I was putting together a short version of my BBA and MBA-targeted presentation Risk Management - an introduction and I started thinking about risks - a/k/a threats - that a risk management practitioner would identify, but that a business continuity practitioner probably would consider "out of scope."
There are only 76, but the list hardly is "all-inclusive." An " * " by an entry indicates a risk I would expect a business continuity practitioner to identify.
- Acquisitions
Alternate site - short term
Alternate site - long term
Auditors
B&D insurance
Business interruption insurance *
Changes (personnel, processes, product, etc.)
Chemicals - for processes, cleaning
Civic events
Clients/Customers
Competition
Compliance - all areas (HR, product, supplies)
Construction
Copyright, trademark issues
Discrimination in workplace
Disabled and the ADA
Documentation (government-required, processes, product, etc.)
Employee travel
Employee welfare *
Ethics
Evacuation/Sheltering policies
Family issues (domestic violence, illnesses, death, etc.)
Financial vendors
Fire *
Flood *
Government - Federal
Government - Local
Government - State/Provincial
Harassment of/by employees
HazMat on site *
HazMat off-site
Hiring practices
Hurricanes *
Injuries (staff, visitors)
Image (corporate, executives)
Industrial espionage
In-place sheltering site and policies (safety, food, legal issues)
Internal communications *
IT failure *
Legal
Loss of facility other than fire, flood (plane, satellite crash)
Management
Marketing (false claims, etc.)
Media response *
Neighbors
Planning and Zoning *
Policies & procedures
Politics
Public relations *
Regulators
Relocation - to/from alternate site
Remote recovery conditions
Secondary strikes
Security - data *
Security - facility (inside and outside)
Security - intellectual property
Social media
Special interests (e.g., ADA)
Stock and bond markets
Succession
Supplemental staffing (vetting)
Telecommunications failure *
Terrorism
Tornados *
Training - incorrect, incomplete
Transportation *
Utilities *
Vendors *
Vendors - post-event
Vendors' vendors
Web site
Work actions *
Work actions - government agencies (fire, police, Customs)
Work actions - secondary (vendors, transportation, etc.)
UBIQUITOUS "OTHER"
There always is a ubiquitous "other" that can be discovered during all-hands "What If" sessions. As this is written, Chicken Little's worst fears are coming to fruition - the sky is falling, or at least parts of a man-made satellite are bearing down the third planet from the sun. It can't be a "black swan" - or even a grey one - since you and I know about it.
PowerPoint short and long Risk Management presentations available to BBA and MBA programs.
If I wrote it, you may quote it.
No comments:
Post a Comment