SlideShare uma empresa Scribd logo
1 de 31
Welcome
Navigating Through Uncertainties of Risk Dr Goh Moh Heng  PhD BCCE DRCE BCCLA President 2
BCM Institute Started in January 2005. Provide competency based BC-DR  training to all levels. Certify BC-DR  professionals globally. Started Certification programme in April 2007. More than 1500 professionals from 850 organizations and 40 countries.
Professional Certification Business Continuity IT Disaster  Recovery BCM Audit Membership
Business Continuity Management or Risk Management? Aligning Expectations for Business Strategies Dr. Goh Moh Heng PhD BCCE DRCE BCCLAPresident, BCM Institute and Managing Director, GMH Continuity Architects
Agenda BC Planning Methodology Risk Analysis and Review Risk Assessment Process Step-by-stepAchieving Certification
BCM Planning Methodology Source: 	 Goh, Moh Heng (2008): Analyzing and Review the Risk for Business Continuity Planning ISBN: 978-981-05-9215-8
Risk Analysis & Review
Identify Assets & Threats ,[object Object]
Identify Threats,[object Object]
Identify Threats Man-Made Toxic and radioactive contamination Sabotage (both external and internal) Riot, civil disorder and coup Fraud and embezzlement Accidental explosion (on and offsite) Water leak and plumbing failure Workplace violence Terrorism Aircraft crash Vandalism Arson Physical asset theft Misuse of resources Building and physical security weakness Fire Natural Tornado (wind storm) Thunderstorm and hail storm Lightning and electrical storm Snow and winter ice storm Typhoon and hurricane Flood and other water-based incident Earthquake Mudslide Volcanic eruption and ash fallout Tsunami Large natural fire Epidemic and pandemic
Identify Threats Business Power outage Labor dispute Employee turnover and single point of failure Unavailability of key personnel Human error Gas outage Water outage Loss of transportation Single source suppliers Information Technology  Voice and data telecommunication failure IT equipment failure Human error from programmers and users Security vulnerability Data and software sabotage In-house developed application failure HVAC failure Defective software
Analyse Risks Estimate the risk likelihood of occurrence Identify risk impact of the threat materializing Determine risk (rating) level
Descriptor: Risk Likelihood of Event
Descriptor: Risk Impact of Event
Risk Analysis Process Controls What is cost for the Controls to be implemented? What Controls are in place? Risk  Rating What is the potential loss exposures to business? How does the threat affect business operations? What is the likelihood that the threat will adversely affect business operations? Threats Risk Likelihood What is the effects on people, infrastructure, facilities, and systems? Risk Impact What are the adverse events that can occur?
Risk Evaluation Assess Risk Rating and prioritized for further treatment
Risk Rating andLevel Matrix
Risk Evaluation: Risk Rating
Evaluation Criteria Criteria Examples: People Processes Infrastructure Weighting for different criteria
Risk Treatment Explore Risk Treatment Strategies for risks deemed unacceptable Document reasons for selection of strategy for each risk treatment
Risk Analysis Process Controls What is cost for the Controls to be implemented? What Controls are in place? What risk treatment? Risk  Rating What is the potential loss exposures to business? How does the threat affect business operations? What is the likelihood that the threat will adversely affect business operations? Threats Risk Likelihood What is the effects on people, infrastructure, facilities, and systems? Risk Impact What are the adverse events that can occur?
Risk Treatment Strategies Risk Acceptance Risk Avoidance Risk Transfer Risk Reduction
Risk Treatment Strategies Transfer Avoid Reduce /  Active Control Reduce (if Cost  Justifiable) Accept
Risk Reduction Fire Pandemic Business Continuity Plan (BCP)
Risk Analysis and Business Continuity Planning Process Risk Treatment Strategies Treatment for risks that could potentially interrupt business operations
Risk Treatment 27 04-
Implement & Monitor Present Recommendations to management for approval  Implement recommendations Monitor results Adjust as necessary
Risk Analysis Process
THANK YOU Dr Goh Moh Heng President Mobile: +65 96711022 Tel: +65 63231500 Fax: +65 63230933 Email:  moh_heng@bcm-institute.org

Mais conteúdo relacionado

Mais procurados

Business Continuity Management
Business Continuity ManagementBusiness Continuity Management
Business Continuity Management
ECC International
 
