SlideShare une entreprise Scribd logo
1  sur  21
Télécharger pour lire hors ligne
Contact us: info@alvinintegrated.com | +91 8802 505619, +91
8287509289 | www.alvinintegrated.com
Platinum Sponsor
OUR SPONSORS & PARTNERS
Event Partner
www.alvinintegrated.com
Knowledge Partners
27th FEB 2021
(SATURDAY)
09:00 AM - 17:30 PM IST
ISO 31000:2018 Risk
Management System,
Framework and
Implementation
27th February 2021 (Saturday)
Time: 09:05 am - 09:30 am IST
ISO 31000:2018 By Sanjay Gore, Principal Consultant,
Alvin Integrated Service [AIS]
Speaker Introduction:
Mr. Sanjay Gore hails from Pune, Maharashtra, India, is
a Senior Consultant and Speaker on Information Security, Risk Management and
Privacy.
He has rich experience of 20 years in working with customers in India, Middle East
at top management level, business owners and technical team members for
securing and deploying information security and risk management and privacy
solutions. He holds professional designations such as: ISO-27001-LA, ISO 27005-
RM, CDPSE CPISI, CRMA, CISA, and CRISC. He is certified Trainer in 27001
and 27005.
Connect at LinkedIn: Sanjay Gore – LinkedinProfile
Subscribe at YouTube: Sanjay Gore – youtubechannel
Mr Sanjay Gore
ISO-27001-LA, ISO 27005-
RM, CDPSE CPISI, CRMA,
CISA, and CRISC | Certified
Trainer in 27001 and 27005 |
Pune, Maharashtra – India
Risk Opportunity or Threat??
4
Threat
1. Find a way to avoid the risk
2. Find a way to transfer to another
party ( Insurance, Contract
conditions)
3. Find a way to mitigate the risk
reducing probability or severeness
Opportunity
1. Exploit the opportunity
2. Share with another party
3. Enhance by increasing the effect or the
probability
Accept
Do nothing
Risk
Edifice of ISO 31000:2018
ISO 31000:2018
The principles
provide the
foundation and
describe the qualities
of effective risk
management in an
organization
Principles
ISO 31000:2018
Framework
The framework
manages the overall
process and its full
integration into the
organization
ISO 31000:2018
Process
The process focuses
on individual or
groups of risks, their
identification,
analysis, evaluation
and treatment
5
ISO 31000:2018 Scope of Document
6
1. Managing risk faced by organizations.
2. The application of these guidelines can be customized on any organization and
its context.
3. This document provides a common approach to managing any type of risk and
is not industry or sector specific
4. This document can be used throughout the life of the organization and can be
applied to any activity, including decision making
ISO 31000 Concepts, Terms and Definitions-
7
1. Risk is an effect of uncertainty on objectives
2. An effect is a deviation from the expected.
3. It can be positive, negative or both, and can address, create or result in opportunities
and threats.
4. Objectives can have different aspects and categories, and can be applied at different
levels.
5. Risk is usually expressed in terms of
• Risk Sources
• Potential Events
• Their Consequences
• Their Likelihood
Risk
ISO 31000 Concepts, Terms and Definitions-
8
• Event occurrence or change of a particular set of circumstances
• An event can have one or more occurrences, and can have several
causes and several consequences
• An event can also be something that is expected which does not
happen, or something that is not expected which does happen.
• An event can be a risk source.
Event
ISO 31000 Concepts, Terms Definitions-
9
• Consequence is an outcome of an event affecting objectives
• A consequence can be certain or uncertain and can have positive
or negative direct or indirect effects on objectives.
• Consequences can be expressed qualitatively or quantitatively.
• Any consequence can escalate through cascading and cumulative
effects.
Consequence
ISO 31000 Concepts, Terms and Definitions-
10
• Likelihood is chance of something happening
• In risk management terminology, the word “likelihood” is used to refer to the
chance of something happening, whether defined, measured or determined
objectively or subjectively, qualitatively or quantitatively, and described using
general terms or mathematically (such as a probability or a frequency over a
given time period).
The English term “likelihood” does not have a direct equivalent in some languages; instead, the equivalent of the term
“probability” is often used. However, in English, “probability” is often narrowly interpreted as a mathematical term.
Therefore, in risk management terminology, “likelihood” is used with the intent that it should have the same broad
interpretation as the term “probability” has in many languages other than English.
Likelihood
ISO 31000 Concepts, Terms and Definitions-
11
Control measure that maintains and/or modifies risk
• Controls include, but are not limited to, any process, policy, device,
practice, or other conditions and/or actions which maintain and/or
modify risk.
• Controls may not always exert the intended or assumed modifying
effect.
Control
ISO 31000:2018 Risk Management Principles
12
1. Integrated
2. Structured and comprehensive
3. Customized
4. Inclusive
5. Dynamic
6. Best available information
7. Human and cultural factors
8. Continual improvement
Value Creation and Protection
Continuous improvement
Continuous improvement means that organizations are
in a constant state of driving process improvements.
This involves a focus on linear and incremental
improvement within existing processes.
Continual improvement
A continual improvement mean that organizations go
through process improvements in stages. Even and
these stages are separate by a period of time. This
period of time might be necessary to understand if the
improvements did actually help the bottom line! In
some cases, the results might take a while to come to
fruition.
Principles - Continual improvement
13
Risk Management Framework
1. Integration
2. Design
3. Implementation
4. Evaluation
5. Improvement
14
1
2
3
4
5
Leadership and
Commitment
Risk Management Process
15
Scope Context Criteria
Risk Treatment
Recording and Reporting
Communication
and
Consultation
Monitoring
and
Review
Risk Assessment
Risk
Identification
Risk
Analysis
Risk
Evaluation
Process Defining Scope
When planning the approach, considerations include
1. Objectives and decisions that need to be made
2. Outcomes expected from the steps to be taken in the process
3. Time, location, specific inclusions and exclusions
4. Appropriate risk assessment tools and techniques
5. Resources required, responsibilities and records to be kept
6. Relationships with other projects, processes and activities.
16
Process Defining Risk Criteria
To set risk criteria, the following should be considered
1. The nature and type of uncertainties that can affect outcomes and
objectives (both tangible and intangible)
2. How consequences (both positive and negative) and likelihood will
be defined and measured
3. Time-related factors
4. Consistency in the use of measurements
5. How the level of risk is to be determined
6. How combinations and sequences of multiple risks will be taken
into account
7. The organization’s capacity
17
Process Selection of Risk Treatment Options
Depending on the type of risk and its significance to the business,
management and the board may
1. Avoid- e.g., where feasible, choose not to implement certain activities
or processes that would incur risk (i.e., eliminate the risk by eliminating
the cause)
2. Mitigate lessen the probability or impact of the risk by defining,
implementing, and monitoring appropriate controls.
3. Transfer (deflect, or allocate}-e.g.; share risk with partners or transfer
via insurance coverage, contractual agreement, or other means.
4. Accept- formally acknowledge the existence of the risk and monitor it
18
A few Risk Assessment Tools/ Techniques
• Brainstorming
• Delphi Technique
• Checklists
• Root Cause Analysis
• Failure Mode Effect
Analysis (FMEA ) And
FMECA
• Fault Tree Analysis
(FTA)
• Hazard Analysis (PHA)
• Scenario analysis
• Layers of protection
analysis (LOPA)
• Decision Tree Analysis
• Monte Carlo simulation
19
Questions
are
Welcome!
Please give your feedbacks in
the chat box about the webinar.

