wiki.en.it-processmaps.com/images/b/ba/Itil-risk-management.jpg" title="Risk Management">ITIL Risk Management (.JPG)</a></td>
</tr>
<tr>
<td>Author:</td>
<td><span itemprop="author">Stefan Kempter</span>, <span itemprop="creator copyrightHolder publisher">IT Process Maps</span> &nbsp;&nbsp; <a rel="author" href="https://plus.google.com/111925560448291102517"><img style="margin:0px 0px 0px 0px;" src="/skins/Vector/images/itpm/bookmarking/gplus.png" width="16" height="16" title="By: Stefan Kempter | Profile on Google+" alt="Author: Stefan Kempter, IT Process Maps GbR" /></a></td>
</tr>
</table>
 
<p><small>
<span itemscope="itemscope" itemtype="http://data-vocabulary.org/Breadcrumb">
<a href="https://wiki.en.it-processmaps.com/index.php/Risk_Management#Process_Description" itemprop="url"><span itemprop="title">Process Description</span></a> ›
</span>
<span itemscope="itemscope" itemtype="http://data-vocabulary.org/Breadcrumb">
<a href="https://wiki.en.it-processmaps.com/index.php/Risk_Management#Sub-Processes" itemprop="url"><span itemprop="title">Sub-Processes</span></a> ›
</span>
<span itemscope="itemscope" itemtype="http://data-vocabulary.org/Breadcrumb">
<a href="https://wiki.en.it-processmaps.com/index.php/Risk_Management#Definitions" itemprop="url"><span itemprop="title">Definitions</span></a> ›
</span>
<span itemscope="itemscope" itemtype="http://data-vocabulary.org/Breadcrumb">
<a href="https://wiki.en.it-processmaps.com/index.php/Risk_Management#Roles_.7C_Responsibilities" itemprop="url"><span itemprop="title">Roles</span></a>
</span>
</small></p>
</div><!-- end of schema.org/WebPage --><p></html>


<!-- This page is assigned to the following categories: -->
<!-- This page is assigned to the following categories: -->
[[Category:ITIL V3]][[Category:ITIL 2011]][[Category:ITIL process]][[Category:Service Design|Risk Management]][[Category:Risk Management|!]]
[[Category:ITIL V3]][[Category:ITIL 2011]][[Category:ITIL process]][[Category:Service Design|Risk Management]][[Category:Risk Management|!]]
<!-- --- -->
<!-- --- -->

Revision as of 18:39, 22 December 2013

DE - ES - Risk Managementdiese Seite auf Deutschesta página en español
DE - ES - Risk Management


 

Objective: The objective of ITIL Risk Management is to identify, assess and control risks. This includes analyzing the value of assets to the business, identifying threats to those assets, and evaluating how vulnerable each asset is to those threats.

Part of: Service Design

Process Owner: Risk Manager

 

Process Description

Risk Management ITIL
ITIL Risk Management

Risks are addressed within several processes in ITIL; there is, however, no dedicated Risk Management process. ITIL calls for "coordinated risk assessment exercises", so at IT Process Maps we decided to assign clear responsibilities for managing risks, which meant introducing a specific Risk Management process as part of the ITIL® Process Map.

Having a basic Risk Management process in place will provide a good starting point for introducing best-practice Risk Management frameworks like M_o_R (as recommended in the ITIL V3 books).

Following the introduction of Design Coordination in ITIL 2011 the information flows have been adapted slightly. The process overview of ITIL Risk Management (.JPG) is showing the most important interfaces (see Figure 1).

 

Sub-Processes

These are the ITIL Risk Management sub-processes and their process objectives:

 

Risk Management Support

  • Process Objective: To define a framework for Risk Management. Most importantly, this process specifies how risk is quantified, what risks the organization is willing to accept, and who is in charge of the various Risk Management duties.


Business Impact and Risk Analysis

  • Process Objective: To quantify the impact to the business that a loss of service or asset would have, and to determine the likelihood of a threat or vulnerability to actually occur. The result of the "Business Impact and Risk Analysis" is the Risk Register, a prioritized list of risks which must be subsequently addressed.


Assessment of Required Risk Mitigation

  • Process Objective: To determine where risk mitigation measures are required, and to identify Risk Owners who will be responsible for their implementation and ongoing maintenance.


Risk Monitoring

  • Process Objective: To monitor the progress of counter measure implementation, and to take corrective action where necessary.

 

Definitions

The following ITIL terms and acronyms (information objects) are used in the ITIL Risk Management process to represent process outputs and inputs:

 

Business Impact and Risk Analysis

  • Business Impact Analysis (BIA) and Risk Analysis are concepts associated with Risk Management. Their ultimate goal is to identify which risks must be managed and addressed by risk mitigation measures.


Process and Asset Valuation

  • An estimate of the value a process or other asset represents for the business. This value is an important input for Risk Analysis.


Risk Management Policy

  • The Risk Management Policy describes and communicates the organization’s approach to managing risk. Most importantly, it defines how risk is quantified and who is in charge of specific risk management duties. The Risk Management Policy is maintained by the Risk Manager role, but to be effective it needs the backing of senior management.


Risk Register

  • The Risk Register is a tool used by the Risk Management process to keep an overview of identified risks and corresponding counter measures. The Risk Register is sometimes referred to as the Risk Log.

 

Roles | Responsibilities

Risk Manager - Process Owner

  • The Risk Manager is responsible for identifying, assessing and controlling risks. This includes analyzing the value of assets to the business, identifying threats to those assets, and evaluating how vulnerable each asset is to those threats.

 

Verantwortlichkeits-Matrix: ITIL Risk Management
ITIL Role | Sub-Process Risk Manager Other roles involved
Risk Management Support A[1]R[2] -
Business Impact and Risk Analysis AR R[3]
Assessment of Required Risk Mitigation AR -
Risk Monitoring AR -

 

Remarks

[1] A: Accountable according to the RACI Model: Those who are ultimately accountable for the correct and thorough completion of the ITIL Risk Management process.

[2] R: Responsible according to the RACI Model: Those who do the work to achieve a task within Risk Management.

[3] Availability Manager, IT Service Continuity Manager, Information Security Manager, Compliance Manager, and Supplier Manager (see → Role descriptions)

 

 

[ Infobox ]

Link to this page:
Languages: English | Deutsch | español
Image: ITIL Risk Management (.JPG)
Author: , IT Process Maps   

 ›  ›  ›