Business Impact and Risk Assessments in Business Continuity and Disaster Reco...
Business Impact and Risk Assessments in Business Continuity and Disaster Reco...Business Impact and Risk Assessments in Business Continuity and Disaster Reco...
Business Impact and Risk Assessments in Business Continuity and Disaster Reco...
Rochester Security Summit
 

Mais procurados (20)

Business continuity planning and disaster recovery
Business continuity planning and disaster recoveryBusiness continuity planning and disaster recovery
Business continuity planning and disaster recovery
 
Risk and Business Continuity Management
Risk and Business Continuity ManagementRisk and Business Continuity Management
Risk and Business Continuity Management
 
Business Continuity Planning Presentation
Business Continuity Planning PresentationBusiness Continuity Planning Presentation
Business Continuity Planning Presentation
 
Business continuity management system
Business continuity management systemBusiness continuity management system
Business continuity management system
 
BCP Awareness
BCP Awareness BCP Awareness
BCP Awareness
 
Assess Your Business Continuity Management Process
Assess Your Business Continuity Management ProcessAssess Your Business Continuity Management Process
Assess Your Business Continuity Management Process
 
BUSINESS CONTINUITY PLANNING AND RISK MANAGEMENT
BUSINESS CONTINUITY PLANNING AND RISK MANAGEMENTBUSINESS CONTINUITY PLANNING AND RISK MANAGEMENT
BUSINESS CONTINUITY PLANNING AND RISK MANAGEMENT
 
Awareness iso 22301 danang suryo
Awareness iso 22301 danang suryoAwareness iso 22301 danang suryo
Awareness iso 22301 danang suryo
 
KRI (Key Risk Indicators) & IT
KRI (Key Risk Indicators) & ITKRI (Key Risk Indicators) & IT
KRI (Key Risk Indicators) & IT
 
Business Continuity Management
Business Continuity ManagementBusiness Continuity Management
Business Continuity Management
 
Sharing Practice on Enterprise Risk Management (ERM)
Sharing Practice on Enterprise Risk Management (ERM)Sharing Practice on Enterprise Risk Management (ERM)
Sharing Practice on Enterprise Risk Management (ERM)
 
Business Continuity Management PowerPoint Presentation Slides
Business Continuity Management PowerPoint Presentation SlidesBusiness Continuity Management PowerPoint Presentation Slides
Business Continuity Management PowerPoint Presentation Slides
 
Business Impact Analysis - Clause 4 Of BS25999 In Practice
Business Impact Analysis - Clause 4 Of BS25999 In PracticeBusiness Impact Analysis - Clause 4 Of BS25999 In Practice
Business Impact Analysis - Clause 4 Of BS25999 In Practice
 
Integrating Risk Appetite With Strategy Feb 14 2011
Integrating Risk Appetite With Strategy   Feb 14 2011Integrating Risk Appetite With Strategy   Feb 14 2011
Integrating Risk Appetite With Strategy Feb 14 2011
 
Governance, Risk, and Compliance Services
Governance, Risk, and Compliance ServicesGovernance, Risk, and Compliance Services
Governance, Risk, and Compliance Services
 
9 Bcp+Drp
9 Bcp+Drp9 Bcp+Drp
9 Bcp+Drp
 
BUSINESS CONTINUITY MANAGEMENT system
BUSINESS CONTINUITY MANAGEMENT systemBUSINESS CONTINUITY MANAGEMENT system
BUSINESS CONTINUITY MANAGEMENT system
 
Operational risk ppt
Operational risk pptOperational risk ppt
Operational risk ppt
 
What is business continuity planning-bcp
What is business continuity planning-bcpWhat is business continuity planning-bcp
What is business continuity planning-bcp
 
Business Impact and Risk Assessments in Business Continuity and Disaster Reco...
Business Impact and Risk Assessments in Business Continuity and Disaster Reco...Business Impact and Risk Assessments in Business Continuity and Disaster Reco...
Business Impact and Risk Assessments in Business Continuity and Disaster Reco...
 

