Risk sources and consequences Flashcards
1
Q
What types of questions can be asked to establish the cause of a risk event?
A
What went wrong?
Why did it go wrong?
How did it go wrong?
When did it go wrong?
2
Q
How could you assess the consequences of a risk event?
A
Understand the impact to STOC, key dependencies and stakeholders.
3
Q
After understanding the causes and consequences of risk what should happen?
A
Assessment of the existing risk treatment.
Is the risk treatment working, do we need to change it, do we need additional controls, can the risk even be controlled?
4
Q
What is a method used to illustrate the causes and consequences of risk events?
A
The Bow-Tie diagram.