SlideShare una empresa de Scribd logo
1 de 12
Descargar para leer sin conexión
ramirocid.com ramiro@ramirocid.com Twitter: @ramirocid
ISO 31000 - Risk Management
Ramiro Cid | @ramirocid
ISO 31000 - Risk Management
ramirocid.com ramiro@ramirocid.com Twitter: @ramirocid
ISO 31000 - Risk Management
2
Index
1. Introduction Page 3
2. Certification and Accreditation Page 4
3. History Page 5
4. Main concepts Page 6
5. Scope Page 7
6. Implementation Page 8
7. Implications Page 9
8. Managing risk Page 10
9. Related standards Page 11
ramirocid.com ramiro@ramirocid.com Twitter: @ramirocid
ISO 31000 - Risk Management
3
Introduction
The full name of this standard is:
“ISO 31000:2009, Risk management – Principles and guidelines”
This standard provides principles, framework and a process for managing risk. It can be used by any organization
regardless of its size, activity or sector.
Using ISO 31000 can help organizations increase the likelihood of achieving objectives, improve the identification
of opportunities and threats and effectively allocate and use resources for risk treatment.
ISO 31000 family is expected to include:
ISO 31000:2009 - Principles and Guidelines on Implementation
ISO/IEC 31010:2009 - Risk Management - Risk Assessment Techniques
ISO Guide 73:2009 - Risk Management - Vocabulary
ramirocid.com ramiro@ramirocid.com Twitter: @ramirocid
ISO 31000 - Risk Management
4
Certification and Accreditation
Certification:
However, ISO 31000 cannot be used for certification purposes, but does provide guidance for internal or external
audit programs. Organizations using it can compare their risk management practices with an internationally
recognized benchmark, providing sound principles for effective management and corporate governance.
ISO 31000 has not been developed with the intention for certification. (2009)
Accreditation:
Starting from Mar 2013, accreditation and certification of Professional Certificate Lead Trainer & Consultant for ISO
31000 would be organized and conferred by Academy of Professional Certification (APC, http://www.apc.org.hk) in
Hong Kong. APC is an authorized representative of ISO/TC262 for HKSAR Hong Kong.(2013)
ramirocid.com ramiro@ramirocid.com Twitter: @ramirocid
ISO 31000 - Risk Management
5
History
ISO 31000 was published as a standard on the 13th of November 2009, and provides a standard on the
implementation of risk management. A revised and harmonized ISO/IEC Guide 73 was published at the same time.
The purpose of ISO 31000:2009 is to be applicable and adaptable for "any public, private or community enterprise,
association, group or individual.
Accordingly, the general scope of ISO 31000 - as a family of risk management standards - is not developed for a
particular industry group, management system or subject matter field in mind, rather to provide best practice
structure and guidance to all operations concerned with risk management.
ramirocid.com ramiro@ramirocid.com Twitter: @ramirocid
ISO 31000 - Risk Management
6
Main concepts
Risk: “Effect of uncertainty on objectives”
Positive and negative consequences
Safety, compliance, strategy, anything under the sun
Risk management: “coordinated activities to direct and control and organization with regard to risk”
Risk management framework: “set of components that provide the foundations and organizational
arrangements for designing, implementing, monitoring, reviewing and continually improving risk management
processes throughout the organization”.
Risk management process: “systematic application of management policies, procedures and practices to the
tasks of communication, consultation, establishing the context, identifying, analyzing, evaluating, treating,
monitoring and reviewing risk”.
ramirocid.com ramiro@ramirocid.com Twitter: @ramirocid
ISO 31000 - Risk Management
7
Scope
ISO 31000:2009 provides generic guidelines for the design, implementation and maintenance of risk management
processes throughout an organization. This approach to formalizing risk management practices will facilitate
broader adoption by companies who require an enterprise risk management standard that accommodates multiple
‘silo-centric’ management systems.
The scope of this approach to risk management is to enable all strategic, management and operational tasks of an
organization throughout projects, functions, and processes to be aligned to a common set of risk management
objectives.
Accordingly, ISO 31000:2009 is intended for a broad stakeholder group including:
Executive level stakeholders
Appointment holders in the enterprise risk management group
Risk analysts and management officers
Line managers and project managers
Compliance and internal auditors
Independent practitioners.
ramirocid.com ramiro@ramirocid.com Twitter: @ramirocid
ISO 31000 - Risk Management
8
Implementation
The intent of ISO 31000 is to be applied within existing management systems to formalize and improve risk
management processes as opposed to wholesale substitution of legacy management practices. Subsequently,
when implementing ISO 31000, attention is to be given to integrating existing risk management processes in the
new paradigm addressed in the standard.
The focus of many ISO 31000 'Harmonisation' programmes have centred on:
Transferring accountability gaps in enterprise risk management
Aligning objectives of the governance frameworks with ISO 31000
Embedding management system reporting mechanisms
Creating uniform risk criteria and evaluation metrics
ramirocid.com ramiro@ramirocid.com Twitter: @ramirocid
ISO 31000 - Risk Management
9
Implications
Most implications for adopting the new standard concern the re-engineering of existing management practices to
conform with the documentation, communication and socialization of the new risk management operating
paradigm; as opposed to wholesale re-orientation of management practice throughout an organization. Accordingly,
most senior position holders in an enterprise risk management organization will need to be cognizant of the
implication for adopting the standard and be able to develop effective strategies for implementing the standard
across supply chains and commercial operations.
Certain aspects of top management accountability, strategic policy implementation and effective governance
frameworks, will require more consideration by organizations that have previously used now redundant risk
management methodologies.
In some domains that concern risk management, in particular security and corporate social responsibility, which
may operate using relatively unsophisticated risk management processes, more material change will be required,
particularly regarding a clearly articulated risk management policy, formalizing risk ownership processes,
structuring framework processes and adopting continuous improvement programs.
ramirocid.com ramiro@ramirocid.com Twitter: @ramirocid
ISO 31000 - Risk Management
10
Managing risk
ISO 31000:2009 gives a list in order of preference on how to deal with risk:
1. Avoiding the risk by deciding not to start or continue with the activity that gives rise to the risk
2. Accepting or increasing the risk in order to pursue an opportunity
3. Removing the risk source
4. Changing the likelihood
5. Changing the consequences
6. Sharing the risk with another party or parties (including contracts and risk financing)
7. Retaining the risk by informed decision
ramirocid.com ramiro@ramirocid.com Twitter: @ramirocid
ISO 31000 - Risk Management
11
Related standards
A number of other standards also relate to risk management:
ISO Guide 73:2009, Risk management - Vocabulary complements ISO 31000 by providing a collection of terms
and definitions relating to the management of risk.
ISO/IEC 31010:2009, Risk management – Risk assessment techniques focuses on risk assessment. Risk
assessment helps decision makers understand the risks that could affect the achievement of objectives as well
as the adequacy of the controls already in place. ISO/IEC 31010:2009 focuses on risk assessment concepts,
processes and the selection of risk assessment techniques.
ramirocid.com ramiro@ramirocid.com Twitter: @ramirocid
ISO 31000 - Risk Management
Questions?
Many thanks!
ramiro@ramirocid.com
@ramirocid
http://www.linkedin.com/in/ramirocid
http://ramirocid.com http://es.slideshare.net/RamiroCid
http://www.youtube.com/user/cidramiro
Ramiro Cid
CISM, CGEIT, ISO 27001 LA, ISO 22301 LA, ITIL

