SlideShare ist ein Scribd-Unternehmen logo
1 von 31
Project risk analysis has a broad range of
applications, just as the definition of a project is
broad. Project risk analysis is concerned with the
assessment of the risks and uncertainties that
threaten a project.
What is Project?
A temporary endeavor undertaken to create a
unique product of service.
In the broadest sense a project is specific, finite
task to accomplished; whether large or small scale; long
or short run.
What is Risk?
The probability that a particular threat will exploit
a particular vulnerability.
Risk analysis is the review of the risks associated
with a particular event or action. It is applied to
projects, information technology, security issues
and any action where risks may be analyzed on a
quantitative and qualitative basis. Risk analysis
is a component of risk management.
6
Risk Management Cycle
Slide #7
Risk Analysis
1. Calculate the (quantitative) likelihood
of each identified hazard
2. Calculate the (quantitative)
consequences that are expected to
occur for each hazard
3. Develop a locally-tailored qualitative
system of measurement
4. Translate all quantitative data into
qualitative measures
8
Who should be Involved?
Security Experts
Internal domain experts
Managers responsible for implementing
controls
Slide #9
Assets
Identify Assets
Critical Assets
Identify Assets
Physical Assets
Buildings, computers
Logical Assets
Intellectual property, reputation
Slide #11
Critical Assets
People and skills
Goodwill
Hardware/Software
Documentation
Physical plant
Money
Slide #12
Threats
An expression of intention to inflict evil
injury or damage
Attacks against key security services
Confidentiality, integrity, availability
Slide #13
Vulnerabilities
Flaw or weakness in system that can be
exploited to violate system integrity.
Security Procedures
Design
Implementation
Threats trigger vulnerabilities
Accidental
Malicious
Slide #14
Controls/Countermeasures
Mechanisms or procedures for
mitigating vulnerabilities
Prevent
Detect
Recover
Understand cost and coverage of control
Controls follow vulnerability and threat
analysis
Slide #15
Risk/Control Trade Offs
Only Safe Asset is a Dead Asset
Asset that is completely locked away is safe,
but useless
Trade-off between safety and availablity
Do not waste effort on efforts with low loss
value
Don’t spend resources to protect garbage
Control only has to be good enough, not
absolute
Make it tough enough to discourage enemy Slide #16
Types of Risk Analysis
Quantitative
Assigns real numbers to costs of safeguards and damage
Annual loss exposure (ALE)
Probability of event occurring
Can be unreliable/inaccurate
Qualitative
Judges an organization’s risk to threats
Based on judgment, intuition, and experience
Ranks the seriousness of the threats for the sensitivity of the
asserts
Subjective, lacks hard numbers to justify return on investment
Slide #17
Quantitative vs. Qualitative
Quantitative Analysis
Uses mathematical/
statistical data to derive
numerical descriptions
of risk
More precise analysis
More difficult to
perform
Qualitative
Uses defined terms
(words) to describe and
categorize risk
Less precise analysis
Easier to perform
Session 18
Consequence
Deaths/Fatalities (Human)
Injuries (Human)
Damages (Cost, reported in US dollars)
Session 18
Direct Losses
Fatalities
Injuries
Repair and replacement of damaged or
destroyed public and private structures
Relocation costs/temporary housing
Loss of business inventory/agriculture
Loss of income/rental costs
Community response costs
Cleanup costs
20
Indirect Losses
Loss of income
Input/output losses of businesses
Reductions in business /personal spending
– “ripple effects”
Loss of institutional knowledge
Mental illness
Bereavement
Tangible Losses
Cost of building repair/replacement
Response costs
Loss of inventory
Loss of income
22
Intangible Losses
Cultural losses
Stress
Mental illness
Sentimental Value
Environmental Losses
Fatalities/Injuries
23
Quantitative Analysis Outline
1. Identify and value assets
2. Determine vulnerabilities and impact
3. Estimate likelihood of exploitation
4. Compute Annual Loss Exposure
5. Survey applicable controls and their
costs
6. Project annual savings from control
Quantitative
Risk = Risk-impact x Risk-Probability
Loss of car: risk-impact is cost to
replace car, e.g. $10,000
Probability of car loss: 0.10
Risk = 10,000 x 0.10 = 1,000
General measured per year
Annual Loss Exposure (ALE)
Slide #25
Qualitative Risk Analysis
Generally used in Information Security
Hard to make meaningful valuations and
meaningful probabilities
Relative ordering is faster and more important
Many approaches to performing qualitative
risk analysis
Same basic steps as quantitative analysis
Still identifying asserts, threats, vulnerabilities, and
controls
Just evaluating importance differently
Slide #26
Problem Identify
Step 1: Identify Scope
Bound the problem
Step 2: Assemble team
Include subject matter experts, management in
charge of implementing, users
Step 3: Identify Threats
Pick from lists of known threats
Brainstorm new threats
Mixing threats and vulnerabilities here...
Slide #27
Threat prioritization
Prioritize threats for each assert
Likelihood of occurrence
Define a fixed threat rating
Associate a rating with each threat
Approximation to the risk probability in
quantitative approach
Slide #28
Loss Impact
With each threat determine loss impact
Define a fixed ranking
Used to prioritize damage to asset from
threat
Slide #29
Changes in Human Activities
Population Growth
Economic Growth
Technological Innovation
Social Expectations
Growing Interdependence
30
In project risk analysis can understand that
project may be risk or not. what ever the
risk it may be high or low the investor
take decision.
31

