SlideShare a Scribd company logo
1 of 21
Download to read offline
Contact us: info@alvinintegrated.com | +91 8802 505619, +91
8287509289 | www.alvinintegrated.com
Platinum Sponsor
OUR SPONSORS & PARTNERS
Event Partner
www.alvinintegrated.com
Knowledge Partners
27th FEB 2021
(SATURDAY)
09:00 AM - 17:30 PM IST
ISO 31000:2018 Risk
Management System,
Framework and
Implementation
27th February 2021 (Saturday)
Time: 09:05 am - 09:30 am IST
ISO 31000:2018 By Sanjay Gore, Principal Consultant,
Alvin Integrated Service [AIS]
Speaker Introduction:
Mr. Sanjay Gore hails from Pune, Maharashtra, India, is
a Senior Consultant and Speaker on Information Security, Risk Management and
Privacy.
He has rich experience of 20 years in working with customers in India, Middle East
at top management level, business owners and technical team members for
securing and deploying information security and risk management and privacy
solutions. He holds professional designations such as: ISO-27001-LA, ISO 27005-
RM, CDPSE CPISI, CRMA, CISA, and CRISC. He is certified Trainer in 27001
and 27005.
Connect at LinkedIn: Sanjay Gore – LinkedinProfile
Subscribe at YouTube: Sanjay Gore – youtubechannel
Mr Sanjay Gore
ISO-27001-LA, ISO 27005-
RM, CDPSE CPISI, CRMA,
CISA, and CRISC | Certified
Trainer in 27001 and 27005 |
Pune, Maharashtra – India
Risk Opportunity or Threat??
4
Threat
1. Find a way to avoid the risk
2. Find a way to transfer to another
party ( Insurance, Contract
conditions)
3. Find a way to mitigate the risk
reducing probability or severeness
Opportunity
1. Exploit the opportunity
2. Share with another party
3. Enhance by increasing the effect or the
probability
Accept
Do nothing
Risk
Edifice of ISO 31000:2018
ISO 31000:2018
The principles
provide the
foundation and
describe the qualities
of effective risk
management in an
organization
Principles
ISO 31000:2018
Framework
The framework
manages the overall
process and its full
integration into the
organization
ISO 31000:2018
Process
The process focuses
on individual or
groups of risks, their
identification,
analysis, evaluation
and treatment
5
ISO 31000:2018 Scope of Document
6
1. Managing risk faced by organizations.
2. The application of these guidelines can be customized on any organization and
its context.
3. This document provides a common approach to managing any type of risk and
is not industry or sector specific
4. This document can be used throughout the life of the organization and can be
applied to any activity, including decision making
ISO 31000 Concepts, Terms and Definitions-
7
1. Risk is an effect of uncertainty on objectives
2. An effect is a deviation from the expected.
3. It can be positive, negative or both, and can address, create or result in opportunities
and threats.
4. Objectives can have different aspects and categories, and can be applied at different
levels.
5. Risk is usually expressed in terms of
• Risk Sources
• Potential Events
• Their Consequences
• Their Likelihood
Risk
ISO 31000 Concepts, Terms and Definitions-
8
• Event occurrence or change of a particular set of circumstances
• An event can have one or more occurrences, and can have several
causes and several consequences
• An event can also be something that is expected which does not
happen, or something that is not expected which does happen.
• An event can be a risk source.
Event
ISO 31000 Concepts, Terms Definitions-
9
• Consequence is an outcome of an event affecting objectives
• A consequence can be certain or uncertain and can have positive
or negative direct or indirect effects on objectives.
• Consequences can be expressed qualitatively or quantitatively.
• Any consequence can escalate through cascading and cumulative
effects.
Consequence
ISO 31000 Concepts, Terms and Definitions-
10
• Likelihood is chance of something happening
• In risk management terminology, the word “likelihood” is used to refer to the
chance of something happening, whether defined, measured or determined
objectively or subjectively, qualitatively or quantitatively, and described using
general terms or mathematically (such as a probability or a frequency over a
given time period).
The English term “likelihood” does not have a direct equivalent in some languages; instead, the equivalent of the term
“probability” is often used. However, in English, “probability” is often narrowly interpreted as a mathematical term.
Therefore, in risk management terminology, “likelihood” is used with the intent that it should have the same broad
interpretation as the term “probability” has in many languages other than English.
Likelihood
ISO 31000 Concepts, Terms and Definitions-
11
Control measure that maintains and/or modifies risk
• Controls include, but are not limited to, any process, policy, device,
practice, or other conditions and/or actions which maintain and/or
modify risk.
• Controls may not always exert the intended or assumed modifying
effect.
Control
ISO 31000:2018 Risk Management Principles
12
1. Integrated
2. Structured and comprehensive
3. Customized
4. Inclusive
5. Dynamic
6. Best available information
7. Human and cultural factors
8. Continual improvement
Value Creation and Protection
Continuous improvement
Continuous improvement means that organizations are
in a constant state of driving process improvements.
This involves a focus on linear and incremental
improvement within existing processes.
Continual improvement
A continual improvement mean that organizations go
through process improvements in stages. Even and
these stages are separate by a period of time. This
period of time might be necessary to understand if the
improvements did actually help the bottom line! In
some cases, the results might take a while to come to
fruition.
Principles - Continual improvement
13
Risk Management Framework
1. Integration
2. Design
3. Implementation
4. Evaluation
5. Improvement
14
1
2
3
4
5
Leadership and
Commitment
Risk Management Process
15
Scope Context Criteria
Risk Treatment
Recording and Reporting
Communication
and
Consultation
Monitoring
and
Review
Risk Assessment
Risk
Identification
Risk
Analysis
Risk
Evaluation
Process Defining Scope
When planning the approach, considerations include
1. Objectives and decisions that need to be made
2. Outcomes expected from the steps to be taken in the process
3. Time, location, specific inclusions and exclusions
4. Appropriate risk assessment tools and techniques
5. Resources required, responsibilities and records to be kept
6. Relationships with other projects, processes and activities.
16
Process Defining Risk Criteria
To set risk criteria, the following should be considered
1. The nature and type of uncertainties that can affect outcomes and
objectives (both tangible and intangible)
2. How consequences (both positive and negative) and likelihood will
be defined and measured
3. Time-related factors
4. Consistency in the use of measurements
5. How the level of risk is to be determined
6. How combinations and sequences of multiple risks will be taken
into account
7. The organization’s capacity
17
Process Selection of Risk Treatment Options
Depending on the type of risk and its significance to the business,
management and the board may
1. Avoid- e.g., where feasible, choose not to implement certain activities
or processes that would incur risk (i.e., eliminate the risk by eliminating
the cause)
2. Mitigate lessen the probability or impact of the risk by defining,
implementing, and monitoring appropriate controls.
3. Transfer (deflect, or allocate}-e.g.; share risk with partners or transfer
via insurance coverage, contractual agreement, or other means.
4. Accept- formally acknowledge the existence of the risk and monitor it
18
A few Risk Assessment Tools/ Techniques
• Brainstorming
• Delphi Technique
• Checklists
• Root Cause Analysis
• Failure Mode Effect
Analysis (FMEA ) And
FMECA
• Fault Tree Analysis
(FTA)
• Hazard Analysis (PHA)
• Scenario analysis
• Layers of protection
analysis (LOPA)
• Decision Tree Analysis
• Monte Carlo simulation
19
Questions
are
Welcome!
Please give your feedbacks in
the chat box about the webinar.

