RM RISK ANALYSIS
is to comprehend the nature of risk and its characteristics, where appropriate, the level of risk.
Risk analysis
It involves a detailed consideration of uncertainties, risk sources, consequences, likelihood, events, scenarios, controls, and their effectiveness.
Risk Assessment and Risk Analysis
Analysis techniques can be................
qualitative, quantitative
is based on a person's perception or judgement while;
QUALITATIVE RISK ANALYSIS
is based on verified and specific data.
QUANTITATIVE RISK ANALYSIS
is the process of evaluating and rating an identified risk based on its severity and the likelihood of its consequences.
Qualitative Risk Analysis
The goal is to come up with a short list of risks that need to be prioritized above others
Qualitative Risk Analysis
This is achieved by using what’s already known to predict or estimate an outcome.
Quantitative Risk Analysis
The goal is to further specify how much will the impact of the risk cost the business.
Quantitative Risk Analysis
This is achieved by using what’s already known to predict or estimate an outcome.
Quantitative Risk Analysis
Risk Analysis should consider factors such as:
• the likelihood of events and consequences;
• the nature and magnitude of consequences;
• complexity and connectivity;
• time-related factors and volatility;
• the effectiveness of existing controls; and
• sensitivity and confidence levels.
THE RISK ANALYSIS MAY BE INFLUENCED BY:
Divergence of opinions
Biases
Perception of risk
Judgements
prejudice in favor of or against one thing, person, or group compared with another
Biases
stating the difference between two or more things, attitudes, or opinions.
Divergence of opinions
the ability to make considered decisions or come to sensible (practical) conclusions.
Judgements
refers to people's beliefs, attitudes, judgments, and feelings toward risk, and more.
Perception of risk
and on the most appropriate risk treatment strategy and methods.
Risk analysis
decisions on whether risk needs to be treated and how
Risk analysis
provides an input to risk evaluation
Risk analysis
He defined threat assessment as consideration for the full spectrum of threats i.e., (natural,criminal, terrorist, accidental) for a given facility/location.
Renfroe and smith 2016
is a function of the values of threat, consequence, and vulnerability
Risk
Must be performed to consider the potential impact of loss from a successful attack and vulnerability of the facility, location, or event to an attack.
VULNERABILITY ASSESSMENT
Include Detailed analysis of the potential impact of loss from an explosive, chemical, or biological attack.
VULNERABILITY ASSESSMENT
The number of visitors to other facilities in the organization may be reduced by up to 75% for a limited period of time.
DEVASTATING
Most items/assets are lost, destroyed, or damaged beyond
DEVASTATING
The facility is beyond habitable damaged/contaminated use.
DEVASTATING
The number of visitors to this and other facilities in the organization may be reduced by up to 50% for a limited period of time
SEVERE
Some assets may need to be moved to remote locations to protect them from environmental damage.
SEVERE
The facility is partially damaged/contaminated.
SEVERE
Some items/assets in the facility are damaged beyond repair, but the facility remains mostly intact.
SEVERE
The number of visitors to this and other facilities in the organization may be reduced by up to 25% for a limited period of time.
NOTICEABLE
A limited number of assets may be damaged, but the majority of the facility is not affected
NOTICEABLE
The facility is temporarily closed or unable to operate, but can continue without an interruption of more than one day.
NOTICEABLE
The facility experiences no significant impact on operations (downtime is less than four hours) and there is no loss of major assets
Minor
is defined to be a combination of the attractiveness of a facility or an event as a target and the level of deterrence and/or defense provided by the existing countermeasures.
Vulnerability
vulnerability ratings
Very high
High
Moderate
Low
This is a high profile facility that provides a very attractive target for potential adversaries, and the level of defense provided by the existing countermeasures are inadequate
very high
This is a moderate profile facility that provides a attractive target and the level of defense provided by the existing countermeasures is inadequate.
High
This is not a high profile facility and provides a possible and/or target and/or the level of deterrence defense provided by the existing countermeasures is adequate
low
that provides a potential target and/or the level of deterrence and/or defense provided by the existing countermeasures is marginally adequate.
Moderate