Weitere ähnliche Inhalte

Was ist angesagt?

Risk Management in Construction Project
Risk Management in Construction ProjectRisk Management in Construction Project
Risk Management in Construction ProjectDr. Amarjeet Singh
 
Project Risk Management (10)
 Project Risk Management (10) Project Risk Management (10)
Project Risk Management (10)Serdar Temiz
 
Risk & Risk Management
Risk & Risk ManagementRisk & Risk Management
Risk & Risk Managementansula
 
Risk Analysis : PMP- Project Risk Management
Risk Analysis : PMP- Project Risk ManagementRisk Analysis : PMP- Project Risk Management
Risk Analysis : PMP- Project Risk ManagementSaket Bansal
 
Project Risk Management
Project Risk ManagementProject Risk Management
Project Risk ManagementMarkos Mulat G
 
Presentation on project appraisal
Presentation on project appraisalPresentation on project appraisal
Presentation on project appraisaljeni kayastha
 
“Construction Risk Management”
“Construction Risk Management”“Construction Risk Management”
“Construction Risk Management”Ary Jamil
 
11.3 Perform Qualitative Risk Analysis
11.3 Perform Qualitative Risk Analysis11.3 Perform Qualitative Risk Analysis
11.3 Perform Qualitative Risk AnalysisDavidMcLachlan1
 
Risk Management
Risk ManagementRisk Management
Risk Managementcgeorgeo
 
Project Risk Management
Project Risk ManagementProject Risk Management
Project Risk ManagementKaustubh Gupta
 
Advanced program management risk mitigation and management
Advanced program management   risk mitigation and managementAdvanced program management   risk mitigation and management
Advanced program management risk mitigation and managementMarcus Vannini
 
Project Risk Management
Project Risk ManagementProject Risk Management
Project Risk Managementcgautam
 
Risk Management Processes from Jerry Klanac
Risk Management Processes from Jerry KlanacRisk Management Processes from Jerry Klanac
Risk Management Processes from Jerry KlanacPMA Consultants
 
Construction project risk management
Construction project risk managementConstruction project risk management
Construction project risk managementIQPC
 

Was ist angesagt? (20)

Risk Management in Construction Project
Risk Management in Construction ProjectRisk Management in Construction Project
Risk Management in Construction Project
 
Plan Risk responses
Plan Risk responsesPlan Risk responses
Plan Risk responses
 
Project risk management
Project risk managementProject risk management
Project risk management
 
Project Risk Management (10)
 Project Risk Management (10) Project Risk Management (10)
Project Risk Management (10)
 
Risk & Risk Management
Risk & Risk ManagementRisk & Risk Management
Risk & Risk Management
 
Project risk management
Project risk managementProject risk management
Project risk management
 
Risk Analysis : PMP- Project Risk Management
Risk Analysis : PMP- Project Risk ManagementRisk Analysis : PMP- Project Risk Management
Risk Analysis : PMP- Project Risk Management
 
Project Risk Management
Project Risk ManagementProject Risk Management
Project Risk Management
 
Presentation on project appraisal
Presentation on project appraisalPresentation on project appraisal
Presentation on project appraisal
 
“Construction Risk Management”
“Construction Risk Management”“Construction Risk Management”
“Construction Risk Management”
 
Risk Management
Risk ManagementRisk Management
Risk Management
 
11.3 Perform Qualitative Risk Analysis
11.3 Perform Qualitative Risk Analysis11.3 Perform Qualitative Risk Analysis
11.3 Perform Qualitative Risk Analysis
 
Risk Management
Risk ManagementRisk Management
Risk Management
 
Project Risk Management
Project Risk ManagementProject Risk Management
Project Risk Management
 
Risk management
Risk managementRisk management
Risk management
 
Risk Management Assignment
Risk Management AssignmentRisk Management Assignment
Risk Management Assignment
 
Advanced program management risk mitigation and management
Advanced program management   risk mitigation and managementAdvanced program management   risk mitigation and management
Advanced program management risk mitigation and management
 