More Related Content

What's hot

Risk Management
Risk ManagementRisk Management
Risk Managementcgeorgeo
 
PECB Webinar: ISO 31000 - The Benchmark for Risk Management in uncertain times
PECB Webinar: ISO 31000 - The Benchmark for Risk Management in uncertain timesPECB Webinar: ISO 31000 - The Benchmark for Risk Management in uncertain times
PECB Webinar: ISO 31000 - The Benchmark for Risk Management in uncertain timesPECB
 
Risk Management Process And Procedures PowerPoint Presentation Slides
Risk Management Process And Procedures PowerPoint Presentation SlidesRisk Management Process And Procedures PowerPoint Presentation Slides
Risk Management Process And Procedures PowerPoint Presentation SlidesSlideTeam
 
Risk Management Process
Risk Management ProcessRisk Management Process
Risk Management Processno suhaila
 
Risk Management module PowerPoint Presentation Slides
Risk Management module PowerPoint Presentation SlidesRisk Management module PowerPoint Presentation Slides
Risk Management module PowerPoint Presentation SlidesSlideTeam
 
ISO 9001 2015 Overview presentation
ISO 9001 2015 Overview presentation ISO 9001 2015 Overview presentation
ISO 9001 2015 Overview presentation Govind Ramu
 
Risk opportunity analysis ISO 9001:2015
Risk opportunity analysis ISO 9001:2015Risk opportunity analysis ISO 9001:2015
Risk opportunity analysis ISO 9001:2015Ghiru Kanesvaran
 
Managing with KPI's and KRI's
Managing with KPI's and KRI's Managing with KPI's and KRI's
Managing with KPI's and KRI's Andrew Smart
 
Risk Assessment PowerPoint Presentation Slides
Risk Assessment PowerPoint Presentation Slides Risk Assessment PowerPoint Presentation Slides
Risk Assessment PowerPoint Presentation Slides SlideTeam
 
Risk assessment and management
Risk assessment and managementRisk assessment and management
Risk assessment and managementTanmoy Sinha
 
Risk Analysis and Management
Risk Analysis and ManagementRisk Analysis and Management
Risk Analysis and ManagementGenie
 
ISO 45001 Employee Awareness Training
ISO 45001 Employee Awareness TrainingISO 45001 Employee Awareness Training
ISO 45001 Employee Awareness TrainingDr Madhu Aman Sharma
 
Best Practices in Auditing ISO/IEC 27001
Best Practices in Auditing ISO/IEC 27001Best Practices in Auditing ISO/IEC 27001
Best Practices in Auditing ISO/IEC 27001PECB
 
Iso Internal Auditor
Iso Internal AuditorIso Internal Auditor
Iso Internal AuditorDanyah Hejaij
 
Best Practices in Auditing
Best Practices in AuditingBest Practices in Auditing
Best Practices in AuditingPECB
 

What's hot (20)

Iso 45001 certification
Iso 45001 certificationIso 45001 certification
Iso 45001 certification
 
Risk Management
Risk ManagementRisk Management
Risk Management
 
PECB Webinar: ISO 31000 - The Benchmark for Risk Management in uncertain times
PECB Webinar: ISO 31000 - The Benchmark for Risk Management in uncertain timesPECB Webinar: ISO 31000 - The Benchmark for Risk Management in uncertain times
PECB Webinar: ISO 31000 - The Benchmark for Risk Management in uncertain times
 
