#22 – CYBER SECURITY – #1 GLOBAL THREAT – GREG HUTCHINS

Greg Hutchins pixGen. Fang Fenghui, chief of staff of the China’s People’s Liberation Army said:

Cyberattacks could be “as serious as a nuclear bomb” (The Wall Street Journal  China: Cyber Attacks Are Like Nuclear Bombs.’ April 22, 2013).

The U.S. Director of National Intelligence, James R. Clapper recently announced:

“The growing use of cyber capabilities to achieve strategic goals is also outpacing the development of a shared understanding of norms of behavior, increasing the chances for miscalculations and misunderstandings that could lead to unintended escalation. (“Worldwide Threat Assessment of the US Intelligence Community” March 12, 2013.) Continue reading

#22 – RISK BASED AUDITING REDUX – UMBERTO TUNESI

Umberto Tunesi pixI would fool myself if I had to admit that in a more than forty years career in laboratory, sales & technical support, quality inspection, quality, environment, safety audits in fields varying from any kind of chemicals to automotive components, I have not learned at least something on risk-based audit and risk management. Continue reading

#22 – CONTEXT MATTERS WHEN DISCUSSING RISK (EVENT RISKS) – MARK JONES

Mark Jones pixEvent Risk is your typical ‘stuff happens’ risk that pops up over the course of a project. As part of ongoing planning you use the risk register to record them along with any agreed Decision Risks. The vast majority of these can be described in terms of future events with an impact on the project and occurrence uncertainty – once they are certain, i.e. either 100% or 0% probable, they graduate to something else. Continue reading

#22 – CAN PROJECTS INCORPORATE TOO LITTLE RISK? – HOWARD WIENER

Howard Wiener PixGenerally, every effort is made to reduce risks in software development projects to ensure achieving functionality, time and cost goals.  One common risk-mitigation practice is to employ established, stable technologies when new, less well-understood or in-transition business processes are involved.  

However, projects supporting longer-term, strategic business initiatives may produce suboptimal results if organizations do not push the envelope in order to maintain currency with evolving technology standards and preserve options to keep the application consistent with market competition and changing business models over its usable life. 

In this post, I begin to explore how we can identify cases in which accepting risks associated with employing newer technologies, architectures or methodologies can add value to a project. Continue reading