<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-3876764696528253614</id><updated>2011-11-27T17:51:11.306-08:00</updated><title type='text'>Risk Assessment</title><subtitle type='html'></subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://conducting-a-risk-assessment.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3876764696528253614/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://conducting-a-risk-assessment.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>Mike</name><uri>http://www.blogger.com/profile/00059352031471383336</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>1</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-3876764696528253614.post-3799014884240869890</id><published>2007-03-16T05:24:00.000-07:00</published><updated>2007-03-17T10:00:54.448-07:00</updated><title type='text'>Conducting a Risk Assessment</title><content type='html'>&lt;p class="MsoNormal" style="text-align: justify;"&gt;A Risk Assessment is identifying, analyzing, and weighing all the potential risks, threats and hazards to the business’s internal and external environment.&lt;span style=""&gt;  &lt;/span&gt;It discovers if a facility (building) is vulnerable to weather related events, HVAC failure, Internal/External Security vulnerabilities and local area hazards.&lt;span style=""&gt;  &lt;/span&gt;It allows a business to document what mitigating actions have been taken to manage these exposures.&lt;span style=""&gt;  &lt;/span&gt;By identifying the threats that currently are being mitigated verses threats that are not, a business can compile a list of recommendations for improvement.&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;    &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;To be successful, any risk assessment has to concentrate on the local identifiable issues relating to the business.&lt;span style=""&gt;  &lt;/span&gt;Before exploring other concerns, concentrate on the most realistic risks and threats that currently exist in the business environment.&lt;span style=""&gt;  &lt;/span&gt;This can include factors such as:&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;!--[if !supportLists]--&gt;&lt;span style="font-family:Symbol;"&gt;&lt;span style=""&gt;&lt;span style=";font-family:&amp;quot;;font-size:7;"  &gt;        &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;The Nature of the Business&lt;o:p&gt;&lt;/o:p&gt;&lt;/li&gt;&lt;li&gt;&lt;!--[if !supportLists]--&gt;&lt;span style="font-family:Symbol;"&gt;&lt;span style=""&gt;&lt;span style=";font-family:&amp;quot;;font-size:7;"  &gt;        &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;Surrounding Area of Facility&lt;o:p&gt;&lt;/o:p&gt;&lt;/li&gt;&lt;li&gt;&lt;!--[if !supportLists]--&gt;&lt;span style="font-family:Symbol;"&gt;&lt;span style=""&gt;&lt;span style=";font-family:&amp;quot;;font-size:7;"  &gt;        &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;The Construction of the Facility&lt;o:p&gt;&lt;/o:p&gt;&lt;/li&gt;&lt;li&gt;&lt;!--[if !supportLists]--&gt;&lt;span style="font-family:Symbol;"&gt;&lt;span style=""&gt;&lt;span style=";font-family:&amp;quot;;font-size:7;"  &gt;        &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;Common Weather Patterns&lt;/li&gt;&lt;li&gt;&lt;!--[if !supportLists]--&gt;&lt;span style="font-family:Symbol;"&gt;&lt;span style=""&gt;&lt;span style=";font-family:&amp;quot;;font-size:7;"  &gt;        &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;Technology Dependencies&lt;/li&gt;&lt;/ul&gt;          &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;  &lt;h2&gt;&lt;a name="_Toc130606448"&gt;&lt;/a&gt;&lt;a name="_Toc125953069"&gt;&lt;/a&gt;&lt;a name="_Toc125625149"&gt;&lt;span style=""&gt;&lt;span style=""&gt;&lt;b&gt;&lt;i&gt;&lt;u&gt;&lt;span style=";font-family:Arial;font-size:12;"  &gt;Objectives of the Risk Assessment&lt;/span&gt;&lt;/u&gt;&lt;/i&gt;&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;b&gt;&lt;i&gt;&lt;u&gt;&lt;span style=";font-family:Arial;font-size:12;"  &gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/i&gt;&lt;/b&gt;&lt;/h2&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-size:11;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;During the Risk Assessment, risks to the business will be identified and evaluated.