Risk Management Process And Procedures PowerPoint Presentation Slides
Risk Management Process And Procedures PowerPoint Presentation SlidesRisk Management Process And Procedures PowerPoint Presentation Slides
Risk Management Process And Procedures PowerPoint Presentation Slides
 
Risk Management Process
Risk Management ProcessRisk Management Process
Risk Management Process
 
Risk Management module PowerPoint Presentation Slides
Risk Management module PowerPoint Presentation SlidesRisk Management module PowerPoint Presentation Slides
Risk Management module PowerPoint Presentation Slides
 
ISO 9001 2015 Overview presentation
ISO 9001 2015 Overview presentation ISO 9001 2015 Overview presentation
ISO 9001 2015 Overview presentation
 
Risk opportunity analysis ISO 9001:2015
Risk opportunity analysis ISO 9001:2015Risk opportunity analysis ISO 9001:2015
Risk opportunity analysis ISO 9001:2015
 
Iso 31000
Iso 31000Iso 31000
Iso 31000
 
Managing with KPI's and KRI's
Managing with KPI's and KRI's Managing with KPI's and KRI's
Managing with KPI's and KRI's
 
Risk Assessment PowerPoint Presentation Slides
Risk Assessment PowerPoint Presentation Slides Risk Assessment PowerPoint Presentation Slides
Risk Assessment PowerPoint Presentation Slides
 
Overview of ISO 19011:2018 Guidelines for Auditing Management Systems
Overview of ISO 19011:2018 Guidelines for Auditing Management SystemsOverview of ISO 19011:2018 Guidelines for Auditing Management Systems
Overview of ISO 19011:2018 Guidelines for Auditing Management Systems
 
Risk assessment and management
Risk assessment and managementRisk assessment and management
Risk assessment and management
 
Risk Analysis and Management
Risk Analysis and ManagementRisk Analysis and Management
Risk Analysis and Management
 
ISO 45001 Employee Awareness Training
ISO 45001 Employee Awareness TrainingISO 45001 Employee Awareness Training
ISO 45001 Employee Awareness Training
 
Best Practices in Auditing ISO/IEC 27001
Best Practices in Auditing ISO/IEC 27001Best Practices in Auditing ISO/IEC 27001
Best Practices in Auditing ISO/IEC 27001
 
Iso Internal Auditor
Iso Internal AuditorIso Internal Auditor
Iso Internal Auditor
 
Risk management
Risk managementRisk management
Risk management
 
Best Practices in Auditing
Best Practices in AuditingBest Practices in Auditing
Best Practices in Auditing
 
Risk management & ISO 31000
Risk management & ISO 31000Risk management & ISO 31000
Risk management & ISO 31000
 

Similar to ISO 31000:2018 Risk Management System, Framework and Implementation

#Contract Risk Audit# By SN panigrahi
#Contract Risk Audit# By SN panigrahi#Contract Risk Audit# By SN panigrahi
#Contract Risk Audit# By SN panigrahiSN Panigrahi, PMP
 
The IRM India- A Risk Management Standard
The IRM India- A Risk Management StandardThe IRM India- A Risk Management Standard
The IRM India- A Risk Management StandardThe IRM India
 
PECB Webinar: ISO 31000 – Risk Management and how it can help an organization
PECB Webinar: ISO 31000 – Risk Management and how it can help an organizationPECB Webinar: ISO 31000 – Risk Management and how it can help an organization
PECB Webinar: ISO 31000 – Risk Management and how it can help an organizationPECB
 
Management of risk introduction
Management of risk introductionManagement of risk introduction
Management of risk introductionSpyros Ktenas
 
Safety Inspections and Sample Safety Inspection.Health and safety training D...
Safety Inspections and Sample Safety Inspection.Health  and safety training D...Safety Inspections and Sample Safety Inspection.Health  and safety training D...
Safety Inspections and Sample Safety Inspection.Health and safety training D...Salman Jailani
 
Risk Management Toolkit
Risk Management ToolkitRisk Management Toolkit
Risk Management ToolkitPeterFranz6
 
ToTCOOP+i O3 o4 unit-9_final_version_en
ToTCOOP+i O3 o4 unit-9_final_version_enToTCOOP+i O3 o4 unit-9_final_version_en
ToTCOOP+i O3 o4 unit-9_final_version_enToTCOOPiTech
 
Risk management models - Core Consulting
Risk management models - Core ConsultingRisk management models - Core Consulting
Risk management models - Core ConsultingCORE Consulting
 
Corporate and Project Risk Management Toolkit
Corporate and Project Risk Management Toolkit Corporate and Project Risk Management Toolkit
Corporate and Project Risk Management Toolkit Aurelien Domont, MBA
 
Targeted Solutions BMS Profile
Targeted Solutions BMS ProfileTargeted Solutions BMS Profile
Targeted Solutions BMS ProfileLeon Geldenhuys
 
An introduction to finance
An introduction to financeAn introduction to finance
An introduction to financeRobert Reed
 
Pm0016 set-1
Pm0016 set-1Pm0016 set-1
Pm0016 set-1Paul Hunt
 
How to Create a Risk Profile for Your Organization: 10 Essential Steps
How to Create a Risk Profile for Your Organization: 10 Essential StepsHow to Create a Risk Profile for Your Organization: 10 Essential Steps
How to Create a Risk Profile for Your Organization: 10 Essential StepsCase IQ
 

Similar to ISO 31000:2018 Risk Management System, Framework and Implementation (20)