Project Risk Management
Project Risk ManagementProject Risk Management
Project Risk Management
 
Risk Management Processes from Jerry Klanac
Risk Management Processes from Jerry KlanacRisk Management Processes from Jerry Klanac
Risk Management Processes from Jerry Klanac
 
Construction project risk management
Construction project risk managementConstruction project risk management
Construction project risk management
 

Andere mochten auch

Project risk analysis
Project risk analysisProject risk analysis
Project risk analysisrupeshmisal
 
Enterprise Portfolio Risk vs Project Risk - J Fairchild
Enterprise Portfolio Risk vs Project Risk - J FairchildEnterprise Portfolio Risk vs Project Risk - J Fairchild
Enterprise Portfolio Risk vs Project Risk - J FairchildInSync Conference
 
Project Risk Analysis with Risk Event and Event Chain
Project Risk Analysis with Risk Event and Event ChainProject Risk Analysis with Risk Event and Event Chain
Project Risk Analysis with Risk Event and Event ChainIntaver Insititute
 
Chapter 3 slides
Chapter 3 slidesChapter 3 slides
Chapter 3 slidesteg007
 
Introduction to human resource development
Introduction to human resource developmentIntroduction to human resource development
Introduction to human resource developmentsaumyadvd
 
Human Resource Development (HRD)
Human Resource Development (HRD)Human Resource Development (HRD)
Human Resource Development (HRD)Prakash Dhakal
 
Human resource development
Human resource developmentHuman resource development
Human resource developmentGeethu Mary
 
A Guide to SlideShare Analytics - Excerpts from Hubspot's Step by Step Guide ...
A Guide to SlideShare Analytics - Excerpts from Hubspot's Step by Step Guide ...A Guide to SlideShare Analytics - Excerpts from Hubspot's Step by Step Guide ...
A Guide to SlideShare Analytics - Excerpts from Hubspot's Step by Step Guide ...SlideShare
 

Andere mochten auch (9)

Project risk analysis
Project risk analysisProject risk analysis
Project risk analysis
 
Enterprise Portfolio Risk vs Project Risk - J Fairchild
Enterprise Portfolio Risk vs Project Risk - J FairchildEnterprise Portfolio Risk vs Project Risk - J Fairchild
Enterprise Portfolio Risk vs Project Risk - J Fairchild
 
Project Risk Analysis with Risk Event and Event Chain
Project Risk Analysis with Risk Event and Event ChainProject Risk Analysis with Risk Event and Event Chain
Project Risk Analysis with Risk Event and Event Chain
 
Chapter 3 slides
Chapter 3 slidesChapter 3 slides
Chapter 3 slides
 
Introduction to human resource development
Introduction to human resource developmentIntroduction to human resource development
Introduction to human resource development
 
Human Resource Development (HRD)
Human Resource Development (HRD)Human Resource Development (HRD)
Human Resource Development (HRD)
 
Hrd
HrdHrd
Hrd
 
Human resource development
Human resource developmentHuman resource development
Human resource development
 
A Guide to SlideShare Analytics - Excerpts from Hubspot's Step by Step Guide ...
A Guide to SlideShare Analytics - Excerpts from Hubspot's Step by Step Guide ...A Guide to SlideShare Analytics - Excerpts from Hubspot's Step by Step Guide ...
A Guide to SlideShare Analytics - Excerpts from Hubspot's Step by Step Guide ...
 

Ähnlich wie Project risk analysis

Risk Management (1) (1).ppt
Risk Management (1) (1).pptRisk Management (1) (1).ppt
Risk Management (1) (1).pptAjjuSingh2
 
Risk Management
Risk ManagementRisk Management
Risk Managementrajuinstru
 
Comprehensive Overview Of Risk Management
Comprehensive Overview Of Risk ManagementComprehensive Overview Of Risk Management
Comprehensive Overview Of Risk ManagementAndrew Valenti
 
Final Class Presentation on Determining Project Stakeholders & Risks.pptx
Final Class Presentation on Determining Project Stakeholders & Risks.pptxFinal Class Presentation on Determining Project Stakeholders & Risks.pptx
Final Class Presentation on Determining Project Stakeholders & Risks.pptxGeorgeKabongah2
 
e-Symposium_ISACA_Ramsés_Gallego
e-Symposium_ISACA_Ramsés_Gallegoe-Symposium_ISACA_Ramsés_Gallego
e-Symposium_ISACA_Ramsés_GallegoRamsés Gallego
 
Assessment Of Risk Mitigation
Assessment Of Risk MitigationAssessment Of Risk Mitigation
Assessment Of Risk MitigationEneni Oduwole
 