Más contenido relacionado

La actualidad más candente

PECB Webinar: Aligning ISO 31000 and Management of Risk Methodology
PECB Webinar: Aligning ISO 31000 and Management of Risk MethodologyPECB Webinar: Aligning ISO 31000 and Management of Risk Methodology
PECB Webinar: Aligning ISO 31000 and Management of Risk MethodologyPECB
 
Implementing Risk Based Thinking in HLS OF ISO 9001:2015 - Praneet Surti
Implementing Risk Based Thinking in HLS OF ISO 9001:2015 - Praneet SurtiImplementing Risk Based Thinking in HLS OF ISO 9001:2015 - Praneet Surti
Implementing Risk Based Thinking in HLS OF ISO 9001:2015 - Praneet SurtiPraneet Surti
 
Leveraging ISO 31000 for Effective Integration of Risk Management and Interna...
Leveraging ISO 31000 for Effective Integration of Risk Management and Interna...Leveraging ISO 31000 for Effective Integration of Risk Management and Interna...
Leveraging ISO 31000 for Effective Integration of Risk Management and Interna...International Federation of Accountants
 
Risk based thinking ppt mal
Risk based thinking ppt malRisk based thinking ppt mal
Risk based thinking ppt malmichaelnano79
 
Certified Risk and Compliance Management Professional (CRCMP) Prep Course Pa...
Certified Risk and Compliance Management Professional (CRCMP) Prep Course Pa...Certified Risk and Compliance Management Professional (CRCMP) Prep Course Pa...
Certified Risk and Compliance Management Professional (CRCMP) Prep Course Pa...Compliance LLC
 
Implementation of Enterprise Risk Management with ISO 31000 Risk Management S...
Implementation of Enterprise Risk Management with ISO 31000 Risk Management S...Implementation of Enterprise Risk Management with ISO 31000 Risk Management S...
Implementation of Enterprise Risk Management with ISO 31000 Risk Management S...PECB
 
Integrated Management Systems
Integrated Management SystemsIntegrated Management Systems
Integrated Management SystemsDennis Arter
 
Interested party matrix - ISO 14001:2015
Interested party matrix - ISO 14001:2015Interested party matrix - ISO 14001:2015
Interested party matrix - ISO 14001:2015James Charles, PE, CPG
 
Risk Management for Medical Devices - ISO 14971 Overview
Risk Management for Medical Devices - ISO 14971 Overview Risk Management for Medical Devices - ISO 14971 Overview
Risk Management for Medical Devices - ISO 14971 Overview Greenlight Guru
 
NQA ISO 45001 Implementation Guide
NQA ISO 45001 Implementation GuideNQA ISO 45001 Implementation Guide
NQA ISO 45001 Implementation GuideNQA
 
ISO 19011-2018.pptx
ISO 19011-2018.pptxISO 19011-2018.pptx
ISO 19011-2018.pptxSmppMondha
 