Contenu connexe

Tendances

PECB Webinar: ISO 31000 - The Benchmark for Risk Management in uncertain times
PECB Webinar: ISO 31000 - The Benchmark for Risk Management in uncertain timesPECB Webinar: ISO 31000 - The Benchmark for Risk Management in uncertain times
PECB Webinar: ISO 31000 - The Benchmark for Risk Management in uncertain timesPECB
 
ISO 31000 risk management process
ISO 31000 risk management processISO 31000 risk management process
ISO 31000 risk management processMuizz Anibire
 
Sequence and interaction of qms processes
Sequence and interaction of qms processesSequence and interaction of qms processes
Sequence and interaction of qms processesJorge Torres
 
(5) integrated management system (ims)
(5) integrated management system (ims)(5) integrated management system (ims)
(5) integrated management system (ims)ThetSu2
 
PECB Webinar: ISO 31000 – Risk Management and how it can help an organization
PECB Webinar: ISO 31000 – Risk Management and how it can help an organizationPECB Webinar: ISO 31000 – Risk Management and how it can help an organization
PECB Webinar: ISO 31000 – Risk Management and how it can help an organizationPECB
 
ISO 45001 – Health & Safety International Standard
ISO 45001 – Health & Safety International StandardISO 45001 – Health & Safety International Standard
ISO 45001 – Health & Safety International StandardPECB
 
ISO 27001 - Information security user awareness training presentation - part 3
ISO 27001 - Information security user awareness training presentation - part 3ISO 27001 - Information security user awareness training presentation - part 3
ISO 27001 - Information security user awareness training presentation - part 3Tanmay Shinde
 
Best Practices in Auditing ISO/IEC 27001
Best Practices in Auditing ISO/IEC 27001Best Practices in Auditing ISO/IEC 27001
Best Practices in Auditing ISO/IEC 27001PECB
 
Iso 9001:2015 internal auditor Course
Iso 9001:2015  internal auditor Course Iso 9001:2015  internal auditor Course
Iso 9001:2015 internal auditor Course Atif Alhaj
 
ISO 9001: 2015 QUALITY MANAGEMENT SYSTEMS
ISO 9001: 2015 QUALITY MANAGEMENT SYSTEMSISO 9001: 2015 QUALITY MANAGEMENT SYSTEMS
ISO 9001: 2015 QUALITY MANAGEMENT SYSTEMSSubhendu Datta
 

Tendances (20)

Risk based thinking in ms iso 9001 2015
Risk based thinking in ms iso 9001 2015Risk based thinking in ms iso 9001 2015
Risk based thinking in ms iso 9001 2015
 
PECB Webinar: ISO 31000 - The Benchmark for Risk Management in uncertain times
PECB Webinar: ISO 31000 - The Benchmark for Risk Management in uncertain timesPECB Webinar: ISO 31000 - The Benchmark for Risk Management in uncertain times
PECB Webinar: ISO 31000 - The Benchmark for Risk Management in uncertain times
 
