80 likes | 243 Views
Managing Risk – IT Project Framework Adapted from “The Evolution of Security” ACM Queue, April 2007. Total Costs. Avoidance Costs. 2. 1. Costs. 4. 3. Failure Costs. Assurance Level. Intolerable. Total Costs. 1. 2. Avoidance Costs. Costs. 4. 3. Failure Costs. Assurance Level.
E N D
Managing Risk – IT Project Framework Adapted from “The Evolution of Security” ACM Queue, April 2007 Total Costs Avoidance Costs 2 1 Costs 4 3 Failure Costs Assurance Level
Intolerable Total Costs 1 2 Avoidance Costs Costs 4 3 Failure Costs Assurance Level 1. Capitalize Costs Very Challenging to Deal With Invest Over Time High Exposure / Failure Costs High Costs to Assure
Tolerable Total Costs Avoidance Costs 2 1 Costs 4 3 Failure Costs Assurance Level 2. Bear the Risk Do Little (nothing) / Set Expectations Not Worth It Low Exposure / Failure Costs High Costs to Assure
Tolerable Total Costs 2 1 Costs Avoidance Costs 4 3 Failure Costs Assurance Level 3. Low Priority Do Something When Time & Budget Permits Low Exposure / Failure Costs Low Costs to Assure
Intolerable Total Costs 2 1 Costs 4 3 Failure Costs Avoidance Costs Assurance Level 4. Mitigate ASAP Handle Soon High Exposure / Failure Costs Low Costs to Assure
Tolerable Intolerable Invest 2 1 High Over Time ?Quickly Costs 3 4 Low Quickly Assurance Level
IVK Tolerable Intolerable 2 Loan Processing Customer Service Back Office / TPS Network Consolidation Project New / Competitive Systems Partner Integration Web Based Client Systems 1 PDA e-mail Training High Costs 3 4 HR System Low Internal Web Facilities Maintenance Assurance Level
Wholesale Distributor Tolerable Intolerable 2 Order Processing Warehouse Management Back Office / TPS 1 Training High Costs 3 4 Purchasing Supplier Management Low Internal Web Facilities Maintenance Assurance Level