PECB Webinar: ISO 31000 – Risk Management and how it can help an organization
PECB Webinar: ISO 31000 – Risk Management and how it can help an organizationPECB Webinar: ISO 31000 – Risk Management and how it can help an organization
PECB Webinar: ISO 31000 – Risk Management and how it can help an organizationPECB
 
Conducting effective management reviews
Conducting effective management reviewsConducting effective management reviews
Conducting effective management reviewsPECB
 

La actualidad más candente (20)

Risk Management Training
Risk Management TrainingRisk Management Training
Risk Management Training
 
PECB Webinar: Aligning ISO 31000 and Management of Risk Methodology
PECB Webinar: Aligning ISO 31000 and Management of Risk MethodologyPECB Webinar: Aligning ISO 31000 and Management of Risk Methodology
PECB Webinar: Aligning ISO 31000 and Management of Risk Methodology
 
Implementing Risk Based Thinking in HLS OF ISO 9001:2015 - Praneet Surti
Implementing Risk Based Thinking in HLS OF ISO 9001:2015 - Praneet SurtiImplementing Risk Based Thinking in HLS OF ISO 9001:2015 - Praneet Surti
Implementing Risk Based Thinking in HLS OF ISO 9001:2015 - Praneet Surti
 
Risk based thinking in ms iso 9001 2015
Risk based thinking in ms iso 9001 2015Risk based thinking in ms iso 9001 2015
Risk based thinking in ms iso 9001 2015
 
Leveraging ISO 31000 for Effective Integration of Risk Management and Interna...
Leveraging ISO 31000 for Effective Integration of Risk Management and Interna...Leveraging ISO 31000 for Effective Integration of Risk Management and Interna...
Leveraging ISO 31000 for Effective Integration of Risk Management and Interna...
 
Risk based thinking ppt mal
Risk based thinking ppt malRisk based thinking ppt mal
Risk based thinking ppt mal
 
Certified Risk and Compliance Management Professional (CRCMP) Prep Course Pa...
Certified Risk and Compliance Management Professional (CRCMP) Prep Course Pa...Certified Risk and Compliance Management Professional (CRCMP) Prep Course Pa...
Certified Risk and Compliance Management Professional (CRCMP) Prep Course Pa...
 
Implementation of Enterprise Risk Management with ISO 31000 Risk Management S...
Implementation of Enterprise Risk Management with ISO 31000 Risk Management S...Implementation of Enterprise Risk Management with ISO 31000 Risk Management S...
Implementation of Enterprise Risk Management with ISO 31000 Risk Management S...
 
Integrated Management Systems
Integrated Management SystemsIntegrated Management Systems
Integrated Management Systems
 
Overview of ISO 19011:2018 Guidelines for Auditing Management Systems
Overview of ISO 19011:2018 Guidelines for Auditing Management SystemsOverview of ISO 19011:2018 Guidelines for Auditing Management Systems
Overview of ISO 19011:2018 Guidelines for Auditing Management Systems
 
Interested party matrix - ISO 14001:2015
Interested party matrix - ISO 14001:2015Interested party matrix - ISO 14001:2015
Interested party matrix - ISO 14001:2015
 
Iso13485 ppt
Iso13485 pptIso13485 ppt
Iso13485 ppt
 
ISO 45001 audit tool
ISO 45001 audit toolISO 45001 audit tool
ISO 45001 audit tool
 
Risk Management for Medical Devices - ISO 14971 Overview
Risk Management for Medical Devices - ISO 14971 Overview Risk Management for Medical Devices - ISO 14971 Overview
Risk Management for Medical Devices - ISO 14971 Overview
 
NQA ISO 45001 Implementation Guide
NQA ISO 45001 Implementation GuideNQA ISO 45001 Implementation Guide
NQA ISO 45001 Implementation Guide
 
ISO 19011-2018.pptx
ISO 19011-2018.pptxISO 19011-2018.pptx
ISO 19011-2018.pptx
 
ICH Q9 Quality Risk Management
ICH Q9 Quality Risk ManagementICH Q9 Quality Risk Management
ICH Q9 Quality Risk Management
 
PECB Webinar: ISO 31000 – Risk Management and how it can help an organization
PECB Webinar: ISO 31000 – Risk Management and how it can help an organizationPECB Webinar: ISO 31000 – Risk Management and how it can help an organization
PECB Webinar: ISO 31000 – Risk Management and how it can help an organization
 
Conducting effective management reviews
Conducting effective management reviewsConducting effective management reviews
Conducting effective management reviews
 
RISK ASSESSMENTS (QMS)
RISK ASSESSMENTS (QMS)RISK ASSESSMENTS (QMS)
RISK ASSESSMENTS (QMS)
 

Similar a ISO 31000 Risk Management

A structured approach to Enterprise Risk Management (ERM) and the requirement...
A structured approach to Enterprise Risk Management (ERM) and the requirement...A structured approach to Enterprise Risk Management (ERM) and the requirement...
A structured approach to Enterprise Risk Management (ERM) and the requirement...Hassan Zaitoun
 
Dr hatem el bitar quality text (17)د حاتم البيطار #دحاتم_البيطار #timodent...
Dr hatem el bitar quality text (17)د حاتم البيطار  #دحاتم_البيطار   #timodent...Dr hatem el bitar quality text (17)د حاتم البيطار  #دحاتم_البيطار   #timodent...
Dr hatem el bitar quality text (17)د حاتم البيطار #دحاتم_البيطار #timodent...د حاتم البيطار
 
