Penilaian risiko I&T bertujuan agar dapat melihat risiko-risiko yang secara signifikan mempengaruhi pencapaian tujuan organisasi. Berdasarkan COBIT 5 for Risk terdapat beberapa hal yang diperhatikan untuk melakukan penilaian risiko seperti tipe risiko, kategori risiko serta faktor risiko, yang digunakan sebagai informasi awal untuk membangun skenario risiko dan kontrol risikonya.
- Tipe Risiko
- IT benefit / value enablement risk
Risiko berkaitan dengan manfaat atau nilai risiko TI terhadap peningkatan efisiensi dan efektivitas pencapaian tujuan organisasi - IT programme and project delivery risk
Risiko berkaitan program dan proyek risiko TI yang memberikan kontribusinya sebagai solusi bisnis - IT operations and service delivery risk
Risiko terkait dengan stabilitas operasional, ketersediaan, perlindungan dan pemulihan layanan
- IT benefit / value enablement risk
- Kategori Risiko
- Portfolio establishment and maintenance
- Programme/ projects life cycle management (programme/ project initiation, economics, delivery, quality and termination)
- IT investment decision making
- IT expertise and skills
- Staff operations (human error and malicious intent)
- Information (data breach: damage, leakage and access)
- Architectural (vision and design)
- Infrastructure (hardware, operating system and controlling technology) (selection/ implementation, operations and decommissioning)
- Software
- Business ownership of IT
- Supplier selection/performance, contractual compliance, termination of service and transfer
- Regulatory compliance
- Geopolitical
- Infrastructure theft or destruction
- Malware
- Logical attacks
- Industrial action
- Environmental
- Acts of Nature
- Innovation
- Portfolio establishment and maintenance
- Faktor Risiko
- Faktor Kontekstual
- Internal
- Enterprise goals and objectives
- Strategic importance of IT in the enterprise
- Complexity of IT
- Complexity of the enterprise
- Degree of change
- Change management capability
- The risk management philosophy
- Operating model
- Strategic priorities
- Culture of the enterprise
- Financial capacity
- External
- Market/economic factors
- Rate of change in the market in which the enterprise operates
- Competitive environment
- Geopolitical situation
- Regulatory environment
- Technology status and evolution
- Threat landscape
- Internal
- Faktor Kontekstual
Sumber: COBIT 5 for Risk
One Reply to “Pengelolaan Risiko Organisasi: Penilaian Risiko I&T berdasarkan COBIT (Bag.2)”