Archive for the 'Risk Management Questions' Category

Feb 26th 2010 Information (Data) Inventory Questions

  • What information are we collecting?
  • Where and how are we collecting it?
  • Who owns it?
  • Who has access to it?
  • What are we doing with it?
  • What would be the impact to the organization if it got into the wrong hands?
  • What controls are in place?
  • Are efforts to safeguard the information commensurate with its worth?
  • Are we gathering unnecessary information that represents potential risk without opportunity for reward?
  • Are we maximizing the value of what we collect?
  • Could information have more value if we loosened restrictions on it?

Source: Lock It Up or Set It Free? by Ted DeZabala | Deloitte Review, Issue 6

Share

No Comments » Posted by Administrator / IT Questions and Risk Management Questions

Oct 22nd 2007 Diagnose Your Enterprise Resilience: Eight Fundamental Questions

  1. Are the complexity of the extended enterprise and major earnings drivers across it transparent?
  2. Are interdependencies understood and interdependence risks identified?
  3. What programs are in place to ensure the viability of earnings drivers?
  4. Are these programs fully aligned with corporate strategy and objectives, and do we understand the trade-offs within these programs?
  5. Do we know what we spend on resilience?
  6. How good is our situational awareness — that is, do we have enough business intelligence, internal and external, and is it directed to the appropriate parties?
  7. Do we distill such intelligence properly and in a timely enough fashion to react to it?
  8. Who is accountable for resilience, and how do we make decisions and measure progress?

Source:
Enterprise Resilience: Managing Risk in the Networked Economy
by Randy Starr
strategy+business, Spring 2003

Share

No Comments » Posted by Administrator / Risk Management Questions

Oct 21st 2007 3 Key Risk Management Questions

  • How good is my company at understanding risk? i.e., what risks do we face and how does that risk impact on my organization?
  • What control procedures does my company have in place to mitigate these risks?
  • How does my company achieve recognition for the effort we have put into implementing control measures and managing risk?

Source:
An explicit item for the main board
by John Bromfield
European Business Forum, Issue 13

Share

No Comments » Posted by Administrator / Risk Management Questions