Risk Management Procedure¶
RISK MANAGEMENT PROCEDURE
Version history¶
| Version Number | Date | Description | Created By | Approved By |
|---|---|---|---|---|
| 0.1 | 23/Jan/2024 | Initial Copy | [Name] | |
| 0.2 | 18/Jun/2024 | Approved | [Name] | [Name] |
| 0.3 | 28/Aug/2026 | Knowledge kernel, AI/agents, control alignment | Knowledge steward | [Name] |
OBJECTIVES¶
To manage risks, tecciance has developed a Risk Management procedure to ensure that tecciance integrates the process for managing risk into the company’s overall policies, governance, strategy and planning, management, and reporting processes. The document also establishes processes for reviewing existing risks, performing periodic risk assessments, and proactively responding to risks.
tecciance shall take into consideration internal and external issues relevant to its purpose as well as the requirements of interested parties to determine the risks and opportunities to be addressed to so that:
-
tecciance ISMS can achieve its intended objectives.
-
Undesired effects of threats can be prevented or reduced.
-
Continual improvement can be achieved.
tecciance will plan and take action to address any identified risks and opportunities, adjusting processes accordingly and evaluating their effectiveness. The outcome of risk assessment is a list of strengths and weaknesses that are managed using a risk register.
SCOPE¶
This policy & methodology applies to all activities undertaken within tecciance risk scope.
REQUIREMENT¶
Risk Management¶
Risk Management is a process where organizations methodically address the risks associated with organizational activities. It is not a one-time process but an ongoing one that changes as the business and technology environment changes. tecciance’s risk management process covers the following steps:
-
Risk Assessment
-
Risk Treatment
-
Risk Monitoring & Review
-
Communication & Consultation
RISK MANAGEMENT PROCESS
Risk Assessment¶
Risks associated with organizational assets shall be assessed in this phase. The most critical assets shall be given priority over assessment of less critical assets. tecciance shall group information assets with similar profiles into groups based on number of asset types as defined.
Phase includes the following steps:
-
Risk Identification – identification of the Failure Mode, Process, and determination of risks.
-
Risk Analysis – determination of risk frequency, risk consequence, risk rating and risk owner.
-
Risk Evaluation – determination of adequacy of controls and residual risk rating.
Risk Identification¶
As part of the Risk Identification phase, the following steps are performed:
-
Identification of Failure Mode
-
Identification of Process
-
Identifying Existing Controls
-
Identifying the assets impacted
-
Identifying the Threat Effect
-
Identifying the Threat Community.
Identification of Failure Mode¶
The activity involves identification of the potential failure mode(s) in the sub process. This is the issue statement for the identified risk. Failure modes could result from People, Process and Technology. Failure mode is defined as the way or manner in which a process could fail to perform its intended function.
Identification of Process¶
Identifying the processes that are aligned with business objectives of tecciance as well as the information security objectives for a function.
Identifying Existing Controls¶
Existing Mitigating Controls effectiveness and efficiency that prevent or detect the cause of the failure or failure mode to be identified. Controls may include any process, policy, device, practice, or any other action that contributes to reduction/prevention /detection of the risk.
Identifying Assets Impacted¶
Map assets affected as part of the identified risk.
- Identifying the Threat Effect
Map respective threat effects in terms of confidentiality, Integrity, and Available impact for the identified risk,
-
Confidentiality
-
Integrity
-
Availability
Identifying the Threat Community¶
Map respective threat community based on community of the threat.
-
Privileged Insiders
-
Non-Privileged Insiders
-
Cyber Criminals
-
Zero Day Exploits
-
Acts of Nature
Risk Analysis¶
The risk consequence, severity, and frequency are all taken into consideration alongside detailed factors such as available resources and internal/external influences. the following steps are performed:
-
Risk Consequence
-
Risk Frequency
-
Risk Rating
-
Risk Owner
Risk Consequence¶
The Asset owner/Risk Owner shall be responsible for valuing each asset group to determine the consequence or impact of an information security breach.