Understandiing ISO 31000-2009
Understandiing ISO 31000-2009Understandiing ISO 31000-2009
Understandiing ISO 31000-2009Ridwan Ibrahim
 
ISO+31000+2009+Understanding
ISO+31000+2009+UnderstandingISO+31000+2009+Understanding
ISO+31000+2009+UnderstandingSetiono Winardi
 
Relevance of ISO 31000 for risk professionals.pptx
Relevance of ISO 31000 for risk professionals.pptxRelevance of ISO 31000 for risk professionals.pptx
Relevance of ISO 31000 for risk professionals.pptxCaptSameerSharma
 
Module 2 - Approaches to Risk Management.pdf
Module 2 - Approaches to Risk Management.pdfModule 2 - Approaches to Risk Management.pdf
Module 2 - Approaches to Risk Management.pdfmarjondimafilis
 
I need response to the discussion post in 200 words.docx
I need response to the discussion post in 200 words.docxI need response to the discussion post in 200 words.docx
I need response to the discussion post in 200 words.docxsdfghj21
 
I need response to the discussion post in 200 words.docx
I need response to the discussion post in 200 words.docxI need response to the discussion post in 200 words.docx
I need response to the discussion post in 200 words.docxwrite4
 
Failure deriving from underestimating risk management
 Failure deriving from underestimating risk management Failure deriving from underestimating risk management
Failure deriving from underestimating risk managementPECB
 
Implementing a Risk Management System based on the ISO 31000
Implementing a Risk Management System based on the ISO 31000Implementing a Risk Management System based on the ISO 31000
Implementing a Risk Management System based on the ISO 31000Continuity and Resilience
 
Centralized operations – Risk, Control, and Compliance
Centralized operations – Risk, Control, and ComplianceCentralized operations – Risk, Control, and Compliance
Centralized operations – Risk, Control, and CompliancePECB
 
Management of risk introduction
Management of risk introductionManagement of risk introduction
Management of risk introductionSpyros Ktenas
 
Riskpro iso 31000 services 2013
Riskpro iso 31000 services 2013Riskpro iso 31000 services 2013
Riskpro iso 31000 services 2013Nidhi Gupta
 
Riskpro iso 31000 services 2013
Riskpro iso 31000 services 2013Riskpro iso 31000 services 2013
Riskpro iso 31000 services 2013Nidhi Gupta
 

Similar a ISO 31000 Risk Management (20)

A structured approach to Enterprise Risk Management (ERM) and the requirement...
A structured approach to Enterprise Risk Management (ERM) and the requirement...A structured approach to Enterprise Risk Management (ERM) and the requirement...
A structured approach to Enterprise Risk Management (ERM) and the requirement...
 
Risk management erm
Risk management ermRisk management erm
Risk management erm
 
Brochure iso 31000 conference may2013-toronto-l
Brochure iso 31000 conference may2013-toronto-lBrochure iso 31000 conference may2013-toronto-l
Brochure iso 31000 conference may2013-toronto-l
 
Dr hatem el bitar quality text (17)د حاتم البيطار #دحاتم_البيطار #timodent...
Dr hatem el bitar quality text (17)د حاتم البيطار  #دحاتم_البيطار   #timodent...Dr hatem el bitar quality text (17)د حاتم البيطار  #دحاتم_البيطار   #timodent...
Dr hatem el bitar quality text (17)د حاتم البيطار #دحاتم_البيطار #timodent...
 
Understandiing ISO 31000-2009
Understandiing ISO 31000-2009Understandiing ISO 31000-2009
Understandiing ISO 31000-2009
 
ISO+31000+2009+Understanding
ISO+31000+2009+UnderstandingISO+31000+2009+Understanding
ISO+31000+2009+Understanding
 
Relevance of ISO 31000 for risk professionals.pptx
Relevance of ISO 31000 for risk professionals.pptxRelevance of ISO 31000 for risk professionals.pptx
Relevance of ISO 31000 for risk professionals.pptx
 
ISO 27005 - Digital Trust Framework
ISO 27005 - Digital Trust FrameworkISO 27005 - Digital Trust Framework
ISO 27005 - Digital Trust Framework
 
Module 2 - Approaches to Risk Management.pdf
Module 2 - Approaches to Risk Management.pdfModule 2 - Approaches to Risk Management.pdf
Module 2 - Approaches to Risk Management.pdf
 
I need response to the discussion post in 200 words.docx
I need response to the discussion post in 200 words.docxI need response to the discussion post in 200 words.docx
I need response to the discussion post in 200 words.docx
 
I need response to the discussion post in 200 words.docx
I need response to the discussion post in 200 words.docxI need response to the discussion post in 200 words.docx
I need response to the discussion post in 200 words.docx
 
Failure deriving from underestimating risk management
 Failure deriving from underestimating risk management Failure deriving from underestimating risk management
Failure deriving from underestimating risk management
 
#corpriskforum2016 - Alex Dali
#corpriskforum2016 - Alex Dali#corpriskforum2016 - Alex Dali
#corpriskforum2016 - Alex Dali
 
