Case Study 2

profileromeoone21
Riskassessmementassignment.xlsx

Sheet1

RISK ASSESSMENT FORM
Project Name Risk Assessment Migration Update
Prepared By Ateko Lawson
Date 27-Jan-19
Business Area Business processes associated with area (identify four or more processes associated with the business area) Risks Identified Description Probability of Occurrence Justification for probability of Occurence - Why did you select this? Impact Intensity Justification for Impact Intensity - why did you classify as you did (high, medium or low?) Existing Measures Mitigation Strategy Justification for selecting your mitigation strategy. Why? Additional Measures Contingency Plan
Management Change Human error due to lack of continuity .Anita's Predecessor management was accompanied by problems that resulted to his decision to resign from the employment. The previous management failed to have adequate planning for occurence of a disaster. Human errors done previously are still experienced in the new management. Unlikely: 11-40% The New CIO expects the company to have a recovery plan that is effective which is not the case. The new CIO is likely to experience the problem in solving the new disaster occurrence bcause the company fails to have a continuity plan. However, Anital is highly skills and identifies the probelm when she asked from the disaster recovery plan and aspited thet CEO is identify ways of solving it by imposing strategies to be used in improving the recovery plan. High Lack of a proper Disaster recovery plan affects the continuity of the company highly since it will take time to recover from the web server. The plan is strong on Disaster Recovery for situations such as fire and other disasters of that nature. Exact details of the recovery plan are not mentioned. Risk Limitation The recovery plan will be improved to state specific recovery plan to be used in disaster occurence to prevent similar problems in future. Proper placement and orietation plan Establish management change procedure through identification of proper orientation and placement of the new employees. The new employees should be informed about recovery plans so that its effectiveness is identified.
Human Resource Workforce Training and Developemnt Human error due to inexperience The development of new technologies fails to be addresssed clearly in the recovery plan. The workforce is not trained adequately on ways of handling disasters emanating from flood Unlikely: 11-40% The CIO during thet council meeting provides a solution to the problems by urging the company to identify high skilled employees who can participate in the development of an effective recovery plan. High Lack of proper training will lead to numerous errors occureineg to the web server even in the recovery plan. Risk limitation training of thet workforce is developed The workforce should identify areas thet require exaact details on the recovery plan and who to conduct the process. The workforce especially those involved in the recovery plan should be trained on areas the require exact informateiosn on the recivery plan so the the recovery process of the server is made accoridngly.
Adapting to Innovation Web Server are destroyed by Floods the new technology of developing new web servers that provide information to various groups fails to have a porper planning on how it can be recoverey in case of disiter to prevent occurrence of hore harm to thet customers. Unlikely: 11-40% the new technology is understood well by thet CIO and thet IT departement hence the infrastructures used in the development of the web server are apropriate. High Lack of information of web server repairs and recovery Risk limitation a backup is required A backup stragegy will help the comaonye and customer to continue with they work before the server is recovered. A backup stratety is important to prevent loss of information after the damage of the web server occurred. Customers will also ensure continuity even after the web server is damaged.
Recruiting Talented Employees Data Center Power Outage caused by tornado Every position in the company has description and responsibilities essentials for the employee. Damage o thet data centre will result to loss of this informateiosn hence identified talenste matching thet position is strained. Unlikely: 11-40% The Human resource identifies the role of employees in the company and strive to match responsibilities with talents. Thus the human resource understand the company even when the data center is damaged but some of essential responsibilities may be left out. High Data lost after damage to the Data centre The recovery plan does not indicate exact source of data incase the data centre is damaged. Risk limitation A back is needed the Human reource department shoudl posses a backup on employees role and description so that they can recovey it easily in thet face of data center damage. A backup stratety is important to prevent loss of information after the damage of the web server occurred. Customers will also ensure continuity even after the web server is damaged.
Employees benefits Web Server are destrored by Floods Employees benefits are recorded and retrieved from the server since all employees have different levels of benefits depending in their ranks. Destruction of the web server by the floods will affect thet identification of employees benefits. Unlikely: 11-40% The probability of this occurrence is unlikely due to redundancy High The occurenc of the problem will result to signifant issues if some benefits of the employees are not meet The plan is adequate but it fails to provide exact information on the recovery plan of this issue Risk Limitation Backups are required Backup strategies should be identified in case the server is damages which will provide employee benefit information A backup strategy should be in place incase the server fails froms which information about benefits entitled to every employees are obtained.
Payroll Payroll processing Data Center Power Outage caused by tornado Data center experiences a tornado that causes a massive power outage impacting the ability to complete processing of the payroll Unlikely: 11-40% The probability of this occurrence is unlikely due to redundancy High The intesity of the occurrence of such event would cause significant damage to the company The recovery plan is appropriate but fail to have clear and specific information about the recovery process of this event Risk Limitation Backups are required Backup strategy shoudl be in place to aid payroll processing in case the server fails. The backup centre should be in place so that the processing of payroll is completed in case the server fails.
Payroll compliance Web Server are destrored by Floods The company relies on the webserver to obtain information about the benefits and compensatsion of every employees. Damage to the web server will lead to non-compliaance of the company to the payroll. Unlikely: 11-40% The probability of this occurrence is unlikely due to redundancy High The intesity of the occurrence of such event would cause significant damage to many companies The plan is strong on Disaster Recovery for situations such as fire and other disasters of that nature. Exact details of the recovery plan are not mentioned. Risk Limitation Backups are required A backup stratety should be developed to provide informatsion about payroll compliance. The backup strategy should contain information that will aid compliance to the payroll.
