SEC400 Threats and Risks Assessment
Threats and Assessments
SEC400 Threats and Risks Assessment
Name
Class
Date
Professor
Threats and Risks Assessment
Every organization on the globe faces security threats and potential loss from criminals but in the new information age the threat of loss is greater and could result in damage to the reputation of the organization, the loss of private information of customers, and financial loss for the organization. The threat of theft or intrusion into the private information of the organization is not the only threats faced by the organization. The organization also faces potential threat from natural and manmade hazards. In order for an organization to minimize the risk and have an appropriate response in place in the event of a hazard the organization must be properly prepared.
The threat and risk assessment is one of the most valuable tools to the organization especially an organization the size of Wal-Mart. Wal-Mart has locations across the globe making the potential for a natural, manmade or technological hazard much greater than the average organization. The threat and risk assessment will assist members of the Wal-Mart organization in better understanding the range of natural hazards that affect America, technological hazards and their causes and effects, and the threat posed by national and international terrorists as well as the risks faced by the organization in the event of the hazard.
A hazard is defined as a “source of danger that may or may not lead to an emergency or disaster and is named after the emergency/disaster that could be so precipitated (Bayne, 2002). The risk is the danger posed to the organizational members or citizens in society. The threat and risk assessment will provide data on what the organization needs to protect, identifying the threats, determining who or what needs to be protected, understanding the implications, and the value of the risk assessment to the organization.
Natural hazards are dangers or situations in the natural environment that pose a threat to human populations and communities (Haddow, 2008). While natural hazards cannot be planned for the risks can be first assessed in order to determine the likelihood the disaster would occur. For example building a Wal-Mart along the Mississippi coastline would result in a risk for hurricane or building a Wal-Mart on an earthquake fault line would put the location at risk for an earthquake. If the Wal-Mart is located in an area that is prone to hurricanes then the security team would first need to assess the risk and determine the security risk faced by this natural hazard event.
A perfect example of this situation is the natural disaster of Hurricane Katrina. Wal-Mart on the gulf coasts of Mississippi, Alabama, and Louisiana suffered damage from the hurricane but many stores in these areas also faced loss from looting. Because the Wal-Mart stores were closed down and abandoned during the storm it was easier for citizens to break in and loot when left with no food or water for survival. Not only did several stores lose all of its assets they also faced the destruction of the actual store location. By not being effectively prepared for the event of the hurricane Wal-Mart was vulnerable to the security breaches and losses that occurred during Hurricane Katrina.
In the case of the manmade disaster the organization faces the same risk of potential loss of assets, property, or even life while a technological hazard involves the creation of an accidental disaster such as an oil spill. These threats include weapons or bombs made by man or threats from aviation disasters. Technological threats are a category of the man made hazard and include threats such as chemical spills, terrorism, power outages structural collapse, and industrial hazards and fire (Haddow, 2008). When the security in an organization is not prepared for the eventuality of these hazards the risk is increased. If Wal-Mart ad conducted a threat and risk assessment prior to the hazard the organization could have better mitigated some of the destruction and loss caused by the hurricane.
Security officials determine the threats and risk of the natural, hazards by collecting data on the vulnerabilities associated with the natural, manmade, and technological hazards, monitoring hazards and emergencies occurring in areas where there is Wal-Mart stores located, and identifying and organizing resources available to respond to these threats. The assessment process includes conducting a threat/hazard risk assessment and conducting a vulnerabilities assessment. The risk assessment will provide security personnel with information on the likelihood of the disaster occurring and the impact if it did occur. This includes potential loss of life, property, and important functions of the organization.
In order to plan for a hazard the organization must understand the potential risks posed as well as understand the vulnerabilities of the organization. The vulnerability assessment provides critical data to the organization that uses security officials to determine the vulnerabilities to natural, man-made, and technological hazards to help increase safety in the work setting (Stoneburner, 2002). The type of vulnerabilities the security staff at Wal-Mart might assess includes weaknesses in the external property perimeters, building structure, and company information systems as well as potential weaknesses in internal structures. The vulnerability assessment would alert the security staff to criminal activity in the area, accessibility to transportation, and potential resources available to assist.
The risk assessment will assist security personnel in determining the relative risk for each threat against each asset as well as in selecting mitigation measures that will have the greatest benefit for reducing risk for the organization. The risk assessment will increase awareness by the Wal-Mart security team and will alert them to potential impacts, threats, and existing vulnerabilities within the organization. In order to be effectively prepared for any type of hazard the security staff must identify the risks and the vulnerabilities and be proactive in taking step to mitigate these risks and eliminating the vulnerabilities.
In order for the organization to be protected and to limit the vulnerability to their assets they must have the necessary data to assist in developing an effective response to any hazards. The organization must consider the organizational assets that can be vulnerable to the safety and security of the organization and its people. Information, technology, and data systems need constant updating and improvement and any potential vulnerabilities in the security but be continuously assessed and addressed. Security officials will determine the different vulnerabilities and develop comprehensive incentives for protection of the systems and assets of the organization.
References
Bayne, J. (2002). An Overview of Threat and Risk Assessment. SANS Institute. Retrieved
September 16, 2012 from
http://www.sans.org/reading_room/whitepapers/auditing/overview-threat-risk-assessment
Haddow, G., Bullock, J. & Coppola, L. (2008). Introduction to Emergency Management: Third
Edition. Retrieved September 16, 2012 from
http://www.scribd.com/doc/80972857/10/Natural-and-Technological-Hazards-and-Risk
Stoneburner, G. (2002). Risk Management Guide for Information Technology Systems.
Retrieved September 16, 2012 from
http://www.hhs.gov/ocr/privacy/hipaa/administrative/securityrule/nist800-30.pdf