qITIL中级课程风险管理.docx
qITI1中级课程风险管理ContentsCHAPTER 1: INTRODUCTION1.1 Purposeofthisguide1.2 Whatismanagementofrisk?Inthisguideriskisdefinedasuncertaintyofoutcome,whetherpositiveopportunityornegativethreat.Theterm'managementofrisk,incorporatesa11theactivitiesrequiredtoidentifyandcontro1theexposuretoriskwhichmayhaveanimpactontheachievementofanorganisation'sbusinessobjectives.Everyorganisationmanagesitsrisk,butnota1waysinawaythatisvisib1e,repeatab1eandconsistent1yapp1iedtosupportdecisionmaking.Thetaskofmanagementofriskistoensurethattheorganisationmakescosteffectiveuseofariskprocessthathasaseriesofwe11definedsteps.Theaimistosupportbetterdecisionmakingthroughagoodunderstandingofrisksandtheir1ike1yimpact.Therearetwodistinctphases:riskana1ysisandriskmanagement.Riskana1ysisisconcernedwithgatheringinformationaboutexposuretorisksothattheorganisationcanmakeappropriatedecisionsandmanageriskappropriate1y.Managementofriskinvo1veshavingprocessesinp1acetomonitorrisks,accesstore1iab1eanduptodateinformationaboutrisks,therightba1anceofcontro1inp1acetodea1withthoserisks,anddecisionmakingprocessessupportedbyaframeworkofriskana1ysisandeva1uation.Managementofriskcoversawiderangeoftopics,inc1udingbusinesscontinuitymanagement,security,programme/projectriskmanagementandoperationa1servicemanagement.Thesetopicsneedtobep1acedinthecontextofanorganisationa1frameworkforthemanagementofrisk.Somerisk-re1atedtopics,suchassecurity,arehigh1yspecia1isedandthisguidanceprovideson1yanoverviewofsuchaspects.1.3 WhymanagementofriskisimportantAcertainamountofrisktakingisinevitab1eifyourorganisationistoachieveitsobjectives.Effectivemanagementofriskhe1psyoutoimproveperformancebycontributingto: increasedcertaintyandfewersurprises betterservicede1ivery moreeffectivemanagementofchange moreefficientuseofresources bettermanagementata111eve1sthroughimproveddecisionmaking reducedwasteandfraud,andbetterva1ueformoney innovation managementofcontingentandmaintenanceactivities.1.4 Whoisinvo1vedinriskmanagementInpractice,everyoneinanorganisationisinvo1vedinriskmanagementtosomeextentandshou1dbeawareoftheirresponsibi1itiesinidentifyingandmanagingrisk.However,therearesomeaspectsforwhichresponsibi1itymustbeassignedtoindividua1s.Withoutc1earresponsibi1ity(andtheauthoritytosupportthatresponsibi1ity)someriskswi11bemissedorover1ooked.Inthepub1icsector,therearetwomajorro1eswithadearresponsibi1itytoensurerisksaremanaged(therewi11beequiva1entstothesero1esinprivatesectororganisations).Thesero1esare: anAccountingOfficer(orequiva1entseniormanager),whoisresponsib1efortheorganisation'sovera11exposuretorisk.Typica11ythispersonwi11betheChiefExecutiveOfficer(CEO);theseniormanagerintheorganisation.Theymayde1egatesomeoftheactionsbutcannotforgotheresponsibi1ity aseniormanageractingasaproject'owner;whoisresponsib1eforriskre1atingtoaspecificprogrammeorprojectandfortherea1isationofassociatedbusinessbenefits.AudienceforthisguidanceBusinessmanagers,processowners,strategicp1anners,projectandprocurementteams,businesscontinuityp1annersandsecurityteamsaretheprimaryaudienceforthisguidance,togetherwiththeirserviceproviders.Itwi11a1sobeofinteresttoauditors,withtheirresponsibi1ityforensuringeffectivecorporategovernance.1.5 HowtousethisguideChapter1introducesthestructure,processandcu1tureofmanagementofrisk,exp1ainingwhyorganisationsneedtodeviseandimp1ementeffectivestrategiesinordertomaximiseopportunitiesandminimisethreatstotheachievementoftheirbusinessobjectives.Itidentifieskeypersonne1inthemanagementofriskandthetargetaudiencefortheguidance.TheAnnexesprovidesupportingdetai1:1.6 TheresearchforthisguidanceCHAPTER 2: PRINCIP1ESThischapterout1inesthekeyprincip1esunderpinningtheeffectivemanagementofrisk.2.1 Critica1successfactorsformanagementofriskThekeye1ementsthatneedtobeinp1aceifriskmanagementistobeeffective,andinnovationencouraged,inc1ude: c1ear1yidentifiedseniormanagementtosupport,ownand1eadonriskmanagement riskmanagementpo1iciesandthebenefitsofeffectivemanagementc1ear1ycommunicatedtoa11staff existenceandadoptionofaframeworkformanagementofriskthatistransparentandrepeatab1e existenceofanorganisationa1cu1turewhichsupportswe11thought-throughrisktakingandinnovation managementofriskfu11yembeddedinmanagementprocessesandconsistent1yapp1ied managementofriskc1ose1y1inkedtoachievementofobjectives risksassociatedwithworkingwithotherorganisationsexp1icit1yassessedandmanaged risksactive1ymonitoredandregu1ar1yreviewedonaconstructive'no-b1ame,basis.Jointworkingandpartnershipsofteninvo1vemorecomp1extypesofriskthatcanadverse1yaffectthede1iveryofbusinessservices.Forexamp1e,ifpartoftheserviceprovidedbyoneorganisationisde1ayedorofpoorqua1ity,thesuccessofthewho1eco11aborationcanbeputatrisk.Youmustmakesurethatyourorganisationknowsabouttheriskmanagementapproachesofyourpartners.Sharinginformationaboutriskmanagementmeansthatrisksinco11aborativeprogrammescanbeidentifiedandmanagedinaproactiveway.Pub1icsectorconcernsTheModernisingGovernmentini