Essay On Risk Management
Essay On Risk ManagementEssay On Risk Management
Essay On Risk Management
 
#Contract Risk Audit# By SN panigrahi
#Contract Risk Audit# By SN panigrahi#Contract Risk Audit# By SN panigrahi
#Contract Risk Audit# By SN panigrahi
 
Iso 31000 presentation
Iso 31000 presentationIso 31000 presentation
Iso 31000 presentation
 
The IRM India- A Risk Management Standard
The IRM India- A Risk Management StandardThe IRM India- A Risk Management Standard
The IRM India- A Risk Management Standard
 
PECB Webinar: ISO 31000 – Risk Management and how it can help an organization
PECB Webinar: ISO 31000 – Risk Management and how it can help an organizationPECB Webinar: ISO 31000 – Risk Management and how it can help an organization
PECB Webinar: ISO 31000 – Risk Management and how it can help an organization
 
Management of risk introduction
Management of risk introductionManagement of risk introduction
Management of risk introduction
 
Safety Inspections and Sample Safety Inspection.Health and safety training D...
Safety Inspections and Sample Safety Inspection.Health  and safety training D...Safety Inspections and Sample Safety Inspection.Health  and safety training D...
Safety Inspections and Sample Safety Inspection.Health and safety training D...
 
Risk Management Toolkit
Risk Management ToolkitRisk Management Toolkit
Risk Management Toolkit
 
ToTCOOP+i O3 o4 unit-9_final_version_en
ToTCOOP+i O3 o4 unit-9_final_version_enToTCOOP+i O3 o4 unit-9_final_version_en
ToTCOOP+i O3 o4 unit-9_final_version_en
 
Risk management models - Core Consulting
Risk management models - Core ConsultingRisk management models - Core Consulting
Risk management models - Core Consulting
 
Corporate and Project Risk Management Toolkit
Corporate and Project Risk Management Toolkit Corporate and Project Risk Management Toolkit
Corporate and Project Risk Management Toolkit
 
Proqual l7 ohs (1)
Proqual l7 ohs (1)Proqual l7 ohs (1)
Proqual l7 ohs (1)
 
ISO 31000.pdf
ISO 31000.pdfISO 31000.pdf
ISO 31000.pdf
 
Targeted Solutions BMS Profile
Targeted Solutions BMS ProfileTargeted Solutions BMS Profile
Targeted Solutions BMS Profile
 
An introduction to finance
An introduction to financeAn introduction to finance
An introduction to finance
 
Pm0016 set-1
Pm0016 set-1Pm0016 set-1
Pm0016 set-1
 
Reliability
ReliabilityReliability
Reliability
 
How to Create a Risk Profile for Your Organization: 10 Essential Steps
How to Create a Risk Profile for Your Organization: 10 Essential StepsHow to Create a Risk Profile for Your Organization: 10 Essential Steps
How to Create a Risk Profile for Your Organization: 10 Essential Steps
 
Project/Program Risk management
Project/Program Risk managementProject/Program Risk management
Project/Program Risk management
 
Riskpro iso 31000 services 2013
Riskpro iso 31000 services 2013Riskpro iso 31000 services 2013
Riskpro iso 31000 services 2013
 

More from Alvin Integrated Services [AIS]

Pandemic: Crisis or Opportunity? ISO 22301 best practice Implementation tips ...
Pandemic: Crisis or Opportunity? ISO 22301 best practice Implementation tips ...Pandemic: Crisis or Opportunity? ISO 22301 best practice Implementation tips ...
Pandemic: Crisis or Opportunity? ISO 22301 best practice Implementation tips ...Alvin Integrated Services [AIS]
 
ISO 27017 – What are the Business Advantages of Cloud Security?
ISO 27017 – What are the Business Advantages of Cloud Security?ISO 27017 – What are the Business Advantages of Cloud Security?
ISO 27017 – What are the Business Advantages of Cloud Security?Alvin Integrated Services [AIS]
 
Digital Maturity – Business as Usual & Integration of multiple ISO Management...
Digital Maturity – Business as Usual & Integration of multiple ISO Management...Digital Maturity – Business as Usual & Integration of multiple ISO Management...
Digital Maturity – Business as Usual & Integration of multiple ISO Management...Alvin Integrated Services [AIS]
 
Thinking beyond “Conventional” Crisis Communication.
Thinking beyond “Conventional” Crisis Communication.Thinking beyond “Conventional” Crisis Communication.
Thinking beyond “Conventional” Crisis Communication.Alvin Integrated Services [AIS]
 
Effective Leadership – The Cornerstone – applied study on ISO 22000:2018 Food...
Effective Leadership – The Cornerstone – applied study on ISO 22000:2018 Food...Effective Leadership – The Cornerstone – applied study on ISO 22000:2018 Food...
Effective Leadership – The Cornerstone – applied study on ISO 22000:2018 Food...Alvin Integrated Services [AIS]
 
COVID – 19 and Resilience: Has ISO 22316 standard been responsive?
COVID – 19 and Resilience: Has ISO 22316 standard been responsive?COVID – 19 and Resilience: Has ISO 22316 standard been responsive?
COVID – 19 and Resilience: Has ISO 22316 standard been responsive?Alvin Integrated Services [AIS]
 
Business Continuity Management System: How, Why and for What?
Business Continuity Management System: How, Why and for What?Business Continuity Management System: How, Why and for What?
Business Continuity Management System: How, Why and for What?Alvin Integrated Services [AIS]
 

More from Alvin Integrated Services [AIS] (9)

Designing an effective Crisis Management Framework
Designing an effective Crisis Management FrameworkDesigning an effective Crisis Management Framework
Designing an effective Crisis Management Framework
 
Pandemic: Crisis or Opportunity? ISO 22301 best practice Implementation tips ...
Pandemic: Crisis or Opportunity? ISO 22301 best practice Implementation tips ...Pandemic: Crisis or Opportunity? ISO 22301 best practice Implementation tips ...
Pandemic: Crisis or Opportunity? ISO 22301 best practice Implementation tips ...
 