Paychecking taxes Data Center Power Outage caused by tornado Paychecking as well as taxing will be insufficient when the web server is destroyed by the floods. The compay will experience problems when paychecking and taxing employees. Unlikely: 11-40% The probability of this occurrence is unlikely due to redundancy High The intesity of the occurrence of such event would cause significant damage to the company The plan is strong on Disaster Recovery for situations such as fire and other disasters of that nature. Exact details of the recovery plan are not mentioned. Risk Limitation Backups are required A backup center should be identified to help in paychecking taxes. The backup centre should be in place so that paychecking taxes is completed in case the server fails.
Market Demand Web Server are destrored by Floods The occurrence of disaster and long perido taken before thet server os collected imposes risks of market demand falling. Unlikely: 11-40% The probability of this occurrence is unlikely due to redundancy High The intensity the event will cause significant damage to the market demand for OptiPress services. The plan is adequate but it fails to provide exact information on the recovery plan of this issue Risk Limitation Backups are provided Backup strategies provided ensures the customers continues with their operatiosn hence prevent loss of customers Establish a backup center and notify customers about the incidents. Once the server is recovered they are infromed that the problem is resolved.
Marketing Market Concentration Web Server are destrored by Floods OptiPres has may customer that rely on the site for data tranfer and operations of their company. Thet mareket concentrations can be affected by thet web server damage as many companies will suffer from the problem. Unlikely: 11-40% The probability of this occurrence is unlikely due to redundancy High The intensity of the event will cause significant damage to the market market concentration. The recovery plan is appropriate but fail to have clear and specific information about the recovery process of this event Risk Limitation Backups are provided Back strategy provided will ensure the customer continue to access the services provided by the company Establish a backup center and notify customers about the incidents. Once the server is recovered they are infromed that the problem is resolved.
Information Distribution Web Server are destrored by Floods The company relies on thet server to transfer information through mailing and adversitment. Damage to the server will affect the operations of the company by restricting its information distribution. Unlikely: 11-40% The probability of this occurrence is unlikely due to redundancy High The intensity of occurrence will lead to difficulty in information distribution hence damage the operations of the company The plan is strong on Disaster Recovery for situations such as fire and other disasters of that nature. Exact details of the recovery plan are not mentioned. Risk Limitation Backups are required Backup strategy is required to ensure information is distributed appropriately. Establish a backup strategy that will facilitate information sharing. Once the server is recovered employees should be informed about the resolved problem
Company's Reputation Web Server are destrored by Floods When the company fails to provide adequate services to its customers for a long period, its reputation is tanished hence it will lose customers and find it difficult to obtain new customers. Unlikely: 11-40% The probability of this occurrence is unlikely due to redundancy High the intensitye of the event will cause significant damage to the company's reputation among its customers. The plan is adequate but it fails to provide exact information on the recovery plan of this issue Risk Limitation Backups are provided The backup centers provided will protect the company from damaging its reputation. Establish a backup center and notify customers about the incidents. Once the server is recovered they are infromed that the problem is resolved.
Creating billing invoices The web servers are damaged in a flood In order to charge clients for payment, each service provided by OptiPress must have a billing invoice created to track and report all charges. Human Resources, Accounting and Payroll and all the web servers have been centralized at the Headquarters. If the web servers are damaged, all three business areas cannot operate. Unlikely: 11-40% The probability of this occurrence is unlikely due to redundancy High The intensity if such an event would occur would do significant damage to several sites The plan is strong on Disaster Recovery for situations such as fire and other disasters of that nature. Exact details of the recovery plan are not mentioned. Risk Limitation Backups are provided A backup data center should be identified in the event that the Headquarters servers are damaged. Establish operation control procedures in the event that any of the company sites cannot continue operations. Notify all company members of all changes of control. Once the incident is no longer a problem, give back control to the original site.
Accounting Producing Financil report The web servers are damaged in a flood Finacial report is derived from the paymnet of customers and company's expenditure. Damage to thet web server will affect the billing of customers hence thet finacail reports of incomes will be accurate. Unlikely: 11-40% The probability of this occurrence is Unlikely due to redundancy High The intesity of the occurence of the damage would lead to high losses to the company The plan is strong on Disaster Recovery for situations such as fire and other disasters of that nature. Exact details of the recovery plan are not mentioned. Risk limitation Backups are provided A backup data center should be identified in the event that the Headquarters servers are damaged. The company should establish operation control procedures in case the server is damages or not in operation. Finacial activities should continue to be identified while the server is not in operation and onces it is recovered.
Management of Company financila assets The web servers are damaged in a flood Gamage to the server wiell affect the management of financial asset since OptiPress relies on the server for the management of financial assets such as the billing invoice. Unlikely: 11-40% The probability of this occurrence is Unlikely due to redundancy High The occurenc of this damage will cause damage to the company. The plan is strong on Disaster Recovery for situations such as fire and other disasters of that nature. Exact details of the recovery plan are not mentioned. Risk limitation Backups are provided A backup center should be in place in case thet server is damaged The company should allocate financial control procedures in case the server is damaged. Financial activities should continue even when the server is not in operation.
Manage Customer Accounts Data Center Power Outage caused by tornado Data center experiences a tornado that causes a massive power outage impacting the ability to complete processing and managing of customer accounts Unlikely: 11-40% Data Center has backup power. High Customer payment records could not be processed. Plan was strong on Disaster Recovery for situations such as that at Host Point, it was almost silent on Business Continuity Risk Limitation Backups are provided A backup center should be in place in case thet server is damaged The OptiPress should identify was of managing financial assets even when the server is not in operation through the use of backups

Sheet2

Sheet3