&lt;span style=""&gt;  &lt;/span&gt;The vulnerability of the business to these risks will be rated.&lt;span style=""&gt;  &lt;/span&gt;You will also:&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;  &lt;ul&gt;&lt;li&gt;&lt;!--[if !supportLists]--&gt;&lt;span style="font-family:Symbol;"&gt;&lt;span style=""&gt;&lt;span style=";font-family:&amp;quot;;font-size:7;"  &gt;        &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;Identify what prevention practices are being used&lt;o:p&gt;&lt;/o:p&gt;&lt;/li&gt;&lt;li&gt;&lt;!--[if !supportLists]--&gt;&lt;span style="font-family:Symbol;"&gt;&lt;span style=""&gt;&lt;span style=";font-family:&amp;quot;;font-size:7;"  &gt;        &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;Define and implement safeguards to mitigate risks&lt;o:p&gt;&lt;/o:p&gt;&lt;/li&gt;&lt;li&gt;&lt;!--[if !supportLists]--&gt;&lt;span style="font-family:Symbol;"&gt;&lt;span style=""&gt;&lt;span style=";font-family:&amp;quot;;font-size:7;"  &gt;        &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;Conclude the overall risk to the business&lt;o:p&gt;&lt;/o:p&gt;&lt;/li&gt;&lt;li&gt;&lt;!--[if !supportLists]--&gt;&lt;span style="font-family:Symbol;"&gt;&lt;span style=""&gt;&lt;span style=";font-family:&amp;quot;;font-size:7;"  &gt;        &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;Build a case for strategy selections&lt;o:p&gt;&lt;/o:p&gt;&lt;/li&gt;&lt;/ul&gt;        &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;Once the assessment is completed, a business can make decisions regarding methods of mitigating risks.&lt;span style=""&gt;  &lt;/span&gt;By completing a Risk Assessment and Business Impact Analysis, a business can implement the best strategies for Contingency Planning.&lt;span style=""&gt;  &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;  &lt;h2&gt;&lt;a name="_Toc130606449"&gt;&lt;/a&gt;&lt;a name="_Toc125953070"&gt;&lt;span style=""&gt;&lt;b&gt;&lt;i&gt;&lt;u&gt;&lt;span style=";font-family:Arial;font-size:12;"  &gt;Risk Assessment Process&lt;/span&gt;&lt;/u&gt;&lt;/i&gt;&lt;/b&gt;&lt;/span&gt;&lt;/a&gt;&lt;b&gt;&lt;i&gt;&lt;u&gt;&lt;span style=";font-family:Arial;font-size:12;"  &gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/i&gt;&lt;/b&gt;&lt;/h2&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-size:14;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;Despite the prevention practices utilized, potential hazards that are existent and could result in a loss to the business need to be considered.&lt;span style=""&gt;  &lt;/span&gt;Even though the exact nature of these exposures and their consequences are tough to determine, it is valuable to conduct a risk assessment of all threats that can logically happen. &lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;a name="_Toc125953072"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/a&gt;&lt;/p&gt;  &lt;h2&gt;&lt;span style=""&gt;&lt;a name="_Toc130606450"&gt;&lt;b&gt;&lt;i&gt;&lt;u&gt;&lt;span style=";font-family:Arial;font-size:12;"  &gt;What should be included?&lt;/span&gt;&lt;/u&gt;&lt;/i&gt;&lt;/b&gt;&lt;/a&gt;&lt;/span&gt;&lt;b&gt;&lt;i&gt;&lt;u&gt;&lt;span style=";font-family:Arial;font-size:12;"  &gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/i&gt;&lt;/b&gt;&lt;/h2&gt;  &lt;p class="MsoBodyText"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;All locations and facilities should be included in the risk assessment.&lt;span style=""&gt;  &lt;/span&gt;Surrounding businesses, local fire, police, and community utilities should also be included in the assessment.&lt;span style=""&gt;  &lt;/span&gt;Any vendor provided service that is provided to the business should also be evaluated.&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;  &lt;h2&gt;&lt;a name="_Toc130606451"&gt;&lt;/a&gt;&lt;a name="_Toc125953073"&gt;&lt;span style=""&gt;&lt;b&gt;&lt;i&gt;&lt;u&gt;&lt;span style=";font-family:Arial;font-size:12;"  &gt;Steps to Follow&lt;/span&gt;&lt;/u&gt;&lt;/i&gt;&lt;/b&gt;&lt;/span&gt;&lt;/a&gt;&lt;b&gt;&lt;i&gt;&lt;u&gt;&lt;span style=";font-family:Arial;font-size:12;"  &gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/i&gt;&lt;/b&gt;&lt;/h2&gt;  &lt;p class="MsoBodyText"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;The following steps are necessary for completing a Risk Assessment.