Risk Management
Contents
- 1 Definitions
- 1.1 European Definitions
- 1.2 Other International Definitions
- 1.3 National Definitions
- 1.3.1 Argentina
- 1.3.2 Australia
- 1.3.3 Canada
- 1.3.4 Cape Verde
- 1.3.5 Chile
- 1.3.6 Colombia
- 1.3.7 Cuba
- 1.3.8 Czech Republic
- 1.3.9 El Salvador
- 1.3.10 Finland
- 1.3.11 Gambia
- 1.3.12 Germany
- 1.3.13 Germany
- 1.3.14 Guatemala
- 1.3.15 India
- 1.3.16 Ireland
- 1.3.17 Japan
- 1.3.18 Kiribati
- 1.3.19 Kuwait
- 1.3.20 Liberia
- 1.3.21 Luxembourg
- 1.3.22 Netherlands
- 1.3.23 New Zealand/AOTEAROA
- 1.3.24 Norway
- 1.3.25 Peru
- 1.3.26 Philippines
- 1.3.27 Poland
- 1.3.28 Portugal
- 1.3.29 Republic of Trinidad & Tobago
- 1.3.30 Romania
- 1.3.31 Serbia
- 1.3.32 Singapore
- 1.3.33 Spain
- 1.3.34 Switzerland
- 1.3.35 United Arab Emirates
- 1.3.36 United Kingdom (UK)
- 1.3.37 United States
- 1.4 Standard Definition
- 1.5 Dictionary
- 2 See also
- 3 Notes
- 4 References
Definitions
European Definitions
Council of Europe
EU
ENISA
Other International Definitions
CARICOM
NATO CEP / EAPC
UNISDR
According to UNISDR, risk management comprises risk assessment and analysis, and the implementation of strategies and specific actions to control, reduce and transfer risks. It is widely practiced by organizations to minimise risk in investment decisions and to address operational risks such as those of business disruption, production failure, environmental damage, social impacts and damage from fire and natural hazards. Risk management is a core issue for sectors such as water supply, energy and agriculture whose production is directly affected by extremes of weather and climate.
رويكردي نظامند و به كاربستن مديريت عدم قطعيت براي به حداقل رساندن بالقوه آسيب و زيان
National Definitions
Argentina
NOTA. La gestión de riesgos usualmente incluye la evaluación de riesgos, el tratamiento de riesgos, la aceptación de riesgos y la comunicación de riesgos.
Australia
Canada
Gestion des risques: Recours à des politiques, à des pratiques et à des ressources pour analyser, évaluer et contrôler les risques pour la santé, la sécurité, l’environnement et l’économie. [19] [20]
Cape Verde
A gestão de riscos compreende a avaliação de riscos e análise e da implementação de estratégias e acções específicas para controlar, reduzir e transferir riscos (redução de riscos). É bastante praticada por organizações para minimizar o risco nas decisões de investimento e para enfrentar os riscos operacionais, tais como de interrupção de negócios, falha de produção, danos ambientais, impactos sociais e danos causados pelo fogo e desastres naturais. A gestão de riscos é uma questão central para sectores tais como o de abastecimento de água, energia e agricultura, cuja produção é directamente afectado por eventos climáticos extremos.
Chile
Acciones integradas de reducción de riesgos a través de actividades de prevención, mitigación, preparación para, y atención de emergencias y recuperación post impacto.
Colombia
Cuba
Czech Republic
Risk management are coordinated activities to manage and control an organization in view of the risks. [28]
El Salvador
Finland
Risk management is a systematic action which includes risk analysis as well as the planning, execution and follow-up of operations needed and the corrective operations. -unofficial translation- [30]
Gambia
Germany
Germany
Guatemala
India
Ireland
Japan
(Cyber) Risk management is the process of identifying, controlling, and eliminating or minimizing uncertain events that may affect system resources. [39]
Kiribati
Risk management involves doing conscious, planned activities to address climate risk.
Kuwait
Risk management: it is a continuous process of identifying potential risks, analysis and evaluation of their impact and maintained the risk at an acceptable level. Risk management enables organizations to define policies and controls which are the most likely to protect the assets. [43]
Liberia
Luxembourg
Netherlands
Risicomanagement is het proces dat beoogt risico's te inventariseren en te beheersen. [47]
Risico management/manipulatie: Het proces van afweging van beleidsalternatieven om geschatte risico’s te accepteren, minimaliseren of reduceren en de geschikte mogelijkheden te selecteren en uitvoeren.
Risk management: The process of weighing policy alternatives to accept, minimize or reduce assessed risks and to select and implement appropriate options. [48]
New Zealand/AOTEAROA
The level of risk is arrived at by examining the likelihood and consequences of the hazard and whether the course of action is acceptable for the outcome that needs to be achieved. (Likelihood x Consequences = Risk).
Norway
Risk management is the entire process of defining in what areas and for what adverse events risk analyses should be conducted, conducting the risk analyses, evaluating the risk results (whether the level of risk is justifiable or not) and implementing any risk-reduction measures. [51]
Peru
Philippines
Poland
Portugal
Republic of Trinidad & Tobago
Romania
Riscurile sunt uzual urmărite, în paralel cu identificarea şi analizarea unora noi, iar planurile de atenuare pentru un risc pot conduce la descoperirea altor riscuri.