Iso 9001 2015
Iso 9001 2015 Iso 9001 2015
Iso 9001 2015
 
ISO 31000 risk management process
ISO 31000 risk management processISO 31000 risk management process
ISO 31000 risk management process
 
ISO 9001
ISO 9001ISO 9001
ISO 9001
 
Overview of ISO 19011:2018 Guidelines for Auditing Management Systems
Overview of ISO 19011:2018 Guidelines for Auditing Management SystemsOverview of ISO 19011:2018 Guidelines for Auditing Management Systems
Overview of ISO 19011:2018 Guidelines for Auditing Management Systems
 
ISO 27001_2022 What has changed 2.0 for ISACA.pdf
ISO 27001_2022 What has changed 2.0 for ISACA.pdfISO 27001_2022 What has changed 2.0 for ISACA.pdf
ISO 27001_2022 What has changed 2.0 for ISACA.pdf
 
ISO9001:2015 presentation
ISO9001:2015 presentationISO9001:2015 presentation
ISO9001:2015 presentation
 
Sequence and interaction of qms processes
Sequence and interaction of qms processesSequence and interaction of qms processes
Sequence and interaction of qms processes
 
(5) integrated management system (ims)
(5) integrated management system (ims)(5) integrated management system (ims)
(5) integrated management system (ims)
 
Iso 31000
Iso 31000Iso 31000
Iso 31000
 
PECB Webinar: ISO 31000 – Risk Management and how it can help an organization
PECB Webinar: ISO 31000 – Risk Management and how it can help an organizationPECB Webinar: ISO 31000 – Risk Management and how it can help an organization
PECB Webinar: ISO 31000 – Risk Management and how it can help an organization
 
IMS Training Presentation
IMS Training PresentationIMS Training Presentation
IMS Training Presentation
 
Risk based thinking
Risk based thinkingRisk based thinking
Risk based thinking
 
ISO 45001 – Health & Safety International Standard
ISO 45001 – Health & Safety International StandardISO 45001 – Health & Safety International Standard
ISO 45001 – Health & Safety International Standard
 
ISO 27001 - Information security user awareness training presentation - part 3
ISO 27001 - Information security user awareness training presentation - part 3ISO 27001 - Information security user awareness training presentation - part 3
ISO 27001 - Information security user awareness training presentation - part 3
 
Best Practices in Auditing ISO/IEC 27001
Best Practices in Auditing ISO/IEC 27001Best Practices in Auditing ISO/IEC 27001
Best Practices in Auditing ISO/IEC 27001
 
ISO 27001
ISO 27001ISO 27001
ISO 27001
 
Iso 9001:2015 internal auditor Course
Iso 9001:2015  internal auditor Course Iso 9001:2015  internal auditor Course
Iso 9001:2015 internal auditor Course
 
ISO 9001: 2015 QUALITY MANAGEMENT SYSTEMS
ISO 9001: 2015 QUALITY MANAGEMENT SYSTEMSISO 9001: 2015 QUALITY MANAGEMENT SYSTEMS
ISO 9001: 2015 QUALITY MANAGEMENT SYSTEMS
 

Similaire à ISO 31000:2018 Risk Management System, Framework and Implementation

Implementation of Enterprise Risk Management with ISO 31000 Risk Management S...
Implementation of Enterprise Risk Management with ISO 31000 Risk Management S...Implementation of Enterprise Risk Management with ISO 31000 Risk Management S...
Implementation of Enterprise Risk Management with ISO 31000 Risk Management S...PECB
 
#Contract Risk Audit# By SN panigrahi
#Contract Risk Audit# By SN panigrahi#Contract Risk Audit# By SN panigrahi
#Contract Risk Audit# By SN panigrahiSN Panigrahi, PMP
 
The IRM India- A Risk Management Standard
The IRM India- A Risk Management StandardThe IRM India- A Risk Management Standard
The IRM India- A Risk Management StandardThe IRM India
 
Management of risk introduction
Management of risk introductionManagement of risk introduction
Management of risk introductionSpyros Ktenas
 
Safety Inspections and Sample Safety Inspection.Health and safety training D...
Safety Inspections and Sample Safety Inspection.Health  and safety training D...Safety Inspections and Sample Safety Inspection.Health  and safety training D...
Safety Inspections and Sample Safety Inspection.Health and safety training D...Salman Jailani
 
Risk Management Toolkit
Risk Management ToolkitRisk Management Toolkit
Risk Management ToolkitPeterFranz6
 
ToTCOOP+i O3 o4 unit-9_final_version_en
ToTCOOP+i O3 o4 unit-9_final_version_enToTCOOP+i O3 o4 unit-9_final_version_en
ToTCOOP+i O3 o4 unit-9_final_version_enToTCOOPiTech
 
Risk management models - Core Consulting
Risk management models - Core ConsultingRisk management models - Core Consulting
Risk management models - Core ConsultingCORE Consulting
 
Corporate and Project Risk Management Toolkit
Corporate and Project Risk Management Toolkit Corporate and Project Risk Management Toolkit
Corporate and Project Risk Management Toolkit Aurelien Domont, MBA
 
Targeted Solutions BMS Profile
Targeted Solutions BMS ProfileTargeted Solutions BMS Profile
Targeted Solutions BMS ProfileLeon Geldenhuys
 