ISO 27017 – What are the Business Advantages of Cloud Security?
ISO 27017 – What are the Business Advantages of Cloud Security?ISO 27017 – What are the Business Advantages of Cloud Security?
ISO 27017 – What are the Business Advantages of Cloud Security?
 
Digital Maturity – Business as Usual & Integration of multiple ISO Management...
Digital Maturity – Business as Usual & Integration of multiple ISO Management...Digital Maturity – Business as Usual & Integration of multiple ISO Management...
Digital Maturity – Business as Usual & Integration of multiple ISO Management...
 
ISO 31000: Culture vs Documentation, the way forward
ISO 31000: Culture vs Documentation, the way forwardISO 31000: Culture vs Documentation, the way forward
ISO 31000: Culture vs Documentation, the way forward
 
Thinking beyond “Conventional” Crisis Communication.
Thinking beyond “Conventional” Crisis Communication.Thinking beyond “Conventional” Crisis Communication.
Thinking beyond “Conventional” Crisis Communication.
 
Effective Leadership – The Cornerstone – applied study on ISO 22000:2018 Food...
Effective Leadership – The Cornerstone – applied study on ISO 22000:2018 Food...Effective Leadership – The Cornerstone – applied study on ISO 22000:2018 Food...
Effective Leadership – The Cornerstone – applied study on ISO 22000:2018 Food...
 
COVID – 19 and Resilience: Has ISO 22316 standard been responsive?
COVID – 19 and Resilience: Has ISO 22316 standard been responsive?COVID – 19 and Resilience: Has ISO 22316 standard been responsive?
COVID – 19 and Resilience: Has ISO 22316 standard been responsive?
 
Business Continuity Management System: How, Why and for What?
Business Continuity Management System: How, Why and for What?Business Continuity Management System: How, Why and for What?
Business Continuity Management System: How, Why and for What?
 

Recently uploaded

AUDIENCE THEORY -CULTIVATION THEORY - GERBNER.pptx
AUDIENCE THEORY -CULTIVATION THEORY -  GERBNER.pptxAUDIENCE THEORY -CULTIVATION THEORY -  GERBNER.pptx
AUDIENCE THEORY -CULTIVATION THEORY - GERBNER.pptxiammrhaywood
 
Influencing policy (training slides from Fast Track Impact)
Influencing policy (training slides from Fast Track Impact)Influencing policy (training slides from Fast Track Impact)
Influencing policy (training slides from Fast Track Impact)Mark Reed
 
Textual Evidence in Reading and Writing of SHS
Textual Evidence in Reading and Writing of SHSTextual Evidence in Reading and Writing of SHS
Textual Evidence in Reading and Writing of SHSMae Pangan
 
Student Profile Sample - We help schools to connect the data they have, with ...
Student Profile Sample - We help schools to connect the data they have, with ...Student Profile Sample - We help schools to connect the data they have, with ...
Student Profile Sample - We help schools to connect the data they have, with ...Seán Kennedy
 
Activity 2-unit 2-update 2024. English translation
Activity 2-unit 2-update 2024. English translationActivity 2-unit 2-update 2024. English translation
Activity 2-unit 2-update 2024. English translationRosabel UA
 
EMBODO Lesson Plan Grade 9 Law of Sines.docx
EMBODO Lesson Plan Grade 9 Law of Sines.docxEMBODO Lesson Plan Grade 9 Law of Sines.docx
EMBODO Lesson Plan Grade 9 Law of Sines.docxElton John Embodo
 
USPS® Forced Meter Migration - How to Know if Your Postage Meter Will Soon be...
USPS® Forced Meter Migration - How to Know if Your Postage Meter Will Soon be...USPS® Forced Meter Migration - How to Know if Your Postage Meter Will Soon be...
USPS® Forced Meter Migration - How to Know if Your Postage Meter Will Soon be...Postal Advocate Inc.
 
TEACHER REFLECTION FORM (NEW SET........).docx
TEACHER REFLECTION FORM (NEW SET........).docxTEACHER REFLECTION FORM (NEW SET........).docx
TEACHER REFLECTION FORM (NEW SET........).docxruthvilladarez
 
How to Add Barcode on PDF Report in Odoo 17
How to Add Barcode on PDF Report in Odoo 17How to Add Barcode on PDF Report in Odoo 17
How to Add Barcode on PDF Report in Odoo 17Celine George
 
Oppenheimer Film Discussion for Philosophy and Film
Oppenheimer Film Discussion for Philosophy and FilmOppenheimer Film Discussion for Philosophy and Film
Oppenheimer Film Discussion for Philosophy and FilmStan Meyer
 
Incoming and Outgoing Shipments in 3 STEPS Using Odoo 17
Incoming and Outgoing Shipments in 3 STEPS Using Odoo 17Incoming and Outgoing Shipments in 3 STEPS Using Odoo 17
Incoming and Outgoing Shipments in 3 STEPS Using Odoo 17Celine George
 