&lt;span style=""&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;span style=""&gt;Identify Threats/ Risk      and Vulnerabilities&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;span style=""&gt;&lt;br /&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=""&gt;Analyze risks and      determine vulnerability&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;span style=""&gt;&lt;br /&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=""&gt;Identify mitigation      and recovery options&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;span style=""&gt;&lt;br /&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=""&gt;Evaluate and Choose      Options &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;span style=""&gt;&lt;br /&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=""&gt;Evaluate and Choose      Options &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;      &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;There are additional steps that need to take place during this process.&lt;span style=""&gt;  &lt;/span&gt;Some of those actions are:&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;  &lt;ul&gt;&lt;li&gt;&lt;!--[if !supportLists]--&gt;&lt;span style="font-family:Symbol;"&gt;&lt;span style=""&gt;&lt;span style=";font-family:&amp;quot;;font-size:7;"  &gt;        &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;Review Internal Plans and Policies&lt;o:p&gt;&lt;/o:p&gt;&lt;/li&gt;&lt;li&gt;&lt;!--[if !supportLists]--&gt;&lt;span style="font-family:Symbol;"&gt;&lt;span style=""&gt;&lt;span style=";font-family:&amp;quot;;font-size:7;"  &gt;        &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;Meet with Outside Groups&lt;o:p&gt;&lt;/o:p&gt;&lt;/li&gt;&lt;li&gt;&lt;!--[if !supportLists]--&gt;&lt;span style="font-family:Symbol;"&gt;&lt;span style=""&gt;&lt;span style=";font-family:&amp;quot;;font-size:7;"  &gt;        &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;Identify Assets&lt;o:p&gt;&lt;/o:p&gt;&lt;/li&gt;&lt;li&gt;&lt;!--[if !supportLists]--&gt;&lt;span style="font-family:Symbol;"&gt;&lt;span style=""&gt;&lt;span style=";font-family:&amp;quot;;font-size:7;"  &gt;        &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;Conduct an Insurance Review&lt;o:p&gt;&lt;/o:p&gt;&lt;/li&gt;&lt;/ul&gt;        &lt;div  style="border-style: none none double; padding: 0in 0in 1pt;color:-moz-use-text-color -moz-use-text-color windowtext;"&gt;  &lt;h1 style="border: medium none ; padding: 0in; text-align: right;" align="right"&gt;&lt;a name="_Toc130606452"&gt;&lt;b&gt;&lt;span style=";font-family:Arial;font-size:14;color:#000000;"   &gt;Assessing Your Risk&lt;/span&gt;&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;span style=";font-family:Arial;font-size:14;color:#000000;"   &gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/h1&gt;  &lt;/div&gt;  &lt;p class="MsoBodyText" style="text-align: justify;"&gt;&lt;a name="_Toc125953074"&gt;The process of identifying risks/threats, probability of occurrence, the vulnerability to each risk/threat and the potential impact that could be caused, is necessary to prepare preventative measures and create recovery strategies.&lt;span style=""&gt;  &lt;/span&gt;Risk identification also provides a number of other advantages including:&lt;o:p&gt;&lt;/o:p&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 1in; text-align: justify;"&gt;&lt;span style=""&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;ul&gt;&lt;li&gt;&lt;span style=""&gt;&lt;!--[if !supportLists]--&gt;&lt;span style="font-family:Symbol;"&gt;&lt;span style=""&gt;&lt;span style=";font-family:&amp;quot;;font-size:7;"  &gt;        &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;Exposes previously overlooked vulnerabilities that need to be addressed by plans and procedures&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=""&gt;&lt;!