اهم برزنتيشن لجنك2222
اهم برزنتيشن لجنك2222اهم برزنتيشن لجنك2222
اهم برزنتيشن لجنك2222nashaat algrara
 
Beyond PMP: Risk Management
Beyond PMP: Risk ManagementBeyond PMP: Risk Management
Beyond PMP: Risk Managementabhinayverma
 
Crash Course: Managing Cyber Risk Using Quantitative Analysis
Crash Course: Managing Cyber Risk Using Quantitative AnalysisCrash Course: Managing Cyber Risk Using Quantitative Analysis
Crash Course: Managing Cyber Risk Using Quantitative Analysis"Apolonio \"Apps\"" Garcia
 
CISSP 8 Domains.pdf
CISSP 8 Domains.pdfCISSP 8 Domains.pdf
CISSP 8 Domains.pdfdotco
 
Global Health Comparison Grid TemplateGlobal Health Co
Global Health Comparison Grid TemplateGlobal Health CoGlobal Health Comparison Grid TemplateGlobal Health Co
Global Health Comparison Grid TemplateGlobal Health CoMatthewTennant613
 
Relating Risk to Vulnerability
Relating Risk to Vulnerability Relating Risk to Vulnerability
Relating Risk to Vulnerability Resolver Inc.
 
project risk management
project risk managementproject risk management
project risk managementAshima Thakur
 
INFORMATION SECURITY MANAGEMENT
INFORMATION SECURITY MANAGEMENTINFORMATION SECURITY MANAGEMENT
INFORMATION SECURITY MANAGEMENTNi
 
Top 5 secrets to successfully jumpstarting your cyber-risk program
Top 5 secrets to successfully jumpstarting your cyber-risk programTop 5 secrets to successfully jumpstarting your cyber-risk program
Top 5 secrets to successfully jumpstarting your cyber-risk programPriyanka Aash
 

Ähnlich wie Project risk analysis (20)

06 Crisis & Risk management
06 Crisis & Risk management06 Crisis & Risk management
06 Crisis & Risk management
 
Risk Management (1) (1).ppt
Risk Management (1) (1).pptRisk Management (1) (1).ppt
Risk Management (1) (1).ppt
 
Risk Management
Risk ManagementRisk Management
Risk Management
 
Comprehensive Overview Of Risk Management
Comprehensive Overview Of Risk ManagementComprehensive Overview Of Risk Management
Comprehensive Overview Of Risk Management
 
Final Class Presentation on Determining Project Stakeholders & Risks.pptx
Final Class Presentation on Determining Project Stakeholders & Risks.pptxFinal Class Presentation on Determining Project Stakeholders & Risks.pptx
Final Class Presentation on Determining Project Stakeholders & Risks.pptx
 
Lecture2.pptx
Lecture2.pptxLecture2.pptx
Lecture2.pptx
 
e-Symposium_ISACA_Ramsés_Gallego
e-Symposium_ISACA_Ramsés_Gallegoe-Symposium_ISACA_Ramsés_Gallego
e-Symposium_ISACA_Ramsés_Gallego
 
Assessment Of Risk Mitigation
Assessment Of Risk MitigationAssessment Of Risk Mitigation
Assessment Of Risk Mitigation
 
اهم برزنتيشن لجنك2222
اهم برزنتيشن لجنك2222اهم برزنتيشن لجنك2222
اهم برزنتيشن لجنك2222
 
Beyond PMP: Risk Management
Beyond PMP: Risk ManagementBeyond PMP: Risk Management
Beyond PMP: Risk Management
 
Crash Course: Managing Cyber Risk Using Quantitative Analysis
Crash Course: Managing Cyber Risk Using Quantitative AnalysisCrash Course: Managing Cyber Risk Using Quantitative Analysis
Crash Course: Managing Cyber Risk Using Quantitative Analysis
 
CISSP 8 Domains.pdf
CISSP 8 Domains.pdfCISSP 8 Domains.pdf
CISSP 8 Domains.pdf
 
Global Health Comparison Grid TemplateGlobal Health Co
Global Health Comparison Grid TemplateGlobal Health CoGlobal Health Comparison Grid TemplateGlobal Health Co
Global Health Comparison Grid TemplateGlobal Health Co
 
Relating Risk to Vulnerability
Relating Risk to Vulnerability Relating Risk to Vulnerability
Relating Risk to Vulnerability
 
project risk management
project risk managementproject risk management
project risk management
 
Security assessment isaca sv presentation jan 2016
Security assessment isaca sv presentation jan 2016Security assessment isaca sv presentation jan 2016
Security assessment isaca sv presentation jan 2016
 
Hands on IT risk assessment
Hands on IT risk assessmentHands on IT risk assessment
Hands on IT risk assessment
 