Semelhante a Business Continuity Management or Risk Management? Aligning Expectations for Business Strategies by Dr Goh Moh Heng

Risk Analysis In Business Continuity Management - Jeremy Wong
Risk Analysis In Business Continuity Management - Jeremy WongRisk Analysis In Business Continuity Management - Jeremy Wong
Risk Analysis In Business Continuity Management - Jeremy Wong
BCM Institute
 
Assessment Of Risk Mitigation
Assessment Of Risk MitigationAssessment Of Risk Mitigation
Assessment Of Risk Mitigation
Eneni Oduwole
 
Risk Analysis In IT Projects - TNS09
Risk Analysis In IT Projects - TNS09Risk Analysis In IT Projects - TNS09
Risk Analysis In IT Projects - TNS09
Thomas Danford
 
Risk Management - A Journey
Risk Management - A JourneyRisk Management - A Journey
Risk Management - A Journey
Debashis Gupta
 
Workshop V - Safety Applying Team Concept
Workshop V - Safety Applying Team ConceptWorkshop V - Safety Applying Team Concept
Workshop V - Safety Applying Team Concept
deidretate
 
HIRARC_IBPR111111111111111111111111.pptx
HIRARC_IBPR111111111111111111111111.pptxHIRARC_IBPR111111111111111111111111.pptx
HIRARC_IBPR111111111111111111111111.pptx
Indra271633
 

Semelhante a Business Continuity Management or Risk Management? Aligning Expectations for Business Strategies by Dr Goh Moh Heng (20)

Risk Analysis In Business Continuity Management - Jeremy Wong
Risk Analysis In Business Continuity Management - Jeremy WongRisk Analysis In Business Continuity Management - Jeremy Wong
Risk Analysis In Business Continuity Management - Jeremy Wong
 
Risk Identification.ppt
Risk Identification.pptRisk Identification.ppt
Risk Identification.ppt
 
Enterprise risk & risk management - I
Enterprise risk & risk management - IEnterprise risk & risk management - I
Enterprise risk & risk management - I
 
Risk managementslides
Risk managementslidesRisk managementslides
Risk managementslides
 
2010; Risk Management Workshop Rev.1.1
2010; Risk Management Workshop Rev.1.12010; Risk Management Workshop Rev.1.1
2010; Risk Management Workshop Rev.1.1
 
Assessment Of Risk Mitigation
Assessment Of Risk MitigationAssessment Of Risk Mitigation
Assessment Of Risk Mitigation
 
Risk Analysis In IT Projects - TNS09
Risk Analysis In IT Projects - TNS09Risk Analysis In IT Projects - TNS09
Risk Analysis In IT Projects - TNS09
 
Risk Management (1) (1).ppt
Risk Management (1) (1).pptRisk Management (1) (1).ppt
Risk Management (1) (1).ppt
 
Risk Management - A Journey
Risk Management - A JourneyRisk Management - A Journey
Risk Management - A Journey
 
Introduction to Qualitative Risk Analysis for the PMP.pdf
Introduction to Qualitative Risk Analysis for the PMP.pdfIntroduction to Qualitative Risk Analysis for the PMP.pdf
Introduction to Qualitative Risk Analysis for the PMP.pdf
 
Implementation of Enterprise Risk Management with ISO 31000 Risk Management S...
Implementation of Enterprise Risk Management with ISO 31000 Risk Management S...Implementation of Enterprise Risk Management with ISO 31000 Risk Management S...
Implementation of Enterprise Risk Management with ISO 31000 Risk Management S...
 
Workshop V - Safety Applying Team Concept
Workshop V - Safety Applying Team ConceptWorkshop V - Safety Applying Team Concept
Workshop V - Safety Applying Team Concept
 
Risk management in ILRI
Risk management in ILRI Risk management in ILRI
Risk management in ILRI
 
PECB Webinar: ISO 31000 – Risk Management and how it can help an organization
PECB Webinar: ISO 31000 – Risk Management and how it can help an organizationPECB Webinar: ISO 31000 – Risk Management and how it can help an organization
PECB Webinar: ISO 31000 – Risk Management and how it can help an organization
 
Bcu msc cg week 4 risk management
Bcu msc cg week 4 risk managementBcu msc cg week 4 risk management
Bcu msc cg week 4 risk management
 
Software Engineering
Software EngineeringSoftware Engineering
Software Engineering
 
cue presentation.pptx
cue presentation.pptxcue presentation.pptx
cue presentation.pptx
 
QRM-ICH Q9 & ISO 31000.pdf
QRM-ICH Q9 & ISO 31000.pdfQRM-ICH Q9 & ISO 31000.pdf
QRM-ICH Q9 & ISO 31000.pdf
 
HIRARC_IBPR111111111111111111111111.pptx
HIRARC_IBPR111111111111111111111111.pptxHIRARC_IBPR111111111111111111111111.pptx
HIRARC_IBPR111111111111111111111111.pptx
 
