Risk Management Workflows

  • Process Exit Criteria
  • Risk process continues until the process response is implemented
  • Risk is mitigated to acceptable managed residual risk or removed
  • Mitigated risk where significance is less than “9” & appropriate controls are identified for ongoing risk management
  • Measurements
  • Number of risk management meetings
  • Number of improvement projects
  • Number of improvements to the risk assessment process
  • Level of funding allocated to risk management projects
  • Number & frequency of updates to published Governance Committee reports
  • Risk limits & policies
  • To Sum it Up – Just Do It
  • Risks management policy signed by CISO, CFO and CIO
  • ERM & Security manager responsibilities assigned
  • Appropriate funding allocated (if required)
  • Risk awareness training
  • Meeting time and standard agenda format established
  • Support sessions to enter risk items
  • Risk meeting agenda posted
  • Risk meetings and Quarterly Governance Meetings
  • Posted risk meeting action items and notes
  • Follow up risk response

Iterate enter risks - update risks - post agenda – meeting - post notes - follow up risk response

Main Menu