> For the complete documentation index, see [llms.txt](https://davidjosearaujo.gitbook.io/online-courses/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://davidjosearaujo.gitbook.io/online-courses/is-auditing-controls-and-assurance/introduction-to-information-systems-is-auditing/risk-management-process.md).

# Risk Management Process

## Risk Assessment

Identify the area of having higher risk.

### Step 1 - Define the impact

In this example, the threat will be an earthquake.

<figure><img src="https://1255143828-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FkdhzKw41MSP8Xmr6jhL4%2Fuploads%2FoJJR3JpDkpjglvyQpfUR%2F2024-08-12_23-00.png?alt=media&amp;token=b4ea1001-fd05-4214-b76b-afd39c7dbe0f" alt=""><figcaption></figcaption></figure>

### Step 2 - Define the probability of having risk

| Probability                          | Definition                                             |
| ------------------------------------ | ------------------------------------------------------ |
| <ol start="5"><li>Probable</li></ol> | The event is expected to occur                         |
| <ol start="4"><li>Likely</li></ol>   | The evemt will probably occur                          |
| <ol start="3"><li>Possible</li></ol> | The event might occur at some time                     |
| <ol start="2"><li>Unlikely</li></ol> | The event could occur at some time but is improbable   |
| <ol><li>Very unlikely</li></ol>      | The event could have little or no chance of occurrence |

### Step 3 - Identify the risk for different threats and create a risk matrix

<figure><img src="https://1255143828-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FkdhzKw41MSP8Xmr6jhL4%2Fuploads%2FZnXWd3DbOCZlnWsYMFgw%2Fimage.png?alt=media&amp;token=60155e85-3d3f-4853-85e8-051bb0c53c76" alt=""><figcaption></figcaption></figure>

### Step 4 - Rate the risk

|              |                                                             |
| ------------ | ----------------------------------------------------------- |
| 1-6: Low     | Minor issue of little concern with some small disruptions   |
| 7-14: Medium | Requires attention, inconvenience and risk occur            |
| 15-25: High  | Requires urgent attention, introduce control to reduce risk |

## Risk Mitigation

Reduce risk using control.

| Risk | Control                                                  |
| ---- | -------------------------------------------------------- |
| 0%   | Eliminate riks -> **impossible!!**                       |
| 40%  | Username + password + firewall + encryption + biometrics |
| 50%  | Username + password + firewall + encryption              |
| 60%  | Username + password + firewall                           |
| 80%  | Username + password                                      |
| 100% | No control                                               |

At which level are we going to stop trying to reduce risk? And who should make that decision? **The senior management should!**

More control means higher cost.

### What are the options if senior management still not happy with the existing risk?

* Transfer the remaining risk to 3rd party (e.g. insurance)

### Avoid the risk

If a bank decides to not offer *ebanking*.

This is a **last resort,** as most of the time it can lead to **lost of costumers**.

### Summary

1. Reduce the risk using control to a level acceptable by senior management
2. Transfer the risk to a third party
3. Avoid the risk

## Risk re-evaluation

When should we do it?

### Time driven

Periodically, without any external factor trigger.

### Event driven

When the environment changes.

* Something changed within an organisation or similar organisations
* Government regulation
* Natural disaster
