Unit 6 University of Sunderland COMM80 Risk Assessment of Systems Change Risk Assessment: the Generic Concept COMM80: Risk Assessment of Systems Change.

Slides:



Advertisements
Similar presentations
Determining the Significant Aspects
Advertisements

Control and Accounting Information Systems
Note: See the text itself for full citations. Information Technology Project Management, Seventh Edition.
OPSM 639, C. Akkan1 Defining Risk Risk is –the undesirable events, their chances of occurring and their consequences. Some risk can be identified before.
Project Management Gaafar 2007 / 1 This Presentation is uses information from PMBOK Guide 2000 Project Management Risk Management* Dr. Lotfi Gaafar.
Managing Risk: Turning the Titanic Into the Love Boat Kevin Lyday, CISSP, PMP, CIPP/G, CEA, etc. Associate Director, Information Resources, Office of Public.
Risk Analysis & Management. Phases Initial Risk Assessment Risk Analysis Risk Management and Mitigation.
Introduction to the State-Level Mitigation 20/20 TM Software for Management of State-Level Hazard Mitigation Planning and Programming A software program.
University of Sunderland COMM80 Risk Assessment of Systems ChangeUnit 11 Risk Mitigation and Contingency Planning COMM80: Risk Assessment of Systems Change.
Project Risk Management
1 These courseware materials are to be used in conjunction with Software Engineering: A Practitioner’s Approach, 5/e and are provided with permission by.
1 Chapter 6 Risk Management. 2 Project Risks What can go wrong? What is the likelihood? What will the damage be? What can we do about it?
SQM - 1DCS - ANULECTURE Software Quality Management Software Quality Management Processes V & V of Critical Software & Systems Ian Hirst.
B RITISH B ANKERS' A SSOCIATION Operational Risk & the Regulatory Environment Simon Hills Director - Prudential Capital team.
Project Risk Management. Learning Objectives  Understand what risk is and the importance of good project risk management.  Identify project risks, describe.
Monte Carlo Schedule Analysis The Concept, Benefits and Limitations Intaver Institute Inc. 303, 6707, Elbow Drive S.W, Calgary, AB, Canada Tel: +1(403)
Risk Management & Liability Informa Brownfield Hospital Development Summit June 2009.
1 These courseware materials are to be used in conjunction with Software Engineering: A Practitioner’s Approach, 5/e and are provided with permission by.
Chapter 11: Project Risk Management
Risk management in Software Engineering T erm Paper By By Praveenkumar Sammita Praveenkumar Sammita CSC532 CSC532.
Mark Piekarz, Ian Jenkins and Peter Mills
Risk Management A Key Project Management Knowledge Area.
HIT241 - RISK MANAGEMENT Introduction
BSBPMG407A Apply Risk Management Techniques 1 Apply Risk Management Techniques Project Risk Processes Part 2 C ertificate IV in Project Management
BSBPMG508A Manage Project Risk 11.4 Perform Quantitative Risk Analysis Adapted from PMBOK 4 th Edition InitiationPlanning ExecutionClose Monitor Control.
Software Project Management Lecture # 8. Outline Earned Value Analysis (Chapter 24) Topics from Chapter 25.
VTT-STUK assessment method for safety evaluation of safety-critical computer based systems - application in BE-SECBS project.
University of Sunderland COMM80 Risk Assessment of Systems ChangeUnit 13 Overview of Riskit*: The Method and its Techniques * Further information available.
IOPS Toolkit for Risk-based Supervision Module 4: Risk Mitigation and Scoring.
Managing Risks in Projects. Risk Concepts The Likelihood that some Problematical Event will Occur The Likelihood that some Problematical Event will Occur.
Centro de Estudos e Sistemas Avançados do Recife PMBOK - Chapter 11 Project Risk Management.
Unit 1 University of Sunderland COMM80 Risk Assessment of Systems Change Risk Aspects and Context Covered in the Module COMM80: Risk Assessment of Systems.
Hartley, Project Management: Integrating Strategy, Operations and Change, 3e Tilde Publishing Chapter 10 Risk Management Proactively managing the positive.
1 Project Risk Management Project Risk Management Dr. Said Abu Jalala.
Management & Development of Complex Projects Course Code MS Project Management Perform Qualitative Risk Analysis Lecture # 25.
AMERICA’S ARMY: THE STRENGTH OF THE NATION Mort Anvari 1 Cost Risk and Uncertainty Analysis MORS Special Meeting | September.
Risk Management Production Process. Lecture content Recap on last week What is risk management? Quantitative risk evaluation – Decision trees Expected.
Lecture 7 Risk Analysis CSCI – 3350 Software Engineering II Fall 2014 Bill Pine.
Risk management (lecture). D efinitions of risk General: standard deviation Finance: volatility of return and costs Risk in project management (Lockyer.
Lecture # 17 PRM 702 Project Risk Management Ghazala Amin
Chapter(3) Qualitative Risk Analysis. Risk Model.
Question Four: Project Risk Management PMBOK definition of Project Risk Project risk management is the art and science of identifying, analyzing, and responding.
Integrated Change Control 1 MEC-8. Processing of a Change Processing of a Change 2 Assess Impact within KA Change Request Implemented Change Create a.
Recall The Team Skills 1. Analyzing the Problem (with 5 steps) 2. Understanding User and Stakeholder Needs 3. Defining the System A Use Case Primer Organizing.
Information Technology Project Management Managing IT Project Risk.
University of Sunderland CIFM02 Unit 5 COMM02 Project Hazard Management and Contingency Planning Unit 5.
1 Project Management C53PM Session 4 Russell Taylor Staff Work-base – 1 st Floor
University of Sunderland COMM80 Risk Assessment of Systems ChangeUnit 10 Decision Points COMM80: Risk Assessment of Systems Change Unit 10.
Risk Managament in Software Engineering Abdul Serwadda.
1 These courseware materials are to be used in conjunction with Software Engineering: A Practitioner’s Approach, 5/e and are provided with permission by.
ON “SOFTWARE ENGINEERING” SUBJECT TOPIC “RISK ANALYSIS AND MANAGEMENT” MASTER OF COMPUTER APPLICATION (5th Semester) Presented by: ANOOP GANGWAR SRMSCET,
Risk Assessment: A Practical Guide to Assessing Operational Risk
Managing Project Risk – A simplified approach Presented by : Damian Leonard.
 Define and recognize risk  Define the contents of a risk management plan  Conduct a risk identification and prioritization process  Define.
11.1 Plan Risk Management The process of defining how to conduct risk management activities for a project Detailed risk planning enhances the overall probability.
11.3 Perform Qualitative Risk Analysis
Recognization and management of RISK in educational projects
RiskyProject Enterprise Project Portfolio Risk Management Software
Monte Carlo Schedule Analysis
MANAGING DATA RESOURCES
Software Project Management (SPM)
Assessing Risk Impact Factors affecting the consequences Nature Scope
Probable Impact on Corporation Probability of Occurrence
Construction Projects
Knowing When to Stop: An Examination of Methods to Minimize the False Negative Risk of Automated Abort Triggers RAM XI Training Summit October 2018 Patrick.
Chapter 6 Risk Management
Chapter#8:Project Risk Management Planning
Chapter#8:Project Risk Management Planning
A New Concept for Laboratory Quality Management Systems
State University of Telecommunications
Presentation transcript:

Unit 6 University of Sunderland COMM80 Risk Assessment of Systems Change Risk Assessment: the Generic Concept COMM80: Risk Assessment of Systems Change Unit 6

University of Sunderland COMM80 Risk Assessment of Systems Change Objectives of Session Coverage To understand the importance of risk assessment. To consider some generic techniques: e.g. prioritisation, ranking. To introduce two specific techniques (not dealt within in detail here) To consider the use of software support tools.

Unit 6 University of Sunderland COMM80 Risk Assessment of Systems Change Why Assess Risks? How Assess Risks? Why? Because can’t monitor all risks in a project –so need to monitor and control the most significant ones. How? –Quantify: assign a value to each risk –Prioritise: use the risk value to assign a priority typically high, medium, low (or some numerical scale within a project). –Rank: compare risks within a project against their risk value to determine their relative importance.

Unit 6 University of Sunderland COMM80 Risk Assessment of Systems Change Risk Quantification Risk = (probability of occurrence) x (impact). Need to measure or estimate probability and impact. –These are not absolute values but judgements made by decision makers. Probability is defined on a scale 0 to 1 (impossible to certain) or 0% to 100% Impact is defined on a (user defined) scale –e.g.:scale 0 to 10: no impact (0) to catastrophic (10)

Unit 6 University of Sunderland COMM80 Risk Assessment of Systems Change Generic techniques There are many techniques for risk assessment. Generic/standard techniques include –Prioritisation and Ranking, –Analytical Hierarchy Process, –Decision Trees, –Bayesian Belief Networks.

Unit 6 University of Sunderland COMM80 Risk Assessment of Systems Change Quantifying/ Ranking/Prioritising This basic approach will be illustrated using the Risk Radar TM software to provide examples. Risk Radar TM (V2.02) is a free software product. Developed by Integrated Computer Engineering, Inc (ICE) under a DoD contract –Available from: and (Software Program Managers Network (SPMN)).

Unit 6 University of Sunderland COMM80 Risk Assessment of Systems Change Risk Radar TM Provides standard database functions to add and delete risks, specialised functions for prioritising and retiring project risks. –Including prioritisation of risks through automatic sorting and risk-specific movement. the option of a user-defined risk management plan and a log of historical events for each risk.

Unit 6 University of Sunderland COMM80 Risk Assessment of Systems Change Risk Radar - Initial form

Unit 6 University of Sunderland COMM80 Risk Assessment of Systems Change Set Up Project

Unit 6 University of Sunderland COMM80 Risk Assessment of Systems Change Risk Documentation

Unit 6 University of Sunderland COMM80 Risk Assessment of Systems Change Information About Individual Risks For each risk recorded additional information is held - such as the area of the project it affects, where control resides, etc.

Unit 6 University of Sunderland COMM80 Risk Assessment of Systems ChangePrioritisation Subjective estimates are made: –based on professional judgement of the probability that a risk will occur and its negative impact on the project if it does. risk exposure = probability * impact value.

Unit 6 University of Sunderland COMM80 Risk Assessment of Systems ChangePrioritisation Risk impact could be broken down and quantified into all kinds of impacts areas, such as: the schedule impact in terms of days or cost impact in financial terms, –in reality, it is not possible to quantify these impacts with any degree of accuracy. –Adding multiple impact areas adds complexity to the risk management process for little quantitative benefit. –The impact rating system only suggests the total impact the risk could have on a specific project.

Unit 6 University of Sunderland COMM80 Risk Assessment of Systems ChangePrioritisation Risk Radar TM does not assign any meaning to an impact value. –The project team must define the meanings and keep to them. These numbers are, usually based on past professional experience. –The software uses risk exposure as a means to rank risks relative to one another within a project. –It is inappropriate to compare risks across projects solely based on numerical factors such as probability, impact, or exposure.

Unit 6 University of Sunderland COMM80 Risk Assessment of Systems Change Prioritising Risks in Risk Radar The upper figure shows risks ranked according to exposure rate. However, if a risk manager felt that “Poor Interface Design” should have a higher ranking than “Poor Data Quality” they could be re-arranged them manually as shown below.

Unit 6 University of Sunderland COMM80 Risk Assessment of Systems Change View Risk Impact

Unit 6 University of Sunderland COMM80 Risk Assessment of Systems Change View Risk Impact When this cell is clicked the next window is shown.

Unit 6 University of Sunderland COMM80 Risk Assessment of Systems Change Change in risks profile over time April to July