What is the fundamental process of Risk Management?
This process involves recognizing and addressing risks that may hinder objectives.
What are the steps in the Risk Management Lifecycle?
Each step plays a crucial role in managing risks effectively.
What is the goal of Risk Identification?
Create a comprehensive list based on events hindering objectives
It is a proactive process recognizing potential risks.
What does Risk Analysis evaluate?
It can use qualitative or quantitative methods to prioritize risks.
What are the strategies involved in Risk Treatment?
Strategy choice is based on potential impact and risk tolerance.
What is the purpose of Risk Monitoring?
Ongoing process tracking identified risks
It ensures dynamic responsiveness to organizational changes.
What is the significance of Risk Reporting?
Communicate risk information and effectiveness of risk management to stakeholders
It is crucial for accountability and informed decision-making.
What are the types of Risk Assessment Frequency?
Frequency varies based on organization nature and types of risks involved.
What is the Business Impact Analysis (BIA)?
Key metrics include Recovery Time Objective (RTO) and Recovery Point Objective (RPO).
What does a Risk Register record?
It is a key tool in risk management facilitating communication and risk tracking.
Define Risk Tolerance/Risk Acceptance.
Willingness to deal with uncertainty in pursuit of goals
It represents the maximum amount of risk an organization is willing to accept.
What are the four primary risk management strategies?
Each strategy addresses risk in different ways.
What is Qualitative Risk Analysis?
Assesses risks based on potential impact and likelihood
It categorizes risks as high, medium, or low and relies on expertise.
What does Quantitative Risk Analysis provide?
Objective and numerical evaluation of risks
It is used for financial, safety, and scheduling decisions.
What is the Annualized Loss Expectancy (ALE)?
Expected annual loss from a risk
Calculated as Single Loss Expectancy (SLE) x Annualized Rate of Occurrence (ARO).
What is the purpose of Risk Monitoring and Reporting?
It helps determine Residual Risk and Control Risk.
What does Residual Risk refer to?
Likelihood and impact of the risk after mitigation, transference, or acceptance measures
It assesses the remaining risk after actions have been taken.