Cyber ERM

Cyber Security is going ERM.

The US Department of Energy (DOE) released for public comment the Electricity Subsector CyberSecurity Risk Management Process.  You can download it at:

(http://energy.gov/sites/prod/files/RMP%20Guideline%20Second%20Draft%20for%20Public%20Comment%20-%20March%202012.pdf

It may be a game changer in risk frameworks.  Most risk frameworks are linear risk assessment processes.

The DOE standard is ERM process based, inputs  => activities => outputs, hierarchal (tiered), and follows a novel cycle.

Let’s discuss a few of these:

The RM model is tiered: 1. Tier 1: Organization; 2. Tier 2: Mission and Business Processes; and Tier 3: IT and Industrial Control Systems.

The RM model has a cycle of: Frame => Assess => Respond => Monitor.

Each tier follows a process, much like the Project Management Institute Body of Knowledge (PMBOK)

Different RM model.  ERM based.  Interesting.  Novel.  Check it out.

MORPHING PROFESSIONS

Qur firm – Quality + Engineering – provides professional engineering, forensics, and risk management.  In the last two months, we’ve been contacted to:

1.  Manage outsourced quality operations.
2.  Reframe a much smaller quality group into a risk management group.
3.  Do a combination of the above.

Is the quality profession morphing, disappearing, or maturing?  Or, is this an anomaly to the quality profession?  I don’t think so!

We’re seeing more than one profession changing dramatically.  As I read the NY Times and Wall Street Journal, it’s happening to the legal, marketing, journalism and most professions.    Newly minted lawyers can’t get jobs.  Top law firms are changing their revenue models, revamping their partnership models, or are folding.  Marketing is moving on line, which requires new technical skills.  Journalism is also moving online.

So, the critical questions for most of us are:

  • What changes are happening in our profession?
  • How are we keeping current?
  • What value are we adding to our organization or customers?

 

CERM Bootcamp Lessons Learned

We just ended our first Certified Enterprise Risk Manager(R) Bootcamp in Seattle.  Five days of risk bonding, sharing of risk information, and risk learnings.  it was a great success.

We had a number of lessons learned:

Enterprise Risk Management (ERM) is reshaping many industries from pharma, electric power, water, food, etc.  These industries are developing ERM standards.  The challenge is that many of these standards have not been deployed or adopted.

Adoption of ERM is still early in most companies.  Publicly held companies often have mature ERM as part of their internal control over financial reporting programs to comply with Sarbanes Oxley and other regulations.  The operational ERM programs are still in their infancy.

Material risks are more often in operations, technology, and IT.  Engineering, IT, quality, supply management, and other operational professionals need to learn and implement risk management in their areas.

Tell us your ERM experiences?  Are they the same as our lessons learned?

Critical Questions Answered by CERM® – Electric Reliability™

What does the NERC Reliability Assurance Initiative (RAI), proposed CMEP changes, Actively Monitored List (AML) and the tiered approach to auditing mean to registered entities?

What are the major differences between the current ‘zero defect’ and NERC’s proposed Reliability Assurance Initiative (RAI)?

How will regional entities (best guess) conduct risk-based assessment and compliance monitoring using GAGAS (Yellow Book)?

What are Yellow Book and Red Book Auditing and how will performance and effectiveness audits impact registered entities?

What do fundamental concepts and terms mean such as RAI, risk based decision making, risk assurance, inherent risk, residual risk, risk frameworks, CIP GAGAS, etc

How does the registered entity design, develop, deploy, and assure an adequate control framework and mitigating risk – controls?

What should registered entities do NOW to prepare for RAI and what would an action plan for the next six months and year look like?

Certified Enterprise Risk Manager – Electric Reliability Learning Objectives and Outline

Length – Three Days
CERM – ER Learning Objectives

This course will enable attendees to understand:

  • Common risk concepts and develop an ERM vocabulary
  • How to assess risks
  • How organization determine risk appetite
  • How to prioritize and prepare risk response (treatment) strategies to mitigate and manage organizational or business unit risk
  • How to design, monitor, evaluate, and test the effectiveness of a system of internal controls
  • Determining audit scope and documenting the elements of findings using principles of ERM
  • Determining risk in audits

CERM – ER Course Modules

  1. Context (Risk)
  2. Internal Environment
  3. Objective Setting
  4. Risk/Event Identification
  5. Risk Assessment
  6. Risk Response
  7. Control Activities
  8. Information & Communication
  9. Monitoring
  10. Value Added Auditing™ (GAGAS) Sections
    Planning
    Fieldwork
    Reporting
  11. CERM Exam