#22 – WHEN TO INCORPORATE A RISK INTO THE BASELINE SCHEDULE OR RISK REGISTER – JOHN AYERS

John Ayers pixRisk management involves the identification of risks, prioritization of the risks based on probability of occurrence and impact of occurrence, and mitigation plans to control the risks.  Once identified and prioritized the question then becomes which risks should be incorporated into the schedule and which ones should be included in the risk register? 

The general rule of thumb I have used requires risks with a 50% or greater probability of occurrence to be incorporated into the schedule. The other risks are entered into the risk register. Continue reading

#22 – CYBER SECURITY – #1 GLOBAL THREAT – GREG HUTCHINS

Greg Hutchins pixGen. Fang Fenghui, chief of staff of the China’s People’s Liberation Army said:

Cyberattacks could be “as serious as a nuclear bomb” (The Wall Street Journal  China: Cyber Attacks Are Like Nuclear Bombs.’ April 22, 2013).

The U.S. Director of National Intelligence, James R. Clapper recently announced:

“The growing use of cyber capabilities to achieve strategic goals is also outpacing the development of a shared understanding of norms of behavior, increasing the chances for miscalculations and misunderstandings that could lead to unintended escalation. (“Worldwide Threat Assessment of the US Intelligence Community” March 12, 2013.) Continue reading

#22 – RISK BASED AUDITING REDUX – UMBERTO TUNESI

Umberto Tunesi pixI would fool myself if I had to admit that in a more than forty years career in laboratory, sales & technical support, quality inspection, quality, environment, safety audits in fields varying from any kind of chemicals to automotive components, I have not learned at least something on risk-based audit and risk management. Continue reading

#22 – CONTEXT MATTERS WHEN DISCUSSING RISK (EVENT RISKS) – MARK JONES

Mark Jones pixEvent Risk is your typical ‘stuff happens’ risk that pops up over the course of a project. As part of ongoing planning you use the risk register to record them along with any agreed Decision Risks. The vast majority of these can be described in terms of future events with an impact on the project and occurrence uncertainty – once they are certain, i.e. either 100% or 0% probable, they graduate to something else. Continue reading