--[if !supportLists]--&gt;&lt;span style="font-family:Symbol;"&gt;&lt;span style=""&gt;&lt;span style=";font-family:&amp;quot;;font-size:7;"  &gt;        &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;Identifies where preventative measures are lacking or need reevaluated&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=""&gt;&lt;!--[if !supportLists]--&gt;&lt;span style="font-family:Symbol;"&gt;&lt;span style=""&gt;&lt;span style=";font-family:&amp;quot;;font-size:7;"  &gt;        &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;Can point out the importance of contingency planning to get staff and management on board&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=""&gt;&lt;!--[if !supportLists]--&gt;&lt;span style="font-family:Symbol;"&gt;&lt;span style=""&gt;&lt;span style=";font-family:&amp;quot;;font-size:7;"  &gt;        &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;Will assist in documenting interdependencies between departments and increase communication between internal groups.&lt;span style=""&gt;  &lt;/span&gt;Can also point out single points of failures between critical departments&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;        &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style=""&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style=""&gt;For the ease of this process, categories of risk should be created to focus the thought process.&lt;span style=""&gt;  &lt;/span&gt;In the Risk Assessment Survey, the main categories include, Natural Risks, Man-Made (Human) Risks, and Environmental Risks. These are certainly not requirements, and should not be considered to be constraining.&lt;span style=""&gt;  &lt;/span&gt;&lt;/span&gt;&lt;/p&gt;  &lt;span style=""&gt;&lt;/span&gt;  &lt;h2&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/h2&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;The nature of a risk/threat should be determined, regardless of the type.&lt;span style=""&gt;  &lt;/span&gt;Factors to consider should include (but not limited to):&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;  &lt;ul&gt;&lt;li&gt;&lt;!--[if !supportLists]--&gt;&lt;span style="font-family:Symbol;"&gt;&lt;span style=""&gt;&lt;span style=";font-family:&amp;quot;;font-size:7;"  &gt;        &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;Geographic Location&lt;o:p&gt;&lt;/o:p&gt;&lt;/li&gt;&lt;li&gt;&lt;!--[if !supportLists]--&gt;&lt;span style="font-family:Symbol;"&gt;&lt;span style=""&gt;&lt;span style=";font-family:&amp;quot;;font-size:7;"  &gt;        &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;Weather Patterns for the Area and Surrounding Areas&lt;o:p&gt;&lt;/o:p&gt;&lt;/li&gt;&lt;li&gt;&lt;!--[if !supportLists]--&gt;&lt;span style="font-family:Symbol;"&gt;&lt;span style=""&gt;&lt;span style=";font-family:&amp;quot;;font-size:7;"  &gt;        &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;Internal Hazards (HVAC, Facility Security, Access, etc)&lt;o:p&gt;&lt;/o:p&gt;&lt;/li&gt;&lt;li&gt;&lt;!--[if !supportLists]--&gt;&lt;span style="font-family:Symbol;"&gt;&lt;span style=""&gt;&lt;span style=";font-family:&amp;quot;;font-size:7;"  &gt;        &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;Proximity to Local Response/Support Units&lt;o:p&gt;&lt;/o:p&gt;&lt;/li&gt;&lt;li&gt;&lt;!--[if !supportLists]--&gt;&lt;span style="font-family:Symbol;"&gt;&lt;span style=""&gt;&lt;span style=";font-family:&amp;quot;;font-size:7;"  &gt;        &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;External Hazards (neighboring Highways, Plants, etc)&lt;o:p&gt;&lt;/o:p&gt;&lt;/li&gt;&lt;/ul&gt;          &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;Potential exposures may be classified as: &lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;  &lt;ul&gt;&lt;li&gt;&lt;!--[if !supportLists]--&gt;&lt;span style="font-family:Symbol;"&gt;&lt;span style=""&gt;&lt;span style=";font-family:&amp;quot;;font-size:7;"  &gt;        &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;Natural Threats&lt;o:p&gt;&lt;/o:p&gt;&lt;/li&gt;&lt;li&gt;&lt;!--[if !supportLists]--&gt;&lt;span style="font-family:Symbol;"&gt;&lt;span style=""&gt;&lt;span style=";font-family:&amp;quot;;font-size:7;"  &gt;        &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;Man-made (human) Threats&lt;o:p&gt;&lt;/o:p&gt;&lt;/li&gt;&lt;li&gt;&lt;!