Page 93 - CISSO_Prep_ Guide
P. 93
that it is not on a slow news day where you are the only story in
town!
Hybrid Risk Assessment
Neither the Quantitative nor Qualitative risk assessment
approach is perfect or ideal. Therefore, the two are used together
in a hybrid model to gain a better appreciation for the risk
assessment from both a monetary and non-monetary
perspective.
Other approaches that may be used include models such as the
Failure Modes and Effects (FMEA) model and the Fault Tree
Analysis (FTA) model.
Risk Assessment Report
The results of the risk assessment - whether done through a
quantitative or qualitative approach, or both, should be compiled
into a risk assessment report (RAR). This report will outline to
management what the risk is, the severity of the risk and
priorities for risk response, and recommendations on how to
deal with the risk in an effective manner. This report is provided
to management to inform them of the risk and allow them to
initiate the response process.
Risk Response
The final step of the risk assessment phase was the creation of a
risk assessment report (RAR), which is the input to the next
phase in risk management - the risk response phase. In this
phase, management will make decisions on how to address the