#124 – US FEDERAL ERM REQUIREMENTS – GREG HUTCHINS

Featured

Greg Hutchins pixLast year, we reported that White House Office of Management and Budget (OMB – executive office) is requiring US departments to design and implement Enterprise Risk Management (ERM).  The requirements are part of the OMB Circular A 11 Section 270 – Performance and Strategic Reviews.

Continue reading

#124 – COULD YOU BE LIABLE FOR THE HEALTH OF YOUR EMPLOYEE’S CHILDREN? – ANNETTE DAVISON

Featured

AAA&Could you be liable for the health of your employees’ children and grandchildren?

Work health and safety legislation in Australia places a strict duty on the ‘person conducting the business or undertaking’ to understand, monitor and mitigate workplace risks. This is not new, we know that employers are responsible for their employees. Continue reading

#124 – AN ANGEL IN DISTRESS – DAVID PATRISHKOFF

Featured

David PThis is the second CERM Insights article in a series about the application of Cascade Effect Thinking and tools to mitigate risks and transform them into dramatic improvements and even disruptive innovations for small, mid-sized and very large organizations.

More than a million ISO certified companies will have to integrate risk management with a risk assessment.  We detail a case study how this can be done using quality risk tools.  Four of 40 possible cascading risk assessment and management tools are demonstrated in this case study: Gamified Process Risk Mapping, New Process Wish List, Cascading Risk Map & the Future State Process Map. Continue reading

#124 – ANATOMY OF A MEDICAL DEVICE ATTACK – JEFF HARRIS

Featured

AAA-Jeff-150x150TrapX, a security company that specializes in medical device attacks, outlined how these attacks occur in a report titled “Anatomy of an Attack: MedJack” in May of 2015. In this report several case studies are examined in detail. In the first case study, malware was inserted on a blood gas analyzer. Continue reading

#124 – PERSONAL RISK IN THE INTERNET OF THINGS – KIRBY URNER

Featured

AAA IRBYLast month in this blog, I chronicled a “device failure”:  my car key broke off in the ignition.  I modeled this “exception” (to my reasonable expectations) using Python code, suggesting pseudo-coding one’s risk model as a first step in a risk assessment process. Continue reading