Implementing a Risk Management System based on the ISO 31000
Implementing a Risk Management System based on the ISO 31000Implementing a Risk Management System based on the ISO 31000
Implementing a Risk Management System based on the ISO 31000
 
Risk management
Risk managementRisk management
Risk management
 
Centralized operations – Risk, Control, and Compliance
Centralized operations – Risk, Control, and ComplianceCentralized operations – Risk, Control, and Compliance
Centralized operations – Risk, Control, and Compliance
 
Management of risk introduction
Management of risk introductionManagement of risk introduction
Management of risk introduction
 
Riskpro iso 31000 services 2013
Riskpro iso 31000 services 2013Riskpro iso 31000 services 2013
Riskpro iso 31000 services 2013
 
Riskpro iso 31000 services 2013
Riskpro iso 31000 services 2013Riskpro iso 31000 services 2013
Riskpro iso 31000 services 2013
 
Riskpro iso 31000 services 2013
Riskpro iso 31000 services 2013Riskpro iso 31000 services 2013
Riskpro iso 31000 services 2013
 

Más de Ramiro Cid

Seminario sobre ciberseguridad
Seminario sobre ciberseguridadSeminario sobre ciberseguridad
Seminario sobre ciberseguridadRamiro Cid
 
Captación y registro de comunicaciones orales y de imagen
Captación y registro de comunicaciones orales y de imagenCaptación y registro de comunicaciones orales y de imagen
Captación y registro de comunicaciones orales y de imagenRamiro Cid
 
Passwords for sale
Passwords for salePasswords for sale
Passwords for saleRamiro Cid
 
Cyber security threats for 2017
Cyber security threats for 2017Cyber security threats for 2017
Cyber security threats for 2017Ramiro Cid
 
¿Cuáles son los peligros a los que se enfrenta su sistema informático?
¿Cuáles son los peligros a los que se enfrenta su sistema informático?¿Cuáles son los peligros a los que se enfrenta su sistema informático?
¿Cuáles son los peligros a los que se enfrenta su sistema informático?Ramiro Cid
 
Cloud Computing, IoT, BYOD Ha muerto el perímetro corporativo. ¿y ahora qué?
Cloud Computing, IoT, BYOD Ha muerto el perímetro corporativo. ¿y ahora qué?Cloud Computing, IoT, BYOD Ha muerto el perímetro corporativo. ¿y ahora qué?
Cloud Computing, IoT, BYOD Ha muerto el perímetro corporativo. ¿y ahora qué?Ramiro Cid
 
Lean Six Sigma methodology
Lean Six Sigma methodologyLean Six Sigma methodology
Lean Six Sigma methodologyRamiro Cid
 
IT Governance & ISO 38500
IT Governance & ISO 38500IT Governance & ISO 38500
IT Governance & ISO 38500Ramiro Cid
 
Cyber Security Resilience & Risk Aggregation
Cyber Security Resilience & Risk AggregationCyber Security Resilience & Risk Aggregation
Cyber Security Resilience & Risk AggregationRamiro Cid
 
EU General Data Protection Regulation
EU General Data Protection RegulationEU General Data Protection Regulation
EU General Data Protection RegulationRamiro Cid
 
Social engineering attacks
Social engineering attacksSocial engineering attacks
Social engineering attacksRamiro Cid
 
Thinking on risk analysis
Thinking on risk analysisThinking on risk analysis
Thinking on risk analysisRamiro Cid
 
Drones and their use on critical infrastructure
Drones and their use on critical infrastructureDrones and their use on critical infrastructure
Drones and their use on critical infrastructureRamiro Cid
 
Internet of things, big data & mobility vs privacy
Internet of things, big data & mobility vs privacyInternet of things, big data & mobility vs privacy
Internet of things, big data & mobility vs privacyRamiro Cid
 
Space computing
Space computingSpace computing
Space computingRamiro Cid
 
The relation between internet of things, critical infrastructure and cyber se...
The relation between internet of things, critical infrastructure and cyber se...The relation between internet of things, critical infrastructure and cyber se...
The relation between internet of things, critical infrastructure and cyber se...Ramiro Cid
 
Internet of things
Internet of thingsInternet of things
Internet of thingsRamiro Cid
 
Cyber Security
Cyber SecurityCyber Security
Cyber SecurityRamiro Cid
 
Cyber Security Awareness
Cyber Security AwarenessCyber Security Awareness
Cyber Security AwarenessRamiro Cid
 

Más de Ramiro Cid (20)

Seminario sobre ciberseguridad
Seminario sobre ciberseguridadSeminario sobre ciberseguridad
Seminario sobre ciberseguridad
 
Captación y registro de comunicaciones orales y de imagen
Captación y registro de comunicaciones orales y de imagenCaptación y registro de comunicaciones orales y de imagen
Captación y registro de comunicaciones orales y de imagen
 
Passwords for sale
Passwords for salePasswords for sale
Passwords for sale
 
Cyber security threats for 2017
Cyber security threats for 2017Cyber security threats for 2017
Cyber security threats for 2017
 
¿Cuáles son los peligros a los que se enfrenta su sistema informático?
¿Cuáles son los peligros a los que se enfrenta su sistema informático?¿Cuáles son los peligros a los que se enfrenta su sistema informático?
¿Cuáles son los peligros a los que se enfrenta su sistema informático?
 