INFORMATION SECURITY MANAGEMENT
INFORMATION SECURITY MANAGEMENTINFORMATION SECURITY MANAGEMENT
INFORMATION SECURITY MANAGEMENT
 
Top 5 secrets to successfully jumpstarting your cyber-risk program
Top 5 secrets to successfully jumpstarting your cyber-risk programTop 5 secrets to successfully jumpstarting your cyber-risk program
Top 5 secrets to successfully jumpstarting your cyber-risk program
 
Risk Management 1 (2)
Risk Management 1 (2)Risk Management 1 (2)
Risk Management 1 (2)
 

Kürzlich hochgeladen

(SHREYA) Chakan Call Girls Just Call 7001035870 [ Cash on Delivery ] Pune Esc...
(SHREYA) Chakan Call Girls Just Call 7001035870 [ Cash on Delivery ] Pune Esc...(SHREYA) Chakan Call Girls Just Call 7001035870 [ Cash on Delivery ] Pune Esc...
(SHREYA) Chakan Call Girls Just Call 7001035870 [ Cash on Delivery ] Pune Esc...ranjana rawat
 
Microscopic Analysis of Ceramic Materials.pptx
Microscopic Analysis of Ceramic Materials.pptxMicroscopic Analysis of Ceramic Materials.pptx
Microscopic Analysis of Ceramic Materials.pptxpurnimasatapathy1234
 
Extrusion Processes and Their Limitations
Extrusion Processes and Their LimitationsExtrusion Processes and Their Limitations
Extrusion Processes and Their Limitations120cr0395
 
UNIT-III FMM. DIMENSIONAL ANALYSIS
UNIT-III FMM.        DIMENSIONAL ANALYSISUNIT-III FMM.        DIMENSIONAL ANALYSIS
UNIT-III FMM. DIMENSIONAL ANALYSISrknatarajan
 
Software Development Life Cycle By Team Orange (Dept. of Pharmacy)
Software Development Life Cycle By  Team Orange (Dept. of Pharmacy)Software Development Life Cycle By  Team Orange (Dept. of Pharmacy)
Software Development Life Cycle By Team Orange (Dept. of Pharmacy)Suman Mia
 
Decoding Kotlin - Your guide to solving the mysterious in Kotlin.pptx
Decoding Kotlin - Your guide to solving the mysterious in Kotlin.pptxDecoding Kotlin - Your guide to solving the mysterious in Kotlin.pptx
Decoding Kotlin - Your guide to solving the mysterious in Kotlin.pptxJoão Esperancinha
 
Model Call Girl in Narela Delhi reach out to us at 🔝8264348440🔝
Model Call Girl in Narela Delhi reach out to us at 🔝8264348440🔝Model Call Girl in Narela Delhi reach out to us at 🔝8264348440🔝
Model Call Girl in Narela Delhi reach out to us at 🔝8264348440🔝soniya singh
 
(ANVI) Koregaon Park Call Girls Just Call 7001035870 [ Cash on Delivery ] Pun...
(ANVI) Koregaon Park Call Girls Just Call 7001035870 [ Cash on Delivery ] Pun...(ANVI) Koregaon Park Call Girls Just Call 7001035870 [ Cash on Delivery ] Pun...
(ANVI) Koregaon Park Call Girls Just Call 7001035870 [ Cash on Delivery ] Pun...ranjana rawat
 
Booking open Available Pune Call Girls Koregaon Park 6297143586 Call Hot Ind...
Booking open Available Pune Call Girls Koregaon Park  6297143586 Call Hot Ind...Booking open Available Pune Call Girls Koregaon Park  6297143586 Call Hot Ind...
Booking open Available Pune Call Girls Koregaon Park 6297143586 Call Hot Ind...Call Girls in Nagpur High Profile
 
VIP Call Girls Service Hitech City Hyderabad Call +91-8250192130
VIP Call Girls Service Hitech City Hyderabad Call +91-8250192130VIP Call Girls Service Hitech City Hyderabad Call +91-8250192130
VIP Call Girls Service Hitech City Hyderabad Call +91-8250192130Suhani Kapoor
 
HARDNESS, FRACTURE TOUGHNESS AND STRENGTH OF CERAMICS
HARDNESS, FRACTURE TOUGHNESS AND STRENGTH OF CERAMICSHARDNESS, FRACTURE TOUGHNESS AND STRENGTH OF CERAMICS
HARDNESS, FRACTURE TOUGHNESS AND STRENGTH OF CERAMICSRajkumarAkumalla
 