Patrick_Wayne_Cooper_Graphic_CV_2024.pdf
Patrick_Wayne_Cooper_Graphic_CV_2024.pdfPatrick_Wayne_Cooper_Graphic_CV_2024.pdf
Patrick_Wayne_Cooper_Graphic_CV_2024.pdf
 

Mais de BCM Institute

Mais de BCM Institute (20)

Business Continuity and Resilience: What Lies in the Future and What Steps Ca...
Business Continuity and Resilience: What Lies in the Future and What Steps Ca...Business Continuity and Resilience: What Lies in the Future and What Steps Ca...
Business Continuity and Resilience: What Lies in the Future and What Steps Ca...
 
Enterprise Risk Management and Business Continuity: How Can They Work Togethe...
Enterprise Risk Management and Business Continuity: How Can They Work Togethe...Enterprise Risk Management and Business Continuity: How Can They Work Togethe...
Enterprise Risk Management and Business Continuity: How Can They Work Togethe...
 
Winning Over The Challenges of Implementing BCM in a BPO by Jeremias Astrero,...
Winning Over The Challenges of Implementing BCM in a BPO by Jeremias Astrero,...Winning Over The Challenges of Implementing BCM in a BPO by Jeremias Astrero,...
Winning Over The Challenges of Implementing BCM in a BPO by Jeremias Astrero,...
 
Operational and Business Continuity Management Strategy for Multi-type Nation...
Operational and Business Continuity Management Strategy for Multi-type Nation...Operational and Business Continuity Management Strategy for Multi-type Nation...
Operational and Business Continuity Management Strategy for Multi-type Nation...
 
Business Continuity Management in Healthcare by Dexter Chia, Director, GCOO's...
Business Continuity Management in Healthcare by Dexter Chia, Director, GCOO's...Business Continuity Management in Healthcare by Dexter Chia, Director, GCOO's...
Business Continuity Management in Healthcare by Dexter Chia, Director, GCOO's...
 
Does Your BCP Need A BCP - Outsourcing Business Continuity by Irene Lye, Ente...
Does Your BCP Need A BCP - Outsourcing Business Continuity by Irene Lye, Ente...Does Your BCP Need A BCP - Outsourcing Business Continuity by Irene Lye, Ente...
Does Your BCP Need A BCP - Outsourcing Business Continuity by Irene Lye, Ente...
 
The Evolving Role of BCM and its Importance in Any Industries by Dr Goh Moh H...
The Evolving Role of BCM and its Importance in Any Industries by Dr Goh Moh H...The Evolving Role of BCM and its Importance in Any Industries by Dr Goh Moh H...
The Evolving Role of BCM and its Importance in Any Industries by Dr Goh Moh H...
 
Experience Sharing - Risk Management, Crisis Management & BCM In An Education...
Experience Sharing - Risk Management, Crisis Management & BCM In An Education...Experience Sharing - Risk Management, Crisis Management & BCM In An Education...
Experience Sharing - Risk Management, Crisis Management & BCM In An Education...
 
Planning For The Haze by Jeremy Wong, , Senior Vice President of GMH Continui...
Planning For The Haze by Jeremy Wong, , Senior Vice President of GMH Continui...Planning For The Haze by Jeremy Wong, , Senior Vice President of GMH Continui...
Planning For The Haze by Jeremy Wong, , Senior Vice President of GMH Continui...
 
Challenges, Opportunities and Trends for BCM Profession by Dr Goh Moh Heng, P...
Challenges, Opportunities and Trends for BCM Profession by Dr Goh Moh Heng, P...Challenges, Opportunities and Trends for BCM Profession by Dr Goh Moh Heng, P...
Challenges, Opportunities and Trends for BCM Profession by Dr Goh Moh Heng, P...
 
DR Plan Implementation Experience: A Government Agency's Perspective by Inthr...
DR Plan Implementation Experience: A Government Agency's Perspective by Inthr...DR Plan Implementation Experience: A Government Agency's Perspective by Inthr...
DR Plan Implementation Experience: A Government Agency's Perspective by Inthr...
 
Navigating The Path To BCM Excellence by Dr Suhazimah Dzazali, Deputy Directo...
Navigating The Path To BCM Excellence by Dr Suhazimah Dzazali, Deputy Directo...Navigating The Path To BCM Excellence by Dr Suhazimah Dzazali, Deputy Directo...
Navigating The Path To BCM Excellence by Dr Suhazimah Dzazali, Deputy Directo...
 