Managementul riscului: un proces complex, continuu şi flexibil de identificare, evaluare şi contracarare a riscurilor la adresa securităţii cibernetice, bazat pe utilizarea unor tehnici şi instrumente complexe, pentru prevenirea pierderilor de orice natură. [61]
Serbia
Singapore
Spain
Switzerland
United Arab Emirates
United Kingdom (UK)
Risk Management is a process of identifying, understanding, managing, controlling, monitoring and communicating risk. [70]
Risk Management is putting in place plans to avoid unacceptable consequences of risks. [71]
United States
DHS
NIST
US-CERT
White House
Information sharing facilitates and supports all of these activities.
Standard Definition
IETF
ISO/IEC 27000:2014, ISO 31000:2009 and ISO 22301:2012
These standards defines risk management as:
Definition is based on the ISO Guide 73:2009. [80]
Risk management process is the systematic application of management policies, procedures and practices to the activities of
communicating, consulting, establishing the context and identifying, analysing, evaluating, treating,
monitoring and reviewing risk. [77] (based on the ISO Guide 73:2009 [80]). ISO/IEC 27005 uses the term ‘process’ to describe risk management overall. The elements within the risk management process are termed ‘activities’.
Dictionary
See also
- Disaster Risk
- Risk Analysis
- Risk Assessment
- Risk Identification
- Risk Transfer
- Risk Treatment
- Risk Mitigation
Notes
References
- Jump up ↑ GLOSSAIRE MULTILINGUE DE LA GESTION DU RISQUE pour usagers francophones (2007)/European Centre of Technological Safety (TESEC) - TESEC-EUR-OPA 2001)
- Jump up ↑ European Commission's CBRN Glossary, 2012
- Jump up ↑ ENISA Risk Glossary
- Jump up ↑ Caribbean Disaster Emergency Management Agency (CDEMA) Regional Comprehensive Disaster Management Strategy and Results Framework 2014-2024
- Jump up ↑ NATO EAPC(SCEPC) lexicon.
- Jump up ↑ 2009 UNISDR Terminology on Disaster Risk Reduction
- Jump up ↑ UNISDR glossary
- Jump up ↑ UNISDR glossary
- Jump up ↑ UNISDR glossary
- Jump up ↑ UNISDR glossary
- Jump up ↑ UNISDR glossary in Bahasa
- Jump up ↑ UNISDR glossary in Malay
- Jump up ↑ UNISDR glossary in Tagalog
- Jump up ↑ Internationally agreed glossary of basic terms related to Disaster Management in Farsi
- Jump up ↑ Oficina Nacional de Tecnologías de Información ADMINISTRACION PUBLICA NACIONAL Disposición 3/2013 - Apruébase la “Política de Seguridad de la Información Modelo” (2013)
- Jump up ↑ Australian Emergency Management Glossary, Emergency Management Australia (1998)
- Jump up ↑ Australia AS NZS 5050 (2010)
- Jump up ↑ ADAPTATION TO CLIMATE CHANGE: KEY TERMS, E. Levina and D. Terpak, OECD (2006) - derived from (Australian Greenhouse Office. 2003)
- Jump up ↑ An Emergency Management Framework for Canada (Second Edition)
- Jump up ↑ Vocabulaire de la gestion des urgencies/Emergency Management Emergency Management Vocabulary 281 (2012)
- Jump up ↑ Guide Analyse de risques d'accidents technologiques majeurs (2002)
- Jump up ↑ Avaliação das Necessidades Pós- Desastre (PDNA) ERUPÇÃO VULCÂNICA NO FOGO 2014-2015, Cape Verde
- Jump up ↑ GUÍA ANÁLISIS DE RIESGOS NATURALES PARA EL ORDENAMIENTO TERRITORIAL Subsecretaría de Desarrollo Regional y Administrativo (SUBDERE) Primera Edición, Junio 2011
- Jump up ↑ Glosario Policia Colombia
- Jump up ↑ Glosario Policia Colombia
- Jump up ↑ Glossary of Cyber terms/Glosario de términos, Centro de Seguridad del Ciberespacio
- Jump up ↑ Výkladový slovník kybernetické bezpečnosti (2013)
- Jump up ↑ Act No. 181 of 23 July 2014 On Cyber Security and Change of Related Acts (Act on Cyber Security)
- Jump up ↑ Glosario de Riesgo, Ministerio de Medio Ambiente y Recursos Naturales, El Salvador
- Jump up ↑ Vocabulary of Comprehensive Security. Helsinki (TSK 47) (2014)
- Jump up ↑ THE GAMBIA NATIONAL CYBERSECURITY STRATEGY (2019)
- Jump up ↑ Protection of Critical Infrastructures – Baseline Protection Concept: Recommendation for Companies, BMI.