Call Girls in Nagpur Suman Call 7001035870 Meet With Nagpur Escorts
Call Girls in Nagpur Suman Call 7001035870 Meet With Nagpur EscortsCall Girls in Nagpur Suman Call 7001035870 Meet With Nagpur Escorts
Call Girls in Nagpur Suman Call 7001035870 Meet With Nagpur EscortsCall Girls in Nagpur High Profile
 
SPICE PARK APR2024 ( 6,793 SPICE Models )
SPICE PARK APR2024 ( 6,793 SPICE Models )SPICE PARK APR2024 ( 6,793 SPICE Models )
SPICE PARK APR2024 ( 6,793 SPICE Models )Tsuyoshi Horigome
 
High Profile Call Girls Nagpur Isha Call 7001035870 Meet With Nagpur Escorts
High Profile Call Girls Nagpur Isha Call 7001035870 Meet With Nagpur EscortsHigh Profile Call Girls Nagpur Isha Call 7001035870 Meet With Nagpur Escorts
High Profile Call Girls Nagpur Isha Call 7001035870 Meet With Nagpur Escortsranjana rawat
 
Structural Analysis and Design of Foundations: A Comprehensive Handbook for S...
Structural Analysis and Design of Foundations: A Comprehensive Handbook for S...Structural Analysis and Design of Foundations: A Comprehensive Handbook for S...
Structural Analysis and Design of Foundations: A Comprehensive Handbook for S...Dr.Costas Sachpazis
 
APPLICATIONS-AC/DC DRIVES-OPERATING CHARACTERISTICS
APPLICATIONS-AC/DC DRIVES-OPERATING CHARACTERISTICSAPPLICATIONS-AC/DC DRIVES-OPERATING CHARACTERISTICS
APPLICATIONS-AC/DC DRIVES-OPERATING CHARACTERISTICSKurinjimalarL3
 
(TARA) Talegaon Dabhade Call Girls Just Call 7001035870 [ Cash on Delivery ] ...
(TARA) Talegaon Dabhade Call Girls Just Call 7001035870 [ Cash on Delivery ] ...(TARA) Talegaon Dabhade Call Girls Just Call 7001035870 [ Cash on Delivery ] ...
(TARA) Talegaon Dabhade Call Girls Just Call 7001035870 [ Cash on Delivery ] ...ranjana rawat
 

Kürzlich hochgeladen (20)

(SHREYA) Chakan Call Girls Just Call 7001035870 [ Cash on Delivery ] Pune Esc...
(SHREYA) Chakan Call Girls Just Call 7001035870 [ Cash on Delivery ] Pune Esc...(SHREYA) Chakan Call Girls Just Call 7001035870 [ Cash on Delivery ] Pune Esc...
(SHREYA) Chakan Call Girls Just Call 7001035870 [ Cash on Delivery ] Pune Esc...
 
DJARUM4D - SLOT GACOR ONLINE | SLOT DEMO ONLINE
DJARUM4D - SLOT GACOR ONLINE | SLOT DEMO ONLINEDJARUM4D - SLOT GACOR ONLINE | SLOT DEMO ONLINE
DJARUM4D - SLOT GACOR ONLINE | SLOT DEMO ONLINE
 
Microscopic Analysis of Ceramic Materials.pptx
Microscopic Analysis of Ceramic Materials.pptxMicroscopic Analysis of Ceramic Materials.pptx
Microscopic Analysis of Ceramic Materials.pptx
 
Extrusion Processes and Their Limitations
Extrusion Processes and Their LimitationsExtrusion Processes and Their Limitations
Extrusion Processes and Their Limitations
 
UNIT-III FMM. DIMENSIONAL ANALYSIS
UNIT-III FMM.        DIMENSIONAL ANALYSISUNIT-III FMM.        DIMENSIONAL ANALYSIS
UNIT-III FMM. DIMENSIONAL ANALYSIS
 
Call Us -/9953056974- Call Girls In Vikaspuri-/- Delhi NCR
Call Us -/9953056974- Call Girls In Vikaspuri-/- Delhi NCRCall Us -/9953056974- Call Girls In Vikaspuri-/- Delhi NCR
Call Us -/9953056974- Call Girls In Vikaspuri-/- Delhi NCR
 
Software Development Life Cycle By Team Orange (Dept. of Pharmacy)
Software Development Life Cycle By  Team Orange (Dept. of Pharmacy)Software Development Life Cycle By  Team Orange (Dept. of Pharmacy)
Software Development Life Cycle By Team Orange (Dept. of Pharmacy)
 
Decoding Kotlin - Your guide to solving the mysterious in Kotlin.pptx
Decoding Kotlin - Your guide to solving the mysterious in Kotlin.pptxDecoding Kotlin - Your guide to solving the mysterious in Kotlin.pptx
Decoding Kotlin - Your guide to solving the mysterious in Kotlin.pptx
 