BCM Institute Course Schedule 2016
BCM Institute Course Schedule 2016BCM Institute Course Schedule 2016
BCM Institute Course Schedule 2016
 
Deploying A Crisis Management and Business Continuity Approach to Product Tam...
Deploying A Crisis Management and Business Continuity Approach to Product Tam...Deploying A Crisis Management and Business Continuity Approach to Product Tam...
Deploying A Crisis Management and Business Continuity Approach to Product Tam...
 
Cyber Resilience – Strengthening Cybersecurity Posture & Preparedness by Phil...
Cyber Resilience – Strengthening Cybersecurity Posture & Preparedness by Phil...Cyber Resilience – Strengthening Cybersecurity Posture & Preparedness by Phil...
Cyber Resilience – Strengthening Cybersecurity Posture & Preparedness by Phil...
 
Considerations for Developing Your Organisation’s Pandemic Plan by Jeremy Won...
Considerations for Developing Your Organisation’s Pandemic Plan by Jeremy Won...Considerations for Developing Your Organisation’s Pandemic Plan by Jeremy Won...
Considerations for Developing Your Organisation’s Pandemic Plan by Jeremy Won...
 
Pandemics & Infectious Diseases: Stepping Up Your Business Continuity Prepare...
Pandemics & Infectious Diseases: Stepping Up Your Business Continuity Prepare...Pandemics & Infectious Diseases: Stepping Up Your Business Continuity Prepare...
Pandemics & Infectious Diseases: Stepping Up Your Business Continuity Prepare...
 
Certified Crisis Management Professional Programme Brochure
Certified Crisis Management Professional Programme Brochure Certified Crisis Management Professional Programme Brochure
Certified Crisis Management Professional Programme Brochure
 
BCM Institute Malaysia Course Schedule 2015
BCM Institute Malaysia Course Schedule 2015 BCM Institute Malaysia Course Schedule 2015
BCM Institute Malaysia Course Schedule 2015
 
Dr Goh Moh Heng Building Your Organization Business Continuity Management Com...
Dr Goh Moh Heng Building Your Organization Business Continuity Management Com...Dr Goh Moh Heng Building Your Organization Business Continuity Management Com...
Dr Goh Moh Heng Building Your Organization Business Continuity Management Com...
 

Último

Call Girls Jp Nagar Just Call 👗 7737669865 👗 Top Class Call Girl Service Bang...
Call Girls Jp Nagar Just Call 👗 7737669865 👗 Top Class Call Girl Service Bang...Call Girls Jp Nagar Just Call 👗 7737669865 👗 Top Class Call Girl Service Bang...
Call Girls Jp Nagar Just Call 👗 7737669865 👗 Top Class Call Girl Service Bang...
amitlee9823
 
FULL ENJOY Call Girls In Mahipalpur Delhi Contact Us 8377877756
FULL ENJOY Call Girls In Mahipalpur Delhi Contact Us 8377877756FULL ENJOY Call Girls In Mahipalpur Delhi Contact Us 8377877756
FULL ENJOY Call Girls In Mahipalpur Delhi Contact Us 8377877756
dollysharma2066
 

Último (20)

Yaroslav Rozhankivskyy: Три складові і три передумови максимальної продуктивн...
Yaroslav Rozhankivskyy: Три складові і три передумови максимальної продуктивн...Yaroslav Rozhankivskyy: Три складові і три передумови максимальної продуктивн...
Yaroslav Rozhankivskyy: Три складові і три передумови максимальної продуктивн...
 
7.pdf This presentation captures many uses and the significance of the number...
7.pdf This presentation captures many uses and the significance of the number...7.pdf This presentation captures many uses and the significance of the number...
7.pdf This presentation captures many uses and the significance of the number...
 
Grateful 7 speech thanking everyone that has helped.pdf
Grateful 7 speech thanking everyone that has helped.pdfGrateful 7 speech thanking everyone that has helped.pdf
Grateful 7 speech thanking everyone that has helped.pdf
 
Cracking the Cultural Competence Code.pptx
Cracking the Cultural Competence Code.pptxCracking the Cultural Competence Code.pptx
Cracking the Cultural Competence Code.pptx
 
Call Girls Jp Nagar Just Call 👗 7737669865 👗 Top Class Call Girl Service Bang...
Call Girls Jp Nagar Just Call 👗 7737669865 👗 Top Class Call Girl Service Bang...Call Girls Jp Nagar Just Call 👗 7737669865 👗 Top Class Call Girl Service Bang...
Call Girls Jp Nagar Just Call 👗 7737669865 👗 Top Class Call Girl Service Bang...
 