4.18.24 Movement Legacies, Reflection, and Review.pptx
4.18.24 Movement Legacies, Reflection, and Review.pptx4.18.24 Movement Legacies, Reflection, and Review.pptx
4.18.24 Movement Legacies, Reflection, and Review.pptxmary850239
 
Virtual-Orientation-on-the-Administration-of-NATG12-NATG6-and-ELLNA.pdf
Virtual-Orientation-on-the-Administration-of-NATG12-NATG6-and-ELLNA.pdfVirtual-Orientation-on-the-Administration-of-NATG12-NATG6-and-ELLNA.pdf
Virtual-Orientation-on-the-Administration-of-NATG12-NATG6-and-ELLNA.pdfErwinPantujan2
 
Inclusivity Essentials_ Creating Accessible Websites for Nonprofits .pdf
Inclusivity Essentials_ Creating Accessible Websites for Nonprofits .pdfInclusivity Essentials_ Creating Accessible Websites for Nonprofits .pdf
Inclusivity Essentials_ Creating Accessible Websites for Nonprofits .pdfTechSoup
 
Choosing the Right CBSE School A Comprehensive Guide for Parents
Choosing the Right CBSE School A Comprehensive Guide for ParentsChoosing the Right CBSE School A Comprehensive Guide for Parents
Choosing the Right CBSE School A Comprehensive Guide for Parentsnavabharathschool99
 
Grade 9 Quarter 4 Dll Grade 9 Quarter 4 DLL.pdf
Grade 9 Quarter 4 Dll Grade 9 Quarter 4 DLL.pdfGrade 9 Quarter 4 Dll Grade 9 Quarter 4 DLL.pdf
Grade 9 Quarter 4 Dll Grade 9 Quarter 4 DLL.pdfJemuel Francisco
 
HỌC TỐT TIẾNG ANH 11 THEO CHƯƠNG TRÌNH GLOBAL SUCCESS ĐÁP ÁN CHI TIẾT - CẢ NĂ...
HỌC TỐT TIẾNG ANH 11 THEO CHƯƠNG TRÌNH GLOBAL SUCCESS ĐÁP ÁN CHI TIẾT - CẢ NĂ...HỌC TỐT TIẾNG ANH 11 THEO CHƯƠNG TRÌNH GLOBAL SUCCESS ĐÁP ÁN CHI TIẾT - CẢ NĂ...
HỌC TỐT TIẾNG ANH 11 THEO CHƯƠNG TRÌNH GLOBAL SUCCESS ĐÁP ÁN CHI TIẾT - CẢ NĂ...Nguyen Thanh Tu Collection
 

Recently uploaded (20)

AUDIENCE THEORY -CULTIVATION THEORY - GERBNER.pptx
AUDIENCE THEORY -CULTIVATION THEORY -  GERBNER.pptxAUDIENCE THEORY -CULTIVATION THEORY -  GERBNER.pptx
AUDIENCE THEORY -CULTIVATION THEORY - GERBNER.pptx
 
Influencing policy (training slides from Fast Track Impact)
Influencing policy (training slides from Fast Track Impact)Influencing policy (training slides from Fast Track Impact)
Influencing policy (training slides from Fast Track Impact)
 
Textual Evidence in Reading and Writing of SHS
Textual Evidence in Reading and Writing of SHSTextual Evidence in Reading and Writing of SHS
Textual Evidence in Reading and Writing of SHS
 
Student Profile Sample - We help schools to connect the data they have, with ...
Student Profile Sample - We help schools to connect the data they have, with ...Student Profile Sample - We help schools to connect the data they have, with ...
Student Profile Sample - We help schools to connect the data they have, with ...
 
Activity 2-unit 2-update 2024. English translation
Activity 2-unit 2-update 2024. English translationActivity 2-unit 2-update 2024. English translation
Activity 2-unit 2-update 2024. English translation
 
EMBODO Lesson Plan Grade 9 Law of Sines.docx
EMBODO Lesson Plan Grade 9 Law of Sines.docxEMBODO Lesson Plan Grade 9 Law of Sines.docx
EMBODO Lesson Plan Grade 9 Law of Sines.docx
 
FINALS_OF_LEFT_ON_C'N_EL_DORADO_2024.pptx
FINALS_OF_LEFT_ON_C'N_EL_DORADO_2024.pptxFINALS_OF_LEFT_ON_C'N_EL_DORADO_2024.pptx
FINALS_OF_LEFT_ON_C'N_EL_DORADO_2024.pptx
 
USPS® Forced Meter Migration - How to Know if Your Postage Meter Will Soon be...
USPS® Forced Meter Migration - How to Know if Your Postage Meter Will Soon be...USPS® Forced Meter Migration - How to Know if Your Postage Meter Will Soon be...
USPS® Forced Meter Migration - How to Know if Your Postage Meter Will Soon be...
 