Model Call Girl in Narela Delhi reach out to us at 🔝8264348440🔝
Model Call Girl in Narela Delhi reach out to us at 🔝8264348440🔝Model Call Girl in Narela Delhi reach out to us at 🔝8264348440🔝
Model Call Girl in Narela Delhi reach out to us at 🔝8264348440🔝
 
(ANVI) Koregaon Park Call Girls Just Call 7001035870 [ Cash on Delivery ] Pun...
(ANVI) Koregaon Park Call Girls Just Call 7001035870 [ Cash on Delivery ] Pun...(ANVI) Koregaon Park Call Girls Just Call 7001035870 [ Cash on Delivery ] Pun...
(ANVI) Koregaon Park Call Girls Just Call 7001035870 [ Cash on Delivery ] Pun...
 
Roadmap to Membership of RICS - Pathways and Routes
Roadmap to Membership of RICS - Pathways and RoutesRoadmap to Membership of RICS - Pathways and Routes
Roadmap to Membership of RICS - Pathways and Routes
 
Booking open Available Pune Call Girls Koregaon Park 6297143586 Call Hot Ind...
Booking open Available Pune Call Girls Koregaon Park  6297143586 Call Hot Ind...Booking open Available Pune Call Girls Koregaon Park  6297143586 Call Hot Ind...
Booking open Available Pune Call Girls Koregaon Park 6297143586 Call Hot Ind...
 
VIP Call Girls Service Hitech City Hyderabad Call +91-8250192130
VIP Call Girls Service Hitech City Hyderabad Call +91-8250192130VIP Call Girls Service Hitech City Hyderabad Call +91-8250192130
VIP Call Girls Service Hitech City Hyderabad Call +91-8250192130
 
HARDNESS, FRACTURE TOUGHNESS AND STRENGTH OF CERAMICS
HARDNESS, FRACTURE TOUGHNESS AND STRENGTH OF CERAMICSHARDNESS, FRACTURE TOUGHNESS AND STRENGTH OF CERAMICS
HARDNESS, FRACTURE TOUGHNESS AND STRENGTH OF CERAMICS
 
Call Girls in Nagpur Suman Call 7001035870 Meet With Nagpur Escorts
Call Girls in Nagpur Suman Call 7001035870 Meet With Nagpur EscortsCall Girls in Nagpur Suman Call 7001035870 Meet With Nagpur Escorts
Call Girls in Nagpur Suman Call 7001035870 Meet With Nagpur Escorts
 
SPICE PARK APR2024 ( 6,793 SPICE Models )
SPICE PARK APR2024 ( 6,793 SPICE Models )SPICE PARK APR2024 ( 6,793 SPICE Models )
SPICE PARK APR2024 ( 6,793 SPICE Models )
 
High Profile Call Girls Nagpur Isha Call 7001035870 Meet With Nagpur Escorts
High Profile Call Girls Nagpur Isha Call 7001035870 Meet With Nagpur EscortsHigh Profile Call Girls Nagpur Isha Call 7001035870 Meet With Nagpur Escorts
High Profile Call Girls Nagpur Isha Call 7001035870 Meet With Nagpur Escorts
 
Structural Analysis and Design of Foundations: A Comprehensive Handbook for S...
Structural Analysis and Design of Foundations: A Comprehensive Handbook for S...Structural Analysis and Design of Foundations: A Comprehensive Handbook for S...
Structural Analysis and Design of Foundations: A Comprehensive Handbook for S...
 
APPLICATIONS-AC/DC DRIVES-OPERATING CHARACTERISTICS
APPLICATIONS-AC/DC DRIVES-OPERATING CHARACTERISTICSAPPLICATIONS-AC/DC DRIVES-OPERATING CHARACTERISTICS
APPLICATIONS-AC/DC DRIVES-OPERATING CHARACTERISTICS
 
(TARA) Talegaon Dabhade Call Girls Just Call 7001035870 [ Cash on Delivery ] ...
(TARA) Talegaon Dabhade Call Girls Just Call 7001035870 [ Cash on Delivery ] ...(TARA) Talegaon Dabhade Call Girls Just Call 7001035870 [ Cash on Delivery ] ...
(TARA) Talegaon Dabhade Call Girls Just Call 7001035870 [ Cash on Delivery ] ...
 

