Your consulting organization has been hired to develop computer systems for the United Nations in the Middle East.

Create?a Risk Information Sheet for at least five potential risks that should be considered.? At least three of the risks you choose should be business continuity and IT disaster recovery related.? As part of this, consider man-made and natural risks that might apply to this particular situation.?

• The risk description should fully describe the risk
• The probability is the likelihood that the risk will occur (i.e., low, medium, or high)
• The impact is how the organization will be effected if the risk does occur (i.e., low, medium, or high)
• The rationale should explain the reasons for your probability and impact assessments
• The mitigation strategy should explain how each risk will be addressed
• There should be one risk information sheet for each risk identified
• The risk information sheets can be completed in Word, Excel?, or PowerPoint?

The results of your assessment for each risk should be plotted in a Risk Matrix.? One axis should be probability, while the other axis should be impact. The overall risk level will be the intersection of these two factors on the matrix. The risk assessment matrix can be completed in your choice of Word, Excel?, or PowerPoint?.

I have attached what I have so far.

1

United Nations Risk Assessment

CMGT/442 Information Systems Risk Management

May 21, 2016

David Conway

2

RISK INFORMATION SHEET #1

Risk Description: Human factor: Accidental deletion and corruption of files

Probability:

Impact:

Rationale:

Risk Mitigation:

RISK INFORMATION SHEET #2

highly sensitive information

Probability:

Impact:

Rationale:

Risk Mitigation:

RISK INFORMATION SHEET #3

Risk Description: Earthquakes: Major loss of data due to damage/loss of equipment

Probability:

Impact:

Rationale:

Risk Mitigation:

RISK INFORMATION SHEET #4

Risk Description: Fire/smoke/water: Physical loss of assets due to fire, smoke and water

damage

Probability:

Impact:

Rationale:

Risk Mitigation:

RISK INFORMATION SHEET #5

Risk Description:

Probability:

Impact:

Rationale:

Risk Mitigation:

3

I'm sure there are a ton of risks, but I came up with a few off the top of my head.

Natural

Fire - Loss of data. A good continuity of operation plan should be in place

Earth Quake - Loss of data. A good continuity of operation plan should be in

place

Terrorism - Sensitive information is leaked to the enemy, which becomes a

national security issue

Human factor - file/data deletion or corruption of sensitive information

I think any risk cannot be managed without identifying what the risk is and assessing the

severity and likelihood of it occurring. The information gathered during risk identification

and evaluation will identify the specific strategy or strategies to manage the risk.