Pm0016 set-1
Pm0016 set-1Pm0016 set-1
Pm0016 set-1Paul Hunt
 
An introduction to finance
An introduction to financeAn introduction to finance
An introduction to financeRobert Reed
 
How to Create a Risk Profile for Your Organization: 10 Essential Steps
How to Create a Risk Profile for Your Organization: 10 Essential StepsHow to Create a Risk Profile for Your Organization: 10 Essential Steps
How to Create a Risk Profile for Your Organization: 10 Essential StepsCase IQ
 

Similaire à ISO 31000:2018 Risk Management System, Framework and Implementation (20)

Essay On Risk Management
Essay On Risk ManagementEssay On Risk Management
Essay On Risk Management
 
Implementation of Enterprise Risk Management with ISO 31000 Risk Management S...
Implementation of Enterprise Risk Management with ISO 31000 Risk Management S...Implementation of Enterprise Risk Management with ISO 31000 Risk Management S...
Implementation of Enterprise Risk Management with ISO 31000 Risk Management S...
 
#Contract Risk Audit# By SN panigrahi
#Contract Risk Audit# By SN panigrahi#Contract Risk Audit# By SN panigrahi
#Contract Risk Audit# By SN panigrahi
 
Iso 31000 presentation
Iso 31000 presentationIso 31000 presentation
Iso 31000 presentation
 
The IRM India- A Risk Management Standard
The IRM India- A Risk Management StandardThe IRM India- A Risk Management Standard
The IRM India- A Risk Management Standard
 
Management of risk introduction
Management of risk introductionManagement of risk introduction
Management of risk introduction
 
Safety Inspections and Sample Safety Inspection.Health and safety training D...
Safety Inspections and Sample Safety Inspection.Health  and safety training D...Safety Inspections and Sample Safety Inspection.Health  and safety training D...
Safety Inspections and Sample Safety Inspection.Health and safety training D...
 
Risk Management Toolkit
Risk Management ToolkitRisk Management Toolkit
Risk Management Toolkit
 
ToTCOOP+i O3 o4 unit-9_final_version_en
ToTCOOP+i O3 o4 unit-9_final_version_enToTCOOP+i O3 o4 unit-9_final_version_en
ToTCOOP+i O3 o4 unit-9_final_version_en
 
Risk management models - Core Consulting
Risk management models - Core ConsultingRisk management models - Core Consulting
Risk management models - Core Consulting
 
Corporate and Project Risk Management Toolkit
Corporate and Project Risk Management Toolkit Corporate and Project Risk Management Toolkit
Corporate and Project Risk Management Toolkit
 
Proqual l7 ohs (1)
Proqual l7 ohs (1)Proqual l7 ohs (1)
Proqual l7 ohs (1)
 
ISO 31000.pdf
ISO 31000.pdfISO 31000.pdf
ISO 31000.pdf
 
Targeted Solutions BMS Profile
Targeted Solutions BMS ProfileTargeted Solutions BMS Profile
Targeted Solutions BMS Profile
 
Pm0016 set-1
Pm0016 set-1Pm0016 set-1
Pm0016 set-1
 
An introduction to finance
An introduction to financeAn introduction to finance
An introduction to finance
 
Reliability
ReliabilityReliability
Reliability
 
How to Create a Risk Profile for Your Organization: 10 Essential Steps
How to Create a Risk Profile for Your Organization: 10 Essential StepsHow to Create a Risk Profile for Your Organization: 10 Essential Steps
How to Create a Risk Profile for Your Organization: 10 Essential Steps
 
Project/Program Risk management
Project/Program Risk managementProject/Program Risk management
Project/Program Risk management
 
Riskpro iso 31000 services 2013
Riskpro iso 31000 services 2013Riskpro iso 31000 services 2013
Riskpro iso 31000 services 2013
 

Plus de Alvin Integrated Services [AIS]

Pandemic: Crisis or Opportunity? ISO 22301 best practice Implementation tips ...
Pandemic: Crisis or Opportunity? ISO 22301 best practice Implementation tips ...Pandemic: Crisis or Opportunity? ISO 22301 best practice Implementation tips ...
Pandemic: Crisis or Opportunity? ISO 22301 best practice Implementation tips ...Alvin Integrated Services [AIS]
 
ISO 27017 – What are the Business Advantages of Cloud Security?
ISO 27017 – What are the Business Advantages of Cloud Security?ISO 27017 – What are the Business Advantages of Cloud Security?
ISO 27017 – What are the Business Advantages of Cloud Security?Alvin Integrated Services [AIS]
 
Digital Maturity – Business as Usual & Integration of multiple ISO Management...
Digital Maturity – Business as Usual & Integration of multiple ISO Management...Digital Maturity – Business as Usual & Integration of multiple ISO Management...
Digital Maturity – Business as Usual & Integration of multiple ISO Management...Alvin Integrated Services [AIS]
 
Thinking beyond “Conventional” Crisis Communication.
Thinking beyond “Conventional” Crisis Communication.Thinking beyond “Conventional” Crisis Communication.
Thinking beyond “Conventional” Crisis Communication.Alvin Integrated Services [AIS]
 