The following scenarios shall be considered (including but not limited to), and highest impact noted:
-
Loss of Confidentiality, Integrity, or Availability of data
-
Direct financial loss.
-
Loss of business relationship.
-
Loss of brand or reputation.
-
Action by legal or local regulator.
-
Customer service and company/Business disruption.
-
Health and safety.
Risk Frequency¶
-
Risk Frequency is the chance of risk happening.
-
tecciance shall identify and list all threats which may affect the assets identified.
Risk Rating¶
In this step, the risks shall be calculated. This refers to the magnitude of a risk (combination of risk expressed in terms of the combination of consequences and their frequency)
| Risk Rating Matrix | |||||
|---|---|---|---|---|---|
| Risk Consequence | Risk Frequency | ||||
| Rare (1) | Unlikely (2) | Possible (3) | Likely (4) | Almost Certain (5) | |
| Catastrophic (5) | 5 | 10 | 15 | 20 | 25 |
| Major (4) | 4 | 8 | 12 | 16 | 20 |
| Medium (3) | 3 | 6 | 9 | 12 | 15 |
| Minor (2) | 2 | 4 | 6 | 8 | 10 |
| Insignificant (1) | 1 | 2 | 3 | 4 | 5 |
| Risk Rating Scores | |
|---|---|
| Risk Level | Range |
| Very Low | Between 1- 5 |
| Low | Between 6-10 |
| Medium | Between 11-15 |
| High | Between 16-20 |
| Very High | Between 21-25 |
Inherent Risk
Current risk shall be based on the multiple of Inherent Risk Consequence and Inherent Risk Frequency (the consequence impact is calculated taking into consideration the mitigating controls currently in place). Inherent Risk is the risk before implementing the risk treatment plans.
Residual Risk
Residual risk shall be based on the multiple of Residual Risk consequence and Residual Risk Frequency (the Risk Rating is recalculated taking into consideration the additional recommended mitigation controls. Residual Risk is the risk remaining after implementing the risk treatment plans.
Risk Owner¶
Risk owners shall be responsible for the identified risk within the Process/Asset scope handled by the Risk Owner and for determining the course of treatment to be taken to manage any identified risks to an acceptable level.
Risk Evaluation¶
This is the final stage during the Risk Assessment. During the Risk Evaluation phase, the risk rating and the current implemented controls are evaluated. During this phase, a decision is taken if further risk treatment is required for the identified risk.
Risk Treatment¶
Risk treatment involves risk reduction, risk acceptance, risk transfer and risk avoidance.
Each department/function shall use the risks identified as part of the risk assessment to determine the cost-effective controls and reasonable security measures to be established to mitigate exposure to the identified risks. If the costs of implementing safeguards and controls are high and exceeds the cost of the asset and if the department / function is unwilling to sponsor it, the latter should have a formal acceptance of the residual risk.
Risks rated as “Very High”, “High”, “Medium” “Low” or “Very Low” should be managed via one or a combination of the following ways:
Accept Risk
The decision on accepting risk without further action shall be taken depending on risk evaluation. If the level of risk meets the acceptable criteria, there shall be no need for implementing additional controls and the risk shall be accepted.
tecciance Management may choose to accept a current risk if it determines that there are no cost-effective controls to productively reduce the risk. This does not mean that the organization cannot effectively address the risk by implementing one or more controls; instead, it means that the cost of implementing the control or controls, or the impact of those controls on the organization’s ability to conduct business, is too high relative to the value of the asset needing protection.
Reduce Risk
Risk reduction refers to the process of implementing risk management techniques to reduce the frequency and the consequence (one or both). This is generally achieved through the implementation of administrative, technical, or physical controls to mitigate or reduce a risk. Post reduction of the risk, a risk analysis is done to ascertain the residual risk.
Avoid Risk
When the identified risks are considered above the agreed threshold (too high), or the costs of implementing other risk treatment options exceed the benefits, a decision could be made to avoid the risk completely by:
-
Withdrawing from a planned or existing activity or set of activities, or project.
-
Changing the conditions under which an activity is operated at tecciance.
-
Removing the source of risk. E.g., ban the use of removable media.
Transfer Risk
Risk Transference is to relocate the responsibility of loss to another party. The most popular way to transfer risk is through insurance.
Risk Treatment Plan¶
A risk treatment plan shall be developed based on the department/function decision to handle the risk (Transfer or Reduce or Avoid).
The risk owner shall identify what additional controls shall be implemented, who is responsible for them and the target date of closure. The purpose of additional controls selection and implementation is to reduce risk to an acceptable level.
The risk owner along with other respective stakeholders shall calculate the cost of implementation of each control; determine the other costs related to the control, such as user inconvenience or ongoing maintenance cost of the control and assess the degree of risk reduction possible with each control.
Risk Acceptance¶
All residual risks with a rating “Very Low” shall be accepted by Risk Owner.
Risk acceptance criteria:
tecciance management shall choose to accept the risk at any level provided the impact of such acceptance is analyzed, understood, and agreed upon by the Risk Owners. The Risk Acceptance Matrix is provided below.
| Risk Acceptance Matrix | |
|---|---|
| Risk Rating/Risk Rating Scores | Risk Acceptance Level |
| Very Low [≤5] | Accepted default by the Risk owner |
| Low [>5 & ≤10] | Risk Acceptance to be signed off from their respective Department Heads & Risk owners |
| Medium [>10 & ≤15] | Risk Treatment should be identified by the risk owner and risks to be mitigated and brought to acceptance level. |
| High [>15 & ≤20] | |
| Very High [>20 & ≤25] | |
Accepted risks shall be reviewed every six months from the agreed accepted date.
Risk Acceptance Notification to ISMS
The Risk Assessment done by the Risk Owners will be reviewed periodically by ISMS Team.
Risk Accepted by Risk Owners/Business Heads should be notified to ISMS Team with Justifications in place for Risks Accepted for review and signoff by ISMS Team.
Risk Monitoring and Review¶
Effective risk management requires a monitoring and review structure to ensure that the risks are effectively identified, assessed and appropriate controls and responses are implemented. Demonstrating commitment to the risk analysis process includes reviewing the findings with the relevant stakeholders.
The ISMS team shall periodically monitor the identified risks on the Risk Register and the agreed remediation plans with the risk owners. The risks on the risk register shall be reviewed and updated on a yearly basis or as and when needed.
The Risk Register and the Risk Assessment template will also be revisited based on changes in the external factors like the business environment, inputs from clients and other external stakeholders etc.
tecciance shall, as a minimum, undertake a full risk assessment annually, or because of:
-
Significant change within and outside the business such as Customer and Regulatory Requirements.
-
Significant events and incidents.
-
Business continuity events and exercises.
-
New or changed product, service, resources, technologies, operations facility.
-
Any other improvement projects or opportunities.
Communication and Consultation¶
The success of a Risk Management program is dependent on management involvement and commitment. This step completes the feedback loop of the risk management process. Communication of the risk levels shall be done by posting the risk assessment to relevant stakeholders / Risk Owners.
The risk register will be updated monthly and maintained on tecciance SharePoint portal for the Risk Owners and the Senior leadership to get periodical status updates.
Documentation of Results¶
All recorded risks from individual functional risk assessments are centrally tracked and managed on the Risk Register by the ISMS Team.
REVIEW¶
This Policy and Procedure shall be reviewed and approved by IS Head once a year or at the time of any major change in existing environment affecting policy, whichever is earlier.
EXCEPTIONS¶
Any exceptions to this Policy and Procedure shall be reviewed and approved by IS Head prior to acceptance.
CONTROL MAPPING¶
MAPPING TO ISO 27001 CONTROL (S)¶
| ISO 27001:2022 Control | Control Objective |
|---|---|
| Clause 6 | Planning |
| Clause 6.1 | Actions to address risks and opportunities |
| Clause 8 | Operation |
| Clause 8.2 | Information security risk assessment |
| Clause 8.3 | Information security risk treatment |