Paradigm shift in nursing research by RS MEHTA
Paradigm shift in nursing research by RS MEHTAParadigm shift in nursing research by RS MEHTA
Paradigm shift in nursing research by RS MEHTA
 
TEACHER REFLECTION FORM (NEW SET........).docx
TEACHER REFLECTION FORM (NEW SET........).docxTEACHER REFLECTION FORM (NEW SET........).docx
TEACHER REFLECTION FORM (NEW SET........).docx
 
How to Add Barcode on PDF Report in Odoo 17
How to Add Barcode on PDF Report in Odoo 17How to Add Barcode on PDF Report in Odoo 17
How to Add Barcode on PDF Report in Odoo 17
 
Oppenheimer Film Discussion for Philosophy and Film
Oppenheimer Film Discussion for Philosophy and FilmOppenheimer Film Discussion for Philosophy and Film
Oppenheimer Film Discussion for Philosophy and Film
 
LEFT_ON_C'N_ PRELIMS_EL_DORADO_2024.pptx
LEFT_ON_C'N_ PRELIMS_EL_DORADO_2024.pptxLEFT_ON_C'N_ PRELIMS_EL_DORADO_2024.pptx
LEFT_ON_C'N_ PRELIMS_EL_DORADO_2024.pptx
 
Incoming and Outgoing Shipments in 3 STEPS Using Odoo 17
Incoming and Outgoing Shipments in 3 STEPS Using Odoo 17Incoming and Outgoing Shipments in 3 STEPS Using Odoo 17
Incoming and Outgoing Shipments in 3 STEPS Using Odoo 17
 
4.18.24 Movement Legacies, Reflection, and Review.pptx
4.18.24 Movement Legacies, Reflection, and Review.pptx4.18.24 Movement Legacies, Reflection, and Review.pptx
4.18.24 Movement Legacies, Reflection, and Review.pptx
 
Virtual-Orientation-on-the-Administration-of-NATG12-NATG6-and-ELLNA.pdf
Virtual-Orientation-on-the-Administration-of-NATG12-NATG6-and-ELLNA.pdfVirtual-Orientation-on-the-Administration-of-NATG12-NATG6-and-ELLNA.pdf
Virtual-Orientation-on-the-Administration-of-NATG12-NATG6-and-ELLNA.pdf
 
Inclusivity Essentials_ Creating Accessible Websites for Nonprofits .pdf
Inclusivity Essentials_ Creating Accessible Websites for Nonprofits .pdfInclusivity Essentials_ Creating Accessible Websites for Nonprofits .pdf
Inclusivity Essentials_ Creating Accessible Websites for Nonprofits .pdf
 
Choosing the Right CBSE School A Comprehensive Guide for Parents
Choosing the Right CBSE School A Comprehensive Guide for ParentsChoosing the Right CBSE School A Comprehensive Guide for Parents
Choosing the Right CBSE School A Comprehensive Guide for Parents
 
Grade 9 Quarter 4 Dll Grade 9 Quarter 4 DLL.pdf
Grade 9 Quarter 4 Dll Grade 9 Quarter 4 DLL.pdfGrade 9 Quarter 4 Dll Grade 9 Quarter 4 DLL.pdf
Grade 9 Quarter 4 Dll Grade 9 Quarter 4 DLL.pdf
 
HỌC TỐT TIẾNG ANH 11 THEO CHƯƠNG TRÌNH GLOBAL SUCCESS ĐÁP ÁN CHI TIẾT - CẢ NĂ...
HỌC TỐT TIẾNG ANH 11 THEO CHƯƠNG TRÌNH GLOBAL SUCCESS ĐÁP ÁN CHI TIẾT - CẢ NĂ...HỌC TỐT TIẾNG ANH 11 THEO CHƯƠNG TRÌNH GLOBAL SUCCESS ĐÁP ÁN CHI TIẾT - CẢ NĂ...
HỌC TỐT TIẾNG ANH 11 THEO CHƯƠNG TRÌNH GLOBAL SUCCESS ĐÁP ÁN CHI TIẾT - CẢ NĂ...
 