Regression analysis: Simple Linear Regression Multiple Linear Regression
Regression analysis:  Simple Linear Regression Multiple Linear RegressionRegression analysis:  Simple Linear Regression Multiple Linear Regression
Regression analysis: Simple Linear Regression Multiple Linear Regression
 
Mondelez State of Snacking and Future Trends 2023
Mondelez State of Snacking and Future Trends 2023Mondelez State of Snacking and Future Trends 2023
Mondelez State of Snacking and Future Trends 2023
 
Call Girls Pune Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Pune Just Call 9907093804 Top Class Call Girl Service AvailableCall Girls Pune Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Pune Just Call 9907093804 Top Class Call Girl Service Available
 
M.C Lodges -- Guest House in Jhang.
M.C Lodges --  Guest House in Jhang.M.C Lodges --  Guest House in Jhang.
M.C Lodges -- Guest House in Jhang.
 
FULL ENJOY Call Girls In Mahipalpur Delhi Contact Us 8377877756
FULL ENJOY Call Girls In Mahipalpur Delhi Contact Us 8377877756FULL ENJOY Call Girls In Mahipalpur Delhi Contact Us 8377877756
FULL ENJOY Call Girls In Mahipalpur Delhi Contact Us 8377877756
 
Monthly Social Media Update April 2024 pptx.pptx
Monthly Social Media Update April 2024 pptx.pptxMonthly Social Media Update April 2024 pptx.pptx
Monthly Social Media Update April 2024 pptx.pptx
 
HONOR Veterans Event Keynote by Michael Hawkins
HONOR Veterans Event Keynote by Michael HawkinsHONOR Veterans Event Keynote by Michael Hawkins
HONOR Veterans Event Keynote by Michael Hawkins
 
Ensure the security of your HCL environment by applying the Zero Trust princi...
Ensure the security of your HCL environment by applying the Zero Trust princi...Ensure the security of your HCL environment by applying the Zero Trust princi...
Ensure the security of your HCL environment by applying the Zero Trust princi...
 
Famous Olympic Siblings from the 21st Century
Famous Olympic Siblings from the 21st CenturyFamous Olympic Siblings from the 21st Century
Famous Olympic Siblings from the 21st Century
 
VIP Call Girls In Saharaganj ( Lucknow ) 🔝 8923113531 🔝 Cash Payment (COD) 👒
VIP Call Girls In Saharaganj ( Lucknow  ) 🔝 8923113531 🔝  Cash Payment (COD) 👒VIP Call Girls In Saharaganj ( Lucknow  ) 🔝 8923113531 🔝  Cash Payment (COD) 👒
VIP Call Girls In Saharaganj ( Lucknow ) 🔝 8923113531 🔝 Cash Payment (COD) 👒
 
Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...
Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...
Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...
 
Forklift Operations: Safety through Cartoons
Forklift Operations: Safety through CartoonsForklift Operations: Safety through Cartoons
Forklift Operations: Safety through Cartoons
 
B.COM Unit – 4 ( CORPORATE SOCIAL RESPONSIBILITY ( CSR ).pptx
B.COM Unit – 4 ( CORPORATE SOCIAL RESPONSIBILITY ( CSR ).pptxB.COM Unit – 4 ( CORPORATE SOCIAL RESPONSIBILITY ( CSR ).pptx
B.COM Unit – 4 ( CORPORATE SOCIAL RESPONSIBILITY ( CSR ).pptx
 
Value Proposition canvas- Customer needs and pains
Value Proposition canvas- Customer needs and painsValue Proposition canvas- Customer needs and pains
Value Proposition canvas- Customer needs and pains
 
KYC-Verified Accounts: Helping Companies Handle Challenging Regulatory Enviro...
KYC-Verified Accounts: Helping Companies Handle Challenging Regulatory Enviro...KYC-Verified Accounts: Helping Companies Handle Challenging Regulatory Enviro...
KYC-Verified Accounts: Helping Companies Handle Challenging Regulatory Enviro...
 

