Risk and compliances

doddy77
RiskMatrixNew.docx

In Week 5, your task is to create a risk management matrix that identifies potential risks of a BallotsOnline system in the cloud, the probability of the risk occurring, the impact if the threat occurs, and the type of response to the risk.  You will use the  Risk Management Matrix Template  to complete this task.   DO NOT  write an MS word document or create your own table.  Use the template.  Note: When you open the template, use the “Risk Table” tab to populate your risks.  Here are some guidelines for the template headers.

· Causes – What could cause a risk to occur.  Example:  Weak Access Controls.  Keep it general and be more specific in the risk name.  You can have multiple risk names under a single Cause.

· Risk Name – Give your identified risk a short but somewhat specific name.  Example:  Weak Passwords.

· Consequences – Describe what will occur if the risk becomes a reality.  Example:  Unauthorized users will gain access to Ballots Online and have the ability to cast ballots.

· Risk Details – This is where you provide specific details about the risk and why it is important to recognize and respond.  Feel free to provide a lot of details, but remember you are speaking to non-IT executives.

· Risk Owner – This is the entity that generally has the responsibility to address the risk.  Owners determine the probability and impact of a risk and what type of response is necessary.  For this exercise, enter an department (IT, Finance, HR, etc).  Most (perhaps all) for this exercise, will be addressed by the IT department.

· Probability – This is the likelihood of the risk occurring.  There are lots of risks to systems, but not all are in one of the “Likely” categories.  Protections already in place will often lower the probability of a risk occurring.  For example, the probability of an internal company PC being infected with a virus is lowered by continually updated anti-virus software.

· Impact – This the general level of harm that would occur IF a risk becomes reality.  Minor risks may not be addressed in the design.  In other words, the impact is so low that the response is not cost effective to implement.  We just live with it.  That happens every day in the business world.  Impact is probably the biggest driver of design.

· Risk Score -  This is where you determine if the risk is acceptable or not.  Risk score is a measure of  probability and  impact.  If you have a risk that is Very Likely with a Major Impact, then the Risk Score would be an Unacceptable Risk at High or Extremely High.  This means there must be a strong response in either technology, policy, monitoring, and infrastructure (or more likely a combination of all). 

· Response Action Type – You will either avoid (render the risk irrelevant), mitigate (lower the probability and impact), transfer (place the impact of the risk on another entity ; insurance for example), or Accept (live with) all risks. 

· Response Actions – Describe the specific actions you will take, based on the response type.  If you transfer the risk, explain how the transfer protects Ballots Online.  If you Accept the risk, explain why the impact is not worth other actions. 

You will be including this information in your final report in the form of a table, so review the competencies and make sure your capturing the correct material.  Be specific on the risks.  Hacking for example is too generic.  Be specific on how hacking can occur.  Phishing, Firewall vulnerability, poor password policies, Etc.  Remember the CIAs of data (Confidentiality, Integrity, Accuracy).  Address risks that will ensure the CIAs are protected.