您好,欢迎访问三七文档
当前位置:首页 > 商业/管理/HR > 信息化管理 > qITIL中级课程-风险管理
ContentsCHAPTER1:INTRODUCTIONCHAPTER2:PRINCIPLESCHAPTER3:HOWRISKSAREMANAGEDCHAPTER4:MANAGINGRISKATTHESTRATEGICLEVELCHAPTER5:MANAGINGRISKATTHEPROGRAMMELEVELCHAPTER6:MANAGINGRISKSATTHEPROJECTLEVELCHAPTER7:MANAGINGRISKATTHEOPERATIONALLEVELCHAPTER8:TECHNIQUESANNEXA:EXAMPLESOFBENEFITSOFRISKMANAGEMENTANNEXB:HEALTHCHECK:HOWWELLISYOURORGANISATIONMANAGINGRISK?ANNEXC:CATEGORISINGRISKANNEXD:SETTINGASTANDARDFOREVALUATIONOFRISKANNEXE:PROCUREMENT,CONTRACTUALANDLEGALCONSIDERATIONSANNEXF:BUSINESSCONTINUITYMANAGEMENTANNEXG:MANAGINGORGANISATIONALSAFETYANDSECURITYANNEXH:INFORMATIONONFURTHERTECHNIQUESTOSUPPORTMANAGEMENTOFRISKANNEXJ:LESSONSLEARNEDFROMOTHERSANNEXK:ASSESSINGTHESUITABILITYOFTOOLSANNEXL:DOCUMENTATIONOUTLINESCHAPTER1:INTRODUCTION1.1Purposeofthisguide1.2Whatismanagementofrisk?1.3Whymanagementofriskisimportant1.4Whoisinvolvedinriskmanagement1.5Howtousethisguide1.6Theresearchforthisguidance1.1PurposeofthisguideThisguideisintendedtohelporganisationstoputinplaceeffectiveframeworksfortakinginformeddecisionsaboutrisk.Theguidanceprovidesaroutemapforriskmanagement,bringingtogetherrecommendedapproaches,checklistsandpointerstomoredetailedsourcesofadviceontoolsandtechniques.ItexpandsontheOGCGuidelinesforManagingRisk.Theprocessofinvestmentappraisal,inwhichassessmentsaremadeofcosts,benefitsandrisks,isoutsidethescopeofthisguide.However,manyoftheprinciplesandtechniquesdescribedherecanbeusedwhendevelopingthebusinesscase.TheapproachdescribedinthisguidecomplementsOGC’sguidanceonprogrammeandprojectmanagementandiscontinuallyupdatedtoreflectcurrentthinking.Thisapproach,brandedbyOGCasM_o_R(ManagementofRisk),issupportedbytrainingandqualifications.1.2Whatismanagementofrisk?Inthisguideriskisdefinedasuncertaintyofoutcome,whetherpositiveopportunityornegativethreat.Theterm‘managementofrisk’incorporatesalltheactivitiesrequiredtoidentifyandcontroltheexposuretoriskwhichmayhaveanimpactontheachievementofanorganisation’sbusinessobjectives.Everyorganisationmanagesitsrisk,butnotalwaysinawaythatisvisible,repeatableandconsistentlyappliedtosupportdecisionmaking.Thetaskofmanagementofriskistoensurethattheorganisationmakescosteffectiveuseofariskprocessthathasaseriesofwelldefinedsteps.Theaimistosupportbetterdecisionmakingthroughagoodunderstandingofrisksandtheirlikelyimpact.Therearetwodistinctphases:riskanalysisandriskmanagement.Riskanalysisisconcernedwithgatheringinformationaboutexposuretorisksothattheorganisationcanmakeappropriatedecisionsandmanageriskappropriately.Managementofriskinvolveshavingprocessesinplacetomonitorrisks,accesstoreliableanduptodateinformationaboutrisks,therightbalanceofcontrolinplacetodealwiththoserisks,anddecisionmakingprocessessupportedbyaframeworkofriskanalysisandevaluation.Managementofriskcoversawiderangeoftopics,includingbusinesscontinuitymanagement,security,programme/projectriskmanagementandoperationalservicemanagement.Thesetopicsneedtobeplacedinthecontextofanorganisationalframeworkforthemanagementofrisk.Somerisk-relatedtopics,suchassecurity,arehighlyspecialisedandthisguidanceprovidesonlyanoverviewofsuchaspects.1.3WhymanagementofriskisimportantAcertainamountofrisktakingisinevitableifyourorganisationistoachieveitsobjectives.Effectivemanagementofriskhelpsyoutoimproveperformancebycontributingto:increasedcertaintyandfewersurprisesbetterservicedeliverymoreeffectivemanagementofchangemoreefficientuseofresourcesbettermanagementatalllevelsthroughimproveddecisionmakingreducedwasteandfraud,andbettervalueformoneyinnovationmanagementofcontingentandmaintenanceactivities.SeeAnnexAforexamplesofthebenefitsofmoreeffectivemanagementofrisk.1.4WhoisinvolvedinriskmanagementInpractice,everyoneinanorganisationisinvolvedinriskmanagementtosomeextentandshouldbeawareoftheirresponsibilitiesinidentifyingandmanagingrisk.However,therearesomeaspectsforwhichresponsibilitymustbeassignedtoindividuals.Withoutclearresponsibility(andtheauthoritytosupportthatresponsibility)someriskswillbemissedoroverlooked.Inthepublicsector,therearetwomajorroleswithaclearresponsibilitytoensurerisksaremanaged(therewillbeequivalentstotheserolesinprivatesectororganisations).Theserolesare:anAccountingOfficer(orequivalentseniormanager),whoisresponsiblefortheorganisation’soverallexposuretorisk.TypicallythispersonwillbetheChiefExecutiveOfficer(CEO);theseniormanagerintheorganisation.Theymaydelegatesomeoftheactionsbutcannotforgotheresponsibilityaseniormanageractingasaproject‘owner’,whoisresponsibleforriskrelatingtoaspecificprogrammeorprojectandfortherealisationofassociatedbusinessbenefits.AudienceforthisguidanceBusinessmanagers,processowners,strategicplanners,projectandprocurementteams,businesscontinuityplannersandsecurityteamsaretheprimaryaudienceforthisguidance,togetherwiththeirserviceproviders.Itwillalsobeofinteresttoauditors,withtheirresponsibilityforensuringeffectivecorporategovernance.1.5HowtousethisguideChapter1introducesthestructure,processandcultureofmanagementofrisk,explainingwhyorganisationsneedtodeviseandimplementeffectivestrategiesinordertomaximiseopportun
本文标题:qITIL中级课程-风险管理
链接地址:https://www.777doc.com/doc-507209 .html