Effective Leadership – The Cornerstone – applied study on ISO 22000:2018 Food...
Effective Leadership – The Cornerstone – applied study on ISO 22000:2018 Food...Effective Leadership – The Cornerstone – applied study on ISO 22000:2018 Food...
Effective Leadership – The Cornerstone – applied study on ISO 22000:2018 Food...Alvin Integrated Services [AIS]
 
COVID – 19 and Resilience: Has ISO 22316 standard been responsive?
COVID – 19 and Resilience: Has ISO 22316 standard been responsive?COVID – 19 and Resilience: Has ISO 22316 standard been responsive?
COVID – 19 and Resilience: Has ISO 22316 standard been responsive?Alvin Integrated Services [AIS]
 
Business Continuity Management System: How, Why and for What?
Business Continuity Management System: How, Why and for What?Business Continuity Management System: How, Why and for What?
Business Continuity Management System: How, Why and for What?Alvin Integrated Services [AIS]
 

Plus de Alvin Integrated Services [AIS] (9)

Designing an effective Crisis Management Framework
Designing an effective Crisis Management FrameworkDesigning an effective Crisis Management Framework
Designing an effective Crisis Management Framework
 
Pandemic: Crisis or Opportunity? ISO 22301 best practice Implementation tips ...
Pandemic: Crisis or Opportunity? ISO 22301 best practice Implementation tips ...Pandemic: Crisis or Opportunity? ISO 22301 best practice Implementation tips ...
Pandemic: Crisis or Opportunity? ISO 22301 best practice Implementation tips ...
 
ISO 27017 – What are the Business Advantages of Cloud Security?
ISO 27017 – What are the Business Advantages of Cloud Security?ISO 27017 – What are the Business Advantages of Cloud Security?
ISO 27017 – What are the Business Advantages of Cloud Security?
 
Digital Maturity – Business as Usual & Integration of multiple ISO Management...
Digital Maturity – Business as Usual & Integration of multiple ISO Management...Digital Maturity – Business as Usual & Integration of multiple ISO Management...
Digital Maturity – Business as Usual & Integration of multiple ISO Management...
 
ISO 31000: Culture vs Documentation, the way forward
ISO 31000: Culture vs Documentation, the way forwardISO 31000: Culture vs Documentation, the way forward
ISO 31000: Culture vs Documentation, the way forward
 
Thinking beyond “Conventional” Crisis Communication.
Thinking beyond “Conventional” Crisis Communication.Thinking beyond “Conventional” Crisis Communication.
Thinking beyond “Conventional” Crisis Communication.
 
Effective Leadership – The Cornerstone – applied study on ISO 22000:2018 Food...
Effective Leadership – The Cornerstone – applied study on ISO 22000:2018 Food...Effective Leadership – The Cornerstone – applied study on ISO 22000:2018 Food...
Effective Leadership – The Cornerstone – applied study on ISO 22000:2018 Food...
 
COVID – 19 and Resilience: Has ISO 22316 standard been responsive?
COVID – 19 and Resilience: Has ISO 22316 standard been responsive?COVID – 19 and Resilience: Has ISO 22316 standard been responsive?
COVID – 19 and Resilience: Has ISO 22316 standard been responsive?
 
Business Continuity Management System: How, Why and for What?
Business Continuity Management System: How, Why and for What?Business Continuity Management System: How, Why and for What?
Business Continuity Management System: How, Why and for What?
 

Dernier

Paris 2024 Olympic Geographies - an activity
Paris 2024 Olympic Geographies - an activityParis 2024 Olympic Geographies - an activity
Paris 2024 Olympic Geographies - an activityGeoBlogs
 
microwave assisted reaction. General introduction
microwave assisted reaction. General introductionmicrowave assisted reaction. General introduction
microwave assisted reaction. General introductionMaksud Ahmed
 
Grant Readiness 101 TechSoup and Remy Consulting
Grant Readiness 101 TechSoup and Remy ConsultingGrant Readiness 101 TechSoup and Remy Consulting
Grant Readiness 101 TechSoup and Remy ConsultingTechSoup
 
Mastering the Unannounced Regulatory Inspection
Mastering the Unannounced Regulatory InspectionMastering the Unannounced Regulatory Inspection
Mastering the Unannounced Regulatory InspectionSafetyChain Software
 
Incoming and Outgoing Shipments in 1 STEP Using Odoo 17
Incoming and Outgoing Shipments in 1 STEP Using Odoo 17Incoming and Outgoing Shipments in 1 STEP Using Odoo 17
Incoming and Outgoing Shipments in 1 STEP Using Odoo 17Celine George
 
Presiding Officer Training module 2024 lok sabha elections
Presiding Officer Training module 2024 lok sabha electionsPresiding Officer Training module 2024 lok sabha elections
Presiding Officer Training module 2024 lok sabha electionsanshu789521
 
Call Girls in Dwarka Mor Delhi Contact Us 9654467111
Call Girls in Dwarka Mor Delhi Contact Us 9654467111Call Girls in Dwarka Mor Delhi Contact Us 9654467111
Call Girls in Dwarka Mor Delhi Contact Us 9654467111Sapana Sha
 
Q4-W6-Restating Informational Text Grade 3
Q4-W6-Restating Informational Text Grade 3Q4-W6-Restating Informational Text Grade 3
Q4-W6-Restating Informational Text Grade 3JemimahLaneBuaron
 