--[if !supportLists]--&gt;&lt;span style="font-family:Symbol;"&gt;&lt;span style=""&gt;&lt;span style=";font-family:&amp;quot;;font-size:7;"  &gt;        &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;Environmental Threats&lt;o:p&gt;&lt;/o:p&gt;&lt;/li&gt;&lt;/ul&gt;      &lt;h2&gt;&lt;a name="_Toc130606454"&gt;&lt;b&gt;&lt;i&gt;&lt;u&gt;&lt;span style=";font-family:Arial;font-size:12;"  &gt;&lt;o:p&gt;&lt;span style="text-decoration: none;"&gt; &lt;/span&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/i&gt;&lt;/b&gt;&lt;/a&gt;&lt;/h2&gt;  &lt;span style=""&gt;&lt;/span&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;Other steps in conducting Risk Assessment are to review following points:&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;  &lt;ul style="margin-top: 0in;" type="disc"&gt;&lt;li class="MsoNormal" style=""&gt;Probability      of Occurrence&lt;o:p&gt;&lt;/o:p&gt;&lt;/li&gt;&lt;li class="MsoNormal" style=""&gt;&lt;a name="_Toc130606455"&gt;Vulnerability to Risk&lt;/a&gt;&lt;/li&gt;&lt;li class="MsoNormal" style=""&gt;&lt;a name="_Toc130606456"&gt;Potential Impact&lt;/a&gt; &lt;/li&gt;&lt;li class="MsoNormal" style=""&gt;&lt;a name="_Toc130606457"&gt;Preventative Measures in Place&lt;/a&gt;&lt;/li&gt;&lt;li class="MsoNormal" style=""&gt;&lt;a name="_Toc130606458"&gt;Insurance Coverage&lt;/a&gt;&lt;/li&gt;&lt;li class="MsoNormal" style=""&gt;&lt;a name="_Toc130606459"&gt;Past Experiences&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;  &lt;p class="MsoNormal"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;  &lt;div  style="border-style: none none double; padding: 0in 0in 1pt;color:-moz-use-text-color -moz-use-text-color windowtext;"&gt;  &lt;h1 style="border: medium none ; padding: 0in; text-align: right;" align="right"&gt;&lt;a name="_Toc130606460"&gt;&lt;b&gt;&lt;span style=";font-family:Arial;font-size:14;color:#000000;"   &gt;Analyzing the Results&lt;/span&gt;&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;span style=";font-family:Arial;font-size:14;color:#000000;"   &gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/h1&gt;  &lt;/div&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;b style=""&gt;Analyzing the Results&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;Once the Risk Assessment Survey(s) and face to face interviews have been conducted, the next step is to analyze and present the results so that Executive Management can get most use of the data.&lt;span style=""&gt;  &lt;/span&gt;Analysis can be a time-consuming and tedious process, especially with an enormous amount of data, but it is critical to the RA process. &lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;The analysis will be the foundation for planning recommendations to senior management.&lt;span style=""&gt;  &lt;/span&gt;The recovery strategies that need to be developed should be based on the findings of the Risk Assessment Survey and interviews, as well as the Business Impact Analysis findings&lt;span style="letter-spacing: -0.25pt;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;  &lt;div  style="border-style: none none double; padding: 0in 0in 1pt;color:-moz-use-text-color -moz-use-text-color windowtext;"&gt;  &lt;h1 style="border: medium none ; padding: 0in; text-align: right;" align="right"&gt;&lt;a name="_Toc130606464"&gt;&lt;b&gt;&lt;span style=";font-family:Arial;font-size:14;color:#000000;"   &gt;Final Report &amp; Presentation&lt;/span&gt;&lt;/b&gt;&lt;/a&gt;&lt;span style=""&gt;&lt;/span&gt;&lt;span style=";font-family:Arial;font-size:14;"  &gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/h1&gt;  &lt;/div&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;Begin your final report with an executive overview of the Risk Assessment Project.&lt;span style=""&gt;  &lt;/span&gt;This will explain the objectives of the project, what was in scope, and what approach was used.&lt;span style=""&gt;  &lt;/span&gt;Then provide a summary review of potential hazards.