Project risk analysis

  • 1.
  • 2.
  • 3.
  • 4. Project risk analysis has a broad range of applications, just as the definition of a project is broad. Project risk analysis is concerned with the assessment of the risks and uncertainties that threaten a project.
  • 5. What is Project? A temporary endeavor undertaken to create a unique product of service. In the broadest sense a project is specific, finite task to accomplished; whether large or small scale; long or short run. What is Risk? The probability that a particular threat will exploit a particular vulnerability.
  • 6. Risk analysis is the review of the risks associated with a particular event or action. It is applied to projects, information technology, security issues and any action where risks may be analyzed on a quantitative and qualitative basis. Risk analysis is a component of risk management. 6
  • 8. Risk Analysis 1. Calculate the (quantitative) likelihood of each identified hazard 2. Calculate the (quantitative) consequences that are expected to occur for each hazard 3. Develop a locally-tailored qualitative system of measurement 4. Translate all quantitative data into qualitative measures 8
  • 9. Who should be Involved? Security Experts Internal domain experts Managers responsible for implementing controls Slide #9
  • 11. Identify Assets Physical Assets Buildings, computers Logical Assets Intellectual property, reputation Slide #11
  • 12. Critical Assets People and skills Goodwill Hardware/Software Documentation Physical plant Money Slide #12
  • 13. Threats An expression of intention to inflict evil injury or damage Attacks against key security services Confidentiality, integrity, availability Slide #13
  • 14. Vulnerabilities Flaw or weakness in system that can be exploited to violate system integrity. Security Procedures Design Implementation Threats trigger vulnerabilities Accidental Malicious Slide #14
  • 15. Controls/Countermeasures Mechanisms or procedures for mitigating vulnerabilities Prevent Detect Recover Understand cost and coverage of control Controls follow vulnerability and threat analysis Slide #15
  • 16. Risk/Control Trade Offs Only Safe Asset is a Dead Asset Asset that is completely locked away is safe, but useless Trade-off between safety and availablity Do not waste effort on efforts with low loss value Don’t spend resources to protect garbage Control only has to be good enough, not absolute Make it tough enough to discourage enemy Slide #16
  • 17. Types of Risk Analysis Quantitative Assigns real numbers to costs of safeguards and damage Annual loss exposure (ALE) Probability of event occurring Can be unreliable/inaccurate Qualitative Judges an organization’s risk to threats Based on judgment, intuition, and experience Ranks the seriousness of the threats for the sensitivity of the asserts Subjective, lacks hard numbers to justify return on investment Slide #17
  • 18. Quantitative vs. Qualitative Quantitative Analysis Uses mathematical/ statistical data to derive numerical descriptions of risk More precise analysis More difficult to perform Qualitative Uses defined terms (words) to describe and categorize risk Less precise analysis Easier to perform Session 18
  • 20. Direct Losses Fatalities Injuries Repair and replacement of damaged or destroyed public and private structures Relocation costs/temporary housing Loss of business inventory/agriculture Loss of income/rental costs Community response costs Cleanup costs 20
  • 21. Indirect Losses Loss of income Input/output losses of businesses Reductions in business /personal spending – “ripple effects” Loss of institutional knowledge Mental illness Bereavement
  • 22. Tangible Losses Cost of building repair/replacement Response costs Loss of inventory Loss of income 22
  • 23. Intangible Losses Cultural losses Stress Mental illness Sentimental Value Environmental Losses Fatalities/Injuries 23
  • 24. Quantitative Analysis Outline 1. Identify and value assets 2. Determine vulnerabilities and impact 3. Estimate likelihood of exploitation 4. Compute Annual Loss Exposure 5. Survey applicable controls and their costs 6. Project annual savings from control
  • 25. Quantitative Risk = Risk-impact x Risk-Probability Loss of car: risk-impact is cost to replace car, e.g. $10,000 Probability of car loss: 0.10 Risk = 10,000 x 0.10 = 1,000 General measured per year Annual Loss Exposure (ALE) Slide #25
  • 26. Qualitative Risk Analysis Generally used in Information Security Hard to make meaningful valuations and meaningful probabilities Relative ordering is faster and more important Many approaches to performing qualitative risk analysis Same basic steps as quantitative analysis Still identifying asserts, threats, vulnerabilities, and controls Just evaluating importance differently Slide #26
  • 27. Problem Identify Step 1: Identify Scope Bound the problem Step 2: Assemble team Include subject matter experts, management in charge of implementing, users Step 3: Identify Threats Pick from lists of known threats Brainstorm new threats Mixing threats and vulnerabilities here... Slide #27
  • 28. Threat prioritization Prioritize threats for each assert Likelihood of occurrence Define a fixed threat rating Associate a rating with each threat Approximation to the risk probability in quantitative approach Slide #28
  • 29. Loss Impact With each threat determine loss impact Define a fixed ranking Used to prioritize damage to asset from threat Slide #29
  • 30. Changes in Human Activities Population Growth Economic Growth Technological Innovation Social Expectations Growing Interdependence 30
  • 31. In project risk analysis can understand that project may be risk or not. what ever the risk it may be high or low the investor take decision. 31