Introduction to ArtificiaI Intelligence in Higher Education
Introduction to ArtificiaI Intelligence in Higher EducationIntroduction to ArtificiaI Intelligence in Higher Education
Introduction to ArtificiaI Intelligence in Higher Educationpboyjonauth
 
Alper Gobel In Media Res Media Component
Alper Gobel In Media Res Media ComponentAlper Gobel In Media Res Media Component
Alper Gobel In Media Res Media ComponentInMediaRes1
 
Separation of Lanthanides/ Lanthanides and Actinides
Separation of Lanthanides/ Lanthanides and ActinidesSeparation of Lanthanides/ Lanthanides and Actinides
Separation of Lanthanides/ Lanthanides and ActinidesFatimaKhan178732
 
Science 7 - LAND and SEA BREEZE and its Characteristics
Science 7 - LAND and SEA BREEZE and its CharacteristicsScience 7 - LAND and SEA BREEZE and its Characteristics
Science 7 - LAND and SEA BREEZE and its CharacteristicsKarinaGenton
 
Organic Name Reactions for the students and aspirants of Chemistry12th.pptx
Organic Name Reactions  for the students and aspirants of Chemistry12th.pptxOrganic Name Reactions  for the students and aspirants of Chemistry12th.pptx
Organic Name Reactions for the students and aspirants of Chemistry12th.pptxVS Mahajan Coaching Centre
 
Kisan Call Centre - To harness potential of ICT in Agriculture by answer farm...
Kisan Call Centre - To harness potential of ICT in Agriculture by answer farm...Kisan Call Centre - To harness potential of ICT in Agriculture by answer farm...
Kisan Call Centre - To harness potential of ICT in Agriculture by answer farm...Krashi Coaching
 
Hybridoma Technology ( Production , Purification , and Application )
Hybridoma Technology  ( Production , Purification , and Application  ) Hybridoma Technology  ( Production , Purification , and Application  )
Hybridoma Technology ( Production , Purification , and Application ) Sakshi Ghasle
 
SOCIAL AND HISTORICAL CONTEXT - LFTVD.pptx
SOCIAL AND HISTORICAL CONTEXT - LFTVD.pptxSOCIAL AND HISTORICAL CONTEXT - LFTVD.pptx
SOCIAL AND HISTORICAL CONTEXT - LFTVD.pptxiammrhaywood
 
18-04-UA_REPORT_MEDIALITERAСY_INDEX-DM_23-1-final-eng.pdf
18-04-UA_REPORT_MEDIALITERAСY_INDEX-DM_23-1-final-eng.pdf18-04-UA_REPORT_MEDIALITERAСY_INDEX-DM_23-1-final-eng.pdf
18-04-UA_REPORT_MEDIALITERAСY_INDEX-DM_23-1-final-eng.pdfssuser54595a
 
URLs and Routing in the Odoo 17 Website App
URLs and Routing in the Odoo 17 Website AppURLs and Routing in the Odoo 17 Website App
URLs and Routing in the Odoo 17 Website AppCeline George
 
Sanyam Choudhary Chemistry practical.pdf
Sanyam Choudhary Chemistry practical.pdfSanyam Choudhary Chemistry practical.pdf
Sanyam Choudhary Chemistry practical.pdfsanyamsingh5019
 

Dernier (20)

Paris 2024 Olympic Geographies - an activity
Paris 2024 Olympic Geographies - an activityParis 2024 Olympic Geographies - an activity
Paris 2024 Olympic Geographies - an activity
 
Model Call Girl in Tilak Nagar Delhi reach out to us at 🔝9953056974🔝
Model Call Girl in Tilak Nagar Delhi reach out to us at 🔝9953056974🔝Model Call Girl in Tilak Nagar Delhi reach out to us at 🔝9953056974🔝
Model Call Girl in Tilak Nagar Delhi reach out to us at 🔝9953056974🔝
 
microwave assisted reaction. General introduction
microwave assisted reaction. General introductionmicrowave assisted reaction. General introduction
microwave assisted reaction. General introduction
 
Grant Readiness 101 TechSoup and Remy Consulting
Grant Readiness 101 TechSoup and Remy ConsultingGrant Readiness 101 TechSoup and Remy Consulting
Grant Readiness 101 TechSoup and Remy Consulting
 
Mastering the Unannounced Regulatory Inspection
Mastering the Unannounced Regulatory InspectionMastering the Unannounced Regulatory Inspection
Mastering the Unannounced Regulatory Inspection
 
Incoming and Outgoing Shipments in 1 STEP Using Odoo 17
Incoming and Outgoing Shipments in 1 STEP Using Odoo 17Incoming and Outgoing Shipments in 1 STEP Using Odoo 17
Incoming and Outgoing Shipments in 1 STEP Using Odoo 17
 
Presiding Officer Training module 2024 lok sabha elections
Presiding Officer Training module 2024 lok sabha electionsPresiding Officer Training module 2024 lok sabha elections
Presiding Officer Training module 2024 lok sabha elections
 
Call Girls in Dwarka Mor Delhi Contact Us 9654467111
Call Girls in Dwarka Mor Delhi Contact Us 9654467111Call Girls in Dwarka Mor Delhi Contact Us 9654467111
Call Girls in Dwarka Mor Delhi Contact Us 9654467111
 