Business Continuity Management or Risk Management? Aligning Expectations for Business Strategies by Dr Goh Moh Heng

  • 2. Navigating Through Uncertainties of Risk Dr Goh Moh Heng PhD BCCE DRCE BCCLA President 2
  • 3. BCM Institute Started in January 2005. Provide competency based BC-DR training to all levels. Certify BC-DR professionals globally. Started Certification programme in April 2007. More than 1500 professionals from 850 organizations and 40 countries.
  • 4. Professional Certification Business Continuity IT Disaster Recovery BCM Audit Membership
  • 5. Business Continuity Management or Risk Management? Aligning Expectations for Business Strategies Dr. Goh Moh Heng PhD BCCE DRCE BCCLAPresident, BCM Institute and Managing Director, GMH Continuity Architects
  • 6. Agenda BC Planning Methodology Risk Analysis and Review Risk Assessment Process Step-by-stepAchieving Certification
  • 7. BCM Planning Methodology Source: Goh, Moh Heng (2008): Analyzing and Review the Risk for Business Continuity Planning ISBN: 978-981-05-9215-8
  • 9.
  • 10.
  • 11. Identify Threats Man-Made Toxic and radioactive contamination Sabotage (both external and internal) Riot, civil disorder and coup Fraud and embezzlement Accidental explosion (on and offsite) Water leak and plumbing failure Workplace violence Terrorism Aircraft crash Vandalism Arson Physical asset theft Misuse of resources Building and physical security weakness Fire Natural Tornado (wind storm) Thunderstorm and hail storm Lightning and electrical storm Snow and winter ice storm Typhoon and hurricane Flood and other water-based incident Earthquake Mudslide Volcanic eruption and ash fallout Tsunami Large natural fire Epidemic and pandemic
  • 12. Identify Threats Business Power outage Labor dispute Employee turnover and single point of failure Unavailability of key personnel Human error Gas outage Water outage Loss of transportation Single source suppliers Information Technology Voice and data telecommunication failure IT equipment failure Human error from programmers and users Security vulnerability Data and software sabotage In-house developed application failure HVAC failure Defective software
  • 13. Analyse Risks Estimate the risk likelihood of occurrence Identify risk impact of the threat materializing Determine risk (rating) level
  • 16. Risk Analysis Process Controls What is cost for the Controls to be implemented? What Controls are in place? Risk Rating What is the potential loss exposures to business? How does the threat affect business operations? What is the likelihood that the threat will adversely affect business operations? Threats Risk Likelihood What is the effects on people, infrastructure, facilities, and systems? Risk Impact What are the adverse events that can occur?
  • 17. Risk Evaluation Assess Risk Rating and prioritized for further treatment
  • 20. Evaluation Criteria Criteria Examples: People Processes Infrastructure Weighting for different criteria
  • 21. Risk Treatment Explore Risk Treatment Strategies for risks deemed unacceptable Document reasons for selection of strategy for each risk treatment
  • 22. Risk Analysis Process Controls What is cost for the Controls to be implemented? What Controls are in place? What risk treatment? Risk Rating What is the potential loss exposures to business? How does the threat affect business operations? What is the likelihood that the threat will adversely affect business operations? Threats Risk Likelihood What is the effects on people, infrastructure, facilities, and systems? Risk Impact What are the adverse events that can occur?
  • 23. Risk Treatment Strategies Risk Acceptance Risk Avoidance Risk Transfer Risk Reduction
  • 24. Risk Treatment Strategies Transfer Avoid Reduce / Active Control Reduce (if Cost Justifiable) Accept
  • 25. Risk Reduction Fire Pandemic Business Continuity Plan (BCP)
  • 26. Risk Analysis and Business Continuity Planning Process Risk Treatment Strategies Treatment for risks that could potentially interrupt business operations
  • 28. Implement & Monitor Present Recommendations to management for approval Implement recommendations Monitor results Adjust as necessary
  • 30.
  • 31. THANK YOU Dr Goh Moh Heng President Mobile: +65 96711022 Tel: +65 63231500 Fax: +65 63230933 Email: moh_heng@bcm-institute.org

Notas do Editor

  1. BCM Institute Leading global Business Continuity (BC) & Disaster Recovery (D R) Institute. Established in 2005. Offers a wide range of quality BC and DR courses. Certified over 1,250 professionals from 36 countries.
  2. This table is a guide on the severity of the impact caused by the threat that occurred.