Cloud Computing, IoT, BYOD Ha muerto el perímetro corporativo. ¿y ahora qué?
Cloud Computing, IoT, BYOD Ha muerto el perímetro corporativo. ¿y ahora qué?Cloud Computing, IoT, BYOD Ha muerto el perímetro corporativo. ¿y ahora qué?
Cloud Computing, IoT, BYOD Ha muerto el perímetro corporativo. ¿y ahora qué?
 
Lean Six Sigma methodology
Lean Six Sigma methodologyLean Six Sigma methodology
Lean Six Sigma methodology
 
IT Governance & ISO 38500
IT Governance & ISO 38500IT Governance & ISO 38500
IT Governance & ISO 38500
 
Cyber Security Resilience & Risk Aggregation
Cyber Security Resilience & Risk AggregationCyber Security Resilience & Risk Aggregation
Cyber Security Resilience & Risk Aggregation
 
EU General Data Protection Regulation
EU General Data Protection RegulationEU General Data Protection Regulation
EU General Data Protection Regulation
 
Payment fraud
Payment fraudPayment fraud
Payment fraud
 
Social engineering attacks
Social engineering attacksSocial engineering attacks
Social engineering attacks
 
Thinking on risk analysis
Thinking on risk analysisThinking on risk analysis
Thinking on risk analysis
 
Drones and their use on critical infrastructure
Drones and their use on critical infrastructureDrones and their use on critical infrastructure
Drones and their use on critical infrastructure
 
Internet of things, big data & mobility vs privacy
Internet of things, big data & mobility vs privacyInternet of things, big data & mobility vs privacy
Internet of things, big data & mobility vs privacy
 
Space computing
Space computingSpace computing
Space computing
 
The relation between internet of things, critical infrastructure and cyber se...
The relation between internet of things, critical infrastructure and cyber se...The relation between internet of things, critical infrastructure and cyber se...
The relation between internet of things, critical infrastructure and cyber se...
 
Internet of things
Internet of thingsInternet of things
Internet of things
 
Cyber Security
Cyber SecurityCyber Security
Cyber Security
 
Cyber Security Awareness
Cyber Security AwarenessCyber Security Awareness
Cyber Security Awareness
 

Último

CNv6 Instructor Chapter 6 Quality of Service
CNv6 Instructor Chapter 6 Quality of ServiceCNv6 Instructor Chapter 6 Quality of Service
CNv6 Instructor Chapter 6 Quality of Servicegiselly40
 
Salesforce Community Group Quito, Salesforce 101
Salesforce Community Group Quito, Salesforce 101Salesforce Community Group Quito, Salesforce 101
Salesforce Community Group Quito, Salesforce 101Paola De la Torre
 
08448380779 Call Girls In Civil Lines Women Seeking Men
08448380779 Call Girls In Civil Lines Women Seeking Men08448380779 Call Girls In Civil Lines Women Seeking Men
08448380779 Call Girls In Civil Lines Women Seeking MenDelhi Call girls
 
08448380779 Call Girls In Greater Kailash - I Women Seeking Men
08448380779 Call Girls In Greater Kailash - I Women Seeking Men08448380779 Call Girls In Greater Kailash - I Women Seeking Men
08448380779 Call Girls In Greater Kailash - I Women Seeking MenDelhi Call girls
 
WhatsApp 9892124323 ✓Call Girls In Kalyan ( Mumbai ) secure service
WhatsApp 9892124323 ✓Call Girls In Kalyan ( Mumbai ) secure serviceWhatsApp 9892124323 ✓Call Girls In Kalyan ( Mumbai ) secure service
WhatsApp 9892124323 ✓Call Girls In Kalyan ( Mumbai ) secure servicePooja Nehwal
 
How to convert PDF to text with Nanonets
How to convert PDF to text with NanonetsHow to convert PDF to text with Nanonets
How to convert PDF to text with Nanonetsnaman860154
 
A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)Gabriella Davis
 
Developing An App To Navigate The Roads of Brazil
Developing An App To Navigate The Roads of BrazilDeveloping An App To Navigate The Roads of Brazil
Developing An App To Navigate The Roads of BrazilV3cube
 
Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024The Digital Insurer
 
Data Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt RobisonData Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt RobisonAnna Loughnan Colquhoun
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerThousandEyes
 
Histor y of HAM Radio presentation slide
Histor y of HAM Radio presentation slideHistor y of HAM Radio presentation slide
Histor y of HAM Radio presentation slidevu2urc
 
Breaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path MountBreaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path MountPuma Security, LLC
 
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptxHampshireHUG
 
From Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time AutomationFrom Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time AutomationSafe Software
 
Presentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreterPresentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreternaman860154
 
Scaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organizationScaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organizationRadu Cotescu
 
Partners Life - Insurer Innovation Award 2024
Partners Life - Insurer Innovation Award 2024Partners Life - Insurer Innovation Award 2024
Partners Life - Insurer Innovation Award 2024The Digital Insurer
 
The Codex of Business Writing Software for Real-World Solutions 2.pptx
The Codex of Business Writing Software for Real-World Solutions 2.pptxThe Codex of Business Writing Software for Real-World Solutions 2.pptx
The Codex of Business Writing Software for Real-World Solutions 2.pptxMalak Abu Hammad
 
