Difference between revisions of "Risk Management"

From CIPedia
Jump to navigation Jump to search
(Definitions)
Line 1: Line 1:
 
==Definitions==
 
==Definitions==
 
=== European Definitions ===
 
=== European Definitions ===
[CBRN] The process, distinct from [[Risk Assessment]], of weighing policy alternatives, in consultation with all interested parties, considering risk assessment and other factors relevant for the health protection of workers and consumers, the protection of the environment and for the promotion of fair trade practices, and, if needed, selecting appropriate [[prevention]] and [[control]] options <ref name="CBRN">[https://cbrn.jrc.ec.europa.eu European Commission's CBRN Glossary, 2012]</ref>.
+
{{definition|[CBRN] The process, distinct from [[Risk Assessment]], of weighing policy alternatives, in consultation with all interested parties, considering risk assessment and other factors relevant for the health protection of workers and consumers, the protection of the environment and for the promotion of fair trade practices, and, if needed, selecting appropriate [[prevention]] and [[control]] options <ref name="CBRN">[https://cbrn.jrc.ec.europa.eu European Commission's CBRN Glossary, 2012]</ref>.}}
  
 
=== Other International Definitions ===
 
=== Other International Definitions ===
 
==== UNISDR ====
 
==== UNISDR ====
The systematic approach and practice of managing uncertainty to minimize potential [[harm]] and [[loss]].<ref> [http://www.unisdr.org/files/7817_UNISDRTerminologyEnglish.pdf 2009 UNISDR Terminology on Disaster Risk Reduction]</ref>. According to UNISDR, risk management comprises [[Risk Asessment|risk assessment]] and [[Risk Analyis|analysis]], and the implementation of strategies and specific actions to control, reduce and
+
{{definition|The systematic approach and practice of managing uncertainty to minimize potential [[harm]] and [[loss]].<ref> [http://www.unisdr.org/files/7817_UNISDRTerminologyEnglish.pdf 2009 UNISDR Terminology on Disaster Risk Reduction]</ref>.}}
transfer risks. It is widely practiced by organizations to minimise risk in investment decisions and to address operational risks such as those of business disruption, production failure, environmental damage, social impacts and damage from fire and natural hazards. Risk management is a core issue for sectors such as water supply, energy and agriculture whose production is directly affected by extremes of weather and climate.
+
 
 +
<big>According to UNISDR, risk management comprises [[Risk Asessment|risk assessment]] and [[Risk Analyis|analysis]], and the implementation of strategies and specific actions to control, reduce and transfer risks. It is widely practiced by organizations to minimise risk in investment decisions and to address operational risks such as those of business disruption, production failure, environmental damage, social impacts and damage from fire and natural hazards. Risk management is a core issue for sectors such as water supply, energy and agriculture whose production is directly affected by extremes of weather and climate.</big>
  
 
=== National Definitions ===
 
=== National Definitions ===
 
====USA====
 
====USA====
Process of identifying, analyzing, and communicating risk and accepting, avoiding, transferring or controlling it to an acceptable level at an acceptable cost <ref name="DHSLex"> [http://www.dhs.gov/xlibrary/assets/dhs-risk-lexicon-2010.pdf DHS Risk Lexicon 2010 Edition, September 2010]</ref>.
+
{{definition|Process of identifying, analyzing, and communicating risk and accepting, avoiding, transferring or controlling it to an acceptable level at an acceptable cost <ref name="DHSLex"> [http://www.dhs.gov/xlibrary/assets/dhs-risk-lexicon-2010.pdf DHS Risk Lexicon 2010 Edition, September 2010]</ref>.}}
  
Prioritizing, evaluating, and implementing the appropriate risk -reducing [[control|controls]]/[[countermeasure|countermeasures]] recommended from the risk management process.
+
{{definition|Prioritizing, evaluating, and implementing the appropriate risk -reducing [[control|controls]]/[[countermeasure|countermeasures]] recommended from the risk management process. (Source: CNSSI-4009; NIST SP 800-30; NIST SP 800-39)}}
(Source: CNSSI-4009; NIST SP 800-30; NIST SP 800-39)
 
  
 
