Risk Types Flashcards
General vs. Specialized Risk Management
General risk management applies to broad contexts, while specialized risk management targets specific domains.
Example: General: ISO31000 for overall risk frameworks. Specialized: ISO/IEC27005 for information security risk management.
Organization-Centric Risk Management
Focuses on risks affecting the organization as a whole, often conflicting with other entities’ risks.
Example: A company avoids costly code quality measures to reduce financial risk, impacting a client who must implement compensating controls.
SE Project-Centric Risk Management
Centers on risks specific to software projects, including misaligned organizational and project goals.
Example: A project accepts coding shortcuts to meet deadlines but faces post-release security vulnerabilities.
Application-Centric Risk Management
Focuses on technical risks tied to software applications, including coding, testing, and environmental security.
Example: An application runs on unpatched operating systems, increasing vulnerability to attacks.
Supply Chain Risk Management
Manages risks tied to subcontractors and third-party dependencies.
Example: Choosing a subcontractor in a risky jurisdiction without confidentiality clauses in the contract.
Risk Management in Emerging Technologies
Handles risks from technologies with rapid growth, novelty, and uncertainty.
Example: Quantum computing introduces uncertainty in cryptographic algorithms and adoption impacts.
Risk Management through IT Auditing and Checklists
Uses control-based or risk-based audits to identify and manage risks systematically.
Example: A risk-based audit identifies gaps in cloud service provider controls and suggests mitigation steps.
Business Continuity Management as a Risk Management Tool
Prepares for operational resilience and disaster recovery in IT systems.
Example: Using cloud backups to meet a client’s RPO (maximum acceptable data loss) of 1 hour.
List of all types of risk perspectives
- General vis-a-vis specialized risk management
- Organization-centric risk management
- SE Project Centric risk management
- Application-centric risk management
- Supply chain risk management
- Risk management in emerging technologies
- Risk management through IT auditing and checklists.
- Business continuity management as a risk management tool.