- Jump up ↑ Glossar BBK
- Jump up ↑ BSI Glossary
- Jump up ↑ Plan Estratégico de Seguridad de la Nación 2016-2020, Guatemala
- Jump up ↑ India's DGQA Cyber Security Policy (2015)
- Jump up ↑ National Disaster Management Plan (NDMP)- (2016)
- Jump up ↑ A FRAMEWORK FOR MAJOR EMERGENCY MANAGEMENT (APPENDICES)
- Jump up ↑ RFC2828 (Japanese translation)
- Jump up ↑ 重要インフラのサイバーセキュリティを 向上させるためのフレームワーク (2014)
- Jump up ↑ Kiribati BI-LINGUAL GLOSSARY OF CLIMATE CHANGE TERMS, Original translations by Dr Temakei Tebano & Etita Teiabauri, 2008
- Jump up ↑ الاستراتيجية الوطنية للأمن السيبراني لدولة الكويت (2017-2020)
- Jump up ↑ National Cyber Security Strategy 2017-2020
- Jump up ↑ Government of Liberia’s Policy for the Telecommunications and Information Communications Technology (ICT) sectors
- Jump up ↑ Glossaire
- Jump up ↑ Beveiligingsvoorschrift Rijksdienst 2013
- Jump up ↑ Zakboekje Preventie Cybercrime (2008
- Jump up ↑ Patiëntveiligheid Definitielijst (2005)
- Jump up ↑ The New Zealand Coordinated Incident Management System, Department of the Prime Minister and Cabinet, New Zealand. (2014)
- Jump up ↑ DSB, National Risikobild 2014
- Jump up ↑ DSB, National Risk Analysis 2014
- Jump up ↑ El Centro Nacional de Estimación, Prevención y Reducción del Riesgo de Desastres - CENEPRED, Glosario de Términos, Peru
- Jump up ↑ DND GLOSSARY OF CYBER SECURITY TERMS (v.4)
- Jump up ↑ DND GLOSSARY OF CYBER SECURITY TERMS (v.4)
- Jump up ↑ DND GLOSSARY OF CYBER SECURITY TERMS (v.4)
- Jump up ↑ NHS Cyber security glossary
- Jump up ↑ U S TAWA z dnia o krajowym systemie cyberbezpieczeństwa / Polish (draft) law on the national cybersecurity system (2018)
- Jump up ↑ Glossário Centro National de Cibersegurança Portugal
- Jump up ↑ Comprehensive Disaster Management Policy Framework for Trinidad and Tobago
- Jump up ↑ GLOSAR de termeni din domeniul ordinii şi siguranţei publice, MINISTERUL ADMINISTRAŢIEI ŞI INTERNELOR DIRECŢIA GENERALĂ ORGANIZARE, PLANIFICARE MISIUNI ŞI RESURSE
- Jump up ↑ Hotărârea nr. 271/2013 pentru aprobarea Strategiei de securitate cibernetică
- Jump up ↑ ЗАКОН О ИНФОРМАЦИОНОЈ БЕЗБЕДНОСТИ (Law on Information Security), Serbia
- Jump up ↑ Foresight: A Glossary, Civil Service College, Singapore
- Jump up ↑ CIBERSEGURIDAD. RETOS Y AMENAZAS A LA SEGURIDAD NACIONAL EN EL CIBERESPACIO, MINISTERIO DE DEFENSA (2010)
- Jump up ↑ CIBERSEGURIDAD. RETOS Y AMENAZAS A LA SEGURIDAD NACIONAL EN EL CIBERESPACIO, MINISTERIO DE DEFENSA (2010)
- Jump up ↑ Leitfaden Schutz kritischer Infrastrukturen 2015 pointing at ISO 31000
- Jump up ↑ Guide pour la protection des infrastructures critiques 2015/Glossaire des risques, Office fédéral de la protection de la population, 29.4.2013
- Jump up ↑ Abu Dhabi Safety and Security Planning Manual
- Jump up ↑ Glossary - Revision to Emergency Preparedness, Cabinet Office (2012)
- Jump up ↑ Cabinet Office, Section A: Introduction, Definitions and Principles of Infrastructure Resilience n.d.
- Jump up ↑ The National Adaptation Programme: Making the country resilient to a changing climate, UK Government (2013)
- Jump up ↑ DHS Risk Lexicon 2010 Edition, September 2010
- Jump up ↑ NIST Special Publication 800-53 Rev 4: Security and Privacy Controls for Federal Information Systems and Organizations (April 2013)
- Jump up ↑ Cyber Resilience Review (CRR): Method Description and Self-Assessment User Guide (2016)
- Jump up ↑ Presidential Executive Order on Strengthening the Cybersecurity of Federal Networks and Critical Infrastructure (May 11, 2017
- Jump up ↑ IETF RFC449 Internet Security Glossary 2
- ↑ Jump up to: 77.0 77.1 ISO/IEC 27000:2014, Information technology -- Security techniques -- Information security management systems -- Overview and vocabulary
- Jump up ↑ ISO/IEC 31000:2009, Risk management -- Principles and guidelines
- Jump up ↑ ISO 22301:2012 Societal security -- Business continuity management systems --- Requirements
- ↑ Jump up to: 80.0 80.1 ISO Guide 73:2009 Risk management -- Vocabulary
- Jump up ↑ Cybersecurity Woordenboek 2021