Am working on an interim risk review questionnaire to trigger a review and updates to the current risk repository.
Reaching out to other ERM program managers with a request for any industry material used for your interim risk review process (vs. performing a comprehensive assessment) E.g., risk review questionnaire, top 2017/new risk considerations - economic, political, etc.
Replies
Hi,
There was a comment posted by Doug Nagan which was accidentally deleted.
The reason is that the system somehow posts duplicate comments and when one is deleted, both comments are removed. The ticket has been already issued with the support team, sorry for inconvenience.
Doug has added the management guide to fighting cyber predators.
I've attached this guide again.
Management guide to fighting cyber predators Global Risk-1.pdf
Shanti,
You can review the information risk assessment and management method mehari from
www.meharipedia.org
more precisely its knowledge base mehari expert (super excel),
It allows to get quantified results for the risk seriousness, either initial, current or at any future date (based on plans and projects),
The audit questionnaires are going further than just ITC and allows scoring of the organisation to ISO 27002:2013 controls
cyber threats are evidently considered ...
This can be extended to any other regulation (PCI/DSS, GDPR)
mehari is available free and open source
,
Shanti,
You can review the information risk assessment and management method mehari from
www.meharipedia.org
more precisely its knowledge base mehari expert (super excel),
It allows to get quantified results for the risk seriousness, either initial, current or at any future date (based on plans and projects),
The audit questionnaires are going further than just ITC and allows scoring of the organisation to ISO 27002:2013 controls
cyber threats are evidently considered ...
This can be extended to any other regulation (PCI/DSS, GDPR)
mehari is available free and open source
,
Hi Shanthi,
I attached a presentation on how to design the Operational Risk Framework.
This presentation is taken from our course: Mastering Operational Risk
Boris.
designing_orm_framework.ppt
Thanks Doug!