Monday, April 4

BSBRSK501 - Assessment 1

ASSESSMENT 1- WRITTEN ANSWERS

1.      

a.

Risk

The term risk is defined as the effect of uncertainty of objectives.

Effect

An effect is said to be the deviation that is occurred from the expectation. The effect can be positive, negative or even both positive and negative. The effect will be addressing, creation or resulting in threats or opportunities.

 

b.

The purpose of the standard in risk management is that to create and protect the value. This will be used to guide the organizations in integrating the risk management into the various important activities as well as the functions in it.

 

c.

The following are the various key elements or the topics that are covered in the ISO 31000:2018.

·        In the framework, the leadership and commitment, integration, design, implementation, evaluation and improvement of the framework has been discussed.

·        In the process, general, communication and consultation, scope, context and criteria, risk assessment, risk treatment, monitoring and review and recording and reporting.

·        Thus, the standard will be discussing all the risk identification to reporting process that will be helpful in easily managing the risks involved in the project.

 

 

 

 

2.

While dealing with the organization, the legislation and the regulatory context should be clearly understood. Here, the legislative context of an organization that is dealing with the risk management is about the legal laws that should be imposed for the organization. The puspose of the legal laws is that to avoid the issues and the conflicts that will be arised in society and other communities. In terms of risk management, the legal laws will be highly beneficial in order to avoid the issues and risks in organization. The legislative laws are enforced and implemented by the government agencies. Here, the risks could be avoided by adapting the laws that are imposed by the government. The examples of the legislative context in terms of risks in organization are privacy act, security act, workfoce act, health and safety act, and environmental protection act.

 

The regulatory context here will be referring to the rules that are used for governing to avoid the risks in the organization. To follow the legislative laws is also a regulation. The responsibilities that are to be hold by the employees of an organization in order to avoid the risks that may arise in the organization. The challenges in the risk identification, monitoring and assessment can be easily made with the help of regulatory compliances of risk management. The need of this regulatory compliances is to regulate the rules and instructions.  Thus, the regulatory compliances will be the rules and the regulations of the organizations to be followed to avoid the risks. Some of the regulatory compliances in terms of risk management are Tax payment act, protection of intellectual property, governing to employment laws, attaining the government licenses and occupational and heath requirements.

 

3.

The organizational policies for setting up the risk management are the written rules that will be imposed in order to reduce the risks that may arise while performing their jobs. The different types of organizational policies are equal opportunity policy, ethical policy, security and privacy policy, health and safety policy, attendance policy, functional policies, etc. Thus, each of these policies will be made up of several rules that will govern and guide the employees in a proper manner.

 

 

Procedures in security and privacy policies:

·        The employees must be adhering to all the internal security policies of the organization.

·        All employees must be using authentication to the system and should not share with the colleagues.

·        The data security policies and guidelines should be understood and followed in the organization.

·        The incident response and recovery should be able to be understood and perform in situations.

·         The remote access policy with high security and privacy is encouraged.

No comments:

Post a Comment

ITC506 - Topics in Information Technology Ethics - Assessment item 3

  Table of Contents Task 1: Argument Visualization . 3 Task 2 . 3 Introduction . 3 Utilitarianism Theory . 4 Deontology...