Finology Group – Insurtech Innovation Award 2024
Finology Group – Insurtech Innovation Award 2024Finology Group – Insurtech Innovation Award 2024
Finology Group – Insurtech Innovation Award 2024The Digital Insurer
 

Último (20)

CNv6 Instructor Chapter 6 Quality of Service
CNv6 Instructor Chapter 6 Quality of ServiceCNv6 Instructor Chapter 6 Quality of Service
CNv6 Instructor Chapter 6 Quality of Service
 
Salesforce Community Group Quito, Salesforce 101
Salesforce Community Group Quito, Salesforce 101Salesforce Community Group Quito, Salesforce 101
Salesforce Community Group Quito, Salesforce 101
 
08448380779 Call Girls In Civil Lines Women Seeking Men
08448380779 Call Girls In Civil Lines Women Seeking Men08448380779 Call Girls In Civil Lines Women Seeking Men
08448380779 Call Girls In Civil Lines Women Seeking Men
 
08448380779 Call Girls In Greater Kailash - I Women Seeking Men
08448380779 Call Girls In Greater Kailash - I Women Seeking Men08448380779 Call Girls In Greater Kailash - I Women Seeking Men
08448380779 Call Girls In Greater Kailash - I Women Seeking Men
 
WhatsApp 9892124323 ✓Call Girls In Kalyan ( Mumbai ) secure service
WhatsApp 9892124323 ✓Call Girls In Kalyan ( Mumbai ) secure serviceWhatsApp 9892124323 ✓Call Girls In Kalyan ( Mumbai ) secure service
WhatsApp 9892124323 ✓Call Girls In Kalyan ( Mumbai ) secure service
 
How to convert PDF to text with Nanonets
How to convert PDF to text with NanonetsHow to convert PDF to text with Nanonets
How to convert PDF to text with Nanonets
 
A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)
 
Developing An App To Navigate The Roads of Brazil
Developing An App To Navigate The Roads of BrazilDeveloping An App To Navigate The Roads of Brazil
Developing An App To Navigate The Roads of Brazil
 
Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024
 
Data Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt RobisonData Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt Robison
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected Worker
 
Histor y of HAM Radio presentation slide
Histor y of HAM Radio presentation slideHistor y of HAM Radio presentation slide
Histor y of HAM Radio presentation slide
 
Breaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path MountBreaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path Mount
 
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
 
From Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time AutomationFrom Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time Automation
 
Presentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreterPresentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreter
 
Scaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organizationScaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organization
 
Partners Life - Insurer Innovation Award 2024
Partners Life - Insurer Innovation Award 2024Partners Life - Insurer Innovation Award 2024
Partners Life - Insurer Innovation Award 2024
 
The Codex of Business Writing Software for Real-World Solutions 2.pptx
The Codex of Business Writing Software for Real-World Solutions 2.pptxThe Codex of Business Writing Software for Real-World Solutions 2.pptx
The Codex of Business Writing Software for Real-World Solutions 2.pptx
 
Finology Group – Insurtech Innovation Award 2024
Finology Group – Insurtech Innovation Award 2024Finology Group – Insurtech Innovation Award 2024
Finology Group – Insurtech Innovation Award 2024
 