&lt;span style=""&gt;  &lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoBodyText"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;  &lt;h2&gt;&lt;a name="_Toc125953092"&gt;&lt;/a&gt;&lt;a name="_Toc130606465"&gt;&lt;span style=""&gt;&lt;b&gt;&lt;i&gt;&lt;u&gt;&lt;span style=";font-family:Arial;font-size:12;"  &gt;Creation of Executive Report&lt;/span&gt;&lt;/u&gt;&lt;/i&gt;&lt;/b&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style=""&gt;&lt;b&gt;&lt;i&gt;&lt;u&gt;&lt;span style=";font-family:Arial;font-size:12;"  &gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/i&gt;&lt;/b&gt;&lt;/span&gt;&lt;/h2&gt;  &lt;p class="MsoNormal"&gt;&lt;span style=""&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style=""&gt;The findings from the Risk Assessment will form the basis for the final report.&lt;span style=""&gt;  &lt;/span&gt;The purpose is to provide senior management with enough information to make them comfortable in endorsing the recommending strategies, actions, budgets or to accept the level of risk by not implementing recovery strategies.&lt;span style=""&gt;  &lt;/span&gt;The report should include graphs, which visually demonstrate the findings.&lt;span style=""&gt;  &lt;/span&gt;Do not overuse the graphs.&lt;span style=""&gt;  &lt;/span&gt;Too many graphs and reports can make reviewing the information confusing.&lt;span style=""&gt;  &lt;/span&gt;Provide graphs for overall information on the departments, financial impact, etc.&lt;span style=""&gt;  &lt;/span&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style=""&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style=""&gt;The final report should include:&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style=""&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;ul style="margin-top: 0in;" type="disc"&gt;&lt;li class="MsoNormal" style=""&gt;&lt;span style=""&gt;Previous Disruption History&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style=""&gt;&lt;span style=""&gt;Risks &amp; Vulnerabilities&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style=""&gt;&lt;span style=""&gt;Preventative Measures&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;a name="_Toc130606466"&gt;Presenting the      Results&lt;/a&gt;&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/li&gt;&lt;li class="MsoNormal" style=""&gt;&lt;a name="_Toc130606467"&gt;&lt;/a&gt;&lt;a name="_Toc128226299"&gt;&lt;span style=""&gt;Next Steps&lt;/span&gt;&lt;/a&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/li&gt;&lt;/ul&gt;  &lt;p class="MsoNormal"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;The Risk Assessment process is an essential phase of Continuity Planning.&lt;span style=""&gt;  &lt;/span&gt;The possibility of a disaster impacting a business is unpredictable.&lt;span style=""&gt;  &lt;/span&gt;The business should implement a comprehensive Continuity Planning Program and develop recovery plans that encompass all critical operations and functions of the business.&lt;span style=""&gt;                                                  &lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;It is recommended the use the templates to jump start your Risk Assessment project. Benefits of using templates:&lt;/p&gt;  &lt;ul style="margin-top: 0in;" type="disc"&gt;&lt;li class="MsoNormal" style=""&gt;It      saves a lot of time and money for user&lt;/li&gt;&lt;li class="MsoNormal" style=""&gt;You      don't have to reinvent the wheel&lt;/li&gt;&lt;li class="MsoNormal" style=""&gt;Consistent      look and feel&lt;/li&gt;&lt;li class="MsoNormal" style=""&gt;Can      be easily edited to insert information and fine tune to meet organizations      specific requirements.