#28 – ISO 31K SOFTWARE AND IT RISK MANAGEMENT – GARY GACK

GG-photo-20100224When applying Enterprise Risk Management (ERM), as in much else in life, the devil is in the details.  The details are especially critical when attempting to apply standards such as ISO 31000 to software and IT intensive systems.  ISO 31000 describes principles, a framework, and a high level process for ERM.  ISO 31000 clause 5 identifies process steps – in this article I will focus on risk assessment and risk treatment as it applies to software and IT intensive contexts.

  • 5.2 Communication and consultation
  • 5.3 Establishing the Context
  • 5.4 Risk assessment
    • 5.4.2 Risk Identification
    • 5.4.3 Risk Analysis
    • 5.4.4 Risk Evaluation
    • 5.5 Risk Treatment Continue reading

#28 – OBAMACARE VERSUS GOVERNMENT DISRUPTIONS – A RISK ANALYSIS – CAPERS JONES

Capers Jones pixINTRODUCTION
For almost two weeks the country (the United States) and the press have been mesmerized by the partial shut down of the Federal government and by the threat that the U.S. will default on its financial obligations due to failure to raise the debt limit.

These problems are due to conflicts between the Republicans and the Democrats on spending versus taxes, and more recently on the pros and cons of the Affordable Health Care act commonly known as ‘Obamacare.’

Both Obamacare and the government shut down have risks associated with them.  From the external viewpoint of an independent voter whose work involves risk analysis, neither side appears to have done a careful examination of any of the risks from either Obamacare itself or from the shutdown of the government. Continue reading

#28 – ERM SYSTEMS THAT AREN’T! – (C) GREG CARROLL

GregCarrollFollowing is excerpted from Mastering 21st Century Enterprise Risk Management (forthcoming October 2013):

THE NATURE OF RISK
Most systems masquerading as enterprise risk management are re-jigged workplace health-and-safety risk platforms that attempt to apply a predefined standardized methodology.  A one-size-fits-all assessment program cannot be imposed on everyone and achieve any useful results.  Risk-assessment must be relevant to their field if people are to take it seriously.  It must provide meaningful value to them.  It also must go through continual review as the nature of risk changes and evolves. Continue reading

#28 – ISO CAR MAINTENANCE RISKS – UMBERTO TUNESI

Umberto Tunesi pixIn the late 2000’s I was working as auditor for two German registrars.

Both had somehow contracted to supply ISO 9001 initial registration and surveillance services to a number of car shops providing services for:

  1. Meeting the regulatory requirements for periodic, systematic car checks;
  2. Giving to the shops an excellence mark, examples of which can be seen on Formula One cars, relating to car electronics – or “autonics”. Continue reading

#28 – GRATITUDE AT WORK – ELIZABETH LIONS

Elizabeth Lions Pix

The headline on LinkedIn read, “Why I was glad when I got fired – again” and I found myself thinking what a wonderful perspective.

Real gratitude at work is just that.  Being content if it’s a good day or a bad day.  It’s being able to see being fired as transformative when the sting of taking it personally wears off.

Gratitude isn’t just about being thankful that you drive a nice car of live in a large house.  It’s surrender to what is.  And knowing what is (like losing a job in this case) is temporary.  Through pain often comes great realization of something much deeper than the surface of being uncomfortable, mad or sad.  The layoff is merely a vehicle for you to dig deeper at who you really are.  And, to learn you are not your job.  You are much bigger than that. Continue reading