ISO 31000 Risk Management

  • 1. ramirocid.com ramiro@ramirocid.com Twitter: @ramirocid ISO 31000 - Risk Management Ramiro Cid | @ramirocid ISO 31000 - Risk Management
  • 2. ramirocid.com ramiro@ramirocid.com Twitter: @ramirocid ISO 31000 - Risk Management 2 Index 1. Introduction Page 3 2. Certification and Accreditation Page 4 3. History Page 5 4. Main concepts Page 6 5. Scope Page 7 6. Implementation Page 8 7. Implications Page 9 8. Managing risk Page 10 9. Related standards Page 11
  • 3. ramirocid.com ramiro@ramirocid.com Twitter: @ramirocid ISO 31000 - Risk Management 3 Introduction The full name of this standard is: “ISO 31000:2009, Risk management – Principles and guidelines” This standard provides principles, framework and a process for managing risk. It can be used by any organization regardless of its size, activity or sector. Using ISO 31000 can help organizations increase the likelihood of achieving objectives, improve the identification of opportunities and threats and effectively allocate and use resources for risk treatment. ISO 31000 family is expected to include: ISO 31000:2009 - Principles and Guidelines on Implementation ISO/IEC 31010:2009 - Risk Management - Risk Assessment Techniques ISO Guide 73:2009 - Risk Management - Vocabulary
  • 4. ramirocid.com ramiro@ramirocid.com Twitter: @ramirocid ISO 31000 - Risk Management 4 Certification and Accreditation Certification: However, ISO 31000 cannot be used for certification purposes, but does provide guidance for internal or external audit programs. Organizations using it can compare their risk management practices with an internationally recognized benchmark, providing sound principles for effective management and corporate governance. ISO 31000 has not been developed with the intention for certification. (2009) Accreditation: Starting from Mar 2013, accreditation and certification of Professional Certificate Lead Trainer & Consultant for ISO 31000 would be organized and conferred by Academy of Professional Certification (APC, http://www.apc.org.hk) in Hong Kong. APC is an authorized representative of ISO/TC262 for HKSAR Hong Kong.(2013)
  • 5. ramirocid.com ramiro@ramirocid.com Twitter: @ramirocid ISO 31000 - Risk Management 5 History ISO 31000 was published as a standard on the 13th of November 2009, and provides a standard on the implementation of risk management. A revised and harmonized ISO/IEC Guide 73 was published at the same time. The purpose of ISO 31000:2009 is to be applicable and adaptable for "any public, private or community enterprise, association, group or individual. Accordingly, the general scope of ISO 31000 - as a family of risk management standards - is not developed for a particular industry group, management system or subject matter field in mind, rather to provide best practice structure and guidance to all operations concerned with risk management.
  • 6. ramirocid.com ramiro@ramirocid.com Twitter: @ramirocid ISO 31000 - Risk Management 6 Main concepts Risk: “Effect of uncertainty on objectives” Positive and negative consequences Safety, compliance, strategy, anything under the sun Risk management: “coordinated activities to direct and control and organization with regard to risk” Risk management framework: “set of components that provide the foundations and organizational arrangements for designing, implementing, monitoring, reviewing and continually improving risk management processes throughout the organization”. Risk management process: “systematic application of management policies, procedures and practices to the tasks of communication, consultation, establishing the context, identifying, analyzing, evaluating, treating, monitoring and reviewing risk”.
  • 7. ramirocid.com ramiro@ramirocid.com Twitter: @ramirocid ISO 31000 - Risk Management 7 Scope ISO 31000:2009 provides generic guidelines for the design, implementation and maintenance of risk management processes throughout an organization. This approach to formalizing risk management practices will facilitate broader adoption by companies who require an enterprise risk management standard that accommodates multiple ‘silo-centric’ management systems. The scope of this approach to risk management is to enable all strategic, management and operational tasks of an organization throughout projects, functions, and processes to be aligned to a common set of risk management objectives. Accordingly, ISO 31000:2009 is intended for a broad stakeholder group including: Executive level stakeholders Appointment holders in the enterprise risk management group Risk analysts and management officers Line managers and project managers Compliance and internal auditors Independent practitioners.
  • 8. ramirocid.com ramiro@ramirocid.com Twitter: @ramirocid ISO 31000 - Risk Management 8 Implementation The intent of ISO 31000 is to be applied within existing management systems to formalize and improve risk management processes as opposed to wholesale substitution of legacy management practices. Subsequently, when implementing ISO 31000, attention is to be given to integrating existing risk management processes in the new paradigm addressed in the standard. The focus of many ISO 31000 'Harmonisation' programmes have centred on: Transferring accountability gaps in enterprise risk management Aligning objectives of the governance frameworks with ISO 31000 Embedding management system reporting mechanisms Creating uniform risk criteria and evaluation metrics
  • 9. ramirocid.com ramiro@ramirocid.com Twitter: @ramirocid ISO 31000 - Risk Management 9 Implications Most implications for adopting the new standard concern the re-engineering of existing management practices to conform with the documentation, communication and socialization of the new risk management operating paradigm; as opposed to wholesale re-orientation of management practice throughout an organization. Accordingly, most senior position holders in an enterprise risk management organization will need to be cognizant of the implication for adopting the standard and be able to develop effective strategies for implementing the standard across supply chains and commercial operations. Certain aspects of top management accountability, strategic policy implementation and effective governance frameworks, will require more consideration by organizations that have previously used now redundant risk management methodologies. In some domains that concern risk management, in particular security and corporate social responsibility, which may operate using relatively unsophisticated risk management processes, more material change will be required, particularly regarding a clearly articulated risk management policy, formalizing risk ownership processes, structuring framework processes and adopting continuous improvement programs.
  • 10. ramirocid.com ramiro@ramirocid.com Twitter: @ramirocid ISO 31000 - Risk Management 10 Managing risk ISO 31000:2009 gives a list in order of preference on how to deal with risk: 1. Avoiding the risk by deciding not to start or continue with the activity that gives rise to the risk 2. Accepting or increasing the risk in order to pursue an opportunity 3. Removing the risk source 4. Changing the likelihood 5. Changing the consequences 6. Sharing the risk with another party or parties (including contracts and risk financing) 7. Retaining the risk by informed decision
  • 11. ramirocid.com ramiro@ramirocid.com Twitter: @ramirocid ISO 31000 - Risk Management 11 Related standards A number of other standards also relate to risk management: ISO Guide 73:2009, Risk management - Vocabulary complements ISO 31000 by providing a collection of terms and definitions relating to the management of risk. ISO/IEC 31010:2009, Risk management – Risk assessment techniques focuses on risk assessment. Risk assessment helps decision makers understand the risks that could affect the achievement of objectives as well as the adequacy of the controls already in place. ISO/IEC 31010:2009 focuses on risk assessment concepts, processes and the selection of risk assessment techniques.
  • 12. ramirocid.com ramiro@ramirocid.com Twitter: @ramirocid ISO 31000 - Risk Management Questions? Many thanks! ramiro@ramirocid.com @ramirocid http://www.linkedin.com/in/ramirocid http://ramirocid.com http://es.slideshare.net/RamiroCid http://www.youtube.com/user/cidramiro Ramiro Cid CISM, CGEIT, ISO 27001 LA, ISO 22301 LA, ITIL