&lt;/li&gt;&lt;/ul&gt;  &lt;p class="MsoNormal"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;Risk Assessment is the first step towards creating the Disaster recovery and Business Continuity plans. Organizations can use following templates for their projects:&lt;/p&gt;  &lt;p class="MsoNormal"&gt;Risk Assessment: &lt;a href="http://www.training-hipaa.net/template_suite/Risk_assessment_bundle-data_analysis_policies.htm"&gt;http://www.training-hipaa.net/template_suite/Risk_assessment_bundle-data_analysis_policies.htm&lt;/a&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;Business Impact Analysis (BIA): &lt;a href="http://www.training-hipaa.net/template_suite/Business_impact_analysis_bundle_policies.htm"&gt;http://www.training-hipaa.net/template_suite/Business_impact_analysis_bundle_policies.htm&lt;/a&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;st1:place&gt;&lt;st1:placename&gt;Data&lt;/st1:placename&gt; &lt;st1:placetype&gt;Center&lt;/st1:placetype&gt;&lt;/st1:place&gt; Recovery Plan:&lt;span style=""&gt;  &lt;/span&gt;&lt;a href="http://www.training-hipaa.net/template_suite/data_center_template_bundles.htm"&gt;http://www.training-hipaa.net/template_suite/data_center_template_bundles.htm&lt;/a&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;Disaster Recovery &amp; Business Continuity Plan: &lt;a href="http://www.training-hipaa.net/template_suite/Disaster_recovery_plan_template_sample.htm"&gt;http://www.training-hipaa.net/template_suite/Disaster_recovery_plan_template_sample.htm&lt;/a&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b style=""&gt;&lt;span style="font-size:14;"&gt;Key Terminology&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b style=""&gt;&lt;span style=""&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;There can be terminology and definition differences in regards to risk assessment, business impact analysis, hazards, risks, etc.&lt;span style=""&gt;   &lt;/span&gt;For the intent of this document, please apply the following definitions:&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-size:11;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;b style=""&gt;&lt;i style=""&gt;&lt;u&gt;Business Impact Analysis:&lt;/u&gt;&lt;/i&gt;&lt;span style=""&gt;  &lt;/span&gt;&lt;/b&gt;Process of identifying the critical business functions within the business and determining the impact of not performing those business functions.&lt;span style=""&gt;  &lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;b style=""&gt;&lt;i style=""&gt;&lt;u&gt;Hazard/Threat:&lt;/u&gt;&lt;/i&gt;&lt;/b&gt;&lt;span style=""&gt;  &lt;/span&gt;A situation that has the potential to cause injury to people, damage the property or damage to the environment.&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;b style=""&gt;&lt;i style=""&gt;&lt;u&gt;Risk: &lt;/u&gt;&lt;/i&gt;&lt;/b&gt;&lt;span style=""&gt; &lt;/span&gt;Potential for exposure to loss.&lt;span style=""&gt;  &lt;/span&gt;Risks can be man-made, natural or technology related.&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;Benefits Of HIPAA&lt;/p&gt;  &lt;h2&gt;&lt;i style=""&gt;&lt;span style="font-size:16;"&gt;Overview:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/i&gt;&lt;/h2&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;b style=""&gt;&lt;i style=""&gt;&lt;u&gt;Risk Assessment:&lt;/u&gt;&lt;/i&gt;&lt;/b&gt;&lt;span style=""&gt;  &lt;/span&gt;Process of identifying and evaluating the hazards and risks that are present and analyzing the vulnerabilities of the business to these threats.&lt;span style=""&gt;   &lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;b style=""&gt;&lt;span style="font-size:16;"&gt;Benefits Of HIPAA&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;b style=""&gt;&lt;i style=""&gt;&lt;u&gt;Vulnerability:&lt;/u&gt;&lt;/i&gt;&lt;/b&gt;&lt;span style=""&gt;  &lt;/span&gt;Having an exposure to a hazard or risk.&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3876764696528253614-3799014884240869890?l=conducting-a-risk-assessment.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://conducting-a-risk-assessment.blogspot.com/feeds/3799014884240869890/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3876764696528253614&amp;postID=3799014884240869890' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3876764696528253614/posts/default/3799014884240869890'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3876764696528253614/posts/default/3799014884240869890'/><link rel='alternate' type='text/html' href='http://conducting-a-risk-assessment.blogspot.com/2007/03/conducting-risk-assessment.html' title='Conducting a Risk Assessment'/><author><name>Mike</name><uri>http://www.blogger.com/profile/00059352031471383336</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry></feed>