===Standard Definition===
 
===Standard Definition===
 
==== ISO/IEC 27000:2014 ====
 
==== ISO/IEC 27000:2014 ====
The standard defines risk management as "coordinated activities to direct and control an organization with regard to [[risk]]<ref name="ISO27000-14"> [http://www.iso.org/iso/home/store/catalogue_ics/catalogue_detail_ics.htm?csnumber=63411 ISO/IEC 27000:2014, Information technology -- Security techniques -- Information security management systems -- Overview and vocabulary]</ref>(based on the ISO Guide 73:2009<ref name="ISOGuide73">[http://www.iso.org/iso/catalogue_detail?csnumber=44651 ISO Guide 73:2009 Risk management -- Vocabulary]</ref>) .
+
<big>The standard defines risk management as</big>
Risk management process is the systematic application of management policies, procedures and practices to the activities of
+
{{definition|"coordinated activities to direct and control an organization with regard to [[risk]]<ref name="ISO27000-14"> [http://www.iso.org/iso/home/store/catalogue_ics/catalogue_detail_ics.htm?csnumber=63411 ISO/IEC 27000:2014, Information technology -- Security techniques -- Information security management systems -- Overview and vocabulary]</ref>(based on the ISO Guide 73:2009<ref name="ISOGuide73">[http://www.iso.org/iso/catalogue_detail?csnumber=44651 ISO Guide 73:2009 Risk management -- Vocabulary]</ref>).}}
 +
 
 +
<big>Risk management process is the systematic application of management policies, procedures and practices to the activities of
 
communicating, consulting, establishing the context and identifying, analysing, evaluating, treating,
 
communicating, consulting, establishing the context and identifying, analysing, evaluating, treating,
 
monitoring and reviewing [[risk]]<ref name="ISO27000-14"> [http://www.iso.org/iso/home/store/catalogue_ics/catalogue_detail_ics.htm?csnumber=63411 ISO/IEC 27000:2014, Information technology -- Security techniques -- Information security management systems -- Overview and vocabulary]</ref> (based on the ISO Guide 73:2009<ref name="ISOGuide73">[http://www.iso.org/iso/catalogue_detail?csnumber=44651 ISO Guide 73:2009 Risk management -- Vocabulary]</ref>). ISO/IEC 27005 uses the term ‘process’ to describe risk management overall. The elements within
 
monitoring and reviewing [[risk]]<ref name="ISO27000-14"> [http://www.iso.org/iso/home/store/catalogue_ics/catalogue_detail_ics.htm?csnumber=63411 ISO/IEC 27000:2014, Information technology -- Security techniques -- Information security management systems -- Overview and vocabulary]</ref> (based on the ISO Guide 73:2009<ref name="ISOGuide73">[http://www.iso.org/iso/catalogue_detail?csnumber=44651 ISO Guide 73:2009 Risk management -- Vocabulary]</ref>). ISO/IEC 27005 uses the term ‘process’ to describe risk management overall. The elements within
the risk management process are termed ‘activities’.
+
the risk management process are termed ‘activities’.</big>
  
 
==See also==
 
==See also==

Revision as of 11:49, 17 June 2014

Definitions

European Definitions

[CBRN] The process, distinct from Risk Assessment, of weighing policy alternatives, in consultation with all interested parties, considering risk assessment and other factors relevant for the health protection of workers and consumers, the protection of the environment and for the promotion of fair trade practices, and, if needed, selecting appropriate prevention and control options [1].

Other International Definitions

UNISDR

The systematic approach and practice of managing uncertainty to minimize potential harm and loss.[2].

According to UNISDR, risk management comprises risk assessment and analysis, and the implementation of strategies and specific actions to control, reduce and transfer risks. It is widely practiced by organizations to minimise risk in investment decisions and to address operational risks such as those of business disruption, production failure, environmental damage, social impacts and damage from fire and natural hazards. Risk management is a core issue for sectors such as water supply, energy and agriculture whose production is directly affected by extremes of weather and climate.

National Definitions

USA

Process of identifying, analyzing, and communicating risk and accepting, avoiding, transferring or controlling it to an acceptable level at an acceptable cost [3].
Prioritizing, evaluating, and implementing the appropriate risk -reducing controls/countermeasures recommended from the risk management process. (Source: CNSSI-4009; NIST SP 800-30; NIST SP 800-39)

Standard Definition

ISO/IEC 27000:2014

The standard defines risk management as

"coordinated activities to direct and control an organization with regard to risk[4](based on the ISO Guide 73:2009[5]).

Risk management process is the systematic application of management policies, procedures and practices to the activities of communicating, consulting, establishing the context and identifying, analysing, evaluating, treating, monitoring and reviewing risk[4] (based on the ISO Guide 73:2009[5]). ISO/IEC 27005 uses the term ‘process’ to describe risk management overall. The elements within the risk management process are termed ‘activities’.

See also

Notes