Skip to content

Risk Management Procedure

RISK MANAGEMENT PROCEDURE

Version history

Version Number Date Description Created By Approved By
0.1 23/Jan/2024 Initial Copy [Name]
0.2 18/Jun/2024 Approved [Name] [Name]
0.3 28/Aug/2026 Knowledge kernel, AI/agents, control alignment Knowledge steward [Name]

OBJECTIVES

To manage risks, tecciance has developed a Risk Management procedure to ensure that tecciance integrates the process for managing risk into the company’s overall policies, governance, strategy and planning, management, and reporting processes. The document also establishes processes for reviewing existing risks, performing periodic risk assessments, and proactively responding to risks.

tecciance shall take into consideration internal and external issues relevant to its purpose as well as the requirements of interested parties to determine the risks and opportunities to be addressed to so that:

  • tecciance ISMS can achieve its intended objectives.

  • Undesired effects of threats can be prevented or reduced.

  • Continual improvement can be achieved.

tecciance will plan and take action to address any identified risks and opportunities, adjusting processes accordingly and evaluating their effectiveness. The outcome of risk assessment is a list of strengths and weaknesses that are managed using a risk register.

SCOPE

This policy & methodology applies to all activities undertaken within tecciance risk scope.

REQUIREMENT

Risk Management

Risk Management is a process where organizations methodically address the risks associated with organizational activities. It is not a one-time process but an ongoing one that changes as the business and technology environment changes. tecciance’s risk management process covers the following steps:

  • Risk Assessment

  • Risk Treatment

  • Risk Monitoring & Review

  • Communication & Consultation

RISK MANAGEMENT PROCESS

Risk Assessment

Risks associated with organizational assets shall be assessed in this phase. The most critical assets shall be given priority over assessment of less critical assets. tecciance shall group information assets with similar profiles into groups based on number of asset types as defined.

Phase includes the following steps:

  • Risk Identification – identification of the Failure Mode, Process, and determination of risks.

  • Risk Analysis – determination of risk frequency, risk consequence, risk rating and risk owner.

  • Risk Evaluation – determination of adequacy of controls and residual risk rating.

Risk Identification

As part of the Risk Identification phase, the following steps are performed:

  • Identification of Failure Mode

  • Identification of Process

  • Identifying Existing Controls

  • Identifying the assets impacted

  • Identifying the Threat Effect

  • Identifying the Threat Community.

Identification of Failure Mode

The activity involves identification of the potential failure mode(s) in the sub process. This is the issue statement for the identified risk. Failure modes could result from People, Process and Technology. Failure mode is defined as the way or manner in which a process could fail to perform its intended function.

Identification of Process

Identifying the processes that are aligned with business objectives of tecciance as well as the information security objectives for a function.

Identifying Existing Controls

Existing Mitigating Controls effectiveness and efficiency that prevent or detect the cause of the failure or failure mode to be identified. Controls may include any process, policy, device, practice, or any other action that contributes to reduction/prevention /detection of the risk.

Identifying Assets Impacted

Map assets affected as part of the identified risk.

  • Identifying the Threat Effect

Map respective threat effects in terms of confidentiality, Integrity, and Available impact for the identified risk,

  • Confidentiality

  • Integrity

  • Availability

Identifying the Threat Community

Map respective threat community based on community of the threat.

  • Privileged Insiders

  • Non-Privileged Insiders

  • Cyber Criminals

  • Zero Day Exploits

  • Acts of Nature

Risk Analysis

The risk consequence, severity, and frequency are all taken into consideration alongside detailed factors such as available resources and internal/external influences. the following steps are performed:

  • Risk Consequence

  • Risk Frequency

  • Risk Rating

  • Risk Owner

Risk Consequence

The Asset owner/Risk Owner shall be responsible for valuing each asset group to determine the consequence or impact of an information security breach.

The following scenarios shall be considered (including but not limited to), and highest impact noted:

  • Loss of Confidentiality, Integrity, or Availability of data

  • Direct financial loss.

  • Loss of business relationship.

  • Loss of brand or reputation.

  • Action by legal or local regulator.

  • Customer service and company/Business disruption.

  • Health and safety.

Risk Frequency

  • Risk Frequency is the chance of risk happening.

  • tecciance shall identify and list all threats which may affect the assets identified.

Risk Rating

In this step, the risks shall be calculated. This refers to the magnitude of a risk (combination of risk expressed in terms of the combination of consequences and their frequency)

Risk Rating Matrix
Risk Consequence Risk Frequency
Rare (1) Unlikely (2) Possible (3) Likely (4) Almost Certain (5)
Catastrophic (5) 5 10 15 20 25
Major (4) 4 8 12 16 20
Medium (3) 3 6 9 12 15
Minor (2) 2 4 6 8 10
Insignificant (1) 1 2 3 4 5
Risk Rating Scores
Risk Level Range
Very Low Between 1- 5
Low Between 6-10
Medium Between 11-15
High Between 16-20
Very High Between 21-25

Inherent Risk

Current risk shall be based on the multiple of Inherent Risk Consequence and Inherent Risk Frequency (the consequence impact is calculated taking into consideration the mitigating controls currently in place). Inherent Risk is the risk before implementing the risk treatment plans.

Residual Risk

Residual risk shall be based on the multiple of Residual Risk consequence and Residual Risk Frequency (the Risk Rating is recalculated taking into consideration the additional recommended mitigation controls. Residual Risk is the risk remaining after implementing the risk treatment plans.

Risk Owner

Risk owners shall be responsible for the identified risk within the Process/Asset scope handled by the Risk Owner and for determining the course of treatment to be taken to manage any identified risks to an acceptable level.

Risk Evaluation

This is the final stage during the Risk Assessment. During the Risk Evaluation phase, the risk rating and the current implemented controls are evaluated. During this phase, a decision is taken if further risk treatment is required for the identified risk.

Risk Treatment

Risk treatment involves risk reduction, risk acceptance, risk transfer and risk avoidance.

Each department/function shall use the risks identified as part of the risk assessment to determine the cost-effective controls and reasonable security measures to be established to mitigate exposure to the identified risks. If the costs of implementing safeguards and controls are high and exceeds the cost of the asset and if the department / function is unwilling to sponsor it, the latter should have a formal acceptance of the residual risk.

Risks rated as “Very High”, “High”, “Medium” “Low” or “Very Low” should be managed via one or a combination of the following ways:

Accept Risk

The decision on accepting risk without further action shall be taken depending on risk evaluation. If the level of risk meets the acceptable criteria, there shall be no need for implementing additional controls and the risk shall be accepted.

tecciance Management may choose to accept a current risk if it determines that there are no cost-effective controls to productively reduce the risk. This does not mean that the organization cannot effectively address the risk by implementing one or more controls; instead, it means that the cost of implementing the control or controls, or the impact of those controls on the organization’s ability to conduct business, is too high relative to the value of the asset needing protection.

Reduce Risk

Risk reduction refers to the process of implementing risk management techniques to reduce the frequency and the consequence (one or both). This is generally achieved through the implementation of administrative, technical, or physical controls to mitigate or reduce a risk. Post reduction of the risk, a risk analysis is done to ascertain the residual risk.

Avoid Risk

When the identified risks are considered above the agreed threshold (too high), or the costs of implementing other risk treatment options exceed the benefits, a decision could be made to avoid the risk completely by:

  • Withdrawing from a planned or existing activity or set of activities, or project.

  • Changing the conditions under which an activity is operated at tecciance.

  • Removing the source of risk. E.g., ban the use of removable media.

Transfer Risk

Risk Transference is to relocate the responsibility of loss to another party. The most popular way to transfer risk is through insurance.

Risk Treatment Plan

A risk treatment plan shall be developed based on the department/function decision to handle the risk (Transfer or Reduce or Avoid).

The risk owner shall identify what additional controls shall be implemented, who is responsible for them and the target date of closure. The purpose of additional controls selection and implementation is to reduce risk to an acceptable level.

The risk owner along with other respective stakeholders shall calculate the cost of implementation of each control; determine the other costs related to the control, such as user inconvenience or ongoing maintenance cost of the control and assess the degree of risk reduction possible with each control.

Risk Acceptance

All residual risks with a rating “Very Low” shall be accepted by Risk Owner.

Risk acceptance criteria:

tecciance management shall choose to accept the risk at any level provided the impact of such acceptance is analyzed, understood, and agreed upon by the Risk Owners. The Risk Acceptance Matrix is provided below.

Risk Acceptance Matrix
Risk Rating/Risk Rating Scores Risk Acceptance Level
Very Low [≤5] Accepted default by the Risk owner
Low [>5 & ≤10] Risk Acceptance to be signed off from their respective Department Heads & Risk owners
Medium [>10 & ≤15] Risk Treatment should be identified by the risk owner and risks to be mitigated and brought to acceptance level.
High [>15 & ≤20]
Very High [>20 & ≤25]

Accepted risks shall be reviewed every six months from the agreed accepted date.

Risk Acceptance Notification to ISMS

The Risk Assessment done by the Risk Owners will be reviewed periodically by ISMS Team.

Risk Accepted by Risk Owners/Business Heads should be notified to ISMS Team with Justifications in place for Risks Accepted for review and signoff by ISMS Team.

Risk Monitoring and Review

Effective risk management requires a monitoring and review structure to ensure that the risks are effectively identified, assessed and appropriate controls and responses are implemented. Demonstrating commitment to the risk analysis process includes reviewing the findings with the relevant stakeholders.

The ISMS team shall periodically monitor the identified risks on the Risk Register and the agreed remediation plans with the risk owners. The risks on the risk register shall be reviewed and updated on a yearly basis or as and when needed.

The Risk Register and the Risk Assessment template will also be revisited based on changes in the external factors like the business environment, inputs from clients and other external stakeholders etc.

tecciance shall, as a minimum, undertake a full risk assessment annually, or because of:

  • Significant change within and outside the business such as Customer and Regulatory Requirements.

  • Significant events and incidents.

  • Business continuity events and exercises.

  • New or changed product, service, resources, technologies, operations facility.

  • Any other improvement projects or opportunities.

Communication and Consultation

The success of a Risk Management program is dependent on management involvement and commitment. This step completes the feedback loop of the risk management process. Communication of the risk levels shall be done by posting the risk assessment to relevant stakeholders / Risk Owners.

The risk register will be updated monthly and maintained on tecciance SharePoint portal for the Risk Owners and the Senior leadership to get periodical status updates.

Documentation of Results

All recorded risks from individual functional risk assessments are centrally tracked and managed on the Risk Register by the ISMS Team.

REVIEW

This Policy and Procedure shall be reviewed and approved by IS Head once a year or at the time of any major change in existing environment affecting policy, whichever is earlier.

EXCEPTIONS

Any exceptions to this Policy and Procedure shall be reviewed and approved by IS Head prior to acceptance.

CONTROL MAPPING

MAPPING TO ISO 27001 CONTROL (S)

ISO 27001:2022 Control Control Objective
Clause 6 Planning
Clause 6.1 Actions to address risks and opportunities
Clause 8 Operation
Clause 8.2 Information security risk assessment
Clause 8.3 Information security risk treatment