ISO 31000:2018 Risk Management System, Framework and Implementation

  • 1. Contact us: info@alvinintegrated.com | +91 8802 505619, +91 8287509289 | www.alvinintegrated.com Platinum Sponsor OUR SPONSORS & PARTNERS Event Partner www.alvinintegrated.com Knowledge Partners 27th FEB 2021 (SATURDAY) 09:00 AM - 17:30 PM IST
  • 2. ISO 31000:2018 Risk Management System, Framework and Implementation 27th February 2021 (Saturday) Time: 09:05 am - 09:30 am IST ISO 31000:2018 By Sanjay Gore, Principal Consultant, Alvin Integrated Service [AIS]
  • 3. Speaker Introduction: Mr. Sanjay Gore hails from Pune, Maharashtra, India, is a Senior Consultant and Speaker on Information Security, Risk Management and Privacy. He has rich experience of 20 years in working with customers in India, Middle East at top management level, business owners and technical team members for securing and deploying information security and risk management and privacy solutions. He holds professional designations such as: ISO-27001-LA, ISO 27005- RM, CDPSE CPISI, CRMA, CISA, and CRISC. He is certified Trainer in 27001 and 27005. Connect at LinkedIn: Sanjay Gore – LinkedinProfile Subscribe at YouTube: Sanjay Gore – youtubechannel Mr Sanjay Gore ISO-27001-LA, ISO 27005- RM, CDPSE CPISI, CRMA, CISA, and CRISC | Certified Trainer in 27001 and 27005 | Pune, Maharashtra – India
  • 4. Risk Opportunity or Threat?? 4 Threat 1. Find a way to avoid the risk 2. Find a way to transfer to another party ( Insurance, Contract conditions) 3. Find a way to mitigate the risk reducing probability or severeness Opportunity 1. Exploit the opportunity 2. Share with another party 3. Enhance by increasing the effect or the probability Accept Do nothing Risk
  • 5. Edifice of ISO 31000:2018 ISO 31000:2018 The principles provide the foundation and describe the qualities of effective risk management in an organization Principles ISO 31000:2018 Framework The framework manages the overall process and its full integration into the organization ISO 31000:2018 Process The process focuses on individual or groups of risks, their identification, analysis, evaluation and treatment 5
  • 6. ISO 31000:2018 Scope of Document 6 1. Managing risk faced by organizations. 2. The application of these guidelines can be customized on any organization and its context. 3. This document provides a common approach to managing any type of risk and is not industry or sector specific 4. This document can be used throughout the life of the organization and can be applied to any activity, including decision making
  • 7. ISO 31000 Concepts, Terms and Definitions- 7 1. Risk is an effect of uncertainty on objectives 2. An effect is a deviation from the expected. 3. It can be positive, negative or both, and can address, create or result in opportunities and threats. 4. Objectives can have different aspects and categories, and can be applied at different levels. 5. Risk is usually expressed in terms of • Risk Sources • Potential Events • Their Consequences • Their Likelihood Risk
  • 8. ISO 31000 Concepts, Terms and Definitions- 8 • Event occurrence or change of a particular set of circumstances • An event can have one or more occurrences, and can have several causes and several consequences • An event can also be something that is expected which does not happen, or something that is not expected which does happen. • An event can be a risk source. Event
  • 9. ISO 31000 Concepts, Terms Definitions- 9 • Consequence is an outcome of an event affecting objectives • A consequence can be certain or uncertain and can have positive or negative direct or indirect effects on objectives. • Consequences can be expressed qualitatively or quantitatively. • Any consequence can escalate through cascading and cumulative effects. Consequence
  • 10. ISO 31000 Concepts, Terms and Definitions- 10 • Likelihood is chance of something happening • In risk management terminology, the word “likelihood” is used to refer to the chance of something happening, whether defined, measured or determined objectively or subjectively, qualitatively or quantitatively, and described using general terms or mathematically (such as a probability or a frequency over a given time period). The English term “likelihood” does not have a direct equivalent in some languages; instead, the equivalent of the term “probability” is often used. However, in English, “probability” is often narrowly interpreted as a mathematical term. Therefore, in risk management terminology, “likelihood” is used with the intent that it should have the same broad interpretation as the term “probability” has in many languages other than English. Likelihood
  • 11. ISO 31000 Concepts, Terms and Definitions- 11 Control measure that maintains and/or modifies risk • Controls include, but are not limited to, any process, policy, device, practice, or other conditions and/or actions which maintain and/or modify risk. • Controls may not always exert the intended or assumed modifying effect. Control
  • 12. ISO 31000:2018 Risk Management Principles 12 1. Integrated 2. Structured and comprehensive 3. Customized 4. Inclusive 5. Dynamic 6. Best available information 7. Human and cultural factors 8. Continual improvement Value Creation and Protection
  • 13. Continuous improvement Continuous improvement means that organizations are in a constant state of driving process improvements. This involves a focus on linear and incremental improvement within existing processes. Continual improvement A continual improvement mean that organizations go through process improvements in stages. Even and these stages are separate by a period of time. This period of time might be necessary to understand if the improvements did actually help the bottom line! In some cases, the results might take a while to come to fruition. Principles - Continual improvement 13
  • 14. Risk Management Framework 1. Integration 2. Design 3. Implementation 4. Evaluation 5. Improvement 14 1 2 3 4 5 Leadership and Commitment
  • 15. Risk Management Process 15 Scope Context Criteria Risk Treatment Recording and Reporting Communication and Consultation Monitoring and Review Risk Assessment Risk Identification Risk Analysis Risk Evaluation
  • 16. Process Defining Scope When planning the approach, considerations include 1. Objectives and decisions that need to be made 2. Outcomes expected from the steps to be taken in the process 3. Time, location, specific inclusions and exclusions 4. Appropriate risk assessment tools and techniques 5. Resources required, responsibilities and records to be kept 6. Relationships with other projects, processes and activities. 16
  • 17. Process Defining Risk Criteria To set risk criteria, the following should be considered 1. The nature and type of uncertainties that can affect outcomes and objectives (both tangible and intangible) 2. How consequences (both positive and negative) and likelihood will be defined and measured 3. Time-related factors 4. Consistency in the use of measurements 5. How the level of risk is to be determined 6. How combinations and sequences of multiple risks will be taken into account 7. The organization’s capacity 17
  • 18. Process Selection of Risk Treatment Options Depending on the type of risk and its significance to the business, management and the board may 1. Avoid- e.g., where feasible, choose not to implement certain activities or processes that would incur risk (i.e., eliminate the risk by eliminating the cause) 2. Mitigate lessen the probability or impact of the risk by defining, implementing, and monitoring appropriate controls. 3. Transfer (deflect, or allocate}-e.g.; share risk with partners or transfer via insurance coverage, contractual agreement, or other means. 4. Accept- formally acknowledge the existence of the risk and monitor it 18
  • 19. A few Risk Assessment Tools/ Techniques • Brainstorming • Delphi Technique • Checklists • Root Cause Analysis • Failure Mode Effect Analysis (FMEA ) And FMECA • Fault Tree Analysis (FTA) • Hazard Analysis (PHA) • Scenario analysis • Layers of protection analysis (LOPA) • Decision Tree Analysis • Monte Carlo simulation 19
  • 21. Please give your feedbacks in the chat box about the webinar.