Q4-W6-Restating Informational Text Grade 3
Q4-W6-Restating Informational Text Grade 3Q4-W6-Restating Informational Text Grade 3
Q4-W6-Restating Informational Text Grade 3
 
Introduction to ArtificiaI Intelligence in Higher Education
Introduction to ArtificiaI Intelligence in Higher EducationIntroduction to ArtificiaI Intelligence in Higher Education
Introduction to ArtificiaI Intelligence in Higher Education
 
Alper Gobel In Media Res Media Component
Alper Gobel In Media Res Media ComponentAlper Gobel In Media Res Media Component
Alper Gobel In Media Res Media Component
 
Separation of Lanthanides/ Lanthanides and Actinides
Separation of Lanthanides/ Lanthanides and ActinidesSeparation of Lanthanides/ Lanthanides and Actinides
Separation of Lanthanides/ Lanthanides and Actinides
 
Science 7 - LAND and SEA BREEZE and its Characteristics
Science 7 - LAND and SEA BREEZE and its CharacteristicsScience 7 - LAND and SEA BREEZE and its Characteristics
Science 7 - LAND and SEA BREEZE and its Characteristics
 
Organic Name Reactions for the students and aspirants of Chemistry12th.pptx
Organic Name Reactions  for the students and aspirants of Chemistry12th.pptxOrganic Name Reactions  for the students and aspirants of Chemistry12th.pptx
Organic Name Reactions for the students and aspirants of Chemistry12th.pptx
 
Kisan Call Centre - To harness potential of ICT in Agriculture by answer farm...
Kisan Call Centre - To harness potential of ICT in Agriculture by answer farm...Kisan Call Centre - To harness potential of ICT in Agriculture by answer farm...
Kisan Call Centre - To harness potential of ICT in Agriculture by answer farm...
 
Hybridoma Technology ( Production , Purification , and Application )
Hybridoma Technology  ( Production , Purification , and Application  ) Hybridoma Technology  ( Production , Purification , and Application  )
Hybridoma Technology ( Production , Purification , and Application )
 
SOCIAL AND HISTORICAL CONTEXT - LFTVD.pptx
SOCIAL AND HISTORICAL CONTEXT - LFTVD.pptxSOCIAL AND HISTORICAL CONTEXT - LFTVD.pptx
SOCIAL AND HISTORICAL CONTEXT - LFTVD.pptx
 
18-04-UA_REPORT_MEDIALITERAСY_INDEX-DM_23-1-final-eng.pdf
18-04-UA_REPORT_MEDIALITERAСY_INDEX-DM_23-1-final-eng.pdf18-04-UA_REPORT_MEDIALITERAСY_INDEX-DM_23-1-final-eng.pdf
18-04-UA_REPORT_MEDIALITERAСY_INDEX-DM_23-1-final-eng.pdf
 
URLs and Routing in the Odoo 17 Website App
URLs and Routing in the Odoo 17 Website AppURLs and Routing in the Odoo 17 Website App
URLs and Routing in the Odoo 17 Website App
 
Sanyam Choudhary Chemistry practical.pdf
Sanyam Choudhary Chemistry practical.pdfSanyam Choudhary Chemistry practical.pdf
Sanyam Choudhary Chemistry practical.pdf
 

ISO 31000:2018 Risk Management System, Framework and Implementation

  • 1. Contact us: info@alvinintegrated.com | +91 8802 505619, +91 8287509289 | www.alvinintegrated.com Platinum Sponsor OUR SPONSORS & PARTNERS Event Partner www.alvinintegrated.com Knowledge Partners 27th FEB 2021 (SATURDAY) 09:00 AM - 17:30 PM IST
  • 2. ISO 31000:2018 Risk Management System, Framework and Implementation 27th February 2021 (Saturday) Time: 09:05 am - 09:30 am IST ISO 31000:2018 By Sanjay Gore, Principal Consultant, Alvin Integrated Service [AIS]
  • 3. Speaker Introduction: Mr. Sanjay Gore hails from Pune, Maharashtra, India, is a Senior Consultant and Speaker on Information Security, Risk Management and Privacy. He has rich experience of 20 years in working with customers in India, Middle East at top management level, business owners and technical team members for securing and deploying information security and risk management and privacy solutions. He holds professional designations such as: ISO-27001-LA, ISO 27005- RM, CDPSE CPISI, CRMA, CISA, and CRISC. He is certified Trainer in 27001 and 27005. Connect at LinkedIn: Sanjay Gore – LinkedinProfile Subscribe at YouTube: Sanjay Gore – youtubechannel Mr Sanjay Gore ISO-27001-LA, ISO 27005- RM, CDPSE CPISI, CRMA, CISA, and CRISC | Certified Trainer in 27001 and 27005 | Pune, Maharashtra – India
  • 4. Risk Opportunity or Threat?? 4 Threat 1. Find a way to avoid the risk 2. Find a way to transfer to another party ( Insurance, Contract conditions) 3. Find a way to mitigate the risk reducing probability or severeness Opportunity 1. Exploit the opportunity 2. Share with another party 3. Enhance by increasing the effect or the probability Accept Do nothing Risk
  • 5. Edifice of ISO 31000:2018 ISO 31000:2018 The principles provide the foundation and describe the qualities of effective risk management in an organization Principles ISO 31000:2018 Framework The framework manages the overall process and its full integration into the organization ISO 31000:2018 Process The process focuses on individual or groups of risks, their identification, analysis, evaluation and treatment 5
  • 6. ISO 31000:2018 Scope of Document 6 1. Managing risk faced by organizations. 2. The application of these guidelines can be customized on any organization and its context. 3. This document provides a common approach to managing any type of risk and is not industry or sector specific 4. This document can be used throughout the life of the organization and can be applied to any activity, including decision making
  • 7. ISO 31000 Concepts, Terms and Definitions- 7 1. Risk is an effect of uncertainty on objectives 2. An effect is a deviation from the expected. 3. It can be positive, negative or both, and can address, create or result in opportunities and threats. 4. Objectives can have different aspects and categories, and can be applied at different levels. 5. Risk is usually expressed in terms of • Risk Sources • Potential Events • Their Consequences • Their Likelihood Risk
  • 8. ISO 31000 Concepts, Terms and Definitions- 8 • Event occurrence or change of a particular set of circumstances • An event can have one or more occurrences, and can have several causes and several consequences • An event can also be something that is expected which does not happen, or something that is not expected which does happen. • An event can be a risk source. Event
  • 9. ISO 31000 Concepts, Terms Definitions- 9 • Consequence is an outcome of an event affecting objectives • A consequence can be certain or uncertain and can have positive or negative direct or indirect effects on objectives. • Consequences can be expressed qualitatively or quantitatively. • Any consequence can escalate through cascading and cumulative effects. Consequence
  • 10. ISO 31000 Concepts, Terms and Definitions- 10 • Likelihood is chance of something happening • In risk management terminology, the word “likelihood” is used to refer to the chance of something happening, whether defined, measured or determined objectively or subjectively, qualitatively or quantitatively, and described using general terms or mathematically (such as a probability or a frequency over a given time period). The English term “likelihood” does not have a direct equivalent in some languages; instead, the equivalent of the term “probability” is often used. However, in English, “probability” is often narrowly interpreted as a mathematical term. Therefore, in risk management terminology, “likelihood” is used with the intent that it should have the same broad interpretation as the term “probability” has in many languages other than English. Likelihood
  • 11. ISO 31000 Concepts, Terms and Definitions- 11 Control measure that maintains and/or modifies risk • Controls include, but are not limited to, any process, policy, device, practice, or other conditions and/or actions which maintain and/or modify risk. • Controls may not always exert the intended or assumed modifying effect. Control
  • 12. ISO 31000:2018 Risk Management Principles 12 1. Integrated 2. Structured and comprehensive 3. Customized 4. Inclusive 5. Dynamic 6. Best available information 7. Human and cultural factors 8. Continual improvement Value Creation and Protection
  • 13. Continuous improvement Continuous improvement means that organizations are in a constant state of driving process improvements. This involves a focus on linear and incremental improvement within existing processes. Continual improvement A continual improvement mean that organizations go through process improvements in stages. Even and these stages are separate by a period of time. This period of time might be necessary to understand if the improvements did actually help the bottom line! In some cases, the results might take a while to come to fruition. Principles - Continual improvement 13
  • 14. Risk Management Framework 1. Integration 2. Design 3. Implementation 4. Evaluation 5. Improvement 14 1 2 3 4 5 Leadership and Commitment
  • 15. Risk Management Process 15 Scope Context Criteria Risk Treatment Recording and Reporting Communication and Consultation Monitoring and Review Risk Assessment Risk Identification Risk Analysis Risk Evaluation
  • 16. Process Defining Scope When planning the approach, considerations include 1. Objectives and decisions that need to be made 2. Outcomes expected from the steps to be taken in the process 3. Time, location, specific inclusions and exclusions 4. Appropriate risk assessment tools and techniques 5. Resources required, responsibilities and records to be kept 6. Relationships with other projects, processes and activities. 16
  • 17. Process Defining Risk Criteria To set risk criteria, the following should be considered 1. The nature and type of uncertainties that can affect outcomes and objectives (both tangible and intangible) 2. How consequences (both positive and negative) and likelihood will be defined and measured 3. Time-related factors 4. Consistency in the use of measurements 5. How the level of risk is to be determined 6. How combinations and sequences of multiple risks will be taken into account 7. The organization’s capacity 17
  • 18. Process Selection of Risk Treatment Options Depending on the type of risk and its significance to the business, management and the board may 1. Avoid- e.g., where feasible, choose not to implement certain activities or processes that would incur risk (i.e., eliminate the risk by eliminating the cause) 2. Mitigate lessen the probability or impact of the risk by defining, implementing, and monitoring appropriate controls. 3. Transfer (deflect, or allocate}-e.g.; share risk with partners or transfer via insurance coverage, contractual agreement, or other means. 4. Accept- formally acknowledge the existence of the risk and monitor it 18
  • 19. A few Risk Assessment Tools/ Techniques • Brainstorming • Delphi Technique • Checklists • Root Cause Analysis • Failure Mode Effect Analysis (FMEA ) And FMECA • Fault Tree Analysis (FTA) • Hazard Analysis (PHA) • Scenario analysis • Layers of protection analysis (LOPA) • Decision Tree Analysis • Monte Carlo simulation 19
  • 21. Please give your feedbacks in the chat box about the webinar.