4.4 National standards and guides Flashcards
Which British Standard implements ISO 31000?
BS 31100
When was BS31100 published?
2011
BS 31100 provides advice and guidance on d_______, implementing and m___________ proportionate and effective risk management.
developing
maintaining
BS 31100 includes:
- how to manage risk p_________, not reactively
- operating of effective risk management o________
- providing a_______ to the board and senior management
- reporting to s_____________
proactively
oversight
assurance
stakeholders
Which Irish agency provides guidance on implementing ISO31000?
National Standards Agency of Ireland
What is the purpose of the “Orange Book” published by the UK Government?
The Orange Book establishes the concept of risk management for government organisations and departments.
The Orange Book asks government departments to consider the “extended enterprise”. What does this mean?
Extended enterprise refers to the risk management needs of stakeholders.
What are the benefits and downsides of the Institute of Risk Management Standard compared to the ISO31000 standard.
The IRM standard is free to download in 14 languages, but has not been updated as recently as ISO31000.
The IRM Standard (2002) considers risks as having both an u______ and a d________. Good risk management should help organisations exploit o______________ and mitigate t______.
upside
downside
opportunities
threats
The IRM standard identifies four external risk factors, or drivers. What are these?
Financial risks (eg. interest rates) Strategic risks (e.g. research) Operational risks (e.g. regulatory change) Hazard risks (e.g. environmental threats)
The IRM standard identifies four internal risk factors. What are these?
Financial risks (e.g. volatile cash flow) Strategic risks (e.g. competition) Operational risks (e.g. misconduct) Hazard risks (e.g. health and safety)
The COSO Enterprise Risk Management Framework underwent a major revision… when?
2017
The COSO ERM Framework recognises that although risk management is an important part of effective governance, this does not preclude using risk management to help improve s_________ and o___________ performance.
strategic
operational
The COSO ERM framework is presented as a set of principles organised into five components:
- governance and c_______
- strategy and o_______ setting
- performance
- review and r_______
- information, communication and r________
culture
objective
revision
reporting
What is COBIT 5?
Control Objectives for Information and Related Technologies - i.e. a framework for IT related risk.