Sec Prin and Mgmt Flashcards
What is the difference between resilience and risk
Resilience takes a forward looking view of risk, fully integrating business and risk management into the organization’s system of management. Risk is viewed as inevitable and having the potential for positive outcomes. Risk is the effect of uncertainty on the achievement of strategic, operational, tactical, and reputational objectives
What resilience promotes within an organization and what it requires
Resilience promotes a perspective of enterprise wide agility and adaptability in a dynamic and uncertain environment. Resilient organization fully integrate a holistic and proactive risk management perspective into good business management practice to enhance their buffering and adaptive capacity. Resilience requires both the convergence of risk disciplines as well as the elimination of and/or collaboration among organizational siloes to have coordinated plan for managing risk throughout the enterprise. Resilience is not something that is inherent to an organization but develops as organizations mature, learn from successes and mistakes, improve their management and decision making skills
Write 4 characteristics of resilience organizations
i. Recognize that change is constant
ii. Consider the organization’s dependencies and interdependencies in assessing risk to the organization and its risks on others;
iii. Integrate proactive risk management into all their decision making process;
iv. Promote situational awareness and monitoring with an emphasis on identifying indicators of change
What do you mean by resilient organization
Being a resilient organization means efficiently tapping into its human, tangible and intangible resources
What is essential to building resilience? How risk can be better managed
Improving communication and consultation skills is essential building resilience. Risk is best managed with on going consultation and interactive communication among stakeholders. A resilient organization will build the mechanisms needed to support both a top down and bottom up flow of information
Explain the importance of empowering people at all levels of organization to achieve organizational resilience
Empowering people at all levels of the organization fosters the sense of inclusiveness and ownership that encourage the sharing ideas. It helps to promote a risk culture where risk makers and risk takers understand that they are also risk owners and risk managers
What basically the Organizational Resilience Management System enables
The organizational resilience management system (ORMS) enables an organization to identify, assess and manage risks related to the achievement of its strategic, operational, tactical and reputational objectives in the organization and its supply chains.
How an Organizational Resilience Management System can be achieved
An ORMS is achieved by developing designing, documenting, deploying and evaluating fit for purpose proactive management strategies needed to achieve current objectives and identify indicators for potential needs for changes
What provide foundation for good governance
Enhanced security and resilience
Key Performance Indicators (KPI)are defined to support achievement of objectives? What KPI drive?
Key Performance Indicators (KPI) are defined to support achievement of objectives. KPI drive a culture of management by measurement for continual monitoring and performance improvement
When an organization cannot maximize opportunities and minimize negative outcomes?
Unless risk is managed effectively, organizations cannot maximize opportunities and minimize negative outcomes
What the system approach basically examines and when component parts of a system can be understood?
The systems approach examines the linkage and interactions between the elements that compose the entirely of the system. Component parts of a system can best understood in the context of their interrelationships, rather than in isolation, and must be treated as a whole
Cultivating what kind of skills enhances resilience builds trust and contributes to protecting the image and reputation of the organization?
Leadership skills at all levels
Why all organizations need to be cognizant of their resource constrain
To prioritize allocation of resource when managing risk
What can influence they way in which the organization will manage risk
Internal and external factors
What is the necessary in order to understand the organization’s value chain?
Identification of people, assets and services that provide tangible and intangible value
When identifying stakeholders’ needs and requirements, what the organization shall determine?
When identifying stakeholders needs and requirements, the organization shall determine:
(a) Requirements and obligations specified by stakeholders
(b) Legal regulatory and contractual obligations as well as other voluntary commitments
(c)Human right responsibilities and impacts relevant to its activities (d) Needs of the local and impacted communities and other stakeholders
(e) Risk management requirements including stakeholders risk appetite
Every organization should define and document criteria to evaluate the significance of risk, what are the elements of the organization should be evaluated by the risk criteria?
The risk criteria shall reflect organization’s values, objectives and resources
Explain a “statement of applicability” in relation to the scope of Organizational Resilience Management System (ORSM)?
A “Statement of Applicability” shall define the relevant risks that apply to the organization’s scope, legal, regulatory, and contractual obligations and operating environment based on its risk assessment. The organization shall implement adaptive, proactive and or reactive measures to manage risk that apply to the organization’s scope, legal, and regulatory and contractual obligations and operating environment.
How top management should provide evidence of active leadership for the Organizational Resilience Management System (ORSM)?
By overseeing its establishment and implementation, and motivating individuals to integrate security and resilience as a central part of the mission of the organization and its culture.
The organization shall establish, implement and maintain a formal and documented risk assessment process including its relevant supply chain partners and subcontractors activities. What kind of steps should be included in risk assessment process?
(a) Asset identification
(b) Risk identification
(c) Risk analysis
(d) Risk evaluation
What is the difference between risk analysis and risk evaluation?
Risk analysis is a systematically method to analyze and determine those risks that have a significant impact on activities, function, services, products, supply chain and others while in the other side risk evaluation is a systematically method to evaluate and prioritize risk controls and treatment as well as their related costs to determine how to bring risk within an accountable level consistent with risk criteria.
What organization should consider conducting the BIA as a separate analysis
The organizations’ where major variations in recovery priorities and or complex interdependencies are present, the organization should consider conducting the BIA as a separate analysis
Why organizations consider integrating a business impact analysis (BIA) into its risk assessment process?
Because a criticality analysis includes estimating allowable down times, potential impacts over time and recovery time objectives as